6 Steps to Audit Cloud Access Permissions
A cloud access permissions audit finds stale logins, over-shared files, and risky settings before they become a liability. Work through this checklist today.
Key Takeaways
- Stale accounts from former employees are one of the most common and preventable cloud security gaps.
- Every cloud app must be reviewed separately — permissions rarely sync across platforms automatically.
- Least-privilege access means each user gets only the minimum permissions their role actually requires.
- Shared or generic login accounts make it impossible to trace who accessed or changed what.
- A permissions audit is most effective when scheduled at least once per quarter, not just after incidents.
A cloud access permissions audit is a structured review of who can access which cloud applications, files, and settings in your organisation — and whether that access is still appropriate. Done properly, it closes the gaps left by staff turnover, role changes, and years of accumulated sharing habits that nobody is actively managing.
Why Does Cloud Access Go Stale So Quickly?
Cloud apps make it easy to grant access and easy to forget about it. Every time someone joins, moves roles, or leaves, permissions should change — but in practice they often don't. The result is a sprawl of accounts and shared folders with no clear owner and no expiry date.
Former employee accounts left active are one of the most exploitable entry points in any cloud environment. They require no sophisticated attack — just a leaked password and an unlocked door that was never closed when the person walked out. Offboarding checklists that include cloud app deprovisioning are the simplest way to prevent this, but many organisations still rely on informal processes that miss several apps every time.
How Do You Run a Cloud Access Permissions Audit?
Step 1: List Every Cloud App Your Organisation Uses
Start with a complete inventory. Include productivity suites, file storage, accounting software, CRM tools, communication platforms, and any industry-specific apps. Don't overlook shadow IT — applications staff signed up for without formal approval. A quick team survey often surfaces tools that never appeared on any approved list. Document every app in a single spreadsheet so nothing falls through the cracks during the review.
Step 2: Export the Full User List for Each App
Most cloud platforms let an administrator export a list of all active accounts. Pull this report for every app on your inventory. Look for accounts tied to email addresses that no longer exist at your organisation, generic logins like info@ or admin@ shared by multiple people, and any accounts that show no login activity in the past 90 days. These are your highest-priority items to investigate and act on first, before moving further down the list.
Step 3: Check Permission Levels Against Current Roles
For each active account, confirm that the assigned permission level matches what the person actually needs today — not what they needed when they first joined. Pay particular attention to anyone holding administrator or owner-level access. Broad administrative rights should be held by as few people as possible, and only those whose current role genuinely requires them. Downgrade any account where the elevated access is no longer justified. If you are unsure whether someone still needs a permission, temporarily revoke it and ask — it is far easier to restore access than to recover from an incident caused by an account that should have been closed months earlier.
Step 4: Review Shared Files, Folders, and External Links
File-sharing settings deserve their own pass. In platforms like Google Workspace or Microsoft 365, documents can be set to
Darryl Cresswell
CEO & President
MYDWARE IT Solutions Inc.