How a Global Manufacturer Used CoreView to Reduce Microsoft 365 Admin Risk Across a 3,000-User Tenant

How a Global Manufacturer Used CoreView to Reduce Microsoft 365 Admin Risk Across a 3,000-User Tenant
SUMMARY
  • A global manufacturing company needed to manage Microsoft 365 administration for roughly 3,000 users across multiple continents with a small central IT team and regional support staff.
  • Native Microsoft 365 controls made it difficult to limit regional admins’ access to the users and resources they were responsible for managing.  
  • Manual reporting, access reviews, and onboarding and offboarding processes also made it difficult to maintain consistent governance across the tenant.
  • CoreView now provides the company with scoped administration across 42 Virtual Tenants, more than 70 automated workflows, and improved visibility into license usage, user activity, and administrative actions.
  • The company is now evaluating Configuration Manager to extend its governance model into Microsoft 365 configuration backup and drift detection.

Download case study

Background: A Global Manufacturer Managing Microsoft 365 with a Lean IT Team

This global manufacturing company has roughly 3,000 Microsoft 365 users across multiple continents. With a small central IT team managing the tenant and regional support staff handling day-to-day administration, the company needed a more scalable way to govern access, user management, and routine Microsoft 365 processes.

Challenge: Giving Regional Support Teams the Access They Needed Without Increasing Risk

With a lean IT team supporting a global Microsoft 365 environment, the company needed regional support staff in India and the Dominican Republic to take on day-to-day administrative tasks. Native permissions, however, often extended beyond the users and resources each administrator was responsible for managing.  

This created a clear access-control risk. With administrators able to reach more of the tenant than their roles required, a compromised account, human error, or deliberate misuse could have far-reaching consequences.  

Those consequences carry particular weight in a global manufacturing environment, where identity and access decisions can affect production systems, supply chain data, and operational continuity.  

The team also lacked a reliable way to spot when access and usage drifted from their intended state. Licenses could remain assigned unnecessarily, user accounts could stay active after roles changed, and checking who had access to what relied on manual reporting.  

Native Microsoft 365 Controls Left Too Much Reliance on Manual Process

Microsoft 365’s native administrative model did not give the global manufacturing company a straightforward way to scope permissions by region, business unit, or user groups without significant custom development.

As a result, central IT handled what it could directly, while regional support staff operated with permissions that were not always tightly aligned to their responsibilities. Access reviews were manual and infrequent, making ongoing permission checks difficult to conduct consistently.  

Onboarding and offboarding depended on manual workflows, too. Administrators had to complete the required steps in the correct order, with no automated mechanism to ensure every step was completed.

For a lean IT team managing a global environment, these manual processes left too much room for inactive accounts, outdated access, and unused licenses to persist unnoticed.  

Quote top graphic

Solution: Scoped Administration and Automated Workflows Across the Microsoft 365 Tenant

The company implemented CoreView in 2018 to bring more structure and control to its Microsoft 365 administration.

Using CoreView Virtual Tenants, the team created 42 defined administrative scopes across the environment. Support staff in India and the Dominican Republic can now manage the users and resources within their areas of responsibility without extending their reach across the wider tenant.

The company has also used CoreView to build more than 70 automated workflows for processes including onboarding and offboarding. These workflows enforce a defined sequence of steps, removing the need for administrators to carry out each step manually.

Results: Microsoft 365 Administration with Clearer Boundaries and Less Manual Risk

CoreView has made the company’s Microsoft 365 administration more consistent, structured, and easier to govern.  

The core benefits of this shift have included:

  • More auditable administration: Seven tenant admins now operate within defined scopes, giving the team a clearer record of who took which actions, where, and when.
  • Better visibility into license and user exposure: CoreView’s reporting capabilities help surface unused licenses, inactive accounts, and outdated access rights.
  • More consistent onboarding and offboarding: Automated workflows reduce reliance on memory and manual checklists.
  • Less reliance on broad permissions: Regional support teams can do their jobs without requiring access across the full Microsoft 365 tenant.

Together, these changes have given the company a more robust approach to Microsoft 365 administration, reducing access-related exposure across a global manufacturing operation.  

Why CoreView  

CoreView has created a governance layer that controls how administrators interact with the company’s Microsoft 365 tenant.  

Rather than relying on broad native roles, manual checks, or administrator discretion, the platform enforces defined access boundaries and repeatable workflows.

These controls have replaced informal processes with enforced policy, while bringing delegated administration, reporting, and automation into a single governance model.  

Next Steps: With scoped administration and automated workflows already in place, the company is now evaluating CoreView Configuration Manager to strengthen control over its Microsoft 365 configuration settings.

The team is particularly interested in configuration backup and drift detection, which can identify when settings move away from their approved state and support recovery of previous configurations when needed.

Adding these capabilities to the company’s broader governance approach will give the IT team greater visibility and control over security-related configuration changes across its 3,000-user Microsoft 365 tenant.

Get a personalized demo today

Created by M365 experts, for M365 experts.