Assessment
suXus examines external users, public or widely shared locations, missing owners, exceptional permissions, inactive workspaces and deviations from established policies. The organisation determines which access is required for business purposes.
From inventory to controlled change
The assessment starts with the agreed Microsoft 365 components and risk criteria. Findings are prioritised by scope, sensitivity, ownership and potential impact. Before access is changed, dependencies are checked and the person authorising the change and arrangements for unexpected consequences are documented.
Conditions and limitations
A technical report does not independently determine whether access is lawful or necessary for business purposes. Completeness depends on available roles, data sources and the chosen measurement period. Periodic reviews, onboarding and offboarding processes, and change management remain necessary after a clean-up.
Coordinated follow-up
Use policies, compliance and lifecycle management to organise ownership and periodic reviews systematically. For roles, Conditional Access and identity management, the assessment connects with Microsoft Entra ID.
Responsibilities
Responsibilities
suXus maps access, deviations and potential controls, and can implement approved changes technically. The customer validates business necessity, appoints owners and decides on exceptions or revocation. Application and data owners remain responsible for substantive authorisation.
Outcomes
Outcomes
An overview of risks, priorities, an owner for each action and periodic checks where appropriate. Access is revoked only after validation to avoid unintended disruption of business processes.
Technology
Technology used in these services
- Microsoft 365
- Microsoft Teams
- SharePoint