Microsoft 365 lifecycle & offboarding security checks
Dormant accounts, leavers with access, unowned assets and change-management gaps — the checks that catch what HR processes miss.
On Microsoft 365, Black Cat runs 5 checks in this area on every scan. Each one below lists its severity, how to fix it, and the compliance controls it satisfies where a control applies. See what access the Microsoft 365 connector needs.
Checks (5)
severity: high Copilot Agent No Owner fix difficulty: easy #
Assign an owner to the Copilot agent
- Open Power Platform Admin Center
- Locate the agent and assign an active owner
Satisfies: NIS2 Directive NIS2-21.i.2 DORA (SaaS Security) DORA-9.6
severity: low Copilot Agent Never Published (30+ days) fix difficulty: easy #
Publish or delete unused draft agents older than 30 days
- Open Power Platform Admin Center > Copilot Studio
- Review the draft agent and publish it or delete if no longer needed
Satisfies: NIS2 Directive NIS2-21.i.2 DORA (SaaS Security) DORA-9.6
severity: critical Copilot Agent Quarantined fix difficulty: medium #
Investigate and resolve the quarantine on this agent
- Open Power Platform Admin Center > Copilot Studio
- Check quarantine reason and remediate (usually DLP violation)
- Request un-quarantine after fixing the root cause
Satisfies: NIS2 Directive NIS2-21.i.2 DORA (SaaS Security) DORA-9.6
severity: low Copilot Agent Stale (90+ days inactive) fix difficulty: easy #
Review and disable or delete agents inactive for over 90 days
- Open Power Platform Admin Center > Copilot Studio
- Review the agent activity and usage
- Disable or delete if no longer needed
Satisfies: NIS2 Directive NIS2-21.i.2 DORA (SaaS Security) DORA-9.6
severity: high Copilot Agent Orphaned Owner fix difficulty: easy #
Reassign the agent to an active owner
- Verify the current owner is indeed inactive in Entra ID
- Transfer ownership to an active team member
- Update the agent configuration
Satisfies: NIS2 Directive NIS2-21.i.2 DORA (SaaS Security) DORA-9.6