- Home
- Microsoft 365
- Microsoft 365 Access Audit
Who can still open your shared mailboxes?
Most South African businesses cannot answer that question. Staff leave, a licence gets removed, and the delegated access, the forwarding rule and the app password quietly stay behind. We will audit exactly who can reach your Microsoft 365 mailboxes and files — free, with written findings back to you within one working day of getting access.
- Free — no obligation, no contract, not a sales audit in disguise
- Written findings within one working day of getting access
- Covers shared mailboxes, delegated access, forwarding rules and old accounts
- Run by an ISO/IEC 27001:2022-certified team, in SA, since 1999
“Finally, an IT company that catches problems before we do.”
Send this and a named technician calls you back to set the audit up — read-only access or a screen-share, your choice.
MiBOT runs a free Microsoft 365 access audit for South African businesses: we list every person, device and forwarding rule that can still reach your shared mailboxes, delegated folders and files, flag the accounts that should have been closed, and send you written findings within one working day of getting read-only access. No obligation, and no contract to sign first.
What the audit actually looks at
Shared and delegated mailboxes
Every person who can open info@, accounts@, admin@ or any other shared mailbox — including access granted years ago to someone who has since left. You get the list by mailbox, by name.
Forwarding and transfer rules
Rules that quietly send a copy of incoming mail somewhere else — a personal address, an old supplier, a mailbox nobody monitors. These survive a person leaving and are the ones owners are most surprised by.
Dormant accounts and live sessions
Accounts that have not signed in for months but are still enabled, licences still being paid for, phones and tablets still holding a valid session, and app passwords issued to tools you no longer use.
Shared files and external guests
SharePoint and OneDrive links shared outside the business, guest accounts added for a project that ended, and folders shared with "anyone with the link" — the file-side equivalent of the mailbox problem.
How the free audit runs
- 2 minutes
You request it
Fill in the form with your name and a phone number. That is the whole commitment — no contract, no card, no procurement process.
- Within 1 hour, business hours
We call you back
A named MiBOT technician calls you within 1 hour during business hours to agree how we look: either read-only delegated access to your tenant, or a guided screen-share where you stay in control the whole time.
- Same day
We run the audit
We work through mailbox permissions, forwarding and transfer rules, dormant accounts, active sessions, app passwords and external file sharing. We change nothing — this is a read and a report, not a clean-up.
- Within one working day
You get written findings
A plain-English document within one working day of us getting access: who can reach what, what looks wrong, and what we would close first. It is yours to keep and act on, with us or with whoever runs your IT.
The person who left in March can probably still read info@
It is almost never deliberate. Someone resigns, the handover happens, their laptop comes back, and their user licence gets removed to stop paying for it. What does not get removed is the delegated access they were given to the shared mailbox two years ago, the rule that quietly forwards a copy of every invoice to a personal Gmail, or the phone that is still signed in because nobody revoked the session.
The uncomfortable part is not that it happened. It is that most owners have no way to check. Microsoft 365 will happily tell you — but only if you know which four screens to open, and the answer is spread across mailbox permissions, transfer rules, sign-in logs and app passwords. So the honest answer to "who can read our client email?" ends up being a shrug and a hope that IT sorted it.
That shrug is the actual problem. Under POPIA you are responsible for the personal information in those mailboxes, and if it does leak you have to notify the Information Regulator and the affected people as soon as reasonably possible — which is very hard to do well when you are still working out who had access in the first place. Knowing beats hoping, and knowing takes about a day.
- 25+
- Years in SA IT
- ISO 27001
- Certified ISMS (2022)
- Dual
- Offices Centurion + Rustenburg
- <1hr
- Response on logged incidents
- Monthly
- Reports to operators
Why trust us with a look inside your tenant
MiBOT has been doing South African IT since 1999 — 25+ years of it — from two offices: Centurion (54 Union Avenue, Kloofsig) and Rustenburg (193a Kock Street). Remote support is nationwide. The person who calls you back has a name and stays your contact.
Our information security management system is certified to ISO/IEC 27001:2022, independently audited by TNV Global (UAF-accredited, IAF MLA signatory). That matters here for one practical reason: you are about to let someone look at where your client information lives, and how we handle that access is itself audited rather than merely promised.
We are an IT partner, not a compliance consultancy. The audit gives you the technical facts that support your POPIA obligations — who had access to what — so your legal or compliance adviser can do their part properly. We do not sell you a compliance certificate and we do not tell you that you are compliant.
And no, this is not a sales audit. You get the findings whether or not you ever become a client. If the honest answer is that your current setup is fine, we will tell you that — under-promising is cheaper for us than a client who feels sold to.
Free Microsoft 365 access audit — FAQ
Is the audit really free, or is it free until the report arrives?
Really free. You get the written findings with no obligation and no contract, and they are yours to act on however you like — including handing them to whoever currently runs your IT. We do it because it is the most useful first conversation we can have with a business we have never worked with.
What access do you need, and can you change anything?
Either read-only delegated access to your Microsoft 365 tenant, or a guided screen-share where you drive and we tell you what to open. Read-only is faster; screen-share is fine if you would rather not grant anything. Either way we change nothing during the audit — remediation is a separate, explicit decision you make afterwards.
How long does it actually take?
The call to set it up takes a few minutes. The audit itself is same-day work. You have written findings within one working day of us getting access — so if we get access on a Thursday morning, you have the report by Friday.
We already have an IT provider. Is this a poaching exercise?
No. Plenty of businesses run this audit and stay exactly where they are — the report is written so you can hand it straight to your current provider. If it does surface things that should have been caught, that is a conversation for you to have with them, not one we will have for you.
Does this make us POPIA compliant?
No — and be careful of anyone who says it does. POPIA compliance is a legal and organisational programme your compliance or legal adviser owns. What this audit gives you is the technical evidence underneath it: a current, factual answer to who can access personal information in your mailboxes and files, which is exactly what you cannot produce on the day something goes wrong.
What happens if you find something bad?
We tell you plainly, in priority order, with what we would close first. Straightforward things — revoking stale delegated access, killing an unknown forwarding rule, disabling a dormant account — are usually a short piece of work. If you want us to do it, we quote it. If you want to do it yourself, the report tells you exactly what to change.
What does it cost to have MiBOT run our IT afterwards?
Managed IT is R450 per user per month excl VAT on a 12-month contract, which covers unlimited remote support, patch management, network monitoring, antivirus and anti-ransomware, and a sub-1-hour response on logged incidents. Microsoft 365 management, backup and recovery, VoIP and cloud services are add-ons quoted separately — we would rather tell you that up front than surprise you on the first invoice.
Who typically asks for this?
Mostly owners and office managers at 10-80 person professional-services firms — law firms, accounting and audit practices, medical practices, financial advisers — where the shared mailbox holds client information and somebody has recently left. Any SA business on Microsoft 365 can request it.
Try us with zero risk on your side
No money-back gimmicks — just transparent terms and a free assessment so you know exactly what you’re getting before you commit a cent.
Start with a free IT assessment
We come in and do a proper technical review of what you’ve got — servers, network, endpoints, backup state, security posture — not a sales exercise. No obligation, no cost.
Flat R450/user/month — no surprise call-out fees
What we quote is what you pay. One predictable per-user line item every month, excl VAT — never an unexpected after-the-fact call-out invoice.
A documented SLA you can hold us to
Before you sign, you see exactly what’s in scope: response targets, reporting cadence, escalation paths. Transparent terms, written down — not a verbal promise.
Sub-1-hour response on logged incidents
Critical incidents are prioritised immediately. Most problems we catch through proactive monitoring before your team even notices them.
Managed IT across our service area
Other areas we cover
What's included
Service specialisations by city
IT support by industry
If you are not sure who still has access, find out this week
It is one form, one short call, and a written answer within one working day. Then you know — and the next time a client, an insurer or a tender asks who can read their information, you have a real answer instead of a hope.
Get my free access audit →