B BROCENT
Brocent — Your Asia IT Team
BCS Support Center · Hong Kong
it-service@brocent.com
Monthly client report · 04 of 09

System Account Management

Identity lifecycle, joiner-mover-leaver execution, multi-factor coverage, privileged and service account control across the identity estate for the August 2026 reporting period.

Client
Acme Capital Limited
Reporting period
2026-08-01 → 08-31
Issued
2026-09-03
Reference
ACCT-2026-08
Scope
52 accounts · 41 staff
Directories
Entra ID, on-prem AD, 3 apps
Prepared by
BCS Support Center
Classification
Confidential
01 · Executive summary

Leaver control is reliable; service accounts and one shared mailbox need ownership

Fifty-two accounts were active at period end across two directories and three application-local stores: 41 staff accounts, five separate privileged identities and six non-human accounts. All three leavers in the period were disabled on their last working day, with access revoked and mailboxes converted to shared within the four-hour target; the fastest was 38 minutes.

Two weaknesses remain. Four service accounts have no named owner and passwords older than one year, three of which hold write access to the file server. Separately, one shared mailbox is accessed with a common password by four users rather than through delegated permissions, which makes individual actions unattributable. Multi-factor authentication now covers all 41 staff accounts and all five privileged identities. The six non-human accounts are exempt by design — one authenticates with a certificate, five with passwords, which is precisely why those five belong in the vault on a rotation schedule.

Service verdict
On track
All five account-management service levels were met. No orphaned staff account, no leaver with retained access, and no privileged account outside the vault. The two structural items are tracked as ACCT-R01 and ACCT-R02.
02 · Key indicators

Identity position at period end

Active accounts
52
▼ −1 vs Jul
MFA coverage (staff)
41 /41
▲ +2 vs Jul
Service accts unowned
4
— unchanged
Stale > 90 days
3
▲ −2 vs Jul
Leavers processed
3 /3
▲ all in SLA
Mean leaver revoke
1.4 h
▲ −0.9 h
Privileged accounts
5
— unchanged
Shared credentials
1
— unchanged

Account counts are distinct identities, not licences. A staff member with both an Entra ID account and an application-local login counts once, with the application access recorded in the Access Review report.

03 · Key findings

Four items require action

Four service accounts have no owner and passwords older than one year · carried forward (2 periods)
HIGH

Evidence. Four non-human accounts — a backup runner, a scanner-to-folder identity, a market-data feed and a legacy report scheduler — have an empty owner field. Passwords were last set between 2024-11 and 2025-06. Three hold write access to the file server; none has MFA, which is expected for service identities but raises the value of the password.

Impact. Long-lived unowned credentials with write access are the classic lateral-movement path, and no one can authorise their rotation without risking an unknown dependency. Auditors treat this as a control failure regardless of whether abuse occurred.

Recommendation. Assign a named business owner to each account, document its dependency, move the credential into the vault, and rotate on a 180-day schedule. Retire the legacy report scheduler if the report is no longer consumed.

Owner Client IT + BCS Support Center Target 2026-09-30 Ref ACCT-2026-07-01
One shared mailbox is accessed with a common password by four users
HIGH

Evidence. The operations mailbox is a licensed user account whose password is known to four staff, rather than a shared mailbox with delegated access. Sign-in logs show four distinct devices and two countries in the period.

Impact. Actions in the mailbox cannot be attributed to an individual, which undermines both the audit trail and any investigation. MFA also cannot be enforced meaningfully on a credential four people hold.

Recommendation. Convert to a true shared mailbox with delegated send-as permissions for the four users, then disable the underlying sign-in and release the licence.

Owner BCS Support Center Target 2026-09-30 Ref ACCT-2026-08-02
Three accounts have not signed in for more than ninety days
MEDIUM

Evidence. Two accounts belong to staff on extended leave (return dates confirmed with HR) and one to a contractor whose engagement ended in May but whose account was left enabled at the client's request pending a possible return.

Impact. Enabled but unused accounts widen the attack surface without any operational benefit and are routinely sampled in due diligence.

Recommendation. Disable rather than delete the two leave accounts, with a documented re-enable step; close the contractor account and re-provision if the engagement resumes.

Owner Client HR + BCS Target 2026-09-30 Ref ACCT-2026-08-03
Two staff still use SMS as their only second factor
LOW

Evidence. Thirty-nine of 41 staff use an authenticator app or a passkey; two retain SMS after replacing their handsets in August.

Recommendation. Re-enrol both users on the authenticator app during the September site visit and remove SMS as a permitted method for the tenant.

Owner BCS onsite Target 2026-10-31 Ref ACCT-2026-08-04
Closed this period · two staff accounts without MFA now enrolled
RESOLVED

The two accounts reported in July as exempt from multi-factor authentication were enrolled on 2026-08-06 and 2026-08-11, bringing staff coverage to 41 of 41. The conditional access policy no longer contains any user-level exclusion.

04 · Service level attainment

Five of five service levels met

Committed service levelTargetActualStatusNote
Leaver access revoked ≤ 4 hours 1.4 h avg MET 3 of 3 leavers
Joiner account ready By start date 2 of 2 MET Both provisioned one day early
MFA coverage for staff 100% 100% MET 41 of 41 accounts
Privileged access via vault 100% 100% MET 5 accounts, 23 checkouts logged
Monthly report issued By 5th working day 3rd working day MET Issued 2026-09-03
05 · Trend

Three-period movement

MetricJun 2026Jul 2026Aug 2026Direction of travel
Active accounts 54 53 52 Falling gently as leavers exceed joiners.
MFA coverage (staff) 37/42 39/41 41/41 Complete; no user-level exclusions remain.
Stale accounts > 90 days 6 5 3 Halved since June; two are approved leave cases.
Unowned service accounts 4 4 4 No movement — needs a client owner decision.
Mean leaver revocation 3.1 h 2.3 h 1.4 h Improving as the HR notification moved earlier.
Privileged checkouts 31 27 23 Declining with automation; all vault-logged.
Accounts by type · 52 total
Staff · 41 Privileged · 5 Service · 4 Shared / functional · 2

The five privileged accounts are separate administrative identities — four held by named staff or BCS engineers who also have a standard account, plus one sealed break-glass identity. The 41 staff figure counts each person's standard account only. The shared/functional pair is the operations mailbox and one certificate-based service principal.

06 · Detail data

Privileged and non-human accounts

Every account with administrative rights or without a human owner. Standard staff accounts are not listed individually; the full directory export is delivered separately.

AccountTypeRightsOwnerPwd ageMFAStatus
adm.a.chanPrivilegedGlobal admina.chan42 dPasskeyVAULTED
adm.m.wongPrivilegedIntune adminm.wong28 dAppVAULTED
adm.bcs.svc1PrivilegedServer adminBCS15 dAppVAULTED
adm.bcs.svc2PrivilegedNetwork adminBCS15 dAppVAULTED
brk.glass01Break-glassGlobal adminClient COO61 dPasskeySEALED
svc.backupServiceFile server write— none418 dNoneNO OWNER
svc.scan2foldServiceFile server write— none651 dNoneNO OWNER
svc.mdfeedServiceApp server read— none395 dNoneNO OWNER
svc.rptschedServiceFile server write— none602 dNoneRETIRE?
ops.mailboxSharedMailbox + licenceOps lead211 dNoneSHARED PWD
sp.backup.apiService principalGraph readBCSCertCertOK

Authentication methods and sign-in health

Method shares are of the 41 staff accounts. The five privileged identities are enrolled separately — two on passkeys, three on the authenticator app — and are listed individually in the table above.

Method / eventAccountsShareNote
Authenticator app (push + number match)3175.6%Tenant default; phishing-resistant number matching enforced.
Passkey / FIDO2819.5%Front-office staff who sign in from a fixed desk.
SMS only24.9%Re-enrolment scheduled — see finding.
Failed sign-ins blocked by policy184Mostly legacy-protocol attempts from outside HK and SZ.
Risky sign-ins flagged3All confirmed benign: two travel cases, one VPN exit change.
Password resets handled7All identity-verified through the service desk callback procedure.
07 · Risk register

Open items carried between periods

RefRiskSeverityOwnerDueStatusNext action
ACCT-R01 Unowned service accounts with stale passwords — 4 accounts, 3 with write access HIGH Client IT + BCS 2026-09-30 In progress Assign owners, vault credentials, rotate on 180 days.
ACCT-R02 Shared password on the operations mailbox — actions unattributable HIGH BCS Support Center 2026-09-30 Open Convert to a shared mailbox with delegated access; disable sign-in.
ACCT-R03 Enabled accounts with no recent sign-in — 3 accounts over 90 days MEDIUM Client HR + BCS 2026-09-30 Open Disable the two leave accounts; close the contractor account.
ACCT-R04 No documented account review cycle — reviews are performed but not evidenced MEDIUM Client IT + BCS 2026-11-30 Open Formalise the quarterly review with a signed attestation record.
ACCT-R05 SMS permitted as a second factor — weakest allowed method LOW BCS Support Center 2026-10-31 Open Re-enrol 2 users, then remove SMS from the tenant methods policy.

Next period commitments

BCS Support Center willClient is asked to
Convert the operations mailbox to delegated access and release the licence. Nominate a named business owner for each of the four service accounts.
Vault and rotate all four service account credentials once owners are named. Confirm whether the legacy report scheduler is still consumed.
Disable the stale accounts and document the re-enable procedure. Confirm the contractor engagement is closed.
Draft the quarterly account review attestation template. Nominate the approver for the quarterly account review.
Appendix · Method and definitions

How this report was produced

SourceExtractedRecordsUsed for
Entra ID directory export 2026-09-01 02:10 HKT 45 accounts Account state, last sign-in, MFA methods, role assignment.
On-premises directory 2026-09-01 02:15 HKT 7 accounts Service accounts, password age, group membership.
Sign-in and audit logs 2026-09-01 03:00 HKT 31 days Failed sign-ins, risky sign-ins, privileged checkouts.
HR joiner/mover/leaver feed 2026-08-31 6 events Lifecycle timing against the service level.
Credential vault log 2026-09-01 23 checkouts Privileged access evidence and rotation dates.

Method and definitions

Active account is any enabled identity capable of authenticating, in either directory or in an application-local store. Disabled and soft-deleted accounts are excluded from the count but retained for the audit trail for twelve months.

Privileged account is an identity holding an administrative role in the tenant, on a server, or on a network device. Privileged identities are separate from the holder's standard account and are counted separately.

Leaver revocation is measured from the HR notification timestamp to the last access removal, covering directory sign-in, mailbox, VPN, application logins and device enrolment. A leaver is only counted as complete when every one of those is revoked.

Exclusions. Entitlement detail — which files, mailboxes and application roles each account can reach — is reported quarterly in the Access & Permission Review. Microsoft 365 tenant security settings are reported in the M365 Security report.

Anonymisation notice

This copy is an anonymised sample prepared for illustration. The client name, account names, user identifiers and department labels have been replaced with fictitious values; counts, ratios, dates and findings reflect a representative managed identity estate. No real client data appears in this document.

Questions on this report
BCS Support Center · it-service@brocent.com
Brocent — Your Asia IT Team
Frequently asked

Questions clients ask about this report

What does joiner-mover-leaver evidence look like?

Every account created, changed or disabled in the period, with the HR trigger date, the action date and the elapsed time. Leaver timeliness is the single most examined control in an operational due-diligence review, so it is reported per account rather than as an average.

How are privileged and service accounts handled?

Privileged identities are listed individually every month with their justification and authentication method. Non-human service accounts are reported separately, because they are exempt from MFA by design and therefore need vaulting and rotation instead.

What counts as a dormant account?

No interactive sign-in for 90 days. Dormant accounts are reported with a recommendation to disable rather than delete, so that mailbox and file ownership are preserved for records purposes.

Next step

See what your own System Account Management report would say

A free IT health check produces a first version of this report against your real estate, at no cost and with no obligation. It takes about a week and needs a few hours of your team's time.

Book a free IT health check Contact BCS Support Center