Account clean-up
Accounts of former staff, test accounts and generic shared logins. Any account without a clear owner is closed; shared mailboxes take the place of common passwords.
The first time a Microsoft 365 tenant is reviewed, it usually holds more active accounts than people on the payroll. You find the intern from the summer before, the reception@ login four people share with one password, the sales rep who left for a competitor and still syncs email to his phone, and the contractor who ran the migration and kept global admin rights. Each is an open door, and under the GDPR each is unjustified access to personal data. The job is to leave one identity per person, permissions driven by role and a leaving process as quick as the joining one, whether in Entra ID, an on-premises Active Directory or both kept in sync.
The technical side is half the work. The other half is agreeing with you and with HR who grants each permission and what someone receives on their first day.
Accounts of former staff, test accounts and generic shared logins. Any account without a clear owner is closed; shared mailboxes take the place of common passwords.
The start or leaving date entered in Factorial or A3nom triggers creation or blocking of the account. Nobody has to remember to tell IT.
Push notifications in Microsoft Authenticator, passkeys or FIDO2 hardware keys for people who would rather not install anything on a personal phone. Text messages remain a last resort.
Mail and SharePoint are reachable only from managed devices or with stronger MFA, and sign-ins from countries where you have no staff are blocked outright.
Two emergency global admin accounts kept out of daily use, with other tasks spread across narrow roles that are switched on only when needed.
If you keep an on-premises Active Directory, we sync it to Entra ID with Entra Connect, clean out duplicate objects and retain the group policies that still make sense.
Apps that support it, such as Factorial, Holded or your adviser's client portal, are connected to Entra ID. Disabling one account then closes all those doors at once.
How long it takes depends on headcount and how messy the tenant is. Changes are staged, because locking a whole office out of email is not an acceptable side effect.
We audit admin roles, user objects, security defaults, licensing and any link to a local directory.
A single team lives with the new policies for a while. Friction they report is ironed out before wider roll-out.
Second-factor sign-in, access policies and device enrolment extended area by area, each with a single-sheet user guide.
Each quarter every manager receives a list of who can access what in their area, to confirm or correct.
The global admin account is not for reading email. At many small firms the managing director works all day in an account holding every privilege in the tenant, with the same password for years and no second factor. If a phishing message steals it, the attacker owns the whole company. We always keep working accounts apart from admin accounts, and emergency accounts are stored away from everyday use with credentials that do not rely on one person's phone.
An email to helpme@apply.es is enough. We block the account, end sessions on phone and laptop and turn the mailbox into a shared one for the manager. We hold off deleting it so OneDrive files are not lost; the retention period is agreed with you and entered in the record of processing activities.
It is a fair objection with a workable answer: FIDO2 hardware keys, passkeys stored on the laptop, or Windows Hello. What we do not advise is leaving those accounts without a second factor. The chosen option is worth writing into your internal device use policy.
In most cases yes, but not overnight. We begin by listing its remaining dependants, typically file shares, print queues, a legacy payroll tool and Wi-Fi logins. Documents go to SharePoint, the rest is replaced by cloud equivalents, and the box is retired when it has gone quiet.
Conditional access and Intune management come with Microsoft 365 Business Premium, usually the sensible choice for up to 300 users. With Business Standard, Entra ID P1 and Intune must be added separately. We look at what you already pay for before suggesting anything.
Entra ID keeps records of logins, rights changes and privileged role use for the period in question. On top of that we supply group membership with named owners and minutes of each quarterly review. That is precisely what an AEPD inspection or an ENS alignment exercise asks for.
Give us an idea of headcount and the way people log in at present. Our first step is an audit of the identities and admin roles in your tenant.
Your request is with us
Expect an answer within one working day. A reported fault that has halted your team is handled first.
No match found. Try another spelling, or go with the closest provincial capital: every job is done remotely, so the location makes no difference to what we deliver anywhere in Spain.