SpySecure® | Knowledge

7 Entra ID & Google Workspace security gaps | SpySecure®

Written by SpySecure | Aug 7, 2026, 6:00:00 AM

The security tools are usually already there. The problem is that nobody has checked whether the settings apply to every account or whether old access has actually been removed.

Jump to: Seven gapsWhy they persistThree questions

7 common security gaps

For each gap, we explain what can go wrong and what to ask your IT team or provider to check.

 
GAP 1

Daily user accounts also have administrator rights

An administrator uses the same account for e-mail, browsing and administrative work. If that account is compromised, the attacker can gain administrator access too.

✓ Check this nowAsk for a list of all administrator accounts and roles. Every administrator should use a separate, named admin account with MFA and only the rights they need. That account should not be used for e-mail or browsing.
 
GAP 2

MFA is set up, but not enforced

An employee can register an MFA method without being required to use it. Some users, administrators or exceptions may still be able to sign in with only a password.

✓ Check this nowAsk which policy enforces MFA and which accounts it covers. Check all users and administrators, then review and document every exception.
 
GAP 3

Several people use the same login

Addresses such as info@, finance@ or support@ sometimes use one shared password. You can no longer see who did what, and MFA and offboarding become much harder.

✓ Check this nowList every generic account. Give each employee access through their own account. In Microsoft 365, use a shared mailbox with delegated access. In Google Workspace, use mailbox delegation or the appropriate Google Group.
 
GAP 4

Company e-mail is forwarded externally

Messages can be sent automatically to private or external inboxes. This takes company information outside your normal access, retention and monitoring controls. Old forwarding rules are often forgotten.

✓ Check this nowAsk for a list of all external forwarding and routing rules. Block automatic external forwarding by default, document approved exceptions and monitor newly created rules.
 
GAP 5

Guests still have access they no longer need

A customer, supplier or former contractor may still have access after a project ends. Often nobody knows which Teams, SharePoint sites or Google Drive folders they can still open.

✓ Check this nowList all external users and what they can access. Give every guest a business owner, remove access that is no longer needed and repeat this review regularly.
 
GAP 6

Old accounts and access remain active

Former employees may have access beyond their Microsoft or Google account, including groups, applications, delegated mailboxes, shared files and other SaaS platforms. That access must also be removed.

✓ Check this nowCompare the current employee list with active accounts in Microsoft 365, Google Workspace and important SaaS applications. End active sessions, remove group and delegated access, and transfer required data.
 
GAP 7

You keep paying for unused licences

Accounts and licences often remain after an employee leaves or changes role. This costs money and is a clear sign that old accounts are not being cleaned up consistently.

✓ Check this nowCompare the licence invoice with the current employee and account lists. Confirm which shared or service accounts still need a licence. Transfer required data before removing or downgrading anything.

Why nobody notices these gaps

Most gaps develop gradually. A temporary exception becomes permanent, an old account is forgotten or everybody assumes someone else is checking.

 

Small changes add up

New employees, teams, applications and exceptions are added. Old access is removed less consistently.

 

Nobody checks the complete setup

An IT provider may keep the platform running, while security settings and access reviews are not part of the agreement.

 

Management gets no proof

A setting is reported as “enabled”, but there is no current list of covered accounts, exceptions or follow-up.

Start with three simple questions

You do not need to understand every Microsoft or Google setting. Ask your IT team or provider:

1Which user and administrator accounts can still sign in without MFA or have more rights than they need?
2Which shared accounts, guests and external forwarding rules exist, and who approved each one?
3Which accounts, access rights and paid licences should already have been removed?

Ask to see current account lists or reports, not just a verbal confirmation.

Want to know what this looks like in your environment?

Use the contact button at the bottom right or click below. We can help you review your Microsoft 365 or Google Workspace setup.

Talk to us → Technical references