A CEO does not need to know how to change Microsoft 365 settings. They should, however, know who can access the company's important information, what needs attention and who is responsible for taking action. These five questions can help you have a conversation with IT that leads to decisions.
In a company with its own IT staff, security often competes with user support, equipment purchases and other systems work. IT may have a long list of findings without a clear view of which work management wants to make time for. Management, meanwhile, may see only a risk score or hear that everything is fine.
A useful conversation starts with one concrete example. Ask IT to show you a finding, explain what it means for the business and suggest the next step. Where needed, management should agree on responsibilities and decide on priorities and resources.
The answers below are fictional examples. They illustrate the kind of response that helps you agree on the next steps. The same decision will not suit every company.
Customers and partners need files to work with you. The question is whether they still need access. Ask for an example from one completed project: what material was shared, how can it be accessed and who knows whether the recipient still needs it?
A useful answer: “Working files from a completed project can be accessed through a link that does not require sign-in. The project manager confirmed that the customer needs the final material but no longer needs the editable working files. IT can restrict access accordingly.”
The resulting decision: the project manager confirms which recipients need which material, and IT changes the permissions and checks that access works as intended. A file-sharing review is added to the project closure checklist.
Also ask how much the review covered. Checking one project does not cover all the company's files. A sharing link that grants broad access is a reason to review the situation. It does not, by itself, show that information has reached someone outside the company.
An app connected to your Microsoft 365 environment may need data for calendar bookings, reporting or backups, for example. Ask IT to highlight one app with broad permissions: what is it used for, who is responsible for it and are those permissions still needed?
A useful answer: “A reporting app can access data that the current report does not use. Finance recognises the app and still needs the report. We are asking the supplier whether it can do the same job with more limited permissions.”
The resulting decision: finance names a person responsible for the app. IT investigates how to limit its permissions, agrees on a test and checks that the report works after the change.
A familiar name or a previous approval does not establish whether the permissions are still needed. Equally, an app should not be removed simply because the CEO does not recognise it. Before deciding, establish what the app is used for, the scope of its permissions and how a change would affect people's work.
A risk associated with a user might involve inadequate protection or suspicious activity, for example. Ask IT to distinguish the finding from the conclusion: what is known, what still needs investigation and is there a reason to secure the account immediately?
A useful answer: “One user's sign-in differs from their usual activity. We are checking the time, device and app with the user and comparing their answers with the logs. Location information alone is not enough to establish unauthorised access.”
The resulting decision: a named person is assigned to investigate the finding, with an agreed deadline. If the information points to unauthorised access, IT follows the company's security incident procedure without delay. Management makes sure IT has the authority to secure the account in an urgent situation and that the necessary help is available.
Also ask whether users who access important information or administer the environment have unnecessarily broad permissions, and how the accounts of people who have left the company have been handled. These checks complement the investigation of an individual sign-in. They help identify the accounts whose misuse would cause the most harm to the business.
“We have 20 open findings” does not yet help you choose the next task. Ask for the three most important actions, with a named person responsible for each, an estimate of the work involved and a way to verify the result.
A useful answer: “The external sharing review is waiting for responses from project owners. Changing one app's permissions requires guidance from the supplier. We can start the user account review this week once time has been set aside for it.”
The resulting decision: management names the people responsible on the business side and helps remove obstacles to progress. IT agrees on the order of the tasks and explains how the results will be checked.
Distinguish a change that has been made from a result that has been verified. Changing a setting is one step; you then need to check that the intended restriction took effect and that necessary work can still continue.
A new employee, partner or app changes the environment. Ask how new findings are picked up and what happens when the person responsible is away.
A useful answer: “IT reviews new findings as agreed, urgent situations are handled immediately and someone has been named to provide cover during absences. Each month, we review the most important open issues, completed changes and matters awaiting a decision with management.”
The resulting decision: agree on how often the situation will be reviewed, who provides cover and how urgent situations are reported. An urgent finding must not wait for the next monthly meeting.
If some things are deliberately left unchanged, record the reason, the person responsible and the next review date. “Accepted” must not mean that the issue is never revisited.
Vahti brings together Microsoft 365 risk findings and suggested actions in plain language. IT can show a specific finding and its associated task, giving management a basis for discussing the impact and the decision needed. You can explore these views in Vahti's product overview.
The tool helps organise the information, but responsibilities still need to be agreed. IT assesses the technical situation and makes the agreed changes in Microsoft 365. The person responsible for the business activity confirms why the files, apps or permissions are needed. If unclear priorities or a lack of resources are holding up the work, management resolves those issues.
Set aside half an hour for the first conversation and ask IT to bring one real example. Finish by recording three things: what will be investigated or changed, who is responsible and when the result will be checked. Start the next conversation with these agreed tasks.
Explore Vahti's interactive demo with the person responsible for IT. Choose one view from the demo that would help you discuss your own company's situation.