Bus-Factor Report · Guide

Who has access to what in Microsoft 365? A small-business audit

Groups, admin roles, and owners each control a different kind of access in Microsoft 365. Where admins hide, a 15-minute audit, and why job titles mislead.

Groups vs roles vs owners

Three different things decide what someone can do in Microsoft 365, and they are easy to mix up.

Groups decide what someone can reach. A security group might grant access to an app or a set of files. A Microsoft 365 group comes with shared conversations, a calendar, and a SharePoint site, and a team in Teams is built on one. Membership is the access.

Roles decide what someone can change. Admin roles such as Global Administrator, User Administrator, or Exchange Administrator let a person manage the tenant or parts of it. They have nothing to do with the person's job.

Owners decide who can change a group. An owner can add and remove members. When the only owner leaves, the group becomes ownerless, and an admin has to step in to assign a new one.

Where admins hide

Admin roles accumulate. The person who signed up for the subscription became a Global Administrator automatically, and probably still is. The outside helper who ran a migration got a role and kept it. A bookkeeper was made Billing Administrator to update a card. Nobody removed any of it.

Look in two places. In the Microsoft 365 admin center, Role assignments lists each role and who holds it. In the Microsoft Entra admin center, Entra ID > Roles & admins shows the same, and each user's Assigned roles page shows whether a role was granted directly or through a group. Microsoft recommends fewer than five Global Administrators; in a small firm, two named people plus emergency access accounts is a sensible target.

The 15-minute audit

Set a timer. You are not fixing anything yet, only writing down what you find.

Why titles lie

Job titles in the directory are typed once, at hire, and rarely touched again. The receptionist who now runs payables is still a receptionist in Microsoft 365. In most small firms titles do not grant access directly, so nothing breaks when they drift, which is exactly why they drift.

The danger is that people use titles to make access decisions anyway: who to add to the finance group, who should approve an invoice, who to call when payroll fails. When the title is wrong, those decisions go wrong. Access follows what people actually do, so audit it that way.