A large US state government, responsible for public services across health, education, and public safety, manages Microsoft 365 for more than 40,000 employees across 30-plus departments.
Running Microsoft 365 at this scale meant the central IT team was fielding access requests, license questions, and user management tasks from every corner of the organization, all day, every day.
Over time, that pressure had become structural. Departments had no direct way to view their own users, pull their own reports, or act on their own data. Everything was funneled up to the central team, which provided ad hoc reporting when departments asked for it.
With 30-plus departments, the number of routine requests – who has access to what, which accounts are still active, which licenses are assigned – grew faster than the central team could absorb.
Departments could not self-serve, so requests queued. And because no one at the department level had visibility into their own user base, access reviews did not happen on any consistent schedule.
That was more than just an efficiency problem. When department-level staff cannot see their own environment, no one is checking whether access is still appropriate, whether old accounts have been disabled, or whether licenses are still assigned to former employees.
The result was a central IT bottleneck and department-level blind spots. Inactive accounts stayed active. License assignments did not get cleaned up after staff changes.
This created a very real exposure risk: orphaned accounts and unused licenses are two of the most common vectors for both security incidents and audit findings in government Microsoft 365 environments.
After deploying CoreView, the state government was able to give each of the 30-plus departments direct access to its own scoped area of the Microsoft 365 environment – scoped to their users, their reports, and their processes. Boundaries and policies were set by central IT and the departments worked within them.
That shift did something the old model could not: it put accountability where the information lives. Department administrators could now see their own user lists, run reports relevant to their teams, and take action without waiting for central IT to prioritize their requests.
The automation layer took that one step further. Rather than relying on manual reviews to catch stale accounts or redundant licenses, the organization was able to build workflows to do it automatically.
In the 30 days before this case study was written, those workflows executed 9,974 times. That is nearly 10,000 governance actions – account disablement, license cleanup, and user remediation – that would otherwise have required manual intervention or simply not have happened.
The organization is also connecting CoreView to ServiceNow to extend that automation further, closing the loop between IT service management and Microsoft 365 operations.
With CoreView, the organization built a governance model that does not depend on central IT being everywhere at once.
Departments can manage their own environments within defined limits. That means access reviews can happen, license waste gets caught before it compounds, and the central IT team can focus on policy rather than execution.
The key benefits include:
At 30-plus departments and 40,000 employees, the gap between a governance model that works at scale and one that does not is measured in audit risk, unused license spend, and access that outlasts the employment it was tied to. The number of automated actions in a single month gives a reasonable picture gives a reasonable picture of how much of that was going unmanaged before.
CoreView gave the state government the scoped access, reporting, and automation needed to move routine Microsoft 365 governance closer to each department while keeping central IT in control of the boundaries.