M365-001 / SOURCE CONTROLLED
Microsoft 365 governance baseline
A governance baseline is the smallest set of decisions, owners and evidence needed to operate Microsoft 365 deliberately. It is not a list of every tenant setting.
Scope and boundary
This baseline covers six connected control areas: identity, information architecture, external collaboration, information protection, Power Platform lifecycle and automation identities. Each control must name an owner, an operating rule, its evidence source and a review interval.
It does not assume that every workload belongs in SharePoint or that every business process should be rebuilt in Power Platform. Platform fit remains a separate architecture decision.
Identity and access
- Require strong authentication and risk-based access for administrators and sensitive workloads.
- Separate everyday accounts from privileged roles; prefer time-bound elevation over permanent privilege.
- Record application registrations, managed identities, delegated permissions, owners and expiry conditions.
- Test break-glass access and keep its use visible to accountable owners.
SharePoint and information control
- Design sites around stable accountability and information boundaries, not the organisation chart alone.
- Assign an owner and lifecycle state to every production site, team and externally shared workspace.
- Treat sensitivity labels, retention, records management and data-loss prevention as coordinated but distinct controls.
- Use naming, templates and provisioning policy to reduce exceptions without hiding legitimate ones.
Power Platform and automation
| CONTROL | MINIMUM EVIDENCE |
|---|---|
| Environment strategy | Purpose, owner, data boundary, connector policy and release route |
| Solutions and ALM | Source, managed/unmanaged status, dependencies and rollback |
| Dataverse | Data model, roles, ownership, audit and retention |
| Graph/API automation | Identity, permission rationale, secret/certificate lifecycle and action log |
Control evidence pack
- Tenant and workload decision register.
- Identity, privileged-role and application-permission inventory.
- Site, team, environment and data-owner register.
- Sharing, retention, DLP and sensitivity-policy map.
- Release, exception, incident and recovery procedures with last-tested dates.
Operating cadence
Review high-risk changes continuously, exceptions monthly and the baseline quarterly. A control without current evidence is a claim, not a control. The review should close stale workspaces, expired access and abandoned automations—not merely report them.