Securing Microsoft 365 Shared Generic Accounts on Personal Devices
Question details
Prevent former employees from accessing shared Microsoft 365 accounts connected to unidentified personal devices.

- Product
- Microsoft 365
- Device & OS
- not provided
- Scenario
- Managing shared generic accounts connected to employee personal devices where the device list lacks clear user identification.
- Observed behavior
- Difficulty identifying which personal device belongs to former employees to revoke access, creating a risk of unauthorized account usage.
Before modifying security policies, ensure you have Global Administrator or Security Administrator privileges in your Microsoft 365 and Entra ID admin centers.
Use Entra ID Identity Protection and Require MFA
Leverage Microsoft Entra ID to monitor risky sign-ins and prompt for Multi-Factor Authentication (MFA) on unfamiliar personal devices.
Since identifying specific personal devices can be challenging, implementing risk-based conditional access policies helps ensure that any unrecognized device or location requires secondary authentication. This effectively blocks former employees who may still have the shared password.
Log in to the Microsoft Entra admin center using your administrator credentials.
Go to 'Protection' in the left-hand navigation menu and select 'Identity Protection'.
Click on 'Sign-in risk policy'. Under Assignments, select the shared generic accounts you wish to protect. Set the 'Sign-in risk' level to Medium and above.
Under 'Controls', select 'Require multifactor authentication'. Save and enable the policy.
Regularly check the 'Sign-in logs' under 'Monitoring' to identify anomalous activity, unauthorized access attempts, and unmanaged device details.

Transition to Individual Accounts and Shared Mailboxes
Eliminate the security risks of shared generic credentials by provisioning individual user accounts and using Shared Mailboxes or Delegated Access instead.
Try WPS Office for Secure and Lightweight Document Management
While securing your organization's Microsoft 365 infrastructure, consider WPS Office as a free, lightweight, and highly compatible alternative for your team's document creation needs. It offers familiar interfaces and robust file compatibility without complex shared account overhead.
- 1. Download the Installer: Visit the official WPS Office website and download the free version for Windows, Mac, or Linux.
- 2. Install WPS Office: Run the downloaded installer and follow the quick on-screen instructions to complete the setup.
- 3. Open and Edit Microsoft Formats: Launch WPS Office to seamlessly open, edit, and save your existing Word, Excel, and PowerPoint documents.

Frequently Asked Questions
How can I force sign-out for all devices on a Microsoft 365 account?
Go to the Microsoft 365 admin center, select the specific user account, and navigate to the Account tab. Click on 'Sign out of all sessions'. This will invalidate current authentication tokens and force all connected devices to re-authenticate.
Can I restrict Microsoft 365 access to company-owned devices only?
Yes. By utilizing Microsoft Intune and Conditional Access policies in Entra ID, you can configure rules that block access from unmanaged personal devices and only permit access from compliant, company-registered devices.
Why is sharing passwords for generic accounts considered a security risk?
Shared passwords eliminate accountability, meaning administrators cannot track which specific individual performed a malicious or accidental action. Furthermore, revoking access when an employee leaves requires changing the password for everyone, which is disruptive and often delayed.
How do I find which devices are connected to a specific Microsoft 365 account?
In the Microsoft Entra admin center, navigate to 'Users', click on the specific user account you want to investigate, and select 'Devices' from the left menu. This will display a list of all devices registered or joined to that specific login.




