Contoso Legal LLP
Needs attention
9-
high
Sign-in is blocked but the account still holds Directory Readers, Groups Administrator. Remove the roles.Details
-
high
LAPTOP-MARSH: Not compliant; Not encrypted; Windows 10 stopped getting security updates on 14 Oct 2025. Extended Security Updates or LTSC can cover it; otherwise upgrade; No check-in for 45 days.Details
-
high
9 failed sign-ins in the last 7 days, 8 with a wrong password, and locked out. If the person didn't make them, someone is guessing the password: make sure MFA is enforced.Details
-
medium
Sign-in is blocked but the account still holds 1 paid licence (£18.10 a month). Remove them or convert the mailbox to shared.Details
-
medium
Sign-in is blocked but the account still administers Branch offices. Remove the roles.Details
-
medium
Owned Marketing, Project Phoenix and sign-in is now blocked, so nobody active looks after them. Add a new owner.Details
-
low
No usage location is set, so licences can only come from groups (which use the organisation's country). Set one before assigning a licence directly.Details
-
low
Sign-in is blocked but the account can still open or send from 1 other mailbox.Details
-
low
Sign-in is blocked and the OneDrive still holds 39.9 GB. Move what's needed before the account is deleted.Details
Open findings
All findings- medium
No licences on disabled accountsDisabled, holding 1 licence · since 6 Sep 2026
Before you close this account
9 things to do, £18.10 a month
- Licence cost
- £18.10 a month, £217.20 a year
Before you close this account 9
| Area | What's left | What to do |
|---|---|---|
| Licence | Microsoft 365 Business Premium (£18.10 a month) | Remove the licence once the mailbox and files below are dealt with. It comes from All Staff, so take them out of that group. |
| Mailbox | User mailbox bobby.marsh@contoso.example, 25.0 GB | Convert it to a shared mailbox so colleagues can keep using it, then remove the licence. Shared mailboxes under 50 GB need no licence. |
| Mailbox access | Can open or send from accounts@contoso.example | Remove this person's access to that mailbox. |
| OneDrive | 39.9 GB in 50 files | Give their manager access or move what's needed elsewhere. Microsoft deletes the OneDrive some time after the account is deleted (30 days unless the tenant has changed it). |
| Device | LAPTOP-MARSH (Windows 10 (10.0.19045.5011)) | Collect it, then wipe or retire it in Intune. |
| Group owner | Only owner of Marketing (group) | Make someone else an owner, or nobody will be able to manage the group. |
| Group owner | Only owner of Project Phoenix (team) | Make someone else an owner, or nobody will be able to manage the team. |
| Admin role | Directory Readers | Remove the role. Admin roles left on an unused account are a common way in for attackers. |
| Admin role | Groups Administrator | Remove the role. Admin roles left on an unused account are a common way in for attackers. |
Office Sentry only reports; make these changes in the Microsoft 365 admin centre.
Licences
1 licence, £18.10 a month
- Usage location
- Not set
Licences 1
| Licence | Assigned | Cost / month |
|---|---|---|
| Microsoft 365 Business Premium | By group: All Staff | £18.10 |
Microsoft 365 use
No activity in 30 days
- Not in the last 30 days
- Teams
- Not in the last 30 days
- OneDrive
- Not in the last 30 days
- SharePoint
- Not in the last 30 days
- Office apps
- Not in the last 30 days
From Microsoft's usage reports, which run a couple of days behind (as of 9 Oct 2026).
MFA and sign-in protection
Unknown
- MFA set up
- Unknown
- MFA required by
- Require MFA for all users
- Conditional Access policies that apply
- Require MFA for all users
- Legacy sign-in blocked
- No
Admin roles
Directory Readers and 1 more
| Role | How assigned | Scope | Privileged |
|---|---|---|---|
| Directory Readers | Active | Whole directory | No |
| Groups Administrator | Active | Limited scope | No |
Administrative units
Administers 1, In 1
| Unit | Relationship | Membership | Restricted |
|---|---|---|---|
| Branch offices | Administers as Groups Administrator | Dynamic (paused) | Yes |
| Branch offices | Member | Dynamic (paused) | Yes |
Teams and groups
Owner of 2, member of 0
| Name | Type | Role | Note |
|---|---|---|---|
| Project Phoenix | Team | Owner | No active owner left |
| Marketing | Microsoft 365 group | Owner | No active owner left |
Members are read for teams, Microsoft 365 groups and groups used by Conditional Access. For other security groups and distribution lists only owners show.
Mailbox
25.0 GB
- Address
- bobby.marsh@contoso.example
- Type
- User
- Size
- 25.0 GB of 49.5 GB (50%)
- Archive
- Off
- Litigation hold
- Off
- Forwarding
- None
- Older protocols allowed
- None
- More
- Everything about this mailbox
Mailboxes this person can open or send from 1
| Mailbox | Type | Access |
|---|---|---|
| accounts@contoso.example | Shared | Full access |
Devices
1 device, 1 with problems
| Device | Operating system | Compliance | Encrypted | Last check-in | Problems |
|---|---|---|---|---|---|
| LAPTOP-MARSH | Windows 10 (10.0.19045.5011) | Not compliant | No | 45 days ago | Not compliant; Not encrypted; Windows 10 stopped getting security updates on 14 Oct 2025. Extended Security Updates or LTSC can cover it; otherwise upgrade; No check-in for 45 days |
OneDrive
39.9 GB
- Storage used
- 39.9 GB of 1.00 TB
- Files
- 50
- Files active in the last 30 days
- 5
- Last activity
- 7 Oct 2026
Apps this person allowed
None
Hasn't consented to any app on their own behalf.
Recent sign-ins
9 sign-ins, 9 failed
- Successful
- 0
- Failed
- 9 (8 wrong password, 1 lockout, from 3 addresses)
- Last failure
- 8 Oct 2026 (3 days ago): Account is disabled
- Countries
- RU, GB, BR
- Apps
- Office 365 Exchange Online
- Devices
- Windows10
- Addresses that failed
- 198.51.100.7, 192.0.2.10, 203.0.113.66
Where this account signed in 3
| Country | Successful | Failed | Cities | IP addresses | Last success (UTC) |
|---|---|---|---|---|---|
| BR | 0 | 1 | Sao Paulo | 203.0.113.66 | |
| GB | 0 | 1 | London | 192.0.2.10 | |
| RU | 0 | 7 | Moscow | 198.51.100.7 |
Why sign-ins failed 3
| Error code | What it means | Sign-ins |
|---|---|---|
| 50126 | Wrong user name or password | 7 |
| 50053 | Locked out: too many wrong passwords (smart lockout), or the address is known to be malicious | 1 |
| 50057 | Account is disabled | 1 |
Interactive sign-ins in the last 7 days from the Entra ID sign-in log. MFA and other prompts aren't counted as failures.
Sign-in history
Signed in on 3 days of the last 30
- History from
- 13 Jun 2026
- Last sign-in
- 8 Oct 2026 (3 days ago)
- Countries
- BR, GB, RU
Sign-ins by month 1
| Month | Days | Successful | Failed | With MFA | Password only | Countries |
|---|---|---|---|---|---|---|
| Oct 2026 | 3 | 0 | 9 | 0 | 0 | BR, GB, RU |
Every interactive sign-in since 13 Jun 2026, from the activity history's daily summaries, kept as long as Data retention says (25 months by default).
Sign-ins and admin changes
Never
- Last interactive sign-in
- Never
- Last background sign-in
- Never
- Last successful sign-in
- Never
- Legacy sign-ins (30 days)
- None
Admin changes in the last 120 days 2
| When (UTC) | Change | By | Target | Detail |
|---|---|---|---|---|
| 9 Oct 2026, 20:31 | Add member to role | admin@contoso.example | bobby.marsh@contoso.example | Global Administrator |
| 8 Aug 2026, 20:31 | Add member to role | admin@contoso.example | bobby.marsh@contoso.example | Global Administrator |
Office Sentry keeps this tenant's sign-in log from 13 Jun 2026: each day is under Sign-in history, and the last week in detail under Recent sign-ins. Legacy sign-ins and the last sign-in dates show here.
Timeline
5 events
| When | Area | What happened |
|---|---|---|
| 9 Oct 2026, 20:31 UTC | Admin change | Add member to role: Global Administrator (by admin@contoso.example) |
| 8 Oct 2026, 09:00 UTC | Sign-in | Last of 9 failed sign-ins: Account is disabled |
| On or before 6 Sep 2026 | Admin roles | Directory Readers role first seen |
| On or before 6 Sep 2026 | Admin roles | Groups Administrator role first seen |
| 8 Aug 2026, 20:31 UTC | Admin change | Add member to role: Global Administrator (by admin@contoso.example) |
Newest first, the last 90 days (up to 50 events). Admin changes and sign-ins keep their own time; rules, forwarding, app consents, MFA methods and roles are dated when Office Sentry first collected them, so they were set up on or before that day.
History
No changes spotted since 6 Sep 2026.
Found by comparing collections since 6 Sep 2026. The date is when Office Sentry first saw the change.
Data from Users (), MFA registration (), Conditional Access (), Admin roles (), Groups and Teams (), Mailboxes (), Inbox rules (), Mailbox size (), Devices (), SharePoint and OneDrive usage (), Shared files (), Apps and consents (), Legacy sign-ins (), Sign-in activity (), Admin activity ().