Identity & sign-in
Know which accounts are active, how sign-in protections are applied and how urgent access revocation is handled.
Toronto / GTA professional firms
A practical self-review for professional-firm leaders who want clearer evidence about Microsoft 365 access, administrator roles, staff departures, sharing, recovery and IT ownership. It is not a compliance audit or formal security rating.
What does this scorecard evaluate? It organizes leadership questions around identity and sign-in controls, privileged administration, onboarding/offboarding, external sharing and email, device responsibility, backup/recovery, documentation and incident ownership. The goal is to identify what your firm can verify, what is only partly verified and what is still unknown.
Who it is for
Use it when a managing partner, COO, office administrator or operations leader needs to ask better questions of an internal IT team or current provider without starting with vendor jargon.
What to review
Know which accounts are active, how sign-in protections are applied and how urgent access revocation is handled.
Identify privileged accounts and whether broad roles have a documented operational reason.
Review onboarding, role changes and departures so old access is not left to assumption.
Clarify external access, guest-sharing ownership and the process for suspicious email or account activity.
Understand device responsibility, Microsoft 365 recovery expectations and who can show restore evidence.
Know who administers the environment, where documentation lives and who leads incident escalation.
How to score it
For every question, mark the state that best matches what can be demonstrated today.
Scorecard preview
The PDF contains the full worksheet and action pages. These questions are intentionally visible and useful without a form.
| Question | Evidence to look for |
|---|---|
| Who has privileged Microsoft 365 or Microsoft Entra administrator access? | Current role assignments and a named owner for review. |
| How is multifactor authentication applied to users and administrators where appropriate? | Current configuration or policy evidence rather than a verbal assumption. |
| What happens when an employee or contractor leaves? | A repeatable departure checklist covering sign-in, sessions, groups, apps, data and devices as applicable. |
| How are external sharing and guest access reviewed? | Known sharing settings, guest lists or access-review evidence appropriate to the environment. |
| Who owns email-security configuration and suspicious-account escalation? | A named internal/provider responsibility and escalation path. |
| Which business devices are managed, and who is responsible for access when a device is lost or reassigned? | Current device records and a repeatable support/security process. |
| Which Microsoft 365 data is covered by the firm’s recovery approach? | Documented scope, exclusions and ownership. |
| When was important data last restored successfully? | Recent restore/test evidence for the actual data or scope tested. |
| Where is current administration and recovery documentation stored? | A location accessible to authorized people during an incident. |
| Who owns unresolved access, security or recovery gaps? | A named owner and next action rather than an open-ended issue list. |
Questions for your IT provider
Technical reference notes
Scallex uses these references to bound the checklist. Microsoft documentation remains the authority for current product behaviour and configuration requirements.
Technical references reviewed August 17, 2026.
Next step
Use the Free IT Assessment when access, recovery or ownership questions need a broader business IT review. The assessment is a separate next step from this ungated resource.