Microsoft 365 Shared Mailbox, Guest and Admin Access Review Checklist

A Microsoft 365 access review for a Singapore SME should answer three questions: who can use each shared mailbox, which external guests still need access, and who holds administrator roles. Give every resource a business owner, remove access that no longer has a current purpose, and record the decision. This checklist focuses on a periodic review of live access. It complements, but does not replace, joiner, mover and leaver procedures.

Microsoft 365 makes collaboration easy. The awkward part comes six months later, when a project has ended, a vendor contact has changed and nobody remembers why an administrator role was assigned. A useful review is not a screenshot of names. It is a set of owner decisions with follow-up actions that somebody verifies.

Microsoft 365 access review map showing a shared mailbox, an external guest with an expiry date, an administrator account protected by MFA and a reviewer checklist.
Review shared resources, external collaboration and administrator roles as separate access paths, each with an owner and a recorded decision.

What should a Microsoft 365 access review cover?

Start with three separate registers. Combining everything into one long user export makes ownership unclear.

  • Shared mailboxes: address, business purpose, owner, members, Full Access delegates, Send As delegates, Send on Behalf delegates, forwarding rules and last review date.
  • External guests: guest identity, home organisation, sponsoring employee, groups, Teams or SharePoint resources, business purpose, expected end date and last sign-in or activity evidence where available.
  • Administrator access: person or service identity, assigned role, assignment scope, business reason, whether access is permanent or time-limited, MFA state, owner and last review date.

Use exports from the current Microsoft 365 and Microsoft Entra administration interfaces as review inputs. Do not rely on an old spreadsheet as the source of truth. The spreadsheet or ticket should record the decision and evidence, while the tenant remains the authoritative record of actual access.

Who should review and approve access?

Technical staff can produce the list, explain what a permission does and implement approved changes. The business owner should decide whether access is still needed. For example, the finance lead should own the decision for accounts@, while a project owner should decide whether an external design partner still needs a project site.

Use these roles even if one person covers more than one of them:

  • Review coordinator: opens the review, sets the scope and tracks overdue decisions.
  • Resource owner: confirms the business purpose and decides retain, change or remove.
  • Technical operator: implements the approved change using an individual administrator identity.
  • Verifier: confirms the tenant now matches the decision and closes the record.

Do not let the technical operator silently approve broad access merely because a manager did not respond. Escalate an overdue decision to the named alternate. Where access cannot be removed immediately, record the exception, owner and next review date.

Shared mailbox access review checklist

Microsoft describes shared mailboxes as mailboxes that multiple internal users can access, such as information, support or reception addresses. Delegates should use their own licensed mailboxes. The shared mailbox account itself is not intended for direct sign-in, so check that sign-in remains blocked.

  1. Confirm the business owner and purpose. If nobody owns the mailbox, assign an owner before reviewing members. A mailbox with no current purpose should enter a controlled closure process rather than remain available indefinitely.
  2. Review each delegate separately. Full Access, Send As and Send on Behalf are different permissions. Confirm the person still needs each one. Reading messages does not automatically justify sending as the mailbox.
  3. Check access through groups and direct assignment. A person may inherit access through a group even if their name is absent from the direct permission list. Review the group owner and membership as part of the same decision.
  4. Remove shared credentials. Staff should not sign in using a shared mailbox username and password. Use each person’s own identity and delegated permissions so actions remain attributable.
  5. Review forwarding, inbox rules and connected workflows. Confirm the destination, business purpose and owner. Treat forwarding to a personal or unexpected external address as an exception for immediate review.
  6. Check former staff and role changes. Compare delegates with recent leavers, transfers and temporary assignments. A disabled user account may stop direct access, but the stale permission still shows that the removal process is incomplete.
  7. Test the operating path. After changes, ask an authorised user to confirm they can open the mailbox and perform only the sending actions their role requires.

Do not confuse an external guest account with a shared mailbox delegate. Microsoft states that people outside the organisation cannot be given access to a shared mailbox in the usual way. Choose a supported collaboration design rather than sharing mailbox credentials.

External guest user access review checklist

A guest may have access through a Microsoft 365 group, Team, SharePoint site, enterprise application or access package. Deleting one sharing link does not prove every path is gone.

  1. Name the sponsor. Every guest needs an internal person responsible for confirming the relationship and the resources required.
  2. Confirm the current organisation and purpose. A familiar email address is not enough. Ask whether the person still works with the supplier, client or partner and whether the original project remains active.
  3. Review group and application assignments. Check Teams and Microsoft 365 groups, SharePoint access, enterprise applications and any directly shared resources.
  4. Inspect broad or anonymous links. A guest register does not show every “anyone with the link” path. Review sharing links separately and replace broad access with named access where the business process permits it.
  5. Use an end date or review date. Temporary collaboration should have a time boundary. If the platform or licence supports automatic expiry or recurring access reviews, configure it. Otherwise create an owned removal task.
  6. Remove access at the resource and identity levels. Removing a guest from one group may leave other assignments. Deleting the guest identity without first checking ownership or shared work can also disrupt a live project. Follow a deliberate sequence.
  7. Record the outcome. Keep the resource, reviewer, sponsor, decision, reason, implementation ticket and verification date.

Microsoft Entra access reviews can review group memberships, enterprise application access and role assignments on a recurring basis, subject to the applicable licensing. If that feature is not available in the tenant, a controlled manual review can still follow the same owner-decision-change-verification pattern.

Administrator access review checklist

Administrator roles can change users, credentials, policies, applications and other controls. Review them separately from normal collaboration access and use Microsoft’s least-privilege principle: the right permission, over the right scope, for the required period.

  1. Export active and eligible role assignments. Include permanent and time-limited assignments, assignments through groups, administrative units and privileged service identities.
  2. Challenge broad roles first. Ask what task requires the role and whether a narrower Exchange, SharePoint, Teams, User, Helpdesk or other role would cover it.
  3. Keep daily work separate from administration. Where practical, administrators should use a distinct account for privileged tasks rather than reading email and browsing the web under the same identity.
  4. Require MFA for administrator accounts. Confirm registration and policy coverage. Do not treat “the person uses MFA on their normal account” as evidence for a separate admin identity.
  5. Review time boundaries. Use time-limited or just-in-time access where the tenant’s capabilities and operating model support it. Remove project-based or vendor administration when the work ends.
  6. Check service identities and applications. An app registration, automation account or managed identity may hold powerful permissions even though it is absent from a people-only review. Record its owner, credential method, purpose, scopes and rotation or retirement plan.
  7. Protect emergency access. Keep approved emergency administration available, monitored and tested under a separate procedure. It should not become a convenient daily account.
  8. Verify removals. Re-export assignments after implementation and confirm the removed person, group or service identity no longer has the role through another path.

How often should an SME run the review?

There is no single interval that fits every resource. Use a risk-based schedule and event triggers.

  • Administrator access: review more often because one assignment can affect the whole tenant.
  • External guests and project groups: review at project milestones, contract end dates and owner changes.
  • Shared mailboxes: review when team responsibilities change and as part of a regular access cycle.
  • Immediate review triggers: staff departure, manager change, supplier change, suspected account compromise, merger of teams, new application rollout or discovery of an unowned resource.

For a small environment, a quarterly working session may be manageable. Higher-risk access may need a shorter cycle. The useful interval is one the business can operate consistently and tighten when circumstances change, not a date copied from a generic policy.

What evidence should the access review keep?

Keep enough evidence to reconstruct the decision without copying unnecessary personal or confidential data. A practical record includes:

  • review ID, scope and review date;
  • resource or role and current access path;
  • business owner and reviewer;
  • retain, change, remove or exception decision;
  • short reason and any expiry date;
  • technical change reference and operator;
  • post-change verification result;
  • open exception owner and next review date.

Do not store passwords, access tokens or recovery codes in the review record. Restrict the record itself because it maps valuable access paths.

Common review failures

  • Reviewing only active employees and missing guests, applications and service identities.
  • Listing names without identifying who owns the decision.
  • Checking direct permissions while ignoring group-based access.
  • Removing a guest from one Team but leaving application or SharePoint access.
  • Changing an administrator’s title without removing the old role.
  • Closing the ticket when the change was requested rather than when it was verified.
  • Buying governance features without assigning owners to complete the reviews.

A one-page Microsoft 365 access review checklist

  • Current exports taken from Microsoft 365 and Microsoft Entra.
  • Every shared mailbox has a purpose and business owner.
  • Full Access and sending permissions are reviewed separately.
  • Shared mailbox direct sign-in remains blocked.
  • Every guest has a sponsor, purpose and time boundary.
  • Group, site, application and sharing-link paths are checked.
  • Privileged assignments have a current business reason.
  • Administrator accounts use MFA and appropriately narrow roles.
  • Service identities and applications are included.
  • Every removal or change is verified in the tenant.
  • Exceptions have owners and next review dates.

When should you bring in Microsoft 365 support?

Outside support is useful when nobody can produce a reliable access map, shared mailboxes rely on common passwords, guest ownership is unclear, administrator roles have accumulated or reviews stop at an export. Sakal Network’s Microsoft 365 deployment and security services and managed IT services for Singapore SMEs can help document ownership, implement approved changes and operate recurring reviews.

If you are selecting a Microsoft 365 plan with device and identity controls, review Microsoft 365 Business Premium on Sakal Shop. Feature availability and licensing for Microsoft Entra governance, access reviews and privileged identity management should be confirmed against the tenant’s exact requirements. To discuss an existing access problem, contact Sakal Network.

Source notes