Microsoft 365 Security: Fixing Access for 15+ Users
See how Altura Networks improved Microsoft 365 security for 15+ users by reorganizing SharePoint permissions and applying least-privilege access.
MICROSOFT 365


Microsoft 365 can be working exactly as expected and still have a serious security problem.
Recently, Altura Networks worked with a growing professional services organization that relied heavily on Microsoft 365 and SharePoint for its day-to-day operations.
The company had approximately 15+ Microsoft 365 users, including six full-time employees and several contractors.
The problem wasn’t downtime.
The problem was access.
Nearly every user could see nearly everything.
The Challenge: Too Much Access, Not Enough Structure
The company’s SharePoint environment had grown under a single umbrella.
As files and projects accumulated, access had never been fully reorganized around individual responsibilities.
That meant employees and contractors could view information well beyond what they needed to perform their jobs.
This included:
Company financial information
Internal operating documents
Project files
Administrative information
Other business records that did not need to be visible organization-wide
From a usability standpoint, the environment had also become difficult to navigate.
Files were largely organized around individual projects, which meant employees needed to know where a particular project lived before they could find the information they were looking for.
The company had technology.
What it lacked was a repeatable structure for how that technology should be used.
Why Excessive Microsoft 365 Access Matters
It is easy to think of Microsoft 365 security primarily in terms of passwords, multifactor authentication, or antivirus.
Those controls matter.
But permissions matter too.
If an employee account is compromised, the attacker generally inherits whatever access that employee has.
If that account can access nearly every company document, the potential exposure is significantly larger than if the account only has access to information required for that employee’s job.
The same principle applies to contractors.
A contractor may need access to a particular state, project, or set of resources without needing access to internal financial or operating information.
This is the idea behind least privilege:
Give users the access they need to perform their responsibilities—and no more than necessary.
Altura’s Approach
We approached the project with two goals:
Reduce unnecessary access while making the environment easier for employees to use.
Simply locking everything down would not have solved the larger problem.
The organization needed a Microsoft 365 environment that was both more secure and more intuitive.
1. We Created Role-Based Groups and Permissions
Instead of continuing to manage access broadly, we created Microsoft 365 groups and assigned permissions based on actual responsibilities.
Employees and contractors were given access to the information required for their work rather than organization-wide visibility.
This created a much more controlled access model and reduced unnecessary exposure.
2. We Restricted Administrative Privileges
Administrative access was reduced so that only the two business owners retained administrative privileges.
Regular employees and contractors no longer needed elevated access simply to perform everyday work.
That created a clearer separation between:
people who use the environment
and
people who administer the environment.
3. We Reorganized SharePoint Around How the Business Actually Works
The existing file structure was heavily project-based.
We reorganized the environment primarily by state, giving employees a consistent way to locate information regardless of which individual project they were working on.
Instead of remembering:
“Which project folder was that document stored under?”
employees now had a predictable structure for finding the information associated with a particular state.
That helped turn SharePoint from a collection of folders into a more usable business system.
4. We Created a Dedicated Resources Area
Some information genuinely needed to be available across the organization.
Rather than granting broad access to everything simply because some files needed to be shared, we created a dedicated Resources area.
Company-wide resources could live there while sensitive or role-specific information remained protected.
This gave the organization a clear distinction between:
information everyone should have
and
information only certain people should have.
5. We Made Multifactor Authentication Non-Negotiable
Microsoft Authenticator was implemented as a required security control for users.
Passwords alone were no longer considered sufficient protection for company accounts.
Multifactor authentication added another layer of protection against stolen or compromised credentials.
6. We Documented Routine Microsoft 365 Administration
Technology becomes difficult to manage when basic processes only exist in someone’s head.
We documented procedures for common administrative tasks, including:
Adding users
Resetting passwords
Creating groups
Managing permissions
Handling common Microsoft 365 administrative tasks
This gave the organization a repeatable process for maintaining the environment going forward.
The Result
The organization moved from a Microsoft 365 environment where approximately 15+ users had broad visibility across SharePoint to a much more structured and role-based environment.
Before
Employees and contractors could access company information beyond what their responsibilities required.
Company financial and operating information had unnecessary exposure.
Administrative access was not sufficiently separated from normal user access.
Files were difficult to locate consistently.
Shared resources and restricted information lived within the same broad environment.
Routine Microsoft 365 administrative processes were not fully documented.
After
Access was organized through groups and permissions based on responsibilities.
Administrative privileges were limited to the two business owners.
SharePoint was reorganized into a more predictable structure.
Company-wide resources were separated from restricted information.
Microsoft Authenticator became mandatory.
Administrative procedures were documented for future use.
Employees were also able to navigate and locate information more consistently.
The improvement was not simply “better IT.”
It was a Microsoft 365 environment that better reflected how the company actually operated.
The Bigger Lesson
Microsoft 365 environments rarely become disorganized overnight.
They grow.
Someone creates a folder.
Someone shares it.
A contractor gets added.
A new employee joins.
A project starts.
Responsibilities change.
Another Team gets created.
And over several years, access can quietly accumulate.
Eventually, the question becomes:
Does everyone still have the access they should have—or just the access they’ve always had?
Those are not the same thing.
When Was the Last Time You Checked Who Can Access What?
If your organization has grown, added contractors, changed employee responsibilities, or used Microsoft 365 for several years, it may be worth reviewing your current permissions.
Altura Networks helps Middle Tennessee businesses review Microsoft 365 environments for unnecessary access, security gaps, confusing SharePoint structures, and administrative risks.
Request a Microsoft 365 Security & Access Review.
We’ll help you understand who can access what, where unnecessary exposure exists, and what should be addressed first.
