Skip to content

Microsoft 365 lifecycle & offboarding security checks

Dormant accounts, leavers with access, unowned assets and change-management gaps — the checks that catch what HR processes miss.

On Microsoft 365, Black Cat runs 5 checks in this area on every scan. Each one below lists its severity, how to fix it, and the compliance controls it satisfies where a control applies. See what access the Microsoft 365 connector needs.

Checks (5)

severity: high Copilot Agent No Owner fix difficulty: easy #

Assign an owner to the Copilot agent

  1. Open Power Platform Admin Center
  2. Locate the agent and assign an active owner

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.i.2 DORA (SaaS Security) DORA-9.6

severity: low Copilot Agent Never Published (30+ days) fix difficulty: easy #

Publish or delete unused draft agents older than 30 days

  1. Open Power Platform Admin Center > Copilot Studio
  2. Review the draft agent and publish it or delete if no longer needed

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.i.2 DORA (SaaS Security) DORA-9.6

severity: critical Copilot Agent Quarantined fix difficulty: medium #

Investigate and resolve the quarantine on this agent

  1. Open Power Platform Admin Center > Copilot Studio
  2. Check quarantine reason and remediate (usually DLP violation)
  3. Request un-quarantine after fixing the root cause

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.i.2 DORA (SaaS Security) DORA-9.6

severity: low Copilot Agent Stale (90+ days inactive) fix difficulty: easy #

Review and disable or delete agents inactive for over 90 days

  1. Open Power Platform Admin Center > Copilot Studio
  2. Review the agent activity and usage
  3. Disable or delete if no longer needed

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.i.2 DORA (SaaS Security) DORA-9.6

severity: high Copilot Agent Orphaned Owner fix difficulty: easy #

Reassign the agent to an active owner

  1. Verify the current owner is indeed inactive in Entra ID
  2. Transfer ownership to an active team member
  3. Update the agent configuration

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.i.2 DORA (SaaS Security) DORA-9.6

More Microsoft 365 checks

The information on this page is provided for general informational purposes and is believed to be accurate as of its most recent update. Product names, logos, and trademarks are the property of their respective owners and are used for identification purposes only; their use does not imply any affiliation with or endorsement by those owners. Descriptions of third-party applications and of compliance frameworks are based on publicly available documentation and may change over time.

See these checks run on your stack

Start a free 14-day trial — no credit card required.

Start Free Trial