I'm trying to improve our process when someone moves between departments. Their access may involve security groups, Teams, SharePoint sites, shared resources, and mailbox permissions. What's the best way to confirm that outdated access has been removed and the employee has the correct new access without manually checking every system?
5 Answers
The cleanest approach is to make access role-based. Give each position or functional role its own group, assign permissions to that group, and move the employee from the old role group to the new one. Then the access change is mostly a group-membership change instead of a collection of individual permission updates.
Use a checklist for the workflow, but don’t stop at marking tasks complete. After provisioning, test representative access with the employee or a test account: confirm they can reach the resources required for the new role and cannot reach a few known resources from the old department. Automated membership and permission reports can cover the broad check, while targeted tests catch configuration mistakes.
Treat the department change as its own joiner/mover/leaver workflow, triggered by HR. Use the employee’s department and role attributes to drive group membership, then run scripts or reports to compare expected access with actual access. The check should include security groups, Teams, SharePoint memberships, shared mailboxes, and mailbox delegation.
The tricky part is exceptions. Direct SharePoint permissions, manually assigned group memberships, and mailbox permissions can survive a role change even when the main groups are correct. I’d maintain an exception report, review those entries with the manager or data owner, and give temporary backup access an expiration or review date instead of leaving it indefinitely.
Exactly. “Just in case” access tends to become permanent unless someone owns the review and there’s an actual expiry date.
For environments with lots of inconsistent, one-off access, some teams handle a move almost like a termination and rehire: preserve or archive the old account’s mailbox and files, then provision a fresh identity with only the new role’s access. It creates extra work and needs a careful continuity plan for OneDrive, mailbox history, and file ownership, but it can be safer than trying to untangle years of inherited permissions.

That works especially well when permissions are centralized. Direct permissions and one-off exceptions are what usually make department changes difficult.