Microsoft 365 user access review
An ordinary account can open 200,000 files. Review the files, not just the 11 groups.
Most access reviews start from group membership. Auditors ask a different question: what can this person actually open, and should they still be able to? 1Security answers it for every identity in the tenant - employees, Entra guests and SharePoint-only guests included - with files, sites, mailboxes, last sign-in and MFA on one row, so a quarterly review takes an afternoon instead of a quarter.
- 3identity classes reviewed together: internal accounts, Entra guests and SharePoint-only guests that never became directory objects
- 100,000+files a single ordinary account can typically reach through groups, links and inheritance - the number a group list never shows
- 1 yearthe dormancy horizon: accounts with no sign-in for a year that still hold licenses, memberships and access
The problem
The review the auditor asks for is about files, not group lists.
Certifying who is in a group is where most reviews stop. Nobody asked who is in a group. They asked who can open the payroll folder.
Group membership is a proxy for access, and a poor one. It says nothing about the sharing links a person created, the sites they were granted directly, the mailboxes delegated to them, or what all of that adds up to in files. The distance between "member of 11 groups" and "can open 24,000 documents, 900 of them with personal data" is the entire point of a Microsoft 365 user access review - and it is the distance a directory-based review never covers.
Guests make it harder. Entra guests appear in the guest list. SharePoint-only guests arrived through a sharing link or a site permission and never became directory objects, so they are easy to miss - and they hold real, working access. 1Security lists both classes side by side. In a typical tenant the SharePoint-only guests outnumber the ones you know about.
Then there are the accounts nobody has signed into for a year, still licensed, still in groups, still reaching sensitive data. It is common to find 10-30% of paid licenses on such accounts. They are a cost line and an attack path at the same time. 1Security puts the two facts on one row.
What you get
One row per identity: what it can open, what it did, whether it should exist.
Sort by any column. Files reachable, descending, finds the accounts to review first; last sign-in, ascending, finds the ones to remove.
Effective access, resolved
Files, sites, groups, mailboxes and apps one account can open - direct grants, nested groups, sharing links and site inheritance all counted. The size of what a compromised credential would hand over.
Sensitive data in reach
Files with detected sensitive information or a sensitivity label within the account's reach, plus the sharing links this user created and who is still using them.
Activity beside access
Last activity, last sign-in, a 30-day activity trend, emails sent and received - so "can open 24,000 files" sits next to "opened 3 last month".
Account hygiene columns
Enabled or disabled, sign-in blocked, MFA registered, creation date, license assignment - the columns an auditor asks for, in the same row as the access.
Guests split into the classes that matter
Internal, Entra guest and SharePoint-only guest as separate filters. The third class is the easiest to miss and usually the longest list.
Alerts and anomalies on the identity
Defender alerts and 1Security anomaly episodes attached to the account, so the name in an alert opens with its full access and history already loaded.
How deep it goes
Four reviews that are one sort or two filters each.
Each of these is usually a scripting project with several exports. Here each is under a minute.
External exposure review: filter Users to external, then to "can reach sensitive information". This is the report most access reviews are supposed to produce and rarely can, because it needs directory data joined to file-level detections. The list is typically dozens of guests, some from projects that ended years ago.
Dormant with access: sort by last sign-in ascending, filter to licensed. In a mid-size tenant this returns hundreds of accounts. Crossed with group memberships and files reachable, the same list is a license reclaim and an attack-surface cut in one pass.
MFA gaps on privileged reach: filter to no MFA method registered, sort by files reachable. Not every account without MFA matters equally; this narrows the list to the twenty where it would matter most.
Incident scoping: start from the account named in a Defender alert and read its reach, activity, devices and sign-in locations without changing screens. Every user row links into the permission graph, so you see why the access exists, not just that it does.
In practice
The offboarding review, in the order that leaves nothing behind.
Removing the account is the last step, not the first - three of the four steps stop being possible once it is gone.
- 01
Read what the leaver can open
Open the user in Users. The reach panel lists every site, file and mailbox - including what came through nested groups and links rather than a direct grant. For a five-year employee that is typically tens of thousands of files.
- 02
Read what they touched in the last 90 days
Activity logs filtered to the account: downloads, shares, mailbox reads, sign-in locations and devices. This is where a routine offboarding occasionally turns into an investigation - a spike of 600 downloads in the last week is visible here, not in a group list.
- 03
Retire what they created
Sharing links created by this user outlive the account. They are listed on the row - typically dozens, some "anyone" links - and can be expired from the same place, behind the 72-hour review window.
- 04
Then revoke and reclaim
Run the offboarding automation: remove access, disable sign-in, reclaim the license. Every action lands in Actions with who approved it and when - the evidence the next audit will ask for.
What 1Security adds
A review organized by access, not just by account
A directory organizes identities by account. 1Security organizes the same identities by what they can open.
- Everything one named account can open, with nesting, links and inheritance resolved to a file count
- SharePoint-only guests included, even though they never became directory objects
- Sensitive information and labelled files within a single identity's reach
- The sharing links this person created, and who is still using them
- Dormant accounts with their licenses, memberships and reach on the same row
- MFA registration read beside reach, so the gaps that matter rank first
- Emails sent and received with last timestamps, next to file activity
- Defender alerts and anomaly episodes attached to the identity for instant scoping
Scale
Every identity, not a sample - on tenants with 40 million files.
A user access review is only credible if it covers the identities nobody registered: the guests from a project three years ago, the service accounts that predate the current admin team, the SharePoint-only guests no report lists. 1Security resolves effective access for every account from the permission graph, keeps it current, and holds up to three years of activity behind it.
- 500M+files in the largest production tenants the permission graph resolves per identity
- 3 yearsof activity history behind every account - go from 180 days of standard retention to three years
- 0write permissions needed to run the whole review - remediation is a separate opt-in module
Related
Where the review usually ends up
A user review ends somewhere else: in the group that granted most of the access, in the license that costs money, or in the automation that cleans it up. These are the next stops.
Group access analysis
The nesting chain that gave the identity most of its reach - and what one membership request actually unlocks.
See groups →License optimization
The 10-30% of paid seats sitting on accounts that stopped signing in.
See licenses →Remediation automation
Turning the review outcome into staged, reviewable actions with a 72-hour window.
See automations →
FAQ
Questions teams ask first
What is a SharePoint-only guest?
An external person who received access through a sharing link or a site permission without ever being invited into the directory. They hold real, working access and are easy to miss because they never became directory objects, which is why they accumulate quietly for years. In most tenants they are the largest class of guests.
Does "files reachable" include access inherited through groups and links?
Yes. Direct grants, group inheritance including nesting, sharing links, site inheritance and app access all count. Anything less would understate the answer, which is exactly the failure mode of a membership-based review.
Can I export the review as evidence?
Yes - CSV export from any filtered list, saved views so the same review reproduces next quarter, and a read-only REST API if the evidence needs to land in a GRC platform or SOC pipeline rather than a spreadsheet.
Do we need Entra ID P2 or E5 for this?
No. Effective access, guest classes, dormancy, MFA state and activity history run on standard Microsoft 365 licenses over a read-only connection. Nothing to install.
Can it revoke access, or only report?
It can act, under the opt-in write model used across the platform. Removing access, expiring the links a user created, disabling sign-in and reclaiming a license are automations that stage a proposal per resource behind a review window (72 hours by default) before anything is applied, and every action is logged.
Run the review the auditor actually asked for.
Connect read-only and every identity arrives with its files, sites, mailboxes, last sign-in and MFA state the same day. The guest list is usually longer than anyone expected.
Or certify group memberships again and hope that was the question.