Advanced (更新: 2026/7/19)

小型制作公司的 Entra ID 权限盘点

用 Claude Code 检查离职账号、共享账号、组、应用和 Entra ID 日志。

小型制作公司的 Entra ID 权限盘点

小型制作公司的 Microsoft 365 权限经常比项目活得更久。设计师已经离职,社媒共享账号还在用,客户 guest 仍留在 Teams,旧管理员角色没人敢动。第一步不是让 AI 删除账号,而是把 Entra ID 用户列表、组、企业应用、sign-in logs 和 audit logs 放进一张盘点表。

Key Points

  • 分开查看用户、组、应用、共享账号、guest 和角色。
  • Access reviews 可用于定期检查组和应用访问。
  • Audit logs 与 sign-in logs 显示变更和近期使用。
  • Claude Code 准备表格,人来批准操作。
  • 观察离职后仍启用账号、无 owner 共享账号、长期未用组和盘点时间。

Workflow: Build The Review Table First

先建立表格:离职日期、accountEnabled、组、应用、角色、owner 和最后登录。交给 Claude Code 前,把真实姓名、邮箱和客户名替换成样例 ID。

SourceReview fieldHuman decision
Usersleave date, accountEnabled, departmentHR status and exceptions
Groupsowner, guests, project endclient access and contract
Enterprise appsassignment, shared account, rolebusiness need and license
Sign-in logslast activity, failuresleave, exception, or cleanup
Audit logswho changed whatapproval trail

Primary sources checked: access reviews, create access reviews, audit logs, sign-in logs, Lifecycle workflows, sharing accounts, and security defaults.

What Claude Code Does And What Humans Decide

Claude Code can clean an anonymized CSV, find enabled leavers, ownerless shared accounts, stale assignments, old privileged roles, and missing owners. Humans decide disablement, deletion, license removal, role removal, guest removal, shared-account replacement, and emergency-account policy.

3 Use Cases

Use case 1: Find enabled leavers

  • Input: user list, leave date, accountEnabled, groups, app assignments, last sign-in.
  • Output: enabled leavers, remaining groups, app assignments, review owner.
  • Human review: HR status, contractor continuation, mailbox retention, legal hold, approval.

Use Claude Code to prepare a candidate list. Do not let it delete accounts.

Use case 2: Review shared accounts

  • Input: shared account list, app name, owner, MFA, last sign-in, department.
  • Output: ownerless shared accounts, weak authentication, high permission, long-lived access.
  • Human review: whether to move to app assignment, SSO, or another managed pattern.

The first win is visibility: owner, app, authentication method, and review date.

Use case 3: Run monthly group cleanup

  • Input: groups, app assignments, owners, guests, last use, project end date.
  • Output: review target, owner message, keep reason, removal candidate, next review date.
  • Human review: client contract, project continuation, privileged role, audit needs.

Start with client-share groups, external guests, and admin roles.

Copy-Paste Prompt

Act as a Microsoft Entra ID access review assistant for a small agency.
Prepare a human-review table for leavers, shared accounts, stale groups, guests, and privileged roles.

Check enabled leavers, ownerless shared accounts, weak shared-account authentication, unused assignments, stale privileged accounts, and groups with guests.
Never issue deletion or disable commands.
Use anonymized IDs only.
Return the five rows to inspect today.

Working Check Code

// verify-entra-access-review.mjs
// No dependencies. Run with: node verify-entra-access-review.mjs
const accounts = [
  {
    userPrincipalName: "[email protected]",
    department: "design",
    employeeLeaveDate: "2026-06-30",
    accountEnabled: true,
    lastSignInDaysAgo: 2,
    groups: ["client-a-share", "figma-admin"],
    roles: [],
    mfa: true,
    owner: "manager-01"
  },
  {
    userPrincipalName: "[email protected]",
    department: "marketing",
    employeeLeaveDate: null,
    accountEnabled: true,
    lastSignInDaysAgo: 1,
    groups: ["social-media-tools"],
    roles: [],
    mfa: false,
    owner: ""
  },
  {
    userPrincipalName: "[email protected]",
    department: "it",
    employeeLeaveDate: null,
    accountEnabled: true,
    lastSignInDaysAgo: 120,
    groups: [],
    roles: ["Global Administrator"],
    mfa: false,
    owner: "it-lead"
  }
];

const problems = [];
const today = new Date("2026-07-19T00:00:00Z");

for (const account of accounts) {
  if (account.employeeLeaveDate && new Date(account.employeeLeaveDate + "T00:00:00Z") < today && account.accountEnabled) {
    problems.push({ account: account.userPrincipalName, item: "leaver still enabled", fix: "disable account or run the approved offboarding workflow" });
  }
  if (account.userPrincipalName.includes("shared") && !account.owner) {
    problems.push({ account: account.userPrincipalName, item: "shared account owner", fix: "assign an accountable owner and review app assignment" });
  }
  if (account.userPrincipalName.includes("shared") && !account.mfa) {
    problems.push({ account: account.userPrincipalName, item: "shared account MFA", fix: "replace direct password sharing with controlled app access or strong authentication" });
  }
  if (account.roles.length > 0 && account.lastSignInDaysAgo > 90) {
    problems.push({ account: account.userPrincipalName, item: "stale privileged account", fix: "review role need, sign-in logs, and break-glass policy" });
  }
  if (account.groups.length > 0 && account.lastSignInDaysAgo > 30) {
    problems.push({ account: account.userPrincipalName, item: "group access review", fix: "ask the group owner to approve, deny, or remove access" });
  }
}

if (problems.length > 0) {
  console.table(problems);
  process.exitCode = 1;
} else {
  console.log("Entra ID access review checklist passed.");
}

Pitfall: Common Failure Cases

The first failure is using last sign-in as the only signal. Add leave date, owner, role, exception, and approval. The second failure is leaving shared accounts ownerless. The third failure is reviewing users but missing groups. The fourth failure is letting AI decide deletion. Claude Code prepares candidates; humans approve changes.

FAQ

Q. What should a small team review first?

A. Enabled leavers, ownerless shared accounts, and stale privileged accounts.

Q. Are access reviews only for large companies?

A. No. Start with client-share groups, guests, and privileged roles.

Q. Can shared accounts remain?

A. Sometimes, but owner, app purpose, authentication method, and review date must be visible.

Q. Can Claude Code read real logs?

A. Use anonymized CSV data. Do not include real names, emails, client names, phone numbers, or contracts.

Training And Consultation Signal

Measure enabled leavers, ownerless shared accounts, stale groups, guests, review time, and inquiry rate. If those numbers hurt, Entra ID review operations are a fit for ClaudeCodeLab training.

What I Verified

I checked Microsoft Learn references for access reviews, audit logs, sign-in logs, Lifecycle workflows, shared accounts, and security defaults. I also checked the CTA, executable JavaScript, internal link, external links, locale coverage, and queue removal.

#claude-code #制作公司 #entra-id #access-review #offboarding
免费

免费 PDF: Claude Code 速查表

输入邮箱即可获取一页 PDF,整理常用命令、审查习惯和安全工作流。

我们会妥善保护你的信息,不发送垃圾邮件。

让 Claude Code 真正进入可验证的工作流

先用免费 PDF 固定基础,再用 Gumroad 教材复用工作流;如果涉及团队导入、权限或收入路径,可以直接咨询。

Masa

关于作者

Masa

专注 Claude Code 实务流程、团队导入和内容转化的工程师。