Why This Matters
Good governance is what separates a well-run Microsoft 365 environment from a liability
Microsoft 365 is one of the most powerful productivity platforms available to UK organisations. It is also one of the most complex to govern well. Left unmanaged, it accumulates ungoverned Teams, overly permissive sharing settings, unreviewed guest access, unclassified sensitive data, and retention policies that were never configured — creating compliance risk, security exposure, and an environment that becomes harder to manage with every passing month.
Good governance does not mean locking everything down. It means making deliberate decisions about how the platform is configured, who has access to what, where content lives, and how long it is kept — and then maintaining those decisions over time as the organisation and the platform both evolve.
"Microsoft 365 governance is not a one-time configuration task. It is an ongoing programme — and the organisations that treat it as one are the ones that stay in control of their environment rather than being controlled by it."
This checklist covers the seven governance areas that matter most for UK organisations. Each item is practical and actionable. Use it as a starting point for an audit of your current environment, or as a framework for building your governance programme from scratch.
Priority guide:
High — act now
Medium — plan this quarter
Low — review annually
Your progress 0 / 51 items
Area 1 of 7
Identity & access management
Identity is the foundation of Microsoft 365 security and governance. If access to the platform is not managed correctly, every other governance control is weakened. This is the highest-priority area and the right place to start.
HighMFA is enforced for all users, including administratorsNo user should be able to access Microsoft 365 with a password alone. MFA should be mandatory, not optional.
HighSecurity defaults or Conditional Access policies are configuredSecurity defaults provide a baseline; Conditional Access gives more granular control over when and how users can authenticate.
HighGlobal Administrator accounts are dedicated, cloud-only, and monitoredGlobal Admin accounts should never be used for day-to-day work. They should have no mailbox, use strong credentials, and be monitored for sign-in activity.
MediumPrivileged Identity Management (PIM) is configured for admin rolesPIM requires admins to activate elevated permissions on demand, with justification and time limits — reducing the window of exposure if an account is compromised.
MediumLegacy authentication protocols are blockedOlder authentication protocols do not support MFA and are a common attack vector. Block them via Conditional Access.
LowAccess reviews are scheduled for all privileged rolesReview who holds admin roles at least quarterly and remove access that is no longer required.
Area 2 of 7
External access & guest management
External sharing is one of the most common sources of data governance failure in Microsoft 365. Without clear controls, personal data and confidential documents can be shared too broadly — or remain accessible to people who left a project months ago.
HighSharePoint and OneDrive external sharing settings are reviewed and set to the minimum requiredThe default sharing settings are often more permissive than organisations realise. Review and restrict to "Specific people" or "Existing guests" where possible.
HighAnonymous "Anyone with a link" sharing is disabled or restricted by sensitivity labelAnonymous links bypass all access controls. Disable them globally and only enable them for specific, low-risk content via sensitivity labels.
HighGuest access in Teams is governed — guests are reviewed and removed when no longer requiredSet up access reviews for Teams guest members at least quarterly. Stale guest accounts are a persistent governance and security risk.
MediumExternal sharing expiry is configured for shared linksSet shared links to expire automatically — 30 or 60 days is a reasonable default for most organisations. This prevents documents remaining accessible indefinitely.
MediumAn approved domains list is configured to restrict guest invitationsIf your organisation works with a defined set of external partners or clients, restrict guest invitations to their domains only.
Area 3 of 7
Microsoft Teams governance
Without governance controls, Teams environments accumulate rapidly — duplicate Teams, abandoned channels, inconsistent naming, and no clear ownership. A well-governed Teams environment is easier to use, easier to secure, and easier to maintain.
HighTeams creation is restricted to approved users or groupsAllowing all staff to create Teams leads to sprawl. Restrict creation to IT, department leads, or approved requesters — with a simple request process in place.
HighA naming convention is enforced for all TeamsA consistent naming convention (e.g. department-project-name) makes Teams discoverable and manageable. Enforce it via Microsoft 365 group naming policies.
MediumExpiry policies are configured for Microsoft 365 groups and TeamsSet Teams to expire after a defined period of inactivity (90 or 180 days is common). Owners receive a renewal prompt — no response means the Team is archived.
MediumEvery Team has at least two owners — and ownership is reviewed regularlySingle-owner Teams become unmanageable when the owner leaves. Require two owners minimum at creation and review ownership annually.
MediumA Teams governance policy document exists and is communicated to staffA written policy — even a single page — that defines how Teams should be used, named, and managed gives staff clarity and gives IT a reference point for enforcement.
LowInactive Teams are reviewed and archived or deleted on a regular scheduleRun a quarterly audit of Teams with no activity in the past 60 days. Archive or delete those that are no longer needed, with owner confirmation.
Area 4 of 7
Data classification & sensitivity labels
Sensitivity labels are the mechanism through which Microsoft 365 enforces data governance — applying encryption, access restrictions, and visual markings to documents and emails based on their classification. Without them, your governance framework has no teeth.
HighA sensitivity label taxonomy is defined and publishedAt minimum: Public, Internal, Confidential, Highly Confidential. Each label should have a clear definition, example content, and defined protection settings.
HighSensitivity labels are deployed to Microsoft 365 Apps, SharePoint, Teams, and ExchangeLabels should be available across all workloads — not just Word and Outlook. Ensure SharePoint and Teams container labels are configured too.
MediumA default sensitivity label is configured for documents and emailsA default label ensures that unlabelled content is captured within your governance framework rather than falling outside it entirely.
MediumAuto-labelling policies are configured for common sensitive content typesAuto-labelling detects and labels content containing personal data, financial information, or other sensitive types — without relying on staff to label correctly every time.
MediumHighly Confidential content has encryption and access restrictions applied automaticallyThe highest classification label should apply encryption and restrict access to authorised users only — enforced automatically, not dependent on individual action.
LowLabel usage reports are reviewed quarterly to identify unlabelled content and misapplied labelsMicrosoft Purview provides label usage analytics. Review these quarterly and use them to identify training gaps and auto-labelling opportunities.
Area 5 of 7
Retention policies & content lifecycle
UK GDPR requires that personal data is not retained longer than necessary. Retention policies in Microsoft 365 automate this — ensuring content is retained for the required period and then deleted, without manual intervention. Without them, your content accumulates indefinitely.
HighA retention schedule is defined — covering all major content types and locationsYour retention schedule should define what types of content need to be kept, for how long, and what happens when the retention period ends — retain, delete, or review.
HighRetention policies are deployed to Exchange, SharePoint, OneDrive, and TeamsRetention policies need to cover all the locations where content lives — not just email. Teams chat, channel messages, and SharePoint documents all need coverage.
MediumRetention labels are applied to high-risk or regulated content typesFor content with specific legal hold or regulatory requirements — HR records, financial documents, contracts — retention labels provide more precise control than broad policies.
MediumLegal hold capabilities are tested and understoodIf the ICO or a legal team requires content to be preserved beyond its normal retention period, you need to be able to apply a legal hold quickly and confidently. Test this before you need it.
LowRetention policies are reviewed annually against regulatory changesUK GDPR and sector-specific regulations evolve. Review your retention schedule annually and update policies to reflect any changes in legal obligations.
Area 6 of 7
Data loss prevention
DLP policies detect and prevent sensitive information from being shared in ways that violate your governance policy or regulatory obligations. They are your active control layer — catching problems before they become incidents.
HighDLP policies are active across Exchange, SharePoint, OneDrive, and TeamsDLP needs to cover all workloads where sensitive data is handled — email, documents, and Teams messages and files.
HighPolicies target the sensitive information types most relevant to your organisationAt minimum: UK National Insurance numbers, financial account numbers, health information, passport numbers. Tailor to your sector — financial services, healthcare, and legal have specific requirements.
MediumDLP policies are in enforcement mode, not test modeMany organisations deploy DLP in simulation mode and never move to enforcement. Policies only protect you when they are actively blocking or warning — not just monitoring.
MediumDLP alerts are reviewed regularly — and there is a defined process for responding to themDLP alerts are only useful if someone is reviewing them and following up. Define who owns DLP alert review and what the response process looks like.
LowDLP policy match reports are reviewed quarterly to identify patterns and policy gapsRegular review of DLP match data reveals where sensitive data is being handled most frequently — and whether your policies are catching the right things.
Area 7 of 7
Audit logging, monitoring & ongoing review
Governance is not a configuration you set once. It is a programme you maintain. Audit logging gives you the evidence base you need to demonstrate compliance and investigate incidents. Regular review keeps your governance posture current as the platform and your organisation evolve.
HighUnified audit logging is enabled and audit log retention is set to at least 90 days (180 for regulated sectors)Audit logging is not always enabled by default on older tenants. Verify it is on and that retention is sufficient for your regulatory obligations.
HighAdmin activity is monitored — alerts are configured for high-risk actionsConfigure alerts for actions such as bulk file downloads, sharing policy changes, admin role assignments, and mailbox delegation changes.
MediumA named governance owner exists for the Microsoft 365 environmentGovernance without ownership drifts. There should be a named individual — typically an IT Director or Information Manager — accountable for the overall M365 governance posture.
MediumA quarterly governance review is scheduled — covering permissions, sharing, Teams, labels, and DLPA structured quarterly review catches drift before it becomes a problem. Use the Microsoft Secure Score and Compliance Score as inputs to your review.
MediumMicrosoft Secure Score and Compliance Score are tracked and improvingThese scores provide a structured view of your security and compliance posture and highlight specific improvements you can make. Track them quarterly.
MediumA data breach response plan is documented and testedWhen a breach occurs, you have 72 hours to notify the ICO. Your response plan should define who does what, in what order — and it should be tested before you need it.
LowGovernance documentation is reviewed and updated annuallyYour governance policies, retention schedules, and sensitivity label taxonomy should be living documents — reviewed at least annually and updated to reflect changes in the platform, regulation, and the organisation.
Where to Start
If you can only do three things this quarter
This checklist covers a lot of ground. If your organisation is starting from scratch — or has never had a structured governance programme — the breadth of it can feel daunting. Here is where to focus first.
- Enable MFA for all users and block legacy authentication. This is the single highest-impact action you can take for security and it is quick to implement. Everything else in the checklist is harder to protect if identity is not secured first.
- Review your external sharing settings and guest access. Go into the SharePoint admin centre and check your sharing settings. Check Teams for stale guest members. Tighten both. This is where most organisations find their biggest immediate risks.
- Deploy or review your retention policies. If you have none, start with Exchange and SharePoint and apply organisation-wide policies. If you have some, verify they are active and covering the right locations. This is your most direct UK GDPR compliance action.
"A governance programme does not have to be perfect from day one. It has to be started. The organisations with the best governance postures got there incrementally — one controlled improvement at a time."
Next Steps
Where Cordapse can help
Working through this checklist will give you a clear picture of where your Microsoft 365 governance programme stands — and where the gaps are. For many IT leaders, the audit itself surfaces things that have been building quietly for months or years.
At Cordapse, we offer Microsoft 365 governance assessments that work through exactly these areas — giving you a clear, prioritised picture of your current posture and a practical roadmap for improvement. We also implement governance frameworks, configure compliance controls, and provide ongoing governance support for UK organisations that want to stay in control of their environment over time.