Home About Us Expertise Our Work Insight Book a Consultation
Practical Checklist

Microsoft 365 governance: a practical checklist for UK organisations

Published
September 2026
Reading Time
10 minutes
Topic
Compliance & Governance
Audience
IT Directors & Ops Leaders
Scroll to read
Microsoft 365 governance checklist for UK organisations
7
Governance areas covered
50+
Actionable checklist items
1
Place to start — identity and access

Good governance is what separates a well-run Microsoft 365 environment from a liability

Microsoft 365 is one of the most powerful productivity platforms available to UK organisations. It is also one of the most complex to govern well. Left unmanaged, it accumulates ungoverned Teams, overly permissive sharing settings, unreviewed guest access, unclassified sensitive data, and retention policies that were never configured — creating compliance risk, security exposure, and an environment that becomes harder to manage with every passing month.

Good governance does not mean locking everything down. It means making deliberate decisions about how the platform is configured, who has access to what, where content lives, and how long it is kept — and then maintaining those decisions over time as the organisation and the platform both evolve.

"Microsoft 365 governance is not a one-time configuration task. It is an ongoing programme — and the organisations that treat it as one are the ones that stay in control of their environment rather than being controlled by it."

This checklist covers the seven governance areas that matter most for UK organisations. Each item is practical and actionable. Use it as a starting point for an audit of your current environment, or as a framework for building your governance programme from scratch.

Priority guide: High — act now Medium — plan this quarter Low — review annually
Your progress 0 / 51 items

Identity & access management

Identity is the foundation of Microsoft 365 security and governance. If access to the platform is not managed correctly, every other governance control is weakened. This is the highest-priority area and the right place to start.

Multi-Factor Authentication
Protecting user accounts from compromise
High
MFA is enforced for all users, including administratorsNo user should be able to access Microsoft 365 with a password alone. MFA should be mandatory, not optional.
High
Security defaults or Conditional Access policies are configuredSecurity defaults provide a baseline; Conditional Access gives more granular control over when and how users can authenticate.
High
Global Administrator accounts are dedicated, cloud-only, and monitoredGlobal Admin accounts should never be used for day-to-day work. They should have no mailbox, use strong credentials, and be monitored for sign-in activity.
Medium
Privileged Identity Management (PIM) is configured for admin rolesPIM requires admins to activate elevated permissions on demand, with justification and time limits — reducing the window of exposure if an account is compromised.
Medium
Legacy authentication protocols are blockedOlder authentication protocols do not support MFA and are a common attack vector. Block them via Conditional Access.
Low
Access reviews are scheduled for all privileged rolesReview who holds admin roles at least quarterly and remove access that is no longer required.

External access & guest management

External sharing is one of the most common sources of data governance failure in Microsoft 365. Without clear controls, personal data and confidential documents can be shared too broadly — or remain accessible to people who left a project months ago.

Guest & external sharing controls
Managing who outside your organisation can access your content
High
SharePoint and OneDrive external sharing settings are reviewed and set to the minimum requiredThe default sharing settings are often more permissive than organisations realise. Review and restrict to "Specific people" or "Existing guests" where possible.
High
Anonymous "Anyone with a link" sharing is disabled or restricted by sensitivity labelAnonymous links bypass all access controls. Disable them globally and only enable them for specific, low-risk content via sensitivity labels.
High
Guest access in Teams is governed — guests are reviewed and removed when no longer requiredSet up access reviews for Teams guest members at least quarterly. Stale guest accounts are a persistent governance and security risk.
Medium
External sharing expiry is configured for shared linksSet shared links to expire automatically — 30 or 60 days is a reasonable default for most organisations. This prevents documents remaining accessible indefinitely.
Medium
An approved domains list is configured to restrict guest invitationsIf your organisation works with a defined set of external partners or clients, restrict guest invitations to their domains only.

Microsoft Teams governance

Without governance controls, Teams environments accumulate rapidly — duplicate Teams, abandoned channels, inconsistent naming, and no clear ownership. A well-governed Teams environment is easier to use, easier to secure, and easier to maintain.

Teams creation, naming and lifecycle
Keeping your Teams environment manageable and purposeful
High
Teams creation is restricted to approved users or groupsAllowing all staff to create Teams leads to sprawl. Restrict creation to IT, department leads, or approved requesters — with a simple request process in place.
High
A naming convention is enforced for all TeamsA consistent naming convention (e.g. department-project-name) makes Teams discoverable and manageable. Enforce it via Microsoft 365 group naming policies.
Medium
Expiry policies are configured for Microsoft 365 groups and TeamsSet Teams to expire after a defined period of inactivity (90 or 180 days is common). Owners receive a renewal prompt — no response means the Team is archived.
Medium
Every Team has at least two owners — and ownership is reviewed regularlySingle-owner Teams become unmanageable when the owner leaves. Require two owners minimum at creation and review ownership annually.
Medium
A Teams governance policy document exists and is communicated to staffA written policy — even a single page — that defines how Teams should be used, named, and managed gives staff clarity and gives IT a reference point for enforcement.
Low
Inactive Teams are reviewed and archived or deleted on a regular scheduleRun a quarterly audit of Teams with no activity in the past 60 days. Archive or delete those that are no longer needed, with owner confirmation.

Data classification & sensitivity labels

Sensitivity labels are the mechanism through which Microsoft 365 enforces data governance — applying encryption, access restrictions, and visual markings to documents and emails based on their classification. Without them, your governance framework has no teeth.

Sensitivity labels and data classification
Classifying and protecting your organisation's information
High
A sensitivity label taxonomy is defined and publishedAt minimum: Public, Internal, Confidential, Highly Confidential. Each label should have a clear definition, example content, and defined protection settings.
High
Sensitivity labels are deployed to Microsoft 365 Apps, SharePoint, Teams, and ExchangeLabels should be available across all workloads — not just Word and Outlook. Ensure SharePoint and Teams container labels are configured too.
Medium
A default sensitivity label is configured for documents and emailsA default label ensures that unlabelled content is captured within your governance framework rather than falling outside it entirely.
Medium
Auto-labelling policies are configured for common sensitive content typesAuto-labelling detects and labels content containing personal data, financial information, or other sensitive types — without relying on staff to label correctly every time.
Medium
Highly Confidential content has encryption and access restrictions applied automaticallyThe highest classification label should apply encryption and restrict access to authorised users only — enforced automatically, not dependent on individual action.
Low
Label usage reports are reviewed quarterly to identify unlabelled content and misapplied labelsMicrosoft Purview provides label usage analytics. Review these quarterly and use them to identify training gaps and auto-labelling opportunities.

Retention policies & content lifecycle

UK GDPR requires that personal data is not retained longer than necessary. Retention policies in Microsoft 365 automate this — ensuring content is retained for the required period and then deleted, without manual intervention. Without them, your content accumulates indefinitely.

Retention policies and schedules
Managing content lifecycle in line with your legal and regulatory obligations
High
A retention schedule is defined — covering all major content types and locationsYour retention schedule should define what types of content need to be kept, for how long, and what happens when the retention period ends — retain, delete, or review.
High
Retention policies are deployed to Exchange, SharePoint, OneDrive, and TeamsRetention policies need to cover all the locations where content lives — not just email. Teams chat, channel messages, and SharePoint documents all need coverage.
Medium
Retention labels are applied to high-risk or regulated content typesFor content with specific legal hold or regulatory requirements — HR records, financial documents, contracts — retention labels provide more precise control than broad policies.
Medium
Legal hold capabilities are tested and understoodIf the ICO or a legal team requires content to be preserved beyond its normal retention period, you need to be able to apply a legal hold quickly and confidently. Test this before you need it.
Low
Retention policies are reviewed annually against regulatory changesUK GDPR and sector-specific regulations evolve. Review your retention schedule annually and update policies to reflect any changes in legal obligations.

Data loss prevention

DLP policies detect and prevent sensitive information from being shared in ways that violate your governance policy or regulatory obligations. They are your active control layer — catching problems before they become incidents.

DLP policies and monitoring
Preventing sensitive data from leaving your organisation inappropriately
High
DLP policies are active across Exchange, SharePoint, OneDrive, and TeamsDLP needs to cover all workloads where sensitive data is handled — email, documents, and Teams messages and files.
High
Policies target the sensitive information types most relevant to your organisationAt minimum: UK National Insurance numbers, financial account numbers, health information, passport numbers. Tailor to your sector — financial services, healthcare, and legal have specific requirements.
Medium
DLP policies are in enforcement mode, not test modeMany organisations deploy DLP in simulation mode and never move to enforcement. Policies only protect you when they are actively blocking or warning — not just monitoring.
Medium
DLP alerts are reviewed regularly — and there is a defined process for responding to themDLP alerts are only useful if someone is reviewing them and following up. Define who owns DLP alert review and what the response process looks like.
Low
DLP policy match reports are reviewed quarterly to identify patterns and policy gapsRegular review of DLP match data reveals where sensitive data is being handled most frequently — and whether your policies are catching the right things.

Audit logging, monitoring & ongoing review

Governance is not a configuration you set once. It is a programme you maintain. Audit logging gives you the evidence base you need to demonstrate compliance and investigate incidents. Regular review keeps your governance posture current as the platform and your organisation evolve.

Audit, monitoring and governance review
Maintaining visibility and staying in control over time
High
Unified audit logging is enabled and audit log retention is set to at least 90 days (180 for regulated sectors)Audit logging is not always enabled by default on older tenants. Verify it is on and that retention is sufficient for your regulatory obligations.
High
Admin activity is monitored — alerts are configured for high-risk actionsConfigure alerts for actions such as bulk file downloads, sharing policy changes, admin role assignments, and mailbox delegation changes.
Medium
A named governance owner exists for the Microsoft 365 environmentGovernance without ownership drifts. There should be a named individual — typically an IT Director or Information Manager — accountable for the overall M365 governance posture.
Medium
A quarterly governance review is scheduled — covering permissions, sharing, Teams, labels, and DLPA structured quarterly review catches drift before it becomes a problem. Use the Microsoft Secure Score and Compliance Score as inputs to your review.
Medium
Microsoft Secure Score and Compliance Score are tracked and improvingThese scores provide a structured view of your security and compliance posture and highlight specific improvements you can make. Track them quarterly.
Medium
A data breach response plan is documented and testedWhen a breach occurs, you have 72 hours to notify the ICO. Your response plan should define who does what, in what order — and it should be tested before you need it.
Low
Governance documentation is reviewed and updated annuallyYour governance policies, retention schedules, and sensitivity label taxonomy should be living documents — reviewed at least annually and updated to reflect changes in the platform, regulation, and the organisation.

If you can only do three things this quarter

This checklist covers a lot of ground. If your organisation is starting from scratch — or has never had a structured governance programme — the breadth of it can feel daunting. Here is where to focus first.

  • Enable MFA for all users and block legacy authentication. This is the single highest-impact action you can take for security and it is quick to implement. Everything else in the checklist is harder to protect if identity is not secured first.
  • Review your external sharing settings and guest access. Go into the SharePoint admin centre and check your sharing settings. Check Teams for stale guest members. Tighten both. This is where most organisations find their biggest immediate risks.
  • Deploy or review your retention policies. If you have none, start with Exchange and SharePoint and apply organisation-wide policies. If you have some, verify they are active and covering the right locations. This is your most direct UK GDPR compliance action.

"A governance programme does not have to be perfect from day one. It has to be started. The organisations with the best governance postures got there incrementally — one controlled improvement at a time."

Where Cordapse can help

Working through this checklist will give you a clear picture of where your Microsoft 365 governance programme stands — and where the gaps are. For many IT leaders, the audit itself surfaces things that have been building quietly for months or years.

At Cordapse, we offer Microsoft 365 governance assessments that work through exactly these areas — giving you a clear, prioritised picture of your current posture and a practical roadmap for improvement. We also implement governance frameworks, configure compliance controls, and provide ongoing governance support for UK organisations that want to stay in control of their environment over time.

Free consultation

Not sure how your Microsoft 365 governance stacks up?

Book a free, no-obligation consultation and we will help you work through your current governance posture — identifying the gaps that carry the most risk and the improvements that will have the greatest impact.

Book a free consultation →
Microsoft 365 governance for UK organisations

"A governance programme does not have to be perfect from day one. It has to be started — one controlled improvement at a time."

Cordapse · Insight & Opinion · Compliance & Governance

What a well-governed Microsoft 365 environment actually delivers

Governance is sometimes framed as a compliance obligation — something you do to avoid fines rather than to create value. The organisations that govern their Microsoft 365 environment well know that is not the full picture. Good governance creates a platform that is safer, more usable, and more capable of supporting the things the business wants to do next.

Reduced security exposure
MFA, Conditional Access, tightened external sharing, and monitored admin activity close the most common attack vectors — before they are exploited.
Demonstrable UK GDPR compliance
Retention policies, sensitivity labels, DLP, and audit logs give you the evidence base to demonstrate compliance — not just claim it — if the ICO ever asks.
A more usable environment
A governed Teams environment — with consistent naming, clear ownership, and defined purpose — is easier to navigate and more likely to be adopted by staff than an ungoverned one.
Foundation for AI adoption
Microsoft 365 Copilot works best — and most safely — in a well-governed environment. Sensitivity labels, DLP, and tightened permissions are prerequisites for responsible AI deployment.

Ready to get your Microsoft 365 governance in order?

We have spent over 30 years helping UK organisations build well-governed Microsoft 365 environments. Book a free consultation and find out where your governance gaps are — and how to close them.

Book a Free Consultation