SYSTEM 8Discuss a system ↗
DOCS / M365-001

M365-001 / SOURCE CONTROLLED

Microsoft 365 governance baseline

A governance baseline is the smallest set of decisions, owners and evidence needed to operate Microsoft 365 deliberately. It is not a list of every tenant setting.

● CONTROLLEDOWNER / SYSTEM 8REVIEW / MONTHLY
01

Scope and boundary

This baseline covers six connected control areas: identity, information architecture, external collaboration, information protection, Power Platform lifecycle and automation identities. Each control must name an owner, an operating rule, its evidence source and a review interval.

It does not assume that every workload belongs in SharePoint or that every business process should be rebuilt in Power Platform. Platform fit remains a separate architecture decision.

02

Identity and access

  • Require strong authentication and risk-based access for administrators and sensitive workloads.
  • Separate everyday accounts from privileged roles; prefer time-bound elevation over permanent privilege.
  • Record application registrations, managed identities, delegated permissions, owners and expiry conditions.
  • Test break-glass access and keep its use visible to accountable owners.
03

SharePoint and information control

  • Design sites around stable accountability and information boundaries, not the organisation chart alone.
  • Assign an owner and lifecycle state to every production site, team and externally shared workspace.
  • Treat sensitivity labels, retention, records management and data-loss prevention as coordinated but distinct controls.
  • Use naming, templates and provisioning policy to reduce exceptions without hiding legitimate ones.
04

Power Platform and automation

CONTROLMINIMUM EVIDENCE
Environment strategyPurpose, owner, data boundary, connector policy and release route
Solutions and ALMSource, managed/unmanaged status, dependencies and rollback
DataverseData model, roles, ownership, audit and retention
Graph/API automationIdentity, permission rationale, secret/certificate lifecycle and action log
05

Control evidence pack

  • Tenant and workload decision register.
  • Identity, privileged-role and application-permission inventory.
  • Site, team, environment and data-owner register.
  • Sharing, retention, DLP and sensitivity-policy map.
  • Release, exception, incident and recovery procedures with last-tested dates.
06

Operating cadence

Review high-risk changes continuously, exceptions monthly and the baseline quarterly. A control without current evidence is a claim, not a control. The review should close stale workspaces, expired access and abandoned automations—not merely report them.