What is Customer Lockbox? Requiring Approval for Support Data Access in Microsoft 365 E5
About This Article
This article is created using an automated generation workflow leveraging generative AI. Based on official Microsoft information as of September 17, 2026, it outlines the role of Microsoft 365 Customer Lockbox, its positioning in E3/E5, and the approval workflow from a practical perspective.Verification Status: 📘 Official Microsoft Information Confirmed / Actual Device Not Verified
Customer Lockbox is a mechanism that requires explicit approval from the organization when Microsoft support engineers need to access the organization's customer content for troubleshooting or other purposes.
This does not mean that Microsoft personnel can freely read emails and files during routine service operations. Microsoft typically resolves issues using telemetry and diagnostic tools, and uses the Lockbox approval workflow in cases where access to customer content is strictly necessary.
How Do E3 and E5 Differ?
According to official Microsoft documentation, Customer Lockbox is included in Microsoft 365 or Office 365 E5. For other eligible plans, it may be available through additional contracts for Information Protection and Compliance or Advanced Compliance.
| Item | Microsoft 365 E3 | Microsoft 365 E5 |
|---|---|---|
| Customer Lockbox | Not included by default in standalone E3 | Included |
| Additional contract | Check applicable add-ons | Generally available via E5 entitlements |
Because license names vary depending on the licensing channel and SKU, please verify the Microsoft 365 admin center and contract terms during actual deployment.
Supported Services
As of the September 2026 official Microsoft documentation, Customer Lockbox supports Exchange Online, SharePoint Online, OneDrive for Business, Teams, and Windows 365.
First Step: Check Current Settings Only
In the Microsoft 365 admin center, go to Settings > >Org Settings > >Security > &Privacy > >Customer Lockbox to check the current settings.
What to Check Here
Whether 'Require approval for all data access requests' is enabled
Who is assigned as the Customer Lockbox access approver
Whether there is any history under Support > >Customer Lockbox Requests
During the initial check, do not change settings; only verify the current status and operations personnel.
Making a Single Change
Before enabling the feature in production, document the policy for assigning approver roles. Consider operations where routine approvals do not rely solely on Global Administrators, but instead assign Customer Lockbox access approver roles to the minimum necessary personnel.
When Using PowerShell
There are official Microsoft Set-AccessToCustomerDataRequest cmdlets for approving or rejecting Customer Lockbox requests. However, approval is a critical operation that permits Microsoft personnel to access customer data. Executing it as a copy-paste command for initial testing is inappropriate.
Therefore, first check the request details, service request number, expiration time, and justification via the GUI, and proceed with the operation only after following the organization's approval procedure.
What Happens When You Approve?
Even when approved, permanent access rights are not granted to Microsoft engineers. Microsoft explains that based on the principles of least privilege and just-in-time access, access is limited to the required duration and operations.
Approvals, rejections, and related operations performed by Microsoft engineers are also recorded in the Microsoft 365 audit log.
Best Practices for Enterprise Use
Incorporate data access during Microsoft support handling into internal approval workflows
Segregate the roles of the security department and the service management department
Cross-reference approval history with audit logs
Record service request numbers in incident management tickets
Points for Administrators to Verify
Customer Lockbox licensing
Approver design avoiding routine use of Global Administrators
Approver backup for weekends and night shifts
Expiration time for approval requests
Retention and search permissions for Microsoft 365 audit logs
Procedure for matching against support tickets
It is important to avoid operations where you simply click 'Approve' whenever an approval email arrives. Make decisions only after verifying the reason for the request, the target service, and the support ticket number.
Official Microsoft Information / Primary Sources
Customer Lockbox requests: https://learn.microsoft.com/en-us/purview/customer-lockbox-requests
Microsoft Purview licensing guidance: https://learn.microsoft.com/en-us/office365/servicedescriptions/microsoft-365-service-descriptions/microsoft-365-tenantlevel-services-licensing-guidance/microsoft-purview-service-description
Customer Lockbox is not a matter of trusting or distrusting Microsoft, but rather a governance feature designed to 'integrate exceptional customer data access into your organization's own approval process.'

