A former employee can leave the business on Friday and still have access to email, shared files, finance software or a key customer system on Monday. That is exactly why knowing how to audit user access is not just an IT housekeeping task. It is a practical control for protecting your data, maintaining business continuity and proving that people can access only what they need to do their jobs.
For many organisations, access has accumulated gradually. A team member changes role, receives extra permissions for a project, takes on temporary cover, or is added to a shared mailbox. Months later, the original reason has gone, but the access remains. A structured review brings order back without making day-to-day work harder.
What a user access audit should achieve
A user access audit compares who can access a system with who should access it. The goal is not to remove permissions indiscriminately. It is to ensure access reflects current roles, responsibilities and business requirements.
A good audit should identify inactive accounts, former staff, duplicate identities, unnecessary administrator rights, shared accounts and permissions that have no clear owner. It should also highlight where critical systems depend on one person, or where a group has broader access than its work requires.
This matters across more than Microsoft 365. Think about finance and payroll platforms, customer relationship management systems, file servers, cloud storage, remote access, Wi-Fi, line-of-business applications, backup consoles, building systems and managed print. A secure Microsoft 365 tenant is valuable, but it is only one part of the access picture.
The right depth depends on your organisation. A small office may be able to review every user and application directly. A multi-site business may need to prioritise high-risk systems first, then establish a repeatable process for the rest. Either way, the principle is the same: access should be intentional, approved and reviewed.
How to audit user access step by step
1. Set the scope before collecting data
Start by deciding which systems and user groups the audit will cover. If your business has never carried out a formal review, begin with systems containing sensitive data or capable of causing major disruption. Microsoft 365, email, shared files, finance, payroll, remote access and administrator accounts are sensible starting points.
Define the purpose as well. You may be responding to a cyber security concern, preparing for an insurance questionnaire, supporting an external compliance requirement, or simply tightening controls after growth or an office move. A clear purpose helps you avoid a lengthy exercise that produces a spreadsheet but no operational change.
Nominate a business owner for each system. IT can extract account and permission information, but managers are usually best placed to confirm whether their teams still need access. Finance should validate finance software users, for example, while department heads should confirm access to departmental folders and applications.
2. Build a reliable list of identities
Your audit needs a baseline. Export user lists from each in-scope platform and compare them with an up-to-date HR or payroll list. Record each person’s name, department, job role, employment status, manager, account type and last sign-in where available.
Do not overlook non-human accounts. Service accounts, shared mailboxes, generic logins, application integrations and external guest accounts often receive less scrutiny than named user accounts. They can be legitimate, but each should have a documented owner and a business reason for existing.
Pay particular attention to accounts that are disabled but not removed, accounts that have not signed in for a long period, and external users invited to shared resources. Inactive accounts do not automatically represent a problem. Someone may be on extended leave or a supplier account may be needed for support. The key is that exceptions are known, approved and time-bound.
3. Review privileges, not just account numbers
Counting accounts is useful, but the real risk often sits in permissions. A standard user with access to the wrong folder may expose confidential information. An administrator with unrestricted control of Microsoft 365, backup, networking or security tools can create a far greater issue if their account is compromised.
Review privileged roles separately. These include global administrators, domain administrators, billing administrators, application administrators, backup administrators and users with remote management rights. Keep the number of people holding these roles as low as practical, and avoid using highly privileged accounts for ordinary email and web browsing.
The principle of least privilege is helpful here: give each person the minimum access required to complete their work. It is not an instruction to make every task difficult. A senior manager may reasonably need broad visibility across reports, while a temporary staff member may need access only to a specific application for a limited period. Context matters.
4. Check group memberships and shared resources
Permissions are often granted through groups rather than directly to an individual. This is generally easier to manage, provided the groups are organised clearly. During the audit, review group names, owners, members and the resources each group can access.
Look for groups with vague names such as All Staff, Management or General Access. Broad groups are convenient, but they can become a source of excessive permissions if they are reused across unrelated systems. Where possible, use groups that describe a clear function, such as Accounts Payable, Project Team A or Dublin Site Managers.
Shared folders, SharePoint sites, Teams channels and shared mailboxes deserve particular attention. These are common places for historical access to linger after a project ends or a colleague moves departments. Confirm who owns each shared resource and whether external sharing remains necessary.
5. Verify access with managers and system owners
A technical report cannot tell you whether access is commercially appropriate. Send a concise review list to the relevant managers and ask for a simple decision: retain, amend or remove. Keep the process straightforward, with a clear deadline and an escalation route for unclear cases.
Avoid asking managers to interpret technical permission labels without support. Translate the impact into plain English. Rather than asking whether someone should remain in a particular security group, explain that the group gives access to payroll reports, confidential HR files or remote network administration.
For high-risk permissions, use a second approval where appropriate. This is especially useful for finance payments, payroll changes, customer data exports and administrator access. It creates a stronger record and reduces the chance of one person approving their own elevated access.
6. Remove, amend and document changes safely
Once approvals are complete, make changes in a controlled order. Remove access for leavers and inactive accounts first, then reduce unnecessary elevated rights, followed by outdated group memberships and project-based permissions.
Some changes can affect productivity if handled without care. Before removing access from a shared mailbox, file area or application, confirm that work has been handed over and that another authorised user can continue the process. For critical systems, schedule changes during a quieter period and retain a record of what changed in case a legitimate access requirement is discovered later.
Document the decision, approver, date and action taken. This creates an audit trail and makes future reviews far easier. It also gives your business useful evidence when responding to customer security questionnaires, insurers or compliance requests.
Make access reviews part of normal operations
A one-off clean-up is valuable, but access changes constantly. The strongest approach is to connect reviews with the employee lifecycle. New starters should receive role-based access through an approved request. Movers should have their permissions reviewed when their job changes. Leavers should trigger a prompt process to disable accounts, remove active sessions and transfer business data where required.
For most businesses, a quarterly review of privileged accounts and a broader six- or twelve-month review of key systems is a sensible starting point. Organisations handling particularly sensitive information, or those with frequent staff movement, may need more frequent checks. The right schedule depends on risk, system importance and the resources available to manage the process properly.
Multi-factor authentication should support this work, particularly for Microsoft 365, remote access and administrator accounts. It does not replace an access audit, but it reduces the risk that a stolen password alone can be used to access a valid account. Conditional access policies, device compliance and sign-in monitoring can add further protection where they suit the organisation’s environment.
Common gaps that weaken an access audit
The most common mistake is treating the audit as an IT-only exercise. IT may manage identities and permissions, but business leaders must confirm what access is genuinely required. Without that involvement, permissions can be left untouched because nobody is confident enough to make a decision.
Another gap is focusing only on current employees. Former employees, contractors, guests, shared accounts and third-party support access deserve equal attention. Supplier access can be necessary for maintenance and support, but it should be limited, monitored and reviewed when the contract or project changes.
Finally, do not confuse access reviews with backup or disaster recovery. They are connected, but they solve different problems. A backup may restore deleted data, while a user access audit helps prevent unauthorised people from viewing, changing or deleting it in the first place.
A well-run review should leave your business with fewer unknowns, clearer ownership and less avoidable cyber risk. If your internal team needs support turning scattered permissions into a repeatable process, LANCAST can help assess the environment, apply practical controls and keep access management aligned with the way your business actually works.
