it-service@brocent.com
System Account Management
Identity lifecycle, joiner-mover-leaver execution, multi-factor coverage, privileged and service account control across the identity estate for the August 2026 reporting period.
Leaver control is reliable; service accounts and one shared mailbox need ownership
Fifty-two accounts were active at period end across two directories and three application-local stores: 41 staff accounts, five separate privileged identities and six non-human accounts. All three leavers in the period were disabled on their last working day, with access revoked and mailboxes converted to shared within the four-hour target; the fastest was 38 minutes.
Two weaknesses remain. Four service accounts have no named owner and passwords older than one year, three of which hold write access to the file server. Separately, one shared mailbox is accessed with a common password by four users rather than through delegated permissions, which makes individual actions unattributable. Multi-factor authentication now covers all 41 staff accounts and all five privileged identities. The six non-human accounts are exempt by design — one authenticates with a certificate, five with passwords, which is precisely why those five belong in the vault on a rotation schedule.
Identity position at period end
Account counts are distinct identities, not licences. A staff member with both an Entra ID account and an application-local login counts once, with the application access recorded in the Access Review report.
Four items require action
Evidence. Four non-human accounts — a backup runner, a scanner-to-folder identity, a market-data feed and a legacy report scheduler — have an empty owner field. Passwords were last set between 2024-11 and 2025-06. Three hold write access to the file server; none has MFA, which is expected for service identities but raises the value of the password.
Impact. Long-lived unowned credentials with write access are the classic lateral-movement path, and no one can authorise their rotation without risking an unknown dependency. Auditors treat this as a control failure regardless of whether abuse occurred.
Recommendation. Assign a named business owner to each account, document its dependency, move the credential into the vault, and rotate on a 180-day schedule. Retire the legacy report scheduler if the report is no longer consumed.
Evidence. The operations mailbox is a licensed user account whose password is known to four staff, rather than a shared mailbox with delegated access. Sign-in logs show four distinct devices and two countries in the period.
Impact. Actions in the mailbox cannot be attributed to an individual, which undermines both the audit trail and any investigation. MFA also cannot be enforced meaningfully on a credential four people hold.
Recommendation. Convert to a true shared mailbox with delegated send-as permissions for the four users, then disable the underlying sign-in and release the licence.
Evidence. Two accounts belong to staff on extended leave (return dates confirmed with HR) and one to a contractor whose engagement ended in May but whose account was left enabled at the client's request pending a possible return.
Impact. Enabled but unused accounts widen the attack surface without any operational benefit and are routinely sampled in due diligence.
Recommendation. Disable rather than delete the two leave accounts, with a documented re-enable step; close the contractor account and re-provision if the engagement resumes.
Evidence. Thirty-nine of 41 staff use an authenticator app or a passkey; two retain SMS after replacing their handsets in August.
Recommendation. Re-enrol both users on the authenticator app during the September site visit and remove SMS as a permitted method for the tenant.
The two accounts reported in July as exempt from multi-factor authentication were enrolled on 2026-08-06 and 2026-08-11, bringing staff coverage to 41 of 41. The conditional access policy no longer contains any user-level exclusion.
Five of five service levels met
| Committed service level | Target | Actual | Status | Note |
|---|---|---|---|---|
| Leaver access revoked | ≤ 4 hours | 1.4 h avg | MET | 3 of 3 leavers |
| Joiner account ready | By start date | 2 of 2 | MET | Both provisioned one day early |
| MFA coverage for staff | 100% | 100% | MET | 41 of 41 accounts |
| Privileged access via vault | 100% | 100% | MET | 5 accounts, 23 checkouts logged |
| Monthly report issued | By 5th working day | 3rd working day | MET | Issued 2026-09-03 |
Three-period movement
| Metric | Jun 2026 | Jul 2026 | Aug 2026 | Direction of travel |
|---|---|---|---|---|
| Active accounts | 54 | 53 | 52 | Falling gently as leavers exceed joiners. |
| MFA coverage (staff) | 37/42 | 39/41 | 41/41 | Complete; no user-level exclusions remain. |
| Stale accounts > 90 days | 6 | 5 | 3 | Halved since June; two are approved leave cases. |
| Unowned service accounts | 4 | 4 | 4 | No movement — needs a client owner decision. |
| Mean leaver revocation | 3.1 h | 2.3 h | 1.4 h | Improving as the HR notification moved earlier. |
| Privileged checkouts | 31 | 27 | 23 | Declining with automation; all vault-logged. |
The five privileged accounts are separate administrative identities — four held by named staff or BCS engineers who also have a standard account, plus one sealed break-glass identity. The 41 staff figure counts each person's standard account only. The shared/functional pair is the operations mailbox and one certificate-based service principal.
Privileged and non-human accounts
Every account with administrative rights or without a human owner. Standard staff accounts are not listed individually; the full directory export is delivered separately.
| Account | Type | Rights | Owner | Pwd age | MFA | Status |
|---|---|---|---|---|---|---|
| adm.a.chan | Privileged | Global admin | a.chan | 42 d | Passkey | VAULTED |
| adm.m.wong | Privileged | Intune admin | m.wong | 28 d | App | VAULTED |
| adm.bcs.svc1 | Privileged | Server admin | BCS | 15 d | App | VAULTED |
| adm.bcs.svc2 | Privileged | Network admin | BCS | 15 d | App | VAULTED |
| brk.glass01 | Break-glass | Global admin | Client COO | 61 d | Passkey | SEALED |
| svc.backup | Service | File server write | — none | 418 d | None | NO OWNER |
| svc.scan2fold | Service | File server write | — none | 651 d | None | NO OWNER |
| svc.mdfeed | Service | App server read | — none | 395 d | None | NO OWNER |
| svc.rptsched | Service | File server write | — none | 602 d | None | RETIRE? |
| ops.mailbox | Shared | Mailbox + licence | Ops lead | 211 d | None | SHARED PWD |
| sp.backup.api | Service principal | Graph read | BCS | Cert | Cert | OK |
Authentication methods and sign-in health
Method shares are of the 41 staff accounts. The five privileged identities are enrolled separately — two on passkeys, three on the authenticator app — and are listed individually in the table above.
| Method / event | Accounts | Share | Note |
|---|---|---|---|
| Authenticator app (push + number match) | 31 | 75.6% | Tenant default; phishing-resistant number matching enforced. |
| Passkey / FIDO2 | 8 | 19.5% | Front-office staff who sign in from a fixed desk. |
| SMS only | 2 | 4.9% | Re-enrolment scheduled — see finding. |
| Failed sign-ins blocked by policy | 184 | — | Mostly legacy-protocol attempts from outside HK and SZ. |
| Risky sign-ins flagged | 3 | — | All confirmed benign: two travel cases, one VPN exit change. |
| Password resets handled | 7 | — | All identity-verified through the service desk callback procedure. |
Open items carried between periods
| Ref | Risk | Severity | Owner | Due | Status | Next action |
|---|---|---|---|---|---|---|
| ACCT-R01 | Unowned service accounts with stale passwords — 4 accounts, 3 with write access | HIGH | Client IT + BCS | 2026-09-30 | In progress | Assign owners, vault credentials, rotate on 180 days. |
| ACCT-R02 | Shared password on the operations mailbox — actions unattributable | HIGH | BCS Support Center | 2026-09-30 | Open | Convert to a shared mailbox with delegated access; disable sign-in. |
| ACCT-R03 | Enabled accounts with no recent sign-in — 3 accounts over 90 days | MEDIUM | Client HR + BCS | 2026-09-30 | Open | Disable the two leave accounts; close the contractor account. |
| ACCT-R04 | No documented account review cycle — reviews are performed but not evidenced | MEDIUM | Client IT + BCS | 2026-11-30 | Open | Formalise the quarterly review with a signed attestation record. |
| ACCT-R05 | SMS permitted as a second factor — weakest allowed method | LOW | BCS Support Center | 2026-10-31 | Open | Re-enrol 2 users, then remove SMS from the tenant methods policy. |
Next period commitments
| BCS Support Center will | Client is asked to |
|---|---|
| Convert the operations mailbox to delegated access and release the licence. | Nominate a named business owner for each of the four service accounts. |
| Vault and rotate all four service account credentials once owners are named. | Confirm whether the legacy report scheduler is still consumed. |
| Disable the stale accounts and document the re-enable procedure. | Confirm the contractor engagement is closed. |
| Draft the quarterly account review attestation template. | Nominate the approver for the quarterly account review. |
How this report was produced
| Source | Extracted | Records | Used for |
|---|---|---|---|
| Entra ID directory export | 2026-09-01 02:10 HKT | 45 accounts | Account state, last sign-in, MFA methods, role assignment. |
| On-premises directory | 2026-09-01 02:15 HKT | 7 accounts | Service accounts, password age, group membership. |
| Sign-in and audit logs | 2026-09-01 03:00 HKT | 31 days | Failed sign-ins, risky sign-ins, privileged checkouts. |
| HR joiner/mover/leaver feed | 2026-08-31 | 6 events | Lifecycle timing against the service level. |
| Credential vault log | 2026-09-01 | 23 checkouts | Privileged access evidence and rotation dates. |
Method and definitions
Active account is any enabled identity capable of authenticating, in either directory or in an application-local store. Disabled and soft-deleted accounts are excluded from the count but retained for the audit trail for twelve months.
Privileged account is an identity holding an administrative role in the tenant, on a server, or on a network device. Privileged identities are separate from the holder's standard account and are counted separately.
Leaver revocation is measured from the HR notification timestamp to the last access removal, covering directory sign-in, mailbox, VPN, application logins and device enrolment. A leaver is only counted as complete when every one of those is revoked.
Exclusions. Entitlement detail — which files, mailboxes and application roles each account can reach — is reported quarterly in the Access & Permission Review. Microsoft 365 tenant security settings are reported in the M365 Security report.
This copy is an anonymised sample prepared for illustration. The client name, account names, user identifiers and department labels have been replaced with fictitious values; counts, ratios, dates and findings reflect a representative managed identity estate. No real client data appears in this document.
BCS Support Center · it-service@brocent.com
Questions clients ask about this report
Every account created, changed or disabled in the period, with the HR trigger date, the action date and the elapsed time. Leaver timeliness is the single most examined control in an operational due-diligence review, so it is reported per account rather than as an average.
Privileged identities are listed individually every month with their justification and authentication method. Non-human service accounts are reported separately, because they are exempt from MFA by design and therefore need vaulting and rotation instead.
No interactive sign-in for 90 days. Dormant accounts are reported with a recommendation to disable rather than delete, so that mailbox and file ownership are preserved for records purposes.
See what your own System Account Management report would say
A free IT health check produces a first version of this report against your real estate, at no cost and with no obligation. It takes about a week and needs a few hours of your team's time.