Home » Latest news » Pick one person: how much of your Microsoft 365 can they open?
Just over four in ten UK businesses identified a cyber attack or breach in the last twelve months, and among those that did, phishing was the way in for 85% of them (DSIT, Cyber Security Breaches Survey 2025). Most of the advice that follows figures like those is about stopping the phish. This article is about the other half of the problem, which gets far less attention: once a password has gone, the damage is set by what that account could already reach.
An attacker who logs in with a stolen credential doesn't get an attacker's view of your tenant. They get that person's view. Every SharePoint site they were ever added to, every Teams channel, every shared mailbox, every file someone once sent them a link to. In most Microsoft 365 tenants we look at, that is a great deal more than the account's owner would guess.
Because nobody ever takes anything away. A tenant that has been running for five or six years carries years of project sites, shared folders and 'just give them access for now. Someone is added to the finance site for a project in 2021 and is still there. An HR folder is shared with 'everyone' because it was quicker than working out who needed it. A supplier's guest account is created for a job that finished two years ago and never removed. None of it looks like a risk on its own, which is exactly why it survives.
An attacker doesn't need your most senior user for any of this to matter. They need your most over-shared one, and there is almost always one. That is what makes 'who has access to what?' worth answering before someone else answers it for you. It is also one of the first things Cyber Essentials asks about under user access control, which we cover in our Cyber Essentials Plus explainer, and it sits at the centre of how we help organisations reduce risk.
Most of what follows can be done from the admin centres you already have, in an afternoon, without buying anything. Where a check leans on a licence you may not hold, we've said so.
Who still has a live account? Start in the Microsoft Entra admin centre under Users, add the 'Last interactive sign-in time' column and sort by it. Anyone who hasn't signed in for 90 days deserves a question; anyone who has left the business deserves a decision. Disabling an account stops the sign-in, but it does not revoke the sharing links that person created or take them out of groups, so treat disabling as the first step rather than the last. Microsoft's guidance on inactive accounts notes that pulling this data through the Graph API needs Entra ID P1 or P2; the column in the admin centre is enough to start with.
Which guests can still get in? In the same Users view, filter by user type 'Guest'. This is the list of people outside your organisation who can sign in to your tenant, and it is usually longer than anyone expects: former suppliers, ex-contractors, the auditor from two years ago. For each one the questions are simple. Does the engagement still exist, and what can they see if they log in today? If you hold Entra ID P2, access reviews can put this on a schedule. If you don't, a quarterly manual pass beats none.
Which sharing links are still open? Two places. First, SharePoint admin centre, Policies, Sharing, which sets what the whole tenant is allowed to do: whether 'Anyone' links are permitted at all, and whether they expire. If 'Anyone' is on with no expiry, every such link ever created is still live. Second, Reports, Data access governance, where the 'Sharing links' report shows which sites are generating the most 'Anyone' and 'People in your organisation' links. Microsoft's documentation is clear that the full set of reports needs SharePoint Advanced Management, with a reduced version on Microsoft 365 E5. On other licences the tenant policy is your lever and the audit log is your evidence.
Which Conditional Access rules are protecting nothing? Conditional Access is where you decide who may sign in, from where, on what device and with what second factor. In the Entra admin centre under Protection, Conditional Access, look for three things: policies still in report-only mode months after they were created, exclusion lists that have quietly grown, and gaps such as no multi-factor requirement on accounts that can reach your most sensitive sites. Report-only mode is a test state. A policy that has lived there since 2023 is protecting nobody.
Live accounts. Entra admin centre, Users, with the 'Last interactive sign-in time' column added. Good looks like no enabled account unused for 90 days or more, and leavers disabled, removed from groups, and their sharing links revoked.
Guests. Entra admin centre, Users, filtered to user type 'Guest'. Good looks like every guest tied to a live engagement and a named owner, with anything older than the work it was created for gone.
Sharing links. SharePoint admin centre, Policies, Sharing, then Reports, Data access governance, Sharing links. Good looks like 'Anyone' links switched off, or expiring within 30 days, and no site quietly generating hundreds of them.
Conditional Access. Entra admin centre, Protection, Conditional Access, Policies. Good looks like no policy left in report-only for more than a month, multi-factor authentication required on every account that can reach sensitive sites, and exclusion lists you can explain.
The businesses that get this right are rarely the ones with the largest security budgets. They are the ones where somebody owns the question, runs the four checks on a calendar rather than after an incident, and treats what comes back as a to-do list rather than a report. The first pass takes an afternoon and, in our experience, always finds something.
If you would rather have someone alongside you for that first pass, we'll spend half an hour walking through where to look in your own tenant. Nothing to install, nothing changes. And if you'd rather we did the looking, that is a conversation about our cybersecurity services. The wider picture of what a proper review covers is in our earlier piece on what an IT security audit involves, and the phishing half of the problem is in our guide to protecting your business from phishing.