Entra identity and admin roles
- Join
- Account and role
- Change
- Groups and access
- Share
- Guest and owner
- Leave
- Sign-in and sessions
HealthDesk IT helps practices already using Microsoft 365 manage user access, Entra ID, Intune, mailboxes and shared resources as staff and devices change.
For an existing Microsoft 365 environment. Exact work depends on licensing, configuration, contracts and agreed scope. Migration projects and individual support issues have separate paths below.
A staff change can affect identity, mail, collaboration and device access. Review the connected controls together and record who approves the result.
Confirm role, start date, license, mailbox, groups, device path, shared resources, and approver before access is issued.
Review what should be added, retained, or removed when a person changes location, duties, schedule, or device.
Keep mailboxes, Teams, SharePoint, OneDrive, guest access, and ownership aligned with the current business need.
Block sign-in, review sessions and devices, preserve required content, reassign ownership, and document exceptions.
Identify the current setup, missing information, licensing dependencies and decision owners before approving changes.
Administrators, privileged roles, stale users, emergency access, MFA, groups and escalation owners.
Assigned and unused licenses, feature dependencies, mailbox types and questions for Microsoft or your reseller.
Shared mailboxes, Teams, SharePoint, OneDrive, distribution, guests and content owners.
Device enrollment, platform limits, assigned policies and exceptions. Intune status is separate from regulatory compliance.
Access risks, support issues, licensing questions and staged changes, with approvers, validation checks and review dates.
Keep Microsoft 365 administration and its records current. Wider infrastructure and recurring practice operations stay with the managed IT service.
HealthDesk manages only the agreed practice-side scope. Microsoft, licensing partners, practice leadership, and other specialists retain their own authority.
Business need, staff roles, approved access, risk decisions, exceptions, budget, data handling, and operational acceptance.
Agreed discovery, tenant documentation, practice-side administration, staged changes, validation evidence, and vendor coordination.
Platform availability, product behavior, service limits, licensing terms, vendor-controlled remediation, and contracted support.
Formal risk analysis, legal conclusions, policy approval, regulatory interpretation, retention decisions, and clinical workflow authority.
Microsoft 365 features, a Microsoft BAA, MFA, Conditional Access, or an Intune device status do not by themselves establish HIPAA compliance. Applicability and required safeguards depend on the practice's facts, policies, configuration, contracts, and risk analysis.
Protect administrator access, confirm licensing and recovery options, then validate the agreed result. Changes to identity, mail and devices can interrupt practice work.
Use the service that matches the decision or work you need.
User access, licenses, mailboxes, collaboration and devices in an existing environment.
Move email, files or users into Microsoft 365 through a planned project.
Resolve an individual Outlook, password, sign-in, sync or workstation issue.
Coordinate recurring support across the wider practice environment.
Review preventive controls across identity, email, devices and remote access.
Review risk-analysis questions, safeguard evidence and specialist decisions.
Prepare before the review Work through the Microsoft 365 security checklist, save the healthcare phishing response guide, and use the HIPAA email setup guide to identify administrator, MFA, mailbox, encryption, and response decisions that need an owner.
No. This page is primarily for a tenant already in use. A new email, file, or identity move belongs to the cloud migration service.
Yes, within an agreed scope. The first review can organize administrators, identities, licenses, mailboxes, collaboration, device status, open risks, and ownership questions.
Yes. Work can include identity, MFA, administrator roles, Conditional Access questions, enrollment, and device-policy administration when supported by the tenant, license, platform, and scope.
No. Intune compliance means a managed device meets configured organizational rules. It is not a legal or regulatory conclusion and does not replace a fact-specific risk analysis.
Yes. We can scope a one-time cleanup or ongoing administration. If the work belongs with migration, managed IT, routine support or another specialist, we will identify that owner.
Share the broad concern, number of users or locations, tenant history, affected Microsoft 365 areas, timing, and the decision still open. Do not send PHI, passwords, tenant IDs, admin links, screenshots, or configuration exports.
Microsoft documents that Conditional Access capabilities and risk features vary by license, and that Intune device compliance evaluates configured device rules. HHS describes technical safeguards as technology together with policies and procedures. These sources do not endorse HealthDesk, prove a particular practice compliant, or replace Microsoft licensing terms, legal advice, or a formal risk analysis.
Tell us about your Microsoft 365 environment, approximate users or devices, timing and the issue that needs an owner. We will confirm fit and the next step.