Skip to Content

The M365 identity governance no one does (and why it cost...

Many companies believe MFA and strong passwords are enough. But the real risk lies in unmanaged identities: service accounts, delegated permissions, third-party access, and orphaned users. This study reveals what's at stake.
July 13, 2026 by
The M365 identity governance no one does (and why it cost...
Kleber Leal by Zamak Portal

Your company may be protecting the front door while leaving the windows wide open. Many organizations invest fortunes in firewalls, intrusion detection systems, and awareness training, but ignore the Achilles' heel of modern security: identity governance in Microsoft 365. They believe that enabling multi-factor authentication (MFA) and setting strong password policies is enough. It is not. And this gap is costly, in money, reputation, and competitive advantage.

The Microsoft Digital Defense Report 2024 reveals that 73% of successful attacks against mid-sized organizations start with the compromise of an identity. We are not talking about complex exploits or zero-day vulnerabilities. We are talking about service accounts with no password rotation for years, external sharing permissions granted indiscriminately, users who have left the company but still access SharePoint, and third-party applications with unrestricted access to your tenant. These are the silent vulnerabilities that no firewall detects.

The invisible problem of non-human identities

The first reality shock for most managers happens when they discover how many non-human identities exist in their own environment. Service accounts for integrations, registered devices, applications with delegated permissions, automation entities like bots and Power Automate flows. Each of them is a full identity within Microsoft Entra ID (formerly Azure AD), with authentication capabilities and access to resources.

According to the Gartner Magic Quadrant for Access Management 2025, 42% of organizations do not have an updated inventory of service accounts. This means that almost half of companies do not know how many non-human identities operate in their tenants, let alone what permissions they have. When an auditor or an attacker discovers this before your IT team, the damage is done.

The financial impact is direct. Each poorly managed service account can be an attack vector. An attacker who compromises a service account with global administrator permissions can exfiltrate the entire executive mailbox, halt operations with ransomware, or access customer data stored in SharePoint. The average cost of a data breach involving compromised identities is $4.35 million, according to the IBM Cost of a Data Breach Report 2023. For mid-sized companies, this amount can represent months of revenue.

And it’s not just security. Orphaned accounts continue to consume Microsoft 365 licenses. A user who has left the company but has not been disabled generates recurring subscription costs, in addition to risk. In a tenant with 500 employees, it is estimated that 5% to 8% of accounts are orphaned at some point. Multiply by the monthly value of each license and project over a year: it’s money going down the drain without generating value.

Excessive permissions: the silent poison

Another common blind spot is excessive permissions for external users. File sharing via link, B2B invitations in Entra ID, team groups with unrestricted access for guests. In theory, these are legitimate functionalities for collaboration. In practice, they become open doors that no one monitors.

Consider a real scenario: a professional services company shares a SharePoint folder with a project partner. The partner, in turn, shares the link internally without control. Months later, the contract ends, but access remains. The guest can still read, edit, and download confidential documents of new clients. The company does not know, does not audit, does not revoke. This is the cost of fragile identity governance: continuous exposure of critical data.

The same applies to delegated permissions in applications. By granting consent to an OAuth application, the user may be authorizing broad access to emails, files, or contacts without IT review. The attacker does not need to break the password; they just need to trick an employee into accepting a malicious consent prompt. The result is the same: exfiltrated data, tarnished reputation.

What is at stake in the business?

For the partner or owner, the risk is financial. A serious breach can lead to regulatory fines (LGPD, GDPR, CCPA), lawsuits from clients, and loss of contracts. For the C-Level, it is unpredictability: emergency remediation costs, overtime for IT, hiring digital forensics, crisis communication. For the internal IT team, it is the overload: trying to govern identities manually, in spreadsheets, without proper tools, while the business pressures for agility.

The problem is not technical. It is managerial. The lack of identity governance is not a bug; it is an organizational choice. And like any choice, it has consequences.

Practical paths to exit the risk zone

Solving this problem does not require a technological revolution. It requires a strategic approach, with clear processes and tools suitable for the size of the company. Here are the pillars that a technology partner (MSP) should offer to transform identity management from passive to active.

Automated identity lifecycle

The first layer is to establish governance from onboarding to offboarding. Each new identity should be created with the least privilege necessary, and each termination should automatically disable the account, revoke permissions, and remove licenses. Tools like Microsoft Entra ID Governance allow for automating this cycle with business rules. For companies with 50 to 5,000 employees, this is feasible and provides immediate returns in risk and cost reduction.

Periodic access review (access reviews)

It is not enough to set it up once and forget. The access review should be recurring, with frequency defined by criticality. Privileged access every 30 days; third-party access every 90 days; common access every 180 days. Microsoft 365 itself offers native access review features in Entra ID Governance. The challenge is to execute them consistently, with clear responsibilities and evidence for auditing.

Privileged Identity Management (PIM) for administrative accounts

PIM (Privileged Identity Management) is a feature of Microsoft Entra ID that allows elevated permissions to be activated only when necessary, for a limited time, and with approval. For medium-sized companies, it is one of the most impactful measures at the lowest cost. It eliminates the risk of permanently active administrator accounts. The attacker needs to compromise the active session; if the elevation is temporary, the window of opportunity shrinks drastically.

Monitoring of consent and OAuth permissions

Third-party applications with delegated permissions are one of the most exploited vectors. Setting up consent policies in Entra ID to require administrative review of high-risk permissions is essential. Additionally, quarterly auditing of all applications with Graph API permissions can reveal unpleasant surprises.

5 questions every manager should ask about identities in M365

1. How many non-human identities (service accounts, devices, applications) exist in your tenant and who controls them?
2. How to identify and remediate excessive permissions granted to external users via sharing or B2B?
3. What is the financial impact of orphaned accounts that continue to consume licenses and access sensitive data?
4. What privileged access review (PIM/PAM) practices are feasible for medium-sized companies?
5. How to differentiate managed identity from secure identity in the practice of an MSP?

1. How many non-human identities (service accounts, devices, applications) exist in your tenant and who controls them?

This question is the starting point. Without an accurate inventory, there is no governance. In practice, most managers underestimate the number of non-human identities. In a tenant of 200 users, it is common to find 30 to 50 service accounts, dozens of registered applications with permissions, and hundreds of devices. Each of them represents an attack surface.

The control must include identified owner, justification for existence, rotated password (preferably with a secret manager) and minimum permissions. If you do not know who created a service account two years ago, consider it compromised until proven otherwise. A competent MSP should offer an automated scan of Entra ID and reports of non-human identities with action recommendations.

2. How to identify and remediate excessive permissions granted to external users via sharing or B2B?

External sharing is a double-edged sword. It enables collaboration, but without controls, it becomes a data leak. The first action is to audit all active B2B invitations in Entra ID: how many, to whom, with what permissions, how long. Next, set up sharing policies that limit links to specific recipients and require expiration.

Remediation involves revoking unnecessary access and implementing quarterly guest reviews. Tools like Entra ID External Identities allow categorizing and managing external users with the same governance criteria as internal ones. The business gain is direct: reduction of the risk of leaking strategic information and compliance with privacy policies.

3. What is the financial impact of orphaned accounts that continue to consume licenses and access sensitive data?

The calculation is simple, but rarely done. For each orphaned account, add the monthly license cost (from $12 to $57 per user, depending on the plan) and multiply by 12 months. In a company of 500 employees with 7% orphaned accounts, the annual waste can reach $25,000 to $30,000. This amount is pure loss, with no return.

In addition to the direct cost of licensing, there is the opportunity cost of the IT team that needs to investigate incidents caused by unauthorized access. Every hour spent remediating a ghost access is an hour not dedicated to innovation projects. Microsoft licensing audits can also flag discrepancies and generate contractual fines. Identity governance is not an expense; it is an investment with measurable returns.

4. What privileged access review (PIM/PAM) practices are feasible for medium-sized companies?

For companies with 50 to 2,000 employees, the Privileged Identity Management (PIM) of Microsoft Entra ID is the most accessible and effective tool. It allows administrative accounts to be activated on demand, with a limited time (e.g., 4 hours), justification, and supervisor approval. It eliminates the risk of globally active administrator accounts, which are the preferred target of attacks.

On the other hand, Privileged Access Management (PAM) involves more granular control over specific tasks on servers and workstations, requiring solutions like Microsoft Purview Access Policies or third-party tools. For most medium-sized companies, starting with PIM for the 10 to 20 most privileged accounts already covers 80% of the risk. The next step is to extend to critical service accounts. An MSP should structure this deployment in phases, with training and follow-up.

5. How to differentiate managed identity from secure identity in the practice of an MSP?

Managed identity means that the account exists in a central system (Entra ID), has an owner, is in a group, and undergoes reviews. Secure identity goes further: it has automatically rotated passwords, mandatory MFA, just-in-time access, proven minimum permissions, and monitoring of anomalous behavior.

In practice, an MSP should provide reports that show not only how many identities exist, but how many meet the security standard defined in the contract. The key indicator is the percentage of identities with a secure posture. Below 80% is a sign of work to be done. Above 95% is governance maturity. The value for the client is predictability: knowing that the attack surface is under control and that no forgotten identity will cause a crisis.

The cost of ignoring identity governance in Microsoft 365 is high, but the solution is within reach. It is not about technology, but about strategic decision-making. Companies that treat identity as an asset to be managed, rather than a technical detail, better protect their data, spend less on unnecessary licenses, and sleep soundly knowing that their windows are not wide open.

The first step is an honest diagnosis. Do you want to know how many unmanaged identities exist in your tenant and what the real risk is to your business? Talk to Zamak Technologies and request a Complimentary Initial Consultation.

Frequently asked questions

What is the main identity governance gap in Microsoft 365 that many organizations overlook?

Many organizations focus on firewalls and MFA but ignore non-human identities like service accounts, which often lack password rotation and inventory. According to the article, 42% of organizations do not have an updated inventory of service accounts.

What are the risks of excessive permissions for external users in Microsoft 365?

Excessive permissions for external users, such as file sharing links and B2B invitations, can lead to continuous exposure of critical data. The article describes a scenario where a partner retains access to confidential documents after a contract ends, and the company does not audit or revoke it.

What is the financial impact of poorly managed identities according to the article?

The average cost of a data breach involving compromised identities is $4.35 million, according to the IBM Cost of a Data Breach Report 2023. Additionally, orphaned accounts consume Microsoft 365 licenses, with an estimated 5% to 8% of accounts being orphaned in a tenant with 500 employees.

The M365 identity governance no one does (and why it cost...
Kleber Leal by Zamak Portal July 13, 2026
Share this post
Tags
Archive