Reference
Policies for Microsoft 365
See the Microsoft 365 inventory reference for the objects these templates work on.
| Policy | Description | Severity | Category | Checks |
|---|---|---|---|---|
| Licenses assigned to external users ⭐ | Shows licenses which are assigned to external users and could be removed or might unnecessary External users with Microsoft 365 licenses consume resources intended for internal staff and may have broader access than necessary for external collaboration. Review all externally assigned licenses to validate business requirements, revoke unnecessary assignments to reduce costs, and implement approval workflows for any external license requests to ensure appropriate resource allocation and maintain cost control. | Medium | Costs | Subscription |
| Licenses assigned to inactive users ⭐ | Shows licenses which are users that have not signed in in last 90 days Users who haven't signed in for 90 days while retaining active licenses waste organizational resources and may no longer require access. Investigate inactive users to determine if they're on extended leave or have changed roles, revoke licenses from users who no longer need access, and implement automated monitoring through Rencore Governance to flag inactive users for manager review before license removal to balance cost optimization with legitimate absence scenarios. | Medium | Costs | Subscription |
| External users ⭐ | Shows external users (users with user type 'Guest') Guest accounts accumulate over time and may retain access to sensitive resources long after collaboration ends, creating security risks and compliance challenges. Conduct regular reviews through Rencore Governance to validate each guest account's continued necessity, remove inactive or unnecessary external users, or implement automated periodic removals to maintain a secure collaboration environment with only actively required external access. | Information | ExternalAccess | User |
| Licenses assigned to disabled users ⭐ | Shows licenses which are assigned to users with account enabled set to false Keeping licenses active on disabled accounts wastes resources and may indicate incomplete offboarding processes that leave other access rights active. Implement automated workflows through Rencore Governance to detect and remove licenses from disabled accounts immediately upon detection, establish regular review cycles to catch any missed assignments, and ensure your offboarding process includes comprehensive license removal to optimize costs and security. | Medium | Costs | Subscription |
| Groups with disabled user accounts ⭐ | Shows groups with users (owners and members) that have disabled accounts Disabled accounts retaining group membership create security vulnerabilities, may receive sensitive communications, and complicate access management across your organization. Use Rencore Governance to identify and automatically remove disabled accounts from all groups while reassigning ownership responsibilities to active users, ensuring continuous group management and preventing orphaned resources that could impact collaboration and security. | Medium | UserOffboarding | Group |
| Licenses with less than 10 units available | Shows licenses with less than 10 units available to assign to users. Running low on available licenses can disrupt new user onboarding and prevent timely access provisioning for business needs. Monitor license availability through Rencore Governance to receive alerts before shortages impact operations, plan procurement based on growth projections and historical usage patterns, and maintain buffer capacity to ensure smooth onboarding and avoid short noticed purchases at potentially higher costs. | Information | Costs | Subscription |
| External Users with pending acceptance | External users which have not accepted invitation to your tenant Unaccepted invitations may indicate communication issues or changed collaboration needs while leaving potential access points open indefinitely. Use Rencore Governance to send automated reminder emails to external users with pending invitations, set expiration timeframes for all invitations, and automatically remove those that remain unaccepted beyond your defined threshold to maintain a secure and well-managed external access environment. | Low | ExternalAccess | User |
| Users with Power Platform Premium License | Users with assigned Premium License for Power Platform (per user plan) Power Platform Premium licenses carry significant costs and should only be assigned to users actively developing solutions or requiring premium connectors. Review all Premium license assignments through Rencore Governance to verify active usage and business justification, downgrade inactive users to standard licenses or revoke access entirely, and implement approval workflows for future Premium assignments to ensure cost-effective platform utilization. | Information | Costs | User |
| Users with E3 license not using Outlook in last 12 month | Show Users with E3 license not using Outlook in last 12 month. Identify and review users with an E3 license who have not used Outlook in the past 12 months to determine if they still require this level of licensing. Reassign or downgrade their licenses to a more cost-effective option if the advanced features of E3 are not necessary. Rencore Governance helps Organizations implementing a regular audit process to continuously manage and optimize license assignments based on actual usage. | Low | Costs | User |
| License usage for Visio, Project and Power BI Pro ⭐ | Shows units consumed for critical licenses like Visio, Project and Power BI Pro Specialized licenses like Visio, Project, and Power BI Pro represent significant per-user costs that require careful management to avoid waste. Analyze usage patterns through Rencore Governance to identify underutilized licenses, reallocate them to users with actual needs, and implement continuous monitoring with automated alerts to optimize license distribution and control costs while ensuring necessary tools remain available to those who need them. | Medium | Costs | Subscription |
| Users with passwords not changed in last 6 months | Shows users that have not changed their password for more than 6 months Unchanged passwords increase breach risk as credential compromise may go undetected for extended periods, allowing persistent unauthorized access. Enforce immediate password changes for all users exceeding six months, implement regular password expiration policies aligned with security best practices, and consider transitioning to passwordless authentication methods for enhanced security and user experience. | Medium | Security | User |
| Disabled user accounts ⭐ | Shows all disabled user accounts Disabled accounts that remain in your tenant indefinitely create security risks, compliance issues, and administrative overhead while potentially retaining access to sensitive resources. Establish a comprehensive offboarding process that includes data archiving requirements, automated removal of disabled users from all groups, and scheduled account deletion after an appropriate retention period to maintain a clean and secure environment. | Medium | UserOffboarding | User |
| Licenses with unused seats ⭐ | Shows licenses which have a high number of unused seats Large numbers of unused licenses indicate over-procurement that ties up budget unnecessarily and prevents optimal resource allocation. Analyze license utilization to identify products with excessive unused seats, reduce subscription levels to match actual needs plus reasonable buffer, and implement quarterly reviews through Rencore Governance to continuously optimize license counts based on usage trends and organizational changes. | Medium | Costs | Subscription |
| Admin accounts with an Office 365 E3 license assigned | Admin accounts with an Office 365 E3 license assigned (Note: please adjust the email address, prefix or postfix to your company settings) Administrative accounts typically don't require the full productivity suite included in E3 licenses, leading to unnecessary costs and potential security risks from unused features. Review all admin accounts with E3 licenses and downgrade to more appropriate, cost-effective licenses that provide only the necessary administrative capabilities, then implement regular audits through Rencore Governance to ensure license assignments align with actual usage patterns and organizational needs. | Medium | Costs | User |
| Administrators without MFA | Shows administrators that have not activated multi factor authentication Enabling Multi-Factor Authentication (MFA) for admin accounts significantly enhances security by requiring multiple forms of verification, reducing the risk of unauthorized access. Enforcing MFA ensures that users adhere to best practices, protecting sensitive data and systems from potential breaches. Set up an Automation in Rencore Governance to send out a notification to respective users and inform/enforce them to activate MFA for their account. | High | Security | User |
| External users invited 3 month ago with pending acceptance | Shows external users invited more than 3 month ago that have not accepted invitation to the tenant Pending invitations that remain unaccepted for months create security vulnerabilities and administrative clutter while indicating the collaboration may no longer be necessary. Review all invitations older than three months and remove them through Rencore Governance automation, implementing a policy that automatically removes unaccepted invitations after a defined period to maintain security and reduce unnecessary external access points. | Low | ExternalAccess | User |
| Disabled room/place accounts | Shows rooms/places with disabled accounts Disabled room and place accounts can disrupt scheduling systems, prevent resource bookings, and create confusion for users trying to reserve meeting spaces. Re-enable these accounts after verifying they represent active physical resources, ensure proper calendar configurations are in place, and establish a process to maintain accurate resource availability across your organization. | Low | Operation | Rooms & Equipment |
| Disabled user accounts with assigned licenses | Shows disabled user accounts which have any licenses assigned Licenses assigned to disabled accounts directly impact your organization's costs while providing no value and potentially creating security vulnerabilities. Remove all licenses from disabled accounts to reclaim costs, use Rencore Governance to verify whether critical dependencies like Power Automate flows or shared resources depend on these accounts, then transition ownership before license removal to prevent service disruptions. | High | Costs | User |
| Groups with external users ⭐ | Shows groups that have external users External members in groups may access sensitive information and internal communications, requiring careful oversight to balance collaboration needs with security requirements. External access review is crucial for maintaining the security and integrity of your organization's data. By regularly reviewing and managing external access with Rencore Governance, organizations can reduce security risks, enhance compliance and optimize costs. Automate periodic external access reviews including approval workflows to validate external group membership by the respective owner. | Medium | ExternalAccess | Group |
| Global administrators without MFA | Shows global administrators that have not activated multi factor authentication Global administrators possess unrestricted access to your entire Microsoft 365 environment, making unprotected accounts prime targets for attackers who could compromise your entire organization. Immediately enforce MFA for all global administrator accounts without exception, use Rencore Governance to continuously monitor compliance and automatically notify non-compliant administrators, and consider implementing privileged identity management for additional security layers. | High | Security | User |
| Groups with external owners | Shows groups that have external users as owners External users owning internal groups can make uncontrolled membership changes, access sensitive information, and create compliance risks beyond your organization's direct control. Immediately transfer ownership of all externally-owned groups to trusted internal users, use Rencore Governance to continuously monitor and alert on any policy violations to maintain security and governance standards. | High | Security | Group |
| Groups with very few owners | Shows Groups which have fewer owners than defined threshold (default 2 owners) Groups with insufficient owners risk becoming unmanaged when the sole owner leaves or becomes unavailable, potentially disrupting operations and creating orphaned resources. Assign at least two active owners to every group to ensure continuity, use Rencore Governance to automatically notify groups with insufficient ownership and prompt owner assignment, maintaining operational resilience and proper governance across your collaboration environment. | Medium | Operation | Group |
| Guest users with a Dynamics license assigned | Guest users with a Dynamics license assigned Dynamics licenses assigned to guest users typically indicate over-provisioning since external users rarely require full Dynamics functionality, resulting in significant unnecessary costs. Review all guest accounts with Dynamics licenses to validate business justification, revoke licenses where full access isn't essential, and implement approval workflows through Rencore Governance for any future external Dynamics license assignments to control costs and maintain appropriate access levels. | Medium | Costs | User |
| Inactive external users | Shows external users that have not signed in for more than 6 month External users who haven't accessed your environment in six months likely no longer require access, yet retain potential entry points to your systems and data. Remove inactive external users to reduce attack surface and compliance risks, implement automated monitoring through Rencore Governance to flag inactive accounts, and establish regular cleanup cycles to maintain a secure environment with only actively necessary external access. | Medium | ExternalAccess | User |
| Inactive internal users | Shows internal users that have not signed in for more than 6 month Internal users inactive for six months may represent terminated employees, extended leaves, or role changes, but their active accounts pose security risks and consume resources. Review inactive internal accounts to determine current status, disable accounts no longer needed while following proper data retention policies, and implement automated detection through Rencore Governance to ensure timely account lifecycle management and reduced security exposure. | Medium | ExternalAccess | User |
| Over-licensed user Accounts | User accounts that have more than one License assigned with overlapping apps. Users with multiple licenses containing overlapping applications waste resources through redundant assignments that provide no additional value. Consolidate overlapping licenses by identifying the most appropriate single license for each user's needs, remove redundant assignments to immediately reduce costs, and implement automated detection through Rencore Governance to prevent future over-licensing while ensuring users retain all necessary application access. | High | Costs | User |
| Service plans assigned in the last 4 weeks | Shows service plans assigned to users in the last 4 weeks Review the service plans assigned to users in the last four weeks to ensure they align with current needs and usage patterns. Confirm that the assignments are necessary and appropriate, and reassign or revoke any plans that are not being utilized effectively. Implement a regular review process to continuously manage and optimize service plan assignments based on user activity and requirements. | Medium | Operation | App |
| Unused Licenses | Shows M365 licenses with more enabled units than consumed units Licenses with more enabled units than consumed indicate subscription oversizing that wastes budget without providing value. Adjust enabled unit counts to match actual consumption plus a reasonable buffer for growth, implement quarterly reviews through Rencore Governance to track utilization trends, and maintain optimal license levels that balance cost efficiency with operational flexibility for new user onboarding. | Low | Costs | Subscription |
| Users who are creating Microsoft Loop Teams Components | A list of users that are creating Microsoft Loop components in their OneDrive Microsoft Loop component creation in OneDrive requires oversight to ensure secure collaboration practices and prevent data sprawl across personal storage locations. Monitor Loop component creation through Rencore Governance to understand usage patterns, provide guidance on appropriate use cases and security best practices, and implement governance policies that balance collaborative innovation with data protection requirements. | Medium | Operation | User |