Office 365 user provisioning

Provisioning opens doors. Nobody ever closes them.

A new hire with five standard groups can reach 100,000 files on day one. Three years and four teams later the number has only grown - and in a typical tenant 10-30% of paid licenses sit on accounts that have not signed in for months. 1Security shows what every account can actually reach at each stage of its life, and stages the cleanup behind a review window.

  • 100,000+
    files an ordinary account can reach through its groups, links and site inheritance - resolved before the first sign-in
  • 10-30%
    of paid licenses in a typical tenant sit on accounts nobody has signed into for months
  • 72 h
    default review window before any staged offboarding or license reclaim executes

After the account exists

Accounts are created once. Access is added forever.

Provisioning tooling handles the first morning. Nobody owns the years after it.

Onboarding creates the account, assigns the license, adds the starter groups, opens the mailbox. From then on the identity only gains: a project site here, a shared library there, a sharing link that never expires. Team changes add access; they almost never remove it. Someone who has moved through four departments carries four departments of permissions.

A membership list tells you what was granted. What those memberships unlock is a different question, because nested groups, SharePoint site inheritance and sharing links sit between the directory and the answer. The number you never see is what one compromised credential would open - and it is common for an ordinary account to reach hundreds of thousands of files.

The leaver side is worse. The checklist disables the account, but the sharing links they created keep working, their OneDrive stays reachable, and the E3 stays assigned until someone notices the invoice. 1Security resolves all of it per account, keeps it current, and turns joining, moving, leaving and going quiet into checks that take minutes.

What you get

Every account, with what it can reach and whether it should still exist.

One row per identity on the Users screen: reach, sensitive exposure, activity, account state and risk - sortable, filterable, exportable.

  • groups · files · apps

    Reach per user

    The groups, files and apps one credential opens, with nesting and inheritance resolved. Sort "files reachable" descending and the top of the list is your review queue, most dangerous account first.

  • Sensitive exposure

    How many files with card numbers, IDs or health data each user can reach - and the sharing links they personally created, including the ones still working years after the project ended.

  • Account state at a glance

    Enabled, sign-in blocked, MFA registered, license assigned - side by side. Filter to "wide reach + no MFA method" and you have a five-minute check with board-level findings.

  • 90 days · 1 year

    Dormant accounts

    Sort last sign-in ascending and the accounts that should not exist rise to the top. Orphaned indicators flag users and guests with no activity for 90 days or a year, next to the licenses still billing on them.

  • SharePoint-only guests included

    SharePoint-only guests hold real access through links and site permissions without becoming Entra objects, so a directory-based review has nothing to list for them. 1Security lists them next to everyone else, with the same reach columns.

  • 72 h review

    Offboarding that runs itself

    Disable the account, revoke access by source, expire the links, reclaim the license - staged as proposals with a review window and owner sign-off, so offboarding finishes without surprise lockouts.

In practice

The offboarding audit, in four steps.

What closing an account looks like when the platform knows what the account could reach.

  1. 01

    Open the leaver in Users

    The drawer shows every group, site, file and app the account can still reach, resolved through nesting and inheritance - typically tens of thousands of files behind a dozen group names.

  2. 02

    Revoke access by source

    One composite action resolves how each grant exists - direct, sharing link, group, site membership - removes what it safely can, and shows the blast radius per source before you confirm the paths that would affect other people.

  3. 03

    Expire what they created

    The sharing links the user authored keep working after the user is gone. The drawer lists them - often dozens per long-tenured employee - and expires them in one staged action.

  4. 04

    Reclaim the license

    Remove the license in the same reviewed flow. Run the same pass over every account with no sign-in for 90 days and the number lands in your renewal math the same day.

The gap

What we add to the membership list.

The directory records what was granted. 1Security shows what it adds up to.

  • What a new hire's group memberships unlock, resolved before their first sign-in - the 100,000 files behind the group names
  • Which accounts gained access with every team change and never lost any
  • Which sharing links a specific user created, and which of them still work
  • Which SharePoint-only guests hold access - listed next to Entra guests and members
  • Which enabled accounts have not signed in for a year, and what licenses they still hold
  • Which users combine wide reach with no registered MFA method
  • What an offboarded account could still reach the day after IT closed the ticket

Deployment

Same-day start on standard licenses.

Connect with read-only consent and the lifecycle picture assembles itself from what already exists in your tenant - your dormant-accounts and leaver-reach lists appear the same day. Account and license actions are a separate, optional consent; visibility never depends on granting them.

  • Same day
    from read-only consent to your first dormant-account and offboarding findings
  • Business Basic
    everything here runs on standard licensing - no E5, no Entra P2, no agent to install
  • 0 writes
    until you consent to the write module - and even then every action is reversible in the Microsoft admin centers

Use cases

Joiners, movers, leavers - and the renewal.

The busywork gets automated; the receipts stay.

Joiners: before day one, open the planned groups in Groups and read what they resolve to. If the "standard starter set" quietly unlocks the finance archive through a nested group, you find out before the new hire does.

Movers: run the permission-creep review quarterly. Sort Users by files reachable, filter to people who changed teams, and revoke what the old role granted - by source, with blast radius shown before anything executes.

Leavers and the renewal: the offboarding audit closes every door the checklist misses, and license reclaim rides the same flow. In most tenants a ten-minute pass over accounts with no sign-in for 90 days finds enough paid seats to change the renewal conversation.

Keep exploring

Where the lifecycle story continues.

  • Access management

    The permission graph behind every reach number: who can open what, and through which group, link or site.

    See access management
  • Microsoft 365 inventory

    Users next to sites, apps, agents, devices and files - everything one credential can touch, in one live inventory.

    See the inventory tool
  • Office 365 reporting

    The lifecycle numbers exported, saved as views and quoted at the renewal.

    See the reporting tool

FAQ

Common questions.

Does 1Security provision accounts?

No. Provisioning stays in Entra ID and your HR-driven tooling. 1Security is the visibility and cleanup layer around it: what each account can reach at every stage, and the staged actions - disable, revoke, expire, reclaim - when access should end.

How does it handle nested groups?

Effective membership is resolved through every nesting level, in both directions: what a user really belongs to, and what landing in a group would really unlock. The directory shows the declared membership; 1Security shows where it leads.

Can offboarding be automated without lockout accidents?

Yes. Every automation stages per-resource proposals behind a review window - 72 hours by default, or a manual-approval mode that never auto-releases - and rejecting a proposal snoozes it. Actions are native Microsoft operations: disabling an account is accountEnabled = false in Entra, reversible in the admin center, with no shadow permission model.

What about guests and external identities?

Three identity classes sit side by side: members, Entra guests, and SharePoint-only guests - external identities that hold real access but never became directory objects, which is exactly why they accumulate. All three carry the same reach and activity columns.

What Microsoft licenses does this need?

Business Basic upward. The one hard requirement is a single user with a SharePoint Online license, checked at tenant level - no E5, no Entra P2, no add-ons.

See what your accounts can really reach.

Connect read-only and run your first offboarding audit today: reach measured, links listed, dormant accounts and their licenses counted - and the cleanup staged for review.

Or keep trusting that the offboarding checklist caught every link.