Microsoft Teams user onboarding

Five teams on day one can open 100,000 files. Check before you add.

A new hire added to "Sales", "Projects" and "All Staff" reads as one ticket. In the tenant it is dozens of SharePoint sites, shared channels, mailboxes and years of files, granted through nesting no ticket describes. 1Security shows exactly what each team membership opens - before you add the person, on day one, and every time they move.

The problem

Onboarding hands out far more than anyone reviews.

Every team is a Microsoft 365 group, every group unlocks a SharePoint site, and every site carries years of files the new hire was never explicitly granted. Groups also sit inside other groups. A membership list shows the direct members; what adding someone to one team quietly grants - the four sites nested behind it - takes resolving the whole chain, and 1Security does that for every group. In a typical tenant, an ordinary account can reach hundreds of thousands of files through memberships nobody remembers assigning.

Then people move. A transfer adds new teams and nobody removes the old ones, so access grows with tenure. Five years in, one employee's account is worth several new hires' worth of access - and it is exactly that account a phishing attack lands on.

The fix is not slower onboarding. It is seeing what the standard memberships actually open, so the onboarding template gets right-sized once - and every later addition can be checked in seconds instead of trusted.

In practice

A new hire, checked in four steps.

What Teams onboarding looks like when a group membership shows what it really grants.

  1. 01

    Check the team before you add anyone

    Open Groups and click the team's group. The row shows direct members, total users with nesting resolved, external members, and the number of sites and files the group unlocks - 3 sites and 40,000 files is a normal answer for a department team. "If someone lands in this group, what do they get?" answered before the ticket is closed.

  2. 02

    Verify day one

    Open Users and find the new account. Its row shows files, sites, groups and apps in reach, and whether sensitive information is among them - the size of what one compromised credential would open. If a first-week account already reads like a manager's account, the template is wrong, not the hire.

  3. 03

    Catch the creep on every move

    Sort Users by files reachable and compare against role. Old memberships from previous teams surface as accounts whose reach outgrew their job - caught while the difference is one team, not four years of them. A trend policy on "files reachable per user" alerts when a single account jumps.

  4. 04

    Right-size behind a review window

    Where onboarding overshot, cleanup runs as staged proposals with a 72-hour review window. The team's owner can be asked to confirm before any membership or grant is withdrawn, and every executed change is logged in Actions.

What makes it work

Three parts of the platform behind the check.

Onboarding visibility rides on capabilities you can read about in depth.

  • User lifecycle

    Joiners, movers and leavers with reach, activity and account state on one row - from day one to offboarding.

    Explore the feature
  • Access management

    Effective access resolved through nested groups, inherited site permissions and sharing links - what every membership really opens.

    Explore the feature
  • Inventory

    Every team, group and site as a live inventory - including the duplicate and abandoned teams that old onboarding templates left behind.

    Explore the feature

FAQ

Common questions.

Does 1Security create accounts or assign licenses?

No. Provisioning stays in Entra and your existing tooling. 1Security shows what provisioning actually granted - the sites, files and mailboxes behind the memberships - and stages cleanup where it overshot, behind a review window. It is the verification step onboarding never had.

Can we see what a single team unlocks before adding people?

Yes. Every group shows its effective membership with nesting resolved, both directions of the nesting chain, and the count of files and sites it grants access to, with sensitive information flagged - so a team used as an onboarding template can be reviewed as what it really is: an access grant.

What about guests invited into teams?

Guests go through the same resolution - including SharePoint-only guests who never became directory objects, so a review that starts from the directory alone would not have a row for them. You see what each guest can reach and when they were last active, and idle ones surface through the same filters.

Do we need E5 or Entra P2?

No. Group resolution, reach and the user lifecycle views run on standard Microsoft 365 licensing, with no agent to install and read-only access to start.

Onboard with your eyes open.

Connect read-only and see what your onboarding templates actually open the same day - every team, resolved to the sites and files behind it.

Or keep finding out what day one granted at year five.