Subnet Blog

Could Your Microsoft 365 Permissions Expose Client Information?

Written by Ben Luks | 14 September 2026, 03:24:28 Z

Microsoft 365 sits at the centre of many professional services firms. Employees use Outlook to communicate with clients, Teams to collaborate, SharePoint to manage information and OneDrive to work across locations and devices. These platforms help people find documents, share expertise and keep client work moving.

Over time, however, the permissions surrounding that information can become difficult to see and manage. A project team creates a new workspace. A document library is shared with a client. An employee moves into another role but retains access to their previous matters. A guest account remains active after an engagement ends.

Individually, these decisions may be reasonable. Collectively, they can leave people with access to information they no longer require. For professional services firms, that creates a serious question: Are Microsoft 365 permissions still reflecting how client information should be accessed today, or are they preserving decisions made months or years ago?

Access tends to accumulate

Permissions are rarely static. Employees join the firm, change roles, move between teams and work on different clients. Contractors and other external parties may need temporary access. New Teams workspaces and SharePoint sites are created to support projects, departments and client engagements.

Access is granted because someone needs it at a particular point in time. Removing it later is much easier to overlook. This can result in employees retaining access to:

  • Former client matters
  • Previous departments or practice groups
  • Completed projects
  • Confidential management information
  • Financial or employee records
  • Shared folders created for temporary collaboration

The person may never deliberately look for that information. The problem is that the access still exists if their account is compromised, if they open the wrong search result or if another application uses their permissions to retrieve content.

In a professional services firm, the question is therefore broader than whether someone is authorised to use Microsoft 365. It is whether they can access only the information needed for their current responsibilities.

Teams and SharePoint can grow faster than governance

Creating a Team or SharePoint site can be simple. Deciding who owns it, what information belongs there and how long it should remain active requires more thought. Without clear governance, workspaces can accumulate quickly.

Some will have descriptive names and active owners. Others may have generic titles, unclear purposes or owners who have since left the organisation. Similar workspaces may be created for the same client or project, leaving information scattered across several locations.

This makes access difficult to review. An IT administrator might be able to see who belongs to a Team, but the membership list does not necessarily explain why each person still needs access. The person who originally understood the business context may no longer be involved. Professional services firms should be able to answer:

  • Who owns each workspace?
  • What kind of information should it contain?
  • Who should have access?
  • Are external users involved?
  • When was the membership last reviewed?
  • What should happen when the client engagement or project ends?

Without ownership and review, collaboration spaces can become permanent repositories for temporary access decisions.

External sharing needs particular attention

Professional services firms need to exchange information with clients and other external parties. Microsoft 365 provides several ways to support that collaboration, including guest access, shared links and external file sharing.

These capabilities are useful, but they can create uncertainty if sharing is not managed consistently. A file may be shared directly with a named individual. Another may be accessible through a link. A client could be added as a guest to a Team. A supplier or adviser might retain access after their involvement ends. Questions worth reviewing include:

  • Can employees create links that work for anyone who receives them?
  • Do shared links expire automatically?
  • Can external users download or reshare information?
  • Are guest accounts reviewed regularly?
  • Is there a clear process for removing access when an engagement ends?
  • Can the firm identify which information is currently accessible outside the organisation?

External sharing does not need to be prohibited. Professional services firms depend on collaboration. The objective is to ensure that sharing is deliberate, proportionate and visible.

The risk extends beyond the original user

Excessive permissions become more serious when an employee account is compromised. An attacker does not need to bypass every security control surrounding every document. If they gain control of a legitimate account, they may inherit the access already assigned to that user.

That access could include email, Teams conversations, SharePoint sites, OneDrive files and shared client information. The more information the account can reach, the more useful it becomes to an attacker. They may be able to:

  • Read confidential correspondence
  • Search for financial or payment information
  • Access client documents
  • Review conversations and identify trusted relationships
  • Impersonate the employee in an existing discussion
  • Share information outside the firm
  • Use legitimate access to support further social engineering

Strong identity security remains essential, but appropriate permissions help limit what one compromised account can expose. This is the principle of least privilege: people should have the access required to perform their roles, without retaining unnecessary access to unrelated information.

AI makes existing access easier to use

Generative AI introduces another reason to review Microsoft 365 permissions. Tools such as Microsoft 365 Copilot work within the access available to the user. They do not need to bypass permissions to reveal a problem. They can make information the user already has permission to access considerably easier to find, summarise and connect.

Previously, an employee might technically have access to an old SharePoint site but never know that a particular document existed. They would need to locate the workspace, navigate its folders and recognise the relevant file.

An AI assistant can reduce that friction. If permissions are accurate, this can be extremely useful. Employees can find organisational knowledge, summarise documents and work more efficiently.

If permissions are excessive, AI can surface information that should no longer be available to that person. The underlying issue is not necessarily the AI platform. It is the quality of the access controls and information governance beneath it.

This is why a Microsoft 365 permission review should form part of AI readiness. Before asking what Copilot can do with organisational information, firms need to understand what each user is already permitted to see.

File ownership can become unclear

Information governance becomes harder when no one clearly owns a site, Team or document library. IT can manage the platform, but it may not know whether a consultant still needs access to a client file or whether a completed project must remain available to an external adviser.

Those decisions require business context. A practical ownership model might assign responsibility to a practice leader, project owner, department manager or information owner. That person does not need to administer Microsoft 365 directly. They need to confirm:

  • Who should have access
  • Whether external sharing remains appropriate
  • When information should be reviewed
  • Whether the workspace is still required
  • What should happen when its original purpose ends

This separates the technical task of managing permissions from the business decision about who genuinely needs them. Without that ownership, IT teams may be expected to make access decisions without enough context, while business teams assume IT is already managing the issue.

Permission reviews need to be repeatable

A one-off permissions cleanup can remove obvious problems, but access will begin accumulating again unless the firm establishes an ongoing process. The right review frequency will depend on the organisation and the sensitivity of the information involved. High-risk workspaces may need closer oversight than general internal collaboration areas. A repeatable review process could include:

  1. Identify sensitive locations
    Determine which SharePoint sites, Teams and document libraries contain confidential client, financial, employee or management information.
  2. Confirm ownership
    Assign someone with the business knowledge to approve access decisions for each important workspace.
  3. Review membership
    Check whether employees, contractors and guests still require their current access.
  4. Examine external sharing
    Identify active guest accounts and shared links, including how they were created and whether they should remain available.
  5. Remove redundant access
    Revoke permissions that no longer reflect current roles, projects or client relationships.
  6. Review privileged accounts
    Ensure administrative and elevated access is limited, protected and monitored.
  7. Set a future review date
    Make permission reviews part of the firm’s regular governance rather than relying on another large cleanup later.

The process should be practical enough to repeat. An exhaustive review that cannot be maintained may provide less long-term value than a risk-based process with clear owners and regular follow-up.

Start with the areas that matter most

A firm with years of Microsoft 365 activity may not be able to review every workspace immediately. The most useful starting point is usually the information that would cause the greatest harm if accessed inappropriately. That may include:

  • Sensitive client matters
  • Financial and payment information
  • Executive communications
  • Employee records
  • Commercial agreements
  • Intellectual property
  • Merger, acquisition or transaction information
  • Documents shared with external parties

From there, the firm can identify workspaces without active owners, sites with broad membership and areas where external access has not been reviewed. This creates a risk-based starting point without waiting for the entire Microsoft 365 environment to be perfectly documented.

Better permissions support safer collaboration

Professional services firms need employees to collaborate. They also need to exchange information with clients, advisers and other external stakeholders. The answer is not to make every document inaccessible or create so much friction that employees find alternative ways to share information.

The goal is to make access intentional. Employees should be able to reach the information they need. Clients and external partners should be able to collaborate through approved channels. IT teams should have visibility over access and sharing. Business owners should take responsibility for deciding who genuinely needs to see sensitive information.

These foundations become more important as firms adopt AI and connect more applications to Microsoft 365. Before expanding what technology can do with organisational information, it is worth confirming who that technology can retrieve the information for.

Because in a professional services firm, a permission is more than a technical setting. It determines who can reach information that a client has trusted the firm to protect.

Questions for your Microsoft 365 permission review

The following questions can help IT teams identify where further investigation may be required:

  • Do important Teams and SharePoint sites have active business owners?
  • Are permissions based on employees’ current roles?
  • Can the firm identify where sensitive client information is stored?
  • Are guest accounts and externally shared links reviewed regularly?
  • Do links expire when ongoing access is unnecessary?
  • Are inactive or duplicated workspaces still accessible?
  • Is privileged access limited and monitored?
  • Do offboarding and role-change processes remove access consistently?
  • Have permissions been reviewed as part of the firm’s AI or Copilot readiness work?
  • Is there a repeatable process for reviewing high-risk information?

If the answers are unclear, the immediate priority is visibility. Understanding where sensitive information sits, who can access it and who owns those decisions gives the firm a stronger foundation for collaboration, cybersecurity and responsible AI adoption.