Microsoft 365 Customer Lockbox How to Set It Up

Microsoft 365 Customer Lockbox gives your organisation the final say before a Microsoft support engineer can access your tenant content.

Microsoft support does not normally need to open your emails, Teams conversations, SharePoint files or OneDrive documents. Most problems can be investigated using automated diagnostics, service telemetry and other support tools.

There are, however, rare support cases where an engineer may need temporary access to customer content to diagnose the problem. Customer Lockbox makes sure that access cannot begin until someone in your organisation has reviewed and approved the request.

Without Customer Lockbox, Microsoft still uses internal access controls and approval processes. Enabling Customer Lockbox adds your organisation to that approval chain.

If your Microsoft 365 subscription includes the feature, it is a setting worth reviewing.

Never miss an article and subscribe, and don’t forget to check out my YouTube channel, Control Alt Delete Tech Bits

Like the article? Feel free to buy me a coffee

Also check out my redact app, Redact PDFs and images, review email evidence and manage subject access requests without sending source files to a processing server.: https://redactninja.com

What is Microsoft 365 Customer Lockbox?

Customer Lockbox is a Microsoft Purview feature that controls how Microsoft support engineers access customer content during a support case.

When Microsoft determines that access is required, an engineer must create a Customer Lockbox request. The request includes information such as:

  1. The associated Microsoft support request number.
  2. The Microsoft 365 service involved.
  3. The reason access is required.
  4. The expected start time.
  5. How long access is needed.

The request must pass Microsoft’s own internal approval process before it is sent to your organisation.

An authorised approver in your tenant can then review the request and choose whether to approve or deny it. If the request is denied, Microsoft does not receive access to the content.

What services does Customer Lockbox cover?

Microsoft 365 Customer Lockbox currently supports access requests involving:

Exchange Online.

SharePoint Online.

OneDrive for Business.

Microsoft Teams.

Windows 365.

Microsoft 365 Copilot interactions through the support provided for Exchange Online.

    Customer content can include email bodies, attachments, SharePoint documents, Teams chats, meeting recordings, transcripts, voicemail, files shared through Teams and Microsoft 365 Copilot interactions.

    That is a considerable amount of potentially sensitive information.

    For a school or college, this could include safeguarding information, student records, staff correspondence, special educational needs information, HR documents and subject access request material.

    For other organisations, it could include customer data, financial records, legal correspondence, contracts and commercially sensitive documents.

    Customer Lockbox does not prevent Microsoft 365 from operating normally. It only becomes involved when a Microsoft engineer requests human access to customer content.

    How does a Customer Lockbox request work?

    The normal process looks like this:

    1. Your organisation raises a Microsoft support request.
    2. Microsoft investigates the issue using its normal diagnostic tools.
    3. The support engineer determines that access to customer content is required.
    4. The engineer creates a Customer Lockbox request.
    5. A Microsoft Support manager reviews and approves the request internally.
    6. Global Administrators and users assigned the Customer Lockbox Access Approver role receive an email notification.
    7. An approver signs in to the Microsoft 365 admin centre and reviews the request.
    8. The approver selects Approve or Deny.
    9. If approved, the engineer receives temporary access for the period specified in the request.
    10. When the approved period ends, access is automatically removed.

    A Customer Lockbox request expires if nobody responds within 12 hours. The maximum access period that can currently be granted to a Microsoft engineer is four hours, although a shorter period can be requested.

    Microsoft also states that its Customer Lockbox notification emails do not include links asking you to sign in. Rather than clicking a link from the message, open the Microsoft 365 admin centre directly and review the request there.

    Why should you enable Customer Lockbox?

    Customer Lockbox adds a clear decision point before Microsoft can access your organisation’s content.

    This provides several benefits.

    You remain in control

    Microsoft cannot proceed with the requested content access until an authorised person in your organisation approves it.

    You can check that the request matches a genuine support case and that the requested access appears proportionate to the problem being investigated.

    Requests can be denied

    Approval is not automatic.

    If the request is unexpected, does not match an open support ticket or does not contain enough information, you can deny it.

    Each request includes a Microsoft service request number. You can contact Microsoft Support and reference that number if you need more information before making a decision.

    Access is temporary

    Approving a request does not give an engineer permanent access to your tenant.

    Access is provided for the approved period and removed automatically when that period ends. Microsoft says its services use least privilege and just in time access rather than providing staff with ongoing access to customer content.

    Actions are audited

    The approval or denial decision is recorded in the Microsoft 365 audit log.

    Actions performed by Microsoft engineers following an approved request are also logged. These records can be searched using Microsoft Purview Audit or Exchange Online PowerShell.

    It supports compliance evidence

    Customer Lockbox provides evidence that your organisation has an explicit approval process for external support access.

    This can help during internal audits, supplier reviews, data protection assessments and discussions about how access to sensitive information is controlled.

    It does not provide compliance on its own, but it gives you a clear technical control and an audit trail to support your wider policies.

    Customer Lockbox licensing requirements

    For enterprise tenants, Customer Lockbox is included with Office 365 E5 and Microsoft 365 E5 subscriptions. It is also available through qualifying Microsoft Purview packages. Government organisations can access it through qualifying G5 subscriptions

    For education tenants, Customer Lockbox is included with Office 365 A5 and Microsoft 365 A5. It is not included with A1 or A3 by default.

    Before enabling Customer Lockbox

    I recommend completing the following checks first:

    1. Confirm that your subscription includes Customer Lockbox.
    2. Identify at least two trusted approvers so that a request is not missed when someone is unavailable.
    3. Make sure each approver uses multifactor authentication.
    4. Agree who is responsible for checking that a request matches a genuine Microsoft support ticket.
    5. Confirm that the approvers can access the Microsoft 365 admin centre.
    6. Document when a request should be approved or denied.

    Avoid using Global Administrator accounts for routine approvals where a more limited role is available.

    Microsoft provides the Customer Lockbox Access Approver role specifically for this purpose. The role allows someone to approve or deny Customer Lockbox requests without giving them all the permissions of a Global Administrator.

    Assign the Customer Lockbox Access Approver role

    Sign in to the Microsoft 365 admin centre using an account that can manage role assignments.

    Go to:

    Roles > Role assignments

    Select the Microsoft Entra ID tab.

    Search for:

    Customer Lockbox Access Approver

    Open the role and select the Assigned tab.

    Select Add users or Add groups.

    Search for the user who will review Customer Lockbox requests.

    Select the user and then select Add.

    Repeat this process for any additional approvers.

    Microsoft also allows Global Administrators to receive and approve requests, but you should not keep additional Global Administrator assignments solely for Customer Lockbox. Use the dedicated role instead.

    Microsoft 365 Customer Lockbox Access Approver role
    Microsoft 365 Customer Lockbox Access Approver role

    Enable Microsoft 365 Customer Lockbox

    In the Microsoft 365 admin centre, go to:

    Settings > Org settings

    Open the Security & privacy tab.

    Select Customer Lockbox.

    Select:

    Require approval for all data access requests

    Select Save.

    Once enabled, Microsoft must obtain approval from your organisation before accessing content covered by Microsoft 365 Customer Lockbox

    Microsoft 365 Customer Lockbox
    Microsoft 365 Customer Lockbox

    Confirm the configuration

    Refresh the Customer Lockbox settings page and confirm that the approval option remains selected.

    Next, go to:

    Support > Customer Lockbox Requests

    This page displays pending and previous Customer Lockbox requests.

    Do not worry if the list is empty. Requests only appear when Microsoft determines that access to customer content is required during a support case.

    There is no button to create a harmless test request yourself. A request must be raised through the Microsoft support workflow.

    Microsoft 365 Customer Lockbox Data Access Requests
    Microsoft 365 Customer Lockbox Data Access Requests

    Review an access request

    When a request arrives, do not approve it based only on the email notification.

    Open the Microsoft 365 admin centre directly and go to:

    Support > Customer Lockbox Requests

    Select the pending request.

    Check:

    1. The support request number.
    2. The Microsoft 365 service involved.
    3. The reason access is required.
    4. The expected access start time.
    5. The requested duration.
    6. Whether the request matches a support ticket raised by your organisation.

    If everything matches and the access is required to resolve the issue, select Approve.

    If the request is unexpected or you cannot verify it, select Deny.

    If you need more information, contact Microsoft Support and provide the service request number shown in the Customer Lockbox request.

    Audit Customer Lockbox activity

    Approving the request should not be the end of the process.

    Once the support work has finished, review the audit log to see what activity took place.

    Open the Microsoft Purview portal and go to:

    Solutions > Audit

    Create a new search covering the date and time of the Customer Lockbox request.

    Microsoft recommends leaving the Activities, Users and file location fields blank when searching broadly for Customer Lockbox records.

    In the results, look for:

    Set-AccessToCustomerDataRequest

    This records when an approver accepted or denied a request.

    You should also look for activity where the user is shown as:

    Microsoft Operator

    This identifies actions performed by a Microsoft engineer following an approved Customer Lockbox request.

    What Customer Lockbox does not do

    Customer Lockbox is useful, but it is not a replacement for your other Microsoft 365 security controls.

    It does not replace:

    1. Multifactor authentication.
    2. Conditional Access.
    3. Privileged Identity Management.
    4. Data loss prevention.
    5. Sensitivity labels.
    6. Microsoft Purview Audit.
    7. Secure support and change management procedures.

    It also does not control requests made by law enforcement agencies or other third parties. Microsoft handles those requests under separate legal and contractual processes.

    Customer Lockbox controls a specific scenario, temporary access to customer content by Microsoft engineers during service and support operations.

    Should you enable Microsoft 365 Customer Lockbox?

    The setting adds an explicit customer approval stage, provides time limited access and records the resulting activity in the Microsoft 365 audit log.

    For organisations handling personal, financial, legal, educational or commercially sensitive information, that extra approval stage is valuable.

    Enable it, assign the dedicated approver role to trusted staff and make sure everyone involved understands how requests should be checked.

    The feature might sit unused for months or years. That is normal.

    The point is that when a difficult support case eventually requires access to customer content, the decision remains with your organisation.

    You might also like this article

    Does Microsoft normally read customer data?

    No. Microsoft states that most service issues are investigated through automated tools, telemetry and diagnostic information. Customer content access is only requested when it is required to diagnose or resolve a specific issue

    Who can approve a Customer Lockbox request?

    Global Administrators and users assigned the Customer Lockbox Access Approver role can approve or deny requests. The dedicated approver role should be used for routine administration rather than relying on Global Administrator accounts

    How long does a Customer Lockbox request remain available?

    A request expires after 12 hours if your organisation does not approve or deny it. No access is granted when a request expires.

    How long can a Microsoft engineer access the data?

    The current maximum access period is four hours. Microsoft engineers may request a shorter period, and access is automatically removed when the approved period end

    What happens if I deny the request?

    Microsoft does not receive access to the customer content. The support issue may remain unresolved if access was necessary to investigate it

    Can I see what the Microsoft engineer did?

    Yes. Actions performed by Microsoft engineers following an approved request are recorded in the Microsoft 365 audit log and can be identified using the Microsoft Operator value.

    Does Customer Lockbox cover Microsoft Teams and Copilot?

    Customer Lockbox supports Microsoft Teams content. Microsoft also states that Microsoft 365 Copilot interactions are covered through the support available for Exchange Online

    Tags: , ,

    Leave a Reply

    Your email address will not be published. Required fields are marked *