What is Customer Lockbox? Data Access Approval in Microsoft 365 E5

セキュリティカテゴリを表すパンダのイラスト Security

What is Customer Lockbox? Requiring Approval for Support Data Access in Microsoft 365 E5

About This Article
This article is created using an automated generation workflow leveraging generative AI. Based on official Microsoft information as of September 17, 2026, it outlines the role of Microsoft 365 Customer Lockbox, its positioning in E3/E5, and the approval workflow from a practical perspective.

Verification Status: 📘 Official Microsoft Information Confirmed / Actual Device Not Verified

Customer Lockbox is a mechanism that requires explicit approval from the organization when Microsoft support engineers need to access the organization's customer content for troubleshooting or other purposes.

This does not mean that Microsoft personnel can freely read emails and files during routine service operations. Microsoft typically resolves issues using telemetry and diagnostic tools, and uses the Lockbox approval workflow in cases where access to customer content is strictly necessary.

How Do E3 and E5 Differ?

According to official Microsoft documentation, Customer Lockbox is included in Microsoft 365 or Office 365 E5. For other eligible plans, it may be available through additional contracts for Information Protection and Compliance or Advanced Compliance.

ItemMicrosoft 365 E3Microsoft 365 E5
Customer LockboxNot included by default in standalone E3Included
Additional contractCheck applicable add-onsGenerally available via E5 entitlements

Because license names vary depending on the licensing channel and SKU, please verify the Microsoft 365 admin center and contract terms during actual deployment.

Supported Services

As of the September 2026 official Microsoft documentation, Customer Lockbox supports Exchange Online, SharePoint Online, OneDrive for Business, Teams, and Windows 365.

First Step: Check Current Settings Only

In the Microsoft 365 admin center, go to Settings > >Org Settings > >Security > &Privacy > >Customer Lockbox to check the current settings.

What to Check Here

  • Whether 'Require approval for all data access requests' is enabled

  • Who is assigned as the Customer Lockbox access approver

  • Whether there is any history under Support > >Customer Lockbox Requests

During the initial check, do not change settings; only verify the current status and operations personnel.

Making a Single Change

Before enabling the feature in production, document the policy for assigning approver roles. Consider operations where routine approvals do not rely solely on Global Administrators, but instead assign Customer Lockbox access approver roles to the minimum necessary personnel.

When Using PowerShell

There are official Microsoft Set-AccessToCustomerDataRequest cmdlets for approving or rejecting Customer Lockbox requests. However, approval is a critical operation that permits Microsoft personnel to access customer data. Executing it as a copy-paste command for initial testing is inappropriate.

Therefore, first check the request details, service request number, expiration time, and justification via the GUI, and proceed with the operation only after following the organization's approval procedure.

What Happens When You Approve?

Even when approved, permanent access rights are not granted to Microsoft engineers. Microsoft explains that based on the principles of least privilege and just-in-time access, access is limited to the required duration and operations.

Approvals, rejections, and related operations performed by Microsoft engineers are also recorded in the Microsoft 365 audit log.

Best Practices for Enterprise Use

  • Incorporate data access during Microsoft support handling into internal approval workflows

  • Segregate the roles of the security department and the service management department

  • Cross-reference approval history with audit logs

  • Record service request numbers in incident management tickets

Points for Administrators to Verify

  • Customer Lockbox licensing

  • Approver design avoiding routine use of Global Administrators

  • Approver backup for weekends and night shifts

  • Expiration time for approval requests

  • Retention and search permissions for Microsoft 365 audit logs

  • Procedure for matching against support tickets

It is important to avoid operations where you simply click 'Approve' whenever an approval email arrives. Make decisions only after verifying the reason for the request, the target service, and the support ticket number.

Official Microsoft Information / Primary Sources

  • Customer Lockbox requests: https://learn.microsoft.com/en-us/purview/customer-lockbox-requests

  • Microsoft Purview licensing guidance: https://learn.microsoft.com/en-us/office365/servicedescriptions/microsoft-365-service-descriptions/microsoft-365-tenantlevel-services-licensing-guidance/microsoft-purview-service-description

Customer Lockbox is not a matter of trusting or distrusting Microsoft, but rather a governance feature designed to 'integrate exceptional customer data access into your organization's own approval process.'

Document information

Article title
What is Customer Lockbox? Data Access Approval in Microsoft 365 E5
Published
Updated
Source
https://papanda925.com/?p=16384&lang=en

License: Text and original figures for which this site holds the relevant rights are available under CC BY 4.0 , unless otherwise noted. This article may include content created or edited with generative AI. If code has a separate license notice or a linked GitHub repository license, that license takes precedence for the code. Quotations, third-party materials, images, and trademarks are excluded from this license. Usage policy

Copied title and URL