Teams should prioritise mailbox access reviews before cutover, especially for shared mailboxes, VIP mailboxes, and delegated access. The main issue is not just licensing, but whether access is still appropriate in the new environment. Reviewing rights early helps prevent overexposure, keeps operational roles clear, and reduces the chance that legacy permissions quietly follow users into cloud storage.
Why mailbox access reviews belong before cutover
Mailbox access reviews should happen before cutover because the migration is the point where old permissions can be carried forward without anyone revalidating them. Shared mailboxes, VIP mailboxes, and delegated access are the highest-value places to start because they often have the broadest reach and the weakest day-to-day visibility. The question is not whether the mailbox still works, but whether each person or service still needs that access in the target state.
In practice, pre-cutover review is where teams separate legitimate operational access from inherited access that has just persisted for convenience. That is especially important in Office 365 migrations, where access can be tied to roles, support workflows, or legacy exceptions that were never revisited. A clean review before the move reduces the chance that stale permissions become part of the new baseline.
Mailbox access reviews also help distinguish ordinary migration tasks from access governance decisions. If a mailbox is shared across a team, or if a VIP mailbox has delegated access for assistants or support staff, the review should verify who still needs access, whether the access is temporary, and whether the delegated model matches current business use. That makes the migration an opportunity to correct access drift rather than preserve it.
Which mailbox types should be reviewed first
Prioritise mailboxes where access carries the highest exposure or the largest operational dependency. Shared mailboxes should come first because they often accumulate broad access over time and can be overlooked during ownership changes. VIP mailboxes come next because they are attractive targets and often contain sensitive communications or approvals. Delegated access should also be reviewed early because it can mask who actually has effective mailbox control.
The practical order is to review the accounts most likely to have exceptions, then move to the rest of the estate. That usually means support mailboxes, executive mailboxes, team inboxes, and any mailbox with inherited or long-standing delegation. A mailbox with no clear owner, no recent business justification, or no recent usage evidence should be treated as a review priority, not an administrative detail.
For teams that manage access governance centrally, this is also the right time to align mailbox reviews with identity records and role assignments. Access reviews and certification work best when they remove unused access instead of merely confirming that access exists. Where migration scope includes service or machine accounts, the same discipline helps prevent legacy access from being copied forward without a current owner.
How to judge whether access should be kept, changed, or removed
The decision should be based on current business need, not on whether the access existed before migration. If a user cannot explain why they still need mailbox access in the new environment, that access should be removed or reapproved. If access is tied to an operational role, verify that the role still exists and that the person still performs that function. If a delegation exists only because it was never cleaned up, it should not survive the cutover by default.
This is also where governance and migration planning meet. The review should confirm ownership, delegation, and approval path for each mailbox before the move, then ensure the post-migration state matches that decision. A mailbox migration that ignores access review often relocates the same overexposure into a newer platform. A mailbox migration that includes review creates a cleaner baseline for future recertification and support.
Teams can improve the process by using lifecycle thinking, not just permission checking. IAM and IGA basics explain why review, entitlement ownership, and least privilege belong together. For mailbox migrations, that means treating the review as part of the migration control plane, not as a separate audit task after the fact.
Risk and Threat Considerations
Mailbox access that is not reviewed before cutover can create immediate exposure, especially when legacy delegation or broad shared-mailbox access is preserved in the new tenant. The main risk is not only overexposure, but also invisible continuity: access that looked temporary or exceptional in the old environment can become normal in the new one, expanding the blast radius of a compromise or misuse.
Failure mechanism: Old permissions, delegated rights, or shared mailbox access are migrated intact, then remain active because no one revalidates the business need before users rely on the new platform.
Impact: Excessive access can expose sensitive correspondence, enable unauthorized mailbox actions, complicate incident response, and make it harder to prove who should have had access at cutover.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-53 Rev 5 and CIS Controls v8 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-53 Rev 5 | AC-2 — Account Management | Mailbox reviews validate and remove active access before migration cutover. |
| AC-6 — Least Privilege | The question is about reducing unnecessary mailbox exposure during migration. | |
| Recommendation — Review mailbox access, remove unneeded rights, and reapprove exceptions before cutover. Limit mailbox access to the minimum set of users who still need it. | ||
| ISO/IEC 27001:2022 | A.5.15 — Access control | Mailbox access reviews are an access-control decision during tenant migration. |
| A.8.2 — Privileged access rights | Delegated and high-impact mailbox access needs explicit review before cutover. | |
| Recommendation — Revalidate mailbox access against current business need before moving users. Confirm delegated and privileged mailbox access is still required after migration. | ||
| CIS Controls v8 | CIS-6 — Access Control Management | Prioritising mailbox access reviews is an access-control hygiene activity. |
| Recommendation — Inventory mailbox access, remove stale delegates, and keep only approved rights. | ||
Practitioner Guidance
What to prioritise: Start with shared mailboxes, VIP mailboxes, and any mailbox with delegated access or unclear ownership. Those are the cases most likely to contain inherited permissions that need deliberate reapproval before the move.
What to verify: Confirm the current business owner, the access purpose, and whether each delegate still needs rights in the target tenant. If the answer is unclear or historical, treat the access as removable until reapproved.
Decision rule: If the mailbox access cannot be justified in one sentence tied to current work, remove it or place it on an exception track before cutover. Do not wait for post-migration cleanup to fix a known access ambiguity.
Practitioner takeaway: The safest migration pattern is to move mailboxes after access has been rationalised, because cutover is when legacy exceptions are most likely to become the new normal.
Related resources from NHI Mgmt Group
- How should security teams run access reviews for non-human identities?
- When do NHI access reviews create more value than a one-time cleanup?
- Should organisations prioritise external exposure or internal credential governance first?
- Should organisations prioritise machine identities before human access reviews?