Access reviews that only evaluate named users miss shared content, delegated permissions, and service connections that continue to expose data after the user relationship changes. The result is residual access that outlives the business need. Effective governance has to cover the data object and the non-human access path, not just the identity record.
What actually breaks when reviews stop at user accounts?
Microsoft 365 access reviews become incomplete the moment they treat the user record as the whole control surface. The failure is not just missed admin cleanup, it is missed access that survives through shared mailboxes, delegated roles, app consent, and service-to-service connections. That leaves effective access in place even after the named user changes role or leaves.
In practice, the control breaks because the business question is “who can still reach the data?” while the review only answers “does this person still have an account?” Those are not the same. A named user can be removed and the object-level or delegated path can continue to expose the tenant’s data and workflows.
Microsoft 365 environments usually accumulate access through more than one path: mailbox delegation, SharePoint and OneDrive permissions, Teams ownership, app registrations, OAuth grants, and connected services. If review scope does not include those non-human and object-level paths, governance will look clean on paper while exposure remains in the platform.
Why residual access is the real governance failure
The main risk is residual access, which is access that outlives the legitimate business need. That risk matters because it often survives organizational change, transfers, and terminations. A user review can approve removal of a person while leaving behind access tied to a shared resource, delegated authority, or application token that still functions.
For Microsoft 365, that means the object being governed has to be the data path, not only the person. The relevant unit of review is often the mailbox, site, team, app, or connection, along with the permissions that let a human or service continue to act on it. If you do not review those relationships, you cannot reliably say the environment has been recertified.
That is why a strong review process needs to answer two separate questions: who is the account owner, and what still inherits or delegates that account’s authority? The second question is where most of the blind spots live.
How Microsoft 365 permissions keep exposure alive after the user changes
Microsoft 365 permissions frequently persist through inherited access, group membership, delegated mail and calendar rights, application permissions, and shared ownership of content. A person can lose direct login access and still retain control over data through a group, a mailbox rule, or an application that was approved earlier and never revisited. IAM and IGA Basics is useful here because it separates user identity from the access relationships that actually need governance.
This is also where lifecycle thinking matters. Access that was appropriate during onboarding or a temporary project can become stale after a move or departure, but Microsoft 365 does not automatically infer the business context for you. Joiner-Mover-Leaver (JML) Guide is relevant because it treats removal of old access as a lifecycle outcome, not a one-time account event.
When service connections are involved, the risk extends beyond humans entirely. App-only permissions, automation, and connected services can keep accessing content after the original employee relationship is gone. Cloud Workload Identity Guide helps explain why tokens, roles, and federated access paths must be reviewed as part of the access model, not treated as an implementation detail.
Risk and Threat Considerations
Residual Microsoft 365 access creates a quiet but durable exposure because it often blends into normal collaboration traffic. Attackers and careless insiders both benefit when delegated rights, shared resources, or application permissions remain valid after the user relationship should have ended.
Failure mechanism: The review control is scoped too narrowly, so the organization revokes the person but not the permissions, delegation, or service connection that still reaches the data. That leaves a working access path in place even though the account itself may look clean.
Impact: Sensitive mail, files, and collaboration spaces remain exposed, and the exposure can persist long enough to support misuse, lateral movement, or unnoticed data access. In governance terms, the organization believes it has certified access, but the actual blast radius has not changed.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-53 Rev 5 and CIS Controls v8 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-53 Rev 5 | AC-2 — Account Management | Access reviews and removal of stale access map directly to account lifecycle governance. |
| AC-6 — Least Privilege | Residual delegated and shared access reflects privilege that exceeds business need. | |
| IA-5 — Authenticator Management | Service connections and delegated access often depend on tokens, keys, or credentials. | |
| Recommendation — Review and disable unused access paths on a recurring schedule. Restrict each permission path to the minimum access needed. Track and rotate access credentials supporting non-human and delegated access. | ||
| ISO/IEC 27001:2022 | A.5.15 — Access control | The question is about whether access governance covers all relevant Microsoft 365 paths. |
| A.5.18 — Access rights | Residual access arises when access rights are not fully reviewed and withdrawn. | |
| Recommendation — Define access review scope to include shared and delegated permissions. Revoke access rights when the business need ends. | ||
| CIS Controls v8 | CIS-6 — Access Control Management | Reviewing only user accounts misses other access paths that CIS account management expects you to govern. |
| Recommendation — Inventory and review all active access paths, not just named users. | ||
Practitioner Guidance
What to verify: Verify that the review scope includes the object and the path, not only the named user. For Microsoft 365 that means checking shared mailboxes, delegated permissions, group-based access, app consents, and service connections alongside direct user assignments.
Common mistake: Do not use a clean user recertification as evidence that access is clean. If a mailbox, team, site, or app can still be used without that user’s direct sign-in, the control has not actually removed exposure.
Practitioner takeaway: The right question is not whether the account still exists, but whether any reachable data path still depends on that former relationship. Governance is effective only when it can prove the access path itself has been removed or intentionally retained.