TENBEX Microsoft 365 Audit

Internal Management / Sensitive

Microsoft 365 Email Access & Governance Audit

Executive report for Tenbex leadership covering mailbox access, group ownership, external collaboration exposure, legacy identities, privacy, accountability, and business continuity risks.

Shared Mailboxes Reviewed4
Ownerless M365 Groups12
External-Only Groups3
Priority Horizon90 days

Executive Summary

The audit identified several Microsoft 365 governance gaps that require management attention. The most important concerns are excessive or unclear recipient exposure, groups without accountable owners, legacy identities still linked to business processes, external collaboration that lacks formal lifecycle controls, and functional mailboxes that need clearer ownership and retention rules.

Management position: Microsoft 365 content, mailboxes, distribution groups, and collaboration spaces are corporate information assets. Access must be assigned by business need, owned by named accountable personnel, reviewed periodically, and removed when no longer required.

Completed Audit Findings

Shared Mailboxes

Shared mailboxes reviewed:

hr@admin@procurement@sales@

  • These addresses represent official company functions and should not be treated as informal team inboxes.
  • Access should be granted only to staff with a current job function requiring it.
  • Each mailbox needs a business owner, access approver, delegated users list, and periodic review date.
  • Send-as and full-access permissions should be separately reviewed because they create different accountability risks.

enquiry@ Functional UserMailbox

The `enquiry@` address is a functional UserMailbox rather than a conventional shared mailbox. Its forwarding behavior creates operational and privacy considerations.

  • Forwarding should be documented, approved, and reviewed.
  • If this mailbox receives customer or prospect information, forwarding must be limited to authorized recipients.
  • Consider converting to a shared mailbox if interactive login is not required.
  • Disable unnecessary direct sign-in and enforce MFA where sign-in remains required.

Tenbex_info Distribution Group

`Tenbex_info` shows broad recipient exposure and should be reviewed as a corporate-wide communication channel.

  • Confirm who can send to the group.
  • Confirm internal and external recipients.
  • Restrict external senders unless there is a documented business reason.
  • Define whether the group is for announcements, operations, project communication, or client communication.

Microsoft 365 Groups

Microsoft 365 Groups can expose mailbox conversations, files, calendars, Teams content, and membership visibility. Member and subscriber access should be reviewed together.

  • Members may access group resources beyond email.
  • Subscribers may receive group conversations directly in their inboxes.
  • Owners are responsible for membership accuracy and information lifecycle.
  • Guest access must be intentional, named, and periodically reconfirmed.

Group And Identity Risks

Area Finding Risk Recommended Control
Ownerless Groups 12 Microsoft 365 Groups have no assigned owner. No clear authority for access, retention, guest review, or deletion. Assign named business owners or archive/delete after confirmation.
External-Only Groups `MSA ROTATING GPS`, `MSA ROTATING PDB`, and `PPE Petronas` are external-only collaboration groups. External participants may retain access longer than needed. Confirm business need, sponsor, expiry date, and guest review cycle.
TENBEX SBA PCSB External guest exposure identified. Client or project information may be visible to external accounts. Validate all guests, remove stale access, and document client-approved membership.
SIReP TENBEX & NRE External collaboration exists and needs governance. Unclear ownership could weaken client confidence and access accountability. Assign owner, confirm scope, and set a recurring access review.
PTTEP Ownerless / legacy identity issue. Project access may depend on outdated accounts or undocumented responsibility. Replace legacy ownership with current accountable staff.
red Group Dependency on old Shahiffudin identity. Business continuity and accountability risk if legacy identity remains authoritative. Transfer ownership and permissions to the current approved identity.
Shahiffudin Identity Separate legacy User object exists alongside current UserMailbox. Confusion over account ownership, sign-in status, and access lineage. Map both identities, preserve required evidence, then retire or block obsolete identity.
Legacy Collaboration Groups `FORUM22`, `Interview15June2021`, `MSAEx`, `PCARD`, `SBA2021`, `SBA TENBEX - Execute` appear empty or legacy. Unmaintained containers create unnecessary exposure and clutter. Archive evidence where needed, then delete or formally mark retained.

Governance Impact

Privacy

Functional mailboxes and broad groups may contain staff, candidate, vendor, customer, or client information. Access must follow need-to-know principles.

Security

Legacy accounts, ownerless groups, broad recipients, and guest access increase the chance of unauthorized data access or delayed incident response.

Authority

Every mailbox and group needs a named owner who can approve access, answer audit questions, and decide whether the asset remains active.

Business Continuity

Critical communication channels should not depend on one person, one legacy account, or undocumented forwarding paths.

Corporate Ownership

Company email, mailbox history, Teams content, and project files are Tenbex corporate records, not personal workspaces.

Client Credibility

Client-facing collaboration spaces need visible control. Stale guests or unclear ownership can affect trust during client reviews or disputes.

Staff, General Mailbox, And Group Email Guidance

Do

  • Use named individual accounts for staff accountability.
  • Use shared mailboxes for official functions such as HR, admin, procurement, and sales.
  • Assign at least two accountable owners for important groups.
  • Review mailbox and group membership at least quarterly.
  • Document external guests, project sponsors, and expiry dates.
  • Remove access promptly when staff roles change or projects close.
  • Use distribution groups for broadcast communication only when recipient scope is controlled.

Don't

  • Do not share passwords for functional mailboxes.
  • Do not leave Microsoft 365 Groups without owners.
  • Do not allow legacy identities to remain owners of active groups.
  • Do not forward business email to broad or undocumented recipients.
  • Do not keep external guests after the business purpose has ended.
  • Do not use one distribution group for unrelated business purposes.
  • Do not publish this audit report without access protection.

Recommended 90-Day Remediation Roadmap

Days 1-15: Containment And Ownership

  • Protect this audit report with Cloudflare Access or equivalent authentication.
  • Assign executive sponsor and Microsoft 365 governance owner.
  • Freeze creation of new external groups unless approved.
  • Identify owners for shared mailboxes and priority groups.
  • Confirm forwarding behavior for `enquiry@`.

Days 16-30: Access Review

  • Review full access and send-as permissions for `hr@`, `admin@`, `procurement@`, and `sales@`.
  • Review `Tenbex_info` members, external recipients, and sender permissions.
  • Review Microsoft 365 Group members, subscribers, owners, and guests.
  • Document approved business purposes for active external collaboration.

Days 31-60: Remediation

  • Assign owners to the 12 ownerless Microsoft 365 Groups or prepare them for archival/deletion.
  • Clean up external-only groups after business validation.
  • Resolve `PTTEP`, `red`, and Shahiffudin legacy identity dependencies.
  • Remove stale guests from `TENBEX SBA PCSB` and validate `SIReP TENBEX & NRE` access.

Days 61-90: Governance Operating Model

  • Publish mailbox and group ownership standards.
  • Implement quarterly access review cadence.
  • Define onboarding, transfer, and offboarding procedures for email access.
  • Create a formal exception process for external collaboration.
  • Close or archive legacy collaboration groups: `FORUM22`, `Interview15June2021`, `MSAEx`, `PCARD`, `SBA2021`, and `SBA TENBEX - Execute`.

Management Decision Points

  1. Confirm the accountable owner for Microsoft 365 governance.
  2. Approve the 90-day remediation roadmap.
  3. Require formal owner assignment for every shared mailbox and Microsoft 365 Group.
  4. Require Cloudflare Access or equivalent authentication before publishing this site.
  5. Mandate quarterly mailbox, group, and guest access reviews.