ADMIN WORKFLOW / FREEFREE WORKFLOW

Microsoft 365 Access & Ownership Review

Review common ownership, forwarding and external-sharing signals across Exchange Online, Teams and SharePoint Online.

read-only7 guided stepsExchange Online · Microsoft Teams · SharePoint Online
WHEN TO USE IT

Use this workflow when the job is clear and bounded.

This guide is designed for a single administrative task rather than a broad tenant-wide assessment. It keeps discovery, preparation, any manual change and final verification separate so you can review each step before moving on.

A cross-workload ownership and access review built from Free read-only reports
RUNBOOK

The workflow, in order.

Start with the first step. Open later steps only when you need them; all guidance remains on this page and remains crawlable.

  1. 01 · SCRIPTInventory shared mailboxesHide step

    Capture shared mailboxes before reviewing forwarding and ownership-related access around shared resources.

    Open Export shared mailboxes →
  2. 02 · SCRIPTReview mailbox forwardingShow step

    Export mailbox forwarding and confirm that external or unexpected destinations have an approved business reason.

    Open Export mailbox forwarding →
  3. 03 · SCRIPTReview distribution group members and ownersShow step

    Export distribution group membership and ownership so unmanaged or unexpected access paths can be reviewed.

    Open Export distribution group members and owners →
  4. 04 · SCRIPTFind Teams without ownersShow step

    Identify Teams where no current owner is returned and route genuine gaps through your normal ownership process.

    Open Find Teams without owners →
  5. 05 · SCRIPTFind SharePoint ownership gapsShow step

    Review SharePoint sites without the expected ownership signals before making any governance change.

    Open Find SharePoint sites with ownership gaps →
  6. 06 · SCRIPTReview sites that allow external sharingShow step

    Identify sites where external sharing is enabled and confirm that the setting matches the intended collaboration model.

    Open Find SharePoint sites that allow external sharing →
  7. 07 · REVIEWReview exceptions and ownership gapsShow step

    Use the reports as a bounded review set. This Free workflow does not perform deep permission correlation or change access.

PRIVACY & CONTROLYour tenant stays outside Opselith.View details

No tenant connection

The workflow itself never signs in to Active Directory or Microsoft 365. Any generated PowerShell runs only after you review and execute it locally.

Local progress only

Completed workflow step IDs can be stored in your browser. Identity values, tickets, usernames, domains and generated output are not part of that progress record.

Manual changes stay manual

Where no suitable reviewed script exists, the guide labels the action as a manual change rather than pretending the website performed it.

TRUST / EVIDENCEValidation and execution boundariesView details

Recorded trust facts, not a certification. Opselith separates metadata review, static QA, analyzer evidence and runtime evidence. A missing runtime result or a Pending analyzer state is shown as-is rather than converted into a pass claim.

Static QAPassed

Workflow catalog, ordered runbook, local-progress and manual-change boundary QA.

PSScriptAnalyzerNot applicable

A guided workflow is not itself a PowerShell artifact.

Runtime evidenceNot yet recorded

No accepted runtime result is recorded for this workflow yet.

Execution boundaryRead-only

browser-guided-runbook · no website tenant connection · tenant output stays outside Opselith.

Last reviewed29 Aug 2026

Trust metadata reviewed for the current release contract.

Referenced scripts6

6 referenced scripts · 6 analyzer Passed · 0 Pending

Pending and Not yet recorded are evidence states, not failures. Review the generated script or runbook and validate it in your own environment before production use.

RELATED POWERSHELL6 scripts used by this workflowView scripts
BEFORE YOU CLOSE THE JOB

Verify in the authoritative admin tools.

Use the final verification step to confirm the resulting account, membership, licensing or service state in the relevant Microsoft administration portal or Active Directory tooling. Opselith is a runbook and script-generation layer, not the system of record.