Microsoft 365 sits at the centre of many professional services firms. Employees use Outlook to communicate with clients, Teams to collaborate, SharePoint to manage information and OneDrive to work across locations and devices. These platforms help people find documents, share expertise and keep client work moving.
Over time, however, the permissions surrounding that information can become difficult to see and manage. A project team creates a new workspace. A document library is shared with a client. An employee moves into another role but retains access to their previous matters. A guest account remains active after an engagement ends.
Individually, these decisions may be reasonable. Collectively, they can leave people with access to information they no longer require. For professional services firms, that creates a serious question: Are Microsoft 365 permissions still reflecting how client information should be accessed today, or are they preserving decisions made months or years ago?
Permissions are rarely static. Employees join the firm, change roles, move between teams and work on different clients. Contractors and other external parties may need temporary access. New Teams workspaces and SharePoint sites are created to support projects, departments and client engagements.
Access is granted because someone needs it at a particular point in time. Removing it later is much easier to overlook. This can result in employees retaining access to:
The person may never deliberately look for that information. The problem is that the access still exists if their account is compromised, if they open the wrong search result or if another application uses their permissions to retrieve content.
In a professional services firm, the question is therefore broader than whether someone is authorised to use Microsoft 365. It is whether they can access only the information needed for their current responsibilities.
Creating a Team or SharePoint site can be simple. Deciding who owns it, what information belongs there and how long it should remain active requires more thought. Without clear governance, workspaces can accumulate quickly.
Some will have descriptive names and active owners. Others may have generic titles, unclear purposes or owners who have since left the organisation. Similar workspaces may be created for the same client or project, leaving information scattered across several locations.
This makes access difficult to review. An IT administrator might be able to see who belongs to a Team, but the membership list does not necessarily explain why each person still needs access. The person who originally understood the business context may no longer be involved. Professional services firms should be able to answer:
Without ownership and review, collaboration spaces can become permanent repositories for temporary access decisions.
Professional services firms need to exchange information with clients and other external parties. Microsoft 365 provides several ways to support that collaboration, including guest access, shared links and external file sharing.
These capabilities are useful, but they can create uncertainty if sharing is not managed consistently. A file may be shared directly with a named individual. Another may be accessible through a link. A client could be added as a guest to a Team. A supplier or adviser might retain access after their involvement ends. Questions worth reviewing include:
External sharing does not need to be prohibited. Professional services firms depend on collaboration. The objective is to ensure that sharing is deliberate, proportionate and visible.
Excessive permissions become more serious when an employee account is compromised. An attacker does not need to bypass every security control surrounding every document. If they gain control of a legitimate account, they may inherit the access already assigned to that user.
That access could include email, Teams conversations, SharePoint sites, OneDrive files and shared client information. The more information the account can reach, the more useful it becomes to an attacker. They may be able to:
Strong identity security remains essential, but appropriate permissions help limit what one compromised account can expose. This is the principle of least privilege: people should have the access required to perform their roles, without retaining unnecessary access to unrelated information.
Generative AI introduces another reason to review Microsoft 365 permissions. Tools such as Microsoft 365 Copilot work within the access available to the user. They do not need to bypass permissions to reveal a problem. They can make information the user already has permission to access considerably easier to find, summarise and connect.
Previously, an employee might technically have access to an old SharePoint site but never know that a particular document existed. They would need to locate the workspace, navigate its folders and recognise the relevant file.
An AI assistant can reduce that friction. If permissions are accurate, this can be extremely useful. Employees can find organisational knowledge, summarise documents and work more efficiently.
If permissions are excessive, AI can surface information that should no longer be available to that person. The underlying issue is not necessarily the AI platform. It is the quality of the access controls and information governance beneath it.
This is why a Microsoft 365 permission review should form part of AI readiness. Before asking what Copilot can do with organisational information, firms need to understand what each user is already permitted to see.
Information governance becomes harder when no one clearly owns a site, Team or document library. IT can manage the platform, but it may not know whether a consultant still needs access to a client file or whether a completed project must remain available to an external adviser.
Those decisions require business context. A practical ownership model might assign responsibility to a practice leader, project owner, department manager or information owner. That person does not need to administer Microsoft 365 directly. They need to confirm:
This separates the technical task of managing permissions from the business decision about who genuinely needs them. Without that ownership, IT teams may be expected to make access decisions without enough context, while business teams assume IT is already managing the issue.
A one-off permissions cleanup can remove obvious problems, but access will begin accumulating again unless the firm establishes an ongoing process. The right review frequency will depend on the organisation and the sensitivity of the information involved. High-risk workspaces may need closer oversight than general internal collaboration areas. A repeatable review process could include:
The process should be practical enough to repeat. An exhaustive review that cannot be maintained may provide less long-term value than a risk-based process with clear owners and regular follow-up.
A firm with years of Microsoft 365 activity may not be able to review every workspace immediately. The most useful starting point is usually the information that would cause the greatest harm if accessed inappropriately. That may include:
From there, the firm can identify workspaces without active owners, sites with broad membership and areas where external access has not been reviewed. This creates a risk-based starting point without waiting for the entire Microsoft 365 environment to be perfectly documented.
Professional services firms need employees to collaborate. They also need to exchange information with clients, advisers and other external stakeholders. The answer is not to make every document inaccessible or create so much friction that employees find alternative ways to share information.
The goal is to make access intentional. Employees should be able to reach the information they need. Clients and external partners should be able to collaborate through approved channels. IT teams should have visibility over access and sharing. Business owners should take responsibility for deciding who genuinely needs to see sensitive information.
These foundations become more important as firms adopt AI and connect more applications to Microsoft 365. Before expanding what technology can do with organisational information, it is worth confirming who that technology can retrieve the information for.
Because in a professional services firm, a permission is more than a technical setting. It determines who can reach information that a client has trusted the firm to protect.
The following questions can help IT teams identify where further investigation may be required:
If the answers are unclear, the immediate priority is visibility. Understanding where sensitive information sits, who can access it and who owns those decisions gives the firm a stronger foundation for collaboration, cybersecurity and responsible AI adoption.