How a Large US State Government Automated Microsoft 365 Governance at Scale with CoreView

How a Large US State Government Automated Microsoft 365 Governance at Scale with CoreView
SUMMARY
  • Tennessee needed to govern Microsoft 365 at scale: Central IT supported 43,000+ employees across 30+ departments, creating bottlenecks and visibility gaps.
  • CoreView enabled controlled department self-service: Departments gained scoped access to users, reports, and actions within central IT’s boundaries.
  • Automation improved governance consistency: CoreView executed 9,974 workflows in 30 days, including account disablement, license cleanup, and remediation.
Download case study

Background: Managing Microsoft 365 Governance at Scale

A large US state government, responsible for public services across health, education, and public safety, manages Microsoft 365 for more than 40,000 employees across 30-plus departments.

Challenge: Centralized Microsoft 365 Administration Created Department-Level Blind Spots

Running Microsoft 365 at this scale meant the central IT team was fielding access requests, license questions, and user management tasks from every corner of the organization, all day, every day.

Over time, that pressure had become structural. Departments had no direct way to view their own users, pull their own reports, or act on their own data. Everything was funneled up to the central team, which provided ad hoc reporting when departments asked for it.

With 30-plus departments, the number of routine requests – who has access to what, which accounts are still active, which licenses are assigned – grew faster than the central team could absorb.

Departments could not self-serve, so requests queued. And because no one at the department level had visibility into their own user base, access reviews did not happen on any consistent schedule.

That was more than just an efficiency problem. When department-level staff cannot see their own environment, no one is checking whether access is still appropriate, whether old accounts have been disabled, or whether licenses are still assigned to former employees.  

The result was a central IT bottleneck and department-level blind spots. Inactive accounts stayed active. License assignments did not get cleaned up after staff changes.  

This created a very real exposure risk: orphaned accounts and unused licenses are two of the most common vectors for both security incidents and audit findings in government Microsoft 365 environments.

Quote top graphic

Solution: Giving Departments Controlled Access to Their Own Microsoft 365 Data

After deploying CoreView, the state government was able to give each of the 30-plus departments direct access to its own scoped area of the Microsoft 365 environment – scoped to their users, their reports, and their processes. Boundaries and policies were set by central IT and the departments worked within them.

That shift did something the old model could not: it put accountability where the information lives. Department administrators could now see their own user lists, run reports relevant to their teams, and take action without waiting for central IT to prioritize their requests.

The automation layer took that one step further. Rather than relying on manual reviews to catch stale accounts or redundant licenses, the organization was able to build workflows to do it automatically.

In the 30 days before this case study was written, those workflows executed 9,974 times. That is nearly 10,000 governance actions – account disablement, license cleanup, and user remediation – that would otherwise have required manual intervention or simply not have happened.

The organization is also connecting CoreView to ServiceNow to extend that automation further, closing the loop between IT service management and Microsoft 365 operations.

Benefits: Department-Level Control Without Losing Central Governance

With CoreView, the organization built a governance model that does not depend on central IT being everywhere at once.

Departments can manage their own environments within defined limits. That means access reviews can happen, license waste gets caught before it compounds, and the central IT team can focus on policy rather than execution.

The key benefits include:

  • Department-level self-service: Departments can see their own users, run their own reports, and act on their own data within defined boundaries.
  • Reduced IT bottlenecks: Routine requests no longer have to funnel through one central team.
  • More consistent access reviews: Department-level visibility makes it easier to check whether access is still appropriate.
  • Improved license cleanup: Unused licenses can be identified and addressed before waste compounds.
  • Automated governance at scale: CoreView workflows executed 9,974 actions in 30 days, including account disablement, license cleanup, and user remediation.
  • ServiceNow integration in progress: The organization is connecting CoreView to ServiceNow to extend automation across IT service management and Microsoft 365 operations.

At 30-plus departments and 40,000 employees, the gap between a governance model that works at scale and one that does not is measured in audit risk, unused license spend, and access that outlasts the employment it was tied to. The number of automated actions in a single month gives a reasonable picture gives a reasonable picture of how much of that was going unmanaged before.

Why CoreView

CoreView gave the state government the scoped access, reporting, and automation needed to move routine Microsoft 365 governance closer to each department while keeping central IT in control of the boundaries.

Get a personalized demo today

Created by M365 experts, for M365 experts.