Published 15 September 2026 · Primacy ITS
A repeatable review for the person responsible for users, devices, software and the things everyone assumes somebody else is checking.
What this solves
The urgent work is visible. The neglected work is not. Use this review to find missed access removals, failing controls, renewals and unowned risks before they become incidents. This is a monthly health review, not a replacement for daily security alerts, timely patching or incident response.
Before you start
Use read-only reporting access where possible. Have your staff list, device inventory, SaaS register, incident log and previous action list available. Keep the evidence in a restricted company location; do not put tenant exports, employee details or screenshots into a public checklist or an unapproved AI tool.
No new software licence is needed to use the checklist. The reports you can inspect depend on your existing products and permissions. Record a missing report as a visibility gap, rather than assuming the control is healthy.
1. Close the loop on last month
Read the last action list before opening dashboards. For each open item, ask: was the change completed, was the result checked, and is the evidence accessible? A task marked complete without a verification result is still an assumption.
- Record the review date and reviewer.
- Carry forward unresolved actions with their original dates.
- Escalate overdue high-impact items to the business decision-maker.
- Keep a maximum of three improvement priorities for the next month. Incidents and urgent fixes are separate.
2. Check people and access
Compare the authoritative staff changes with your account records. Check leavers, changed roles, temporary access and privileged accounts. Include SaaS applications with their own credentials; disabling an identity-provider account is not proof that every other session or account has been terminated.
Evidence should answer: who still has access, why, and who approved it? Do not paste passwords, recovery codes or access tokens into the record.
For Microsoft 365 offboarding, use Microsoft's current sequence to prevent access, preserve required data and handle licence/account removal. Do not remove a licence or delete an account before checking preservation requirements. Microsoft's offboarding guidance
3. Check devices and patch exceptions
Review missing devices, failed updates, stale check-ins and disabled protection. Check exceptions individually: a laptop that has not checked in cannot be counted as successfully updated. Record the affected asset, the reason, the next action and a due date.
Look for broad policy changes since the last review. If an exception was made to get a person working, confirm that it has an expiry date. Review update rollout results before widening a pilot; do not change every device's settings during this review.
4. Check recovery, not just backup status
Read backup failures and resolve repeated warnings. On a rotating schedule, restore a small, non-sensitive sample into an isolated location and confirm that it opens. Record the source, restore point, elapsed time and result. Do not overwrite production data to test recovery.
A successful backup job and a successful restore answer different questions. If a service has no backup, document exactly which native recovery options you rely on and who has accepted their limits.
5. Check services, suppliers and renewals
Review upcoming renewals and notice periods for the next 90 days. Confirm that each critical service has a business owner, an administrator, a recovery route and a documented dependency. Find unused licences before renewing them, but do not remove access without the owner's agreement.
Check whether suppliers have added AI features, changed data handling or introduced new permissions. Capture any decision needed; do not automatically approve a change because it arrived inside a product you already pay for.
6. Check what people are struggling with
Read the recurring support themes. Select one repeated problem to solve with a short guide, a configuration fix or a better onboarding step. Test that a colleague can follow the instructions without asking what the author meant.
7. Finish with decisions, not a bigger spreadsheet
For each finding record: observation, business impact, action, owner, due date and verification evidence. Use “unknown” when evidence is missing. Do not silently turn unknown into green.
Suggested review record:
- Review month:
- Access exceptions and evidence:
- Device/patch exceptions and evidence:
- Restore test and result:
- Renewals needing a decision:
- Repeated user problem:
- Three next actions, with owner and due date:
- Business risks requiring acceptance:
Verification and safe changes
The review is complete when every material finding has an owner and the previous month's completed actions have evidence. The review itself changes no production settings, so it has no rollback operation. Treat any follow-on configuration change as a separate task with a pilot, approval where necessary and its own rollback plan.
Suggested effort: allow 45–60 minutes for a small, well-documented environment. This is an estimate, not a promise; investigations and remediation take additional time. Primacy ITS's one-hour publishing budget is unrelated to the time a reader needs to operate their IT environment.
Reuse
Copy and adapt this checklist for your organisation's internal use. Keep sensitive evidence in your own systems. Do not claim that completing it is an audit certification or proof of compliance.
Related resources
The solo IT admin monthly review
A repeatable check of access, devices, recovery, suppliers and the next three priorities.
