---
title: "Microsoft 365: access and sharing governance strategy"
description: "Microsoft 365 governance: manage accesses, rights and sharings on Microsoft Teams, SharePoint and OneDrive and engage users"
image: https://blog.idecsi.com/hubfs/Blog%20Images/Microsoft-365-data-governance.png
---

[![Logo-Idecsi-Black-tagline](https://blog.idecsi.com/hs-fs/hubfs/LOGOS%20IDECSI/LOGOS%20OFFICIELS/Logo-Idecsi-Black-tagline.png?width=1010&height=319&name=Logo-Idecsi-Black-tagline.png)](https://www.idecsi.com/)

- Solutions
  
  
  
  
  
  DETOX® pour M365
  
  Audit, Remediation & ROI
  
  [Discover DETOX](https://info.idecsi.com/detox-m365?hsLang=en)
  
  ![Audit, Remediation & ROI](https://blog.idecsi.com/hubfs/ILLU-4.png)
  
  
  
  
  
  Solutions
  
  IDECSI gives security and IT teams full control over their data — across DSPM, Data Access Governance, Human Risk Management, and Data Volume Management.
  
  
  
    - [![download_done](https://blog.idecsi.com/hubfs/download_done.svg) M365 Data Security Platform](https://www.idecsi.com/solution/mydatasecurity/)
    - [![download_done](https://blog.idecsi.com/hubfs/download_done.svg) Data storage optimization](https://www.idecsi.com/solution/mydatamanagement/)
- Challenges
  
  
  
  
  
  M365 Checklist
  
  15 Warning Signs Your M365 Data Is at Risk
  
  [Get the checklist](https://info.idecsi.com/checklist-15-warningsigns?hsLang=en)
  
  ![Checklist risques M365](https://blog.idecsi.com/hubfs/Frame-2147255341.png)
  
  
  
  
  
  Your 2026 Challenges
  
  Address your most critical data security and governance challenges - across your M365 environment
  
  
  
    - [![download_done](https://blog.idecsi.com/hubfs/download_done.svg) Gain visibility accross M365](https://www.idecsi.com/challenges/visibility-microsoft-365)
    - [![download_done](https://blog.idecsi.com/hubfs/download_done.svg) Get Ready For Copilot M365](https://www.idecsi.com/challenges/m365-copilot/)
    - [![download_done](https://blog.idecsi.com/hubfs/download_done.svg) Control external user access](https://www.idecsi.com/challenges/external-access-microsoft-365/)
    - [![download_done](https://blog.idecsi.com/hubfs/download_done.svg) Prevent Sensitive Data Exposure](https://www.idecsi.com/challenges/sensitive-data-m365/)
    - [![download_done](https://blog.idecsi.com/hubfs/download_done.svg) Gain visibility across Microsoft 365](https://www.idecsi.com/challenges/visibility-microsoft-365/)
    - [![download_done](https://blog.idecsi.com/hubfs/download_done.svg) Ensure regulatory compliance](https://www.idecsi.com/challenges/compliance-m365/)
- Resources
  
  
  
  
  
  Is Your Tenant Ready for Copilot?
  
  A Security & Governance Playbook
  
  [Download](https://info.idecsi.com/whitepapper_copilot?hsLang=en)
  
  ![Copilot guide](https://blog.idecsi.com/hubfs/Frame-2147255339.png)
  
  
  
  
  
  Our resources
  
  Check out our useful resources for improving data protection
  
  
  
    - [![download_done](https://blog.idecsi.com/hubfs/download_done.svg) Blog](https://blog.idecsi.com)
    - [![download_done](https://blog.idecsi.com/hubfs/download_done.svg) Help Center](https://help.idecsi.com/)
    - [![download_done](https://blog.idecsi.com/hubfs/download_done.svg) Ressources & News](https://blog.idecsi.com/resources?hsLang=en)
    - [![download_done](https://blog.idecsi.com/hubfs/download_done.svg) About us](https://www.idecsi.com/about-us/)
- [Customers](https://blog.idecsi.com/resources-customer?hsLang=en)
- - [English](https://blog.idecsi.com/microsoft-365-governance-strategy)
    - [Français](https://blog.idecsi.com/fr/office-365-strategie-gouvernance-partages-acces)

Search

[Request a demo](https://info.idecsi.com/demo-idecsi?hsLang=en)

Microsoft 365

03 September 2019

# Microsoft 365 and governance: who is accessing what?

![Microsoft 365 governance](https://f.hubspotusercontent40.net/hubfs/4272098/Blog%20Images/Microsoft-365-data-governance.png)

- [Home](https://www.idecsi.com/)
- [Blog](https://blog.idecsi.com)
- Microsoft 365 and governance: who is accessing what?

With the ongoing data proliferation throughout your organisation, how can you gain visibility and ensure that the CIO has control of the situation? Or give your users visibility to their data security: delegations, access to sensitive documents, anonymous sharing,…

- [Improve visibility to increase the security of your data](https://blog.idecsi.com/microsoft-365-governance-strategy#Improve)
- [What access and sharing governance strategy should be adopted?](https://blog.idecsi.com/microsoft-365-governance-strategy#strategy)

 

## Improve visibility to increase the security of your data

The workspace is no longer limited to specific endpoints or networks. Users share folders, give access, access files, and communicate externally, all from any location with any device. Today’s digital environment brings a multitude of possibilities.

The CISO, CIO, head of HR, CFO, DPO and others are increasingly worried about the security of these tools and data. The perimeter is constantly extending as a result of migration to the cloud, digital transformation and expanding collaboration. In a recent study, the Ponemon Institute revealed that **52% of surveyed companies’ keep their sensitive and confidential data in SharePoint \[1\].**

To ensure that everyone’s data is protected, it’s crucial that only the correct rights and permissions are granted for all resources: users, applications and documents. It can be challenging to ensure that each user – whether **an administrator,** a member of the exec committee or an employee – has appropriate and up-to-date permissions. In some cases, access rights and permissions can be the unintentional result of a chain reaction: a domino effect of access and sharing following exchanges and conversations.

With more users, more data is created. Monitoring the activity of a multitude of data stores or libraries and understanding what is happening seems almost impossible.

**How can the CISO or CIO gain visibility and ensure that the situation is not out of control? How can the users understand their data security?**

 

## What access and sharing governance strategy should be adopted?

There is a huge number of possibilities for users to manage and share their data, and the tools are constantly being enriched with additional services and features. It’s therefore critical to put in place a governance strategy so that the CISO and the user can ensure the security and integrity of the data.

- What functionality can the user access, for example in the case of the Office 365 environment?
- Is it appropriate based on the risk profile and policies of the company?
- Are all the permissions acceptable?

### Map Out the Risks

The starting point is to determine where the risks are:

- At the company level

- - Key sites: locations of the sensitive data and confidential resources
    - Key areas of sensitivity: global configuration, privileged accounts, administrator console
    - Organizational elements: user groups, security policies
- At the individual level
- - Delegations in email accounts “View, Send As”
    - International access (sensitive countries Nigeria, China)
    - Which applications piggyback on the authentication of the user and access their data?
    - Who has access to what on OneDrive, SharePoint, Teams?
    - Who does the user share documents with, internally and externally?
- At the application level, each tool has specific issues that need to be understood and taken into account to provide the optimal security configuration

### Sanitising the environment and ensuring it remains healthy

Are email accounts compromised right now? Who is viewing sensitive SharePoint files? Is there any external or anonymous sharing? What permissions and rights exist, who can access which account, what accesses and access modes are observed, what devices are synchronized, which rules are configured?

Identifying and correcting excessive rights and unauthorised configuration adds great value. Thereafter, it is vital to maintain the health of the environment. Companies have to constantly monitor changes and regularly verify the configuration, rights and permissions. Real time alerting when highly sensitive operations occur ensures that issues are dealt with promptly and breaches are avoided.

### Personalised user based anomaly detection

By monitoring logs and other data in Office 365 or on-premise SharePoint, it is now possible to identify suspicious access, sharing, location, and change of rights or configuration – on a per user or per resource basis.

Personalised user-based protection is about understanding what’s legitimate and what’s not. Beyond statistics, or conventional behavioural analysis, a phase of automatic learning allows the creation of a profile of the user or library. Each action that occurs can be analysed in its exact context (geolocation, schedule, connection protocol, application, …) to determine whether it is legitimate or not.

### Send information directly to the right people for verification

When an alert is issued, it can be sent to CISO team, a SIEM and/or a SOC. It can also be delivered directly to users, for immediate validation by the user who understands how their data should be accessed. The user can see the rights, the devices, the delegates and the accesses to their resources, and confirms or queries the status of their account via a dedicated page: MyDataSecurity.

For each potentially dangerous action, the user immediately reports it to the SOC: a new download or synchronization, access to a sensitive document or library, a full access delegation,… The alert can be immediately addressed by the user, and the user has, for the first time, global visibility to their data security.

### High-volume processing: productivity and security

Large organisations benefit through this automation. Validation of account security is via such automated engagement with users. The support team focuses only on the alerts where users have confirmed real issues. The security team can quickly investigate through a dashboard that centralizes the users’ notifications and allows forensic analysis of the underlying activity.  
**Users become the first line of defense for the company.**  
End-user validation adds unprecedented value to the operation of a traditional SOC, with a double advantage: on the one hand, preventive – each user is aware of their own security; on the other hand, curative – any abnormal or malicious behaviour can be detected and remediated quickly, with clarity as to the underlying cause.  
**This approach is essential for any organization that wants to increase the security of its information system and the governance of who accesses what? Who can do what? Who shares what? It provides full visibility to the most sensitive Office 365 operations.**  
With a dynamic and collaborative approach, the review of rights and current access is highly efficient and avoids resource limitations. It offers a company wide service at a lower cost. Security breaches are reduced.

 

\[1\] Ponemon institute research report, May 2017

 Recent articles

[Microsoft 365 Copilot Architecture: Technical Deep Dive (2026)](https://blog.idecsi.com/microsoft-365-copilot-architecture?hsLang=en)

[Securing AI Agents in Microsoft 365: Best Practices for 2026](https://blog.idecsi.com/securing-ai-agents-microsoft-365?hsLang=en)

[Data Exposure in Microsoft 365: Understanding the Risks and Taking Back Control](https://blog.idecsi.com/microsoft-365-data-exposure?hsLang=en)

[Copilot Cowork in Microsoft 365: What CIOs Need to Know](https://blog.idecsi.com/copilot-cowork-microsoft-365?hsLang=en)

 Best practices to improve Microsoft Teams security

[![Download the infographic ](https://no-cache.hubspot.com/cta/default/4272098/825ad7d1-e961-4a7a-a6b3-6e380b22285f.png)](https://cta-redirect.hubspot.com/cta/redirect/4272098/825ad7d1-e961-4a7a-a6b3-6e380b22285f)

 Share this article

<https://twitter.com/intent/tweet?text=https://blog.idecsi.com/microsoft-365-governance-strategy> <http://www.facebook.com/sharer.php?u=https://blog.idecsi.com/microsoft-365-governance-strategy> <https://www.linkedin.com/sharing/share-offsite/?url=https://blog.idecsi.com/microsoft-365-governance-strategy>

Subscribe to our newsletter and receive new contents every month

 Our articles

These articles may   
interest you

![](https://4272098.fs1.hubspotusercontent-na1.net/hubfs/4272098/image%20%2858%29.png)

 Microsoft 365

 Security

 Securing AI Agents in Microsoft 365: Best Practices for 2026 

<https://blog.idecsi.com/securing-ai-agents-microsoft-365?hsLang=en> [Lire l'article](https://blog.idecsi.com/securing-ai-agents-microsoft-365?hsLang=en)

![Partages externes des utilisateurs](https://4272098.fs1.hubspotusercontent-na1.net/hubfs/4272098/Blog%20Images/BLOG-PARTAGES-EXTERNES.png)

 Microsoft 365

 Workplace

 Microsoft 365 External Sharing: Best Practices Guide 2026 

<https://blog.idecsi.com/microsoft-365-external-sharing-best-practices?hsLang=en> [Lire l'article](https://blog.idecsi.com/microsoft-365-external-sharing-best-practices?hsLang=en)

![OneDrive Security: 3 pain points to manage data ](https://4272098.fs1.hubspotusercontent-na1.net/hubfs/4272098/Illus-Blog-Onedrive-2%201.png)

 Microsoft 365

 Security

 OneDrive for Business Security: 3 Key Areas to Watch 

<https://blog.idecsi.com/en/onedrive-for-business-security-best-practices?hsLang=en> [Lire l'article](https://blog.idecsi.com/en/onedrive-for-business-security-best-practices?hsLang=en)

![Le versioning de fichiers sur Microsoft 365](https://4272098.fs1.hubspotusercontent-na1.net/hubfs/4272098/Blogpost-Versionning%202.png)

 Microsoft 365

 Storage

 Microsoft 365 Version History: Storage Management Guide 

<https://blog.idecsi.com/m365-version-history-storage?hsLang=en> [Lire l'article](https://blog.idecsi.com/m365-version-history-storage?hsLang=en)

### Data protection, let's discuss your project?

 

[![Contact us](https://no-cache.hubspot.com/cta/default/4272098/bea4f372-c84f-4ec4-980c-ca663747fbfe.png)](https://cta-redirect.hubspot.com/cta/redirect/4272098/bea4f372-c84f-4ec4-980c-ca663747fbfe)

![video background](https://idecsi2a-dev-idecsi.pf27.wpserveur.net/wp-content/uploads/2022/02/video-background-idecsi-responsive-1.png)

[![Logo-Idecsi-White-Ss-ES](https://blog.idecsi.com/hubfs/LOGOS%20IDECSI/LOGOS%20OFFICIELS/Logo-Idecsi-White-Ss-ES.svg)](https://www.idecsi.com/)

 +33 1 84 79 38 30

- <https://twitter.com/IDECSI>
- <https://www.facebook.com/IDECSI-306865969441428/>
- <https://www.linkedin.com/company/idecsi/>

- [Why choose IDECSI?](https://www.idecsi.com/user-security/)
- [About us](https://www.idecsi.com/about-us/)
- [Join the team](https://www.welcometothejungle.com/fr/companies/idecsi)

- Solutions 
    - [Visibility](https://www.idecsi.com/challenge-data-visibility/)
    - [Detection](https://www.idecsi.com/challenge-threat-detection/)
    - [User engagement](https://www.idecsi.com/challenge-involve-user/)
    - [Access review](https://www.idecsi.com/challenge-rights-review/)
    - [Remediation](https://www.idecsi.com/challenge-remediation/)
    - [Sensitive data](https://www.idecsi.com/challenge-sensitive-data/)

- [Products](https://www.idecsi.com/solution/) 
    - [MyDataSecurity](https://www.idecsi.com/solution/mydatasecurity/)
    - [Advanced Monitoring](https://www.idecsi.com/solution/advanced-monitoring/)
    - [MyDataManagement](https://www.idecsi.com/solution/mydatamanagement/)

- Resources 
    - [Resources & News](https://blog.idecsi.com/resources?hsLang=en)
    - [Blog](https://blog.idecsi.com)
    - [Customer success](https://blog.idecsi.com/resources-customer?hsLang=en)
    - [Extranet](https://extranet.idecsi.com?hsLang=en)

 © IDECSI

```json
{
  "@context" : "https://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Mona Piquet",
    "url" : "https://blog.idecsi.com/author/mona-piquet"
  },
  "dateModified" : "2021-12-14T10:07:38.856Z",
  "datePublished" : "2019-09-03T15:42:00.000Z",
  "headline" : "Microsoft 365: access and sharing governance strategy",
  "image" : [ "https://blog.idecsi.com/hubfs/Blog%20Images/Microsoft-365-data-governance.png" ],
  "mainEntityOfPage" : {
    "@id" : "https://blog.idecsi.com/microsoft-365-governance-strategy",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://blog.idecsi.com/hubfs/Logo-Idecsi-Black-tagline.png"
    },
    "name" : "IDECSI"
  }
}
```