Call Us : 01636 34 33 32

How to Audit User Access Without Missing Risk

Blog
Categories

Interested in discussing this further?

Give us a call, drop us a text or chat with us now

How to Audit User Access Without Missing Risk

A former employee who can still access email, a finance user with administrator rights, or a shared login that nobody owns can become a serious business problem very quickly. Knowing how to audit user access gives you a clear view of who can reach your systems, what they can do, and whether that access is still justified.

For small and medium-sized businesses, this is not about creating more paperwork for its own sake. A sensible access audit reduces the chance of fraud, ransomware and accidental data loss. It also helps your team work with fewer delays because people have the access they genuinely need, without unnecessary permissions getting in the way.

How to audit user access: start with a complete picture

The first challenge is that user access is rarely held in one place. Microsoft 365 may control email, Teams, SharePoint and OneDrive, while your accounting package, CRM, payroll portal, line-of-business software, WiFi, VPN, door access and cloud services all have their own user lists.

Start by listing every system that holds company information, processes payments, provides remote access or controls a business service. Then export the user list from each one. The aim is to create a single working record showing the person, their job role, the system, their level of access and the manager responsible for approving it.

Do not rely solely on a list from HR or your active staff directory. Contractors, former staff, temporary workers, external accountants and IT suppliers may have accounts that do not appear there. These accounts can be legitimate, but only if somebody can explain why they remain active and what controls apply.

For each account, record whether it is a standard user, a privileged administrator, a shared account or an external guest. This distinction matters. A standard Microsoft 365 user with access to their own mailbox presents a different level of risk from a global administrator who can change security settings for the whole business.

Match access to the job, not the individual

The most practical way to manage permissions is through roles. A receptionist, finance assistant, solicitor, director and IT administrator all need different access, but people carrying out the same job should usually receive broadly the same set of permissions.

Ask the manager of each department to confirm what their team needs to do their work. This is often more useful than asking whether a named person should retain every permission they already have. Existing access tends to build up over time as people cover holidays, change roles or help with a one-off project.

Apply the principle of least privilege: give each user the minimum access needed to perform their responsibilities. That does not mean making everyday work difficult. It means avoiding broad access “just in case” when a more limited permission would do.

There are trade-offs. A very tightly controlled environment can slow a small business down if every minor request needs formal approval. The answer is not to abandon controls, but to make them proportionate. Standard role-based access can be pre-approved, while access to finance systems, sensitive client data, security tools and administrator functions should receive closer scrutiny.

Focus first on high-risk permissions

When time is limited, review the accounts that could cause the greatest damage if misused or compromised. These usually include global administrators in Microsoft 365, Azure administrators, finance and payroll users, people able to create new accounts, remote access users, and anyone with access to confidential client information.

For every privileged account, ask five straightforward questions:

  • Is this level of access necessary for the person’s current role?
  • Is there a named individual responsible for the account?
  • Is multi-factor authentication enabled and working?
  • Could a standard account be used for normal daily work instead?
  • Has the access been approved and reviewed recently?

Administrators should normally have separate accounts for administrative work. Using a privileged account for email, web browsing and day-to-day documents increases the impact of a phishing attack. Separate accounts add a small amount of administration, but they are a sensible control where the account can alter users, devices, licences or security settings.

Also check service accounts. These are accounts used by backup software, printers, applications or automated processes rather than a person. They are easily overlooked because they may not sign in interactively. Each should have a clear purpose, an owner, a strong managed password or certificate where supported, and only the permissions it requires.

Check leavers, movers, guests and shared logins

Most access problems are caused by routine changes that were never completed. A staff member leaves, but their account remains active. Someone moves from operations to sales, but retains access to financial folders. A supplier is invited to a SharePoint site for a project and is never removed afterwards.

Compare your access list with current HR records and recent leavers. Disable accounts that are no longer needed rather than deleting them immediately. Retaining an inactive account for an agreed period can preserve mailboxes, files and audit evidence, but it must not remain available for sign-in.

Review external guest accounts separately. A guest might need access to one Team or document library, but not to search the wider organisation or download sensitive material. If you cannot identify the business reason, the account owner or the date it should expire, remove access.

Shared logins deserve particular attention. They make it difficult to know who did what and often remain in use after passwords have been passed around. Where possible, replace them with individual named accounts. If a shared account is unavoidable for a legacy system, limit its permissions, store credentials securely, change the password when staff leave, and document who is authorised to use it.

Review access beyond Microsoft 365

Microsoft 365 is often the starting point, but it should not be the end of the audit. A user removed from email could still access your accounting platform, hosted phone system, remote desktop, business mobile portal or cloud backup console.

Look at devices too. Local administrator rights on laptops and desktops can allow software installation, security changes and access to stored credentials. Some technical staff need this access, while most office users do not. Removing local administrator rights may require better software deployment and a quicker support response, so plan the change rather than simply switching it off without notice.

Physical access should follow the same principles. Review who holds office fobs, alarm codes, server room keys and door access permissions. Digital and physical security are closely linked: there is little value in protecting a server with strong passwords if an old contractor can still enter the comms room.

Document decisions and fix issues properly

An audit only delivers value when the findings lead to action. Keep a simple record of every decision: retain access, reduce permissions, disable the account, remove it, or investigate further. Include the person who approved the decision and the completion date.

Prioritise urgent changes first. Remove unknown administrators, disable departed staff, secure accounts without multi-factor authentication and investigate unexplained forwarding rules or suspicious mailbox permissions. Then work through lower-risk improvements, such as tidying unused groups and standardising access for each job role.

This record is also useful when clients, insurers, auditors or regulators ask how access is controlled. Professional services firms and charities may have particular obligations around confidential information, but every organisation benefits from being able to show that access is reviewed rather than assumed.

Set a review cycle that fits your business

User access should be checked whenever somebody joins, changes role or leaves. That is the day-to-day control. Alongside it, carry out a scheduled wider review at least every six to twelve months.

The right frequency depends on your risk. A business handling client money, special category data or highly confidential legal files may need quarterly checks for privileged and finance access. A smaller organisation with stable staffing may find an annual full review, supported by prompt joiner, mover and leaver processes, is proportionate.

Assign clear ownership. HR should notify the right people about staffing changes, department managers should confirm what access their teams require, and IT should make the technical changes and retain the evidence. If one person is expected to do all three without a process, gaps are likely.

For businesses without dedicated internal IT, an experienced managed IT provider can help export reports, identify risky permissions and put a repeatable process in place. The important point is that management remains involved: technical reports can show who has access, but only the business can decide whether that access still makes sense.

A good access audit is not a one-off clean-up exercise. It is a practical habit that keeps former staff out, gives current staff the tools they need, and makes your business far less attractive to anyone looking for an easy way in.

Tags :
Share :