SlideShare a Scribd company logo
Microsoft 365 Copilot: How to boost your productivity with AI. Part two: Data security and governance | IntraTeam event | April 2024
Nikki Chapple
Principal Cloud Architect
nikkichapple
@chapplenikki
www.nikkichapple.com
All Things M365 Compliance
Agenda
• The risks of not addressing data security and governance as part of
your Microsoft 365 Copilot transformation
• How to configure Microsoft 365 for “just enough access” to safeguard
your sensitive data
• How to improve data governance to deliver more accurate and
relevant recommendations
Big Data - A New Era
4
Essentials for Copilot success
Nominate and
activate your
Copilot executive
sponsors, in
partnership with
your AI Council
Define initial high
value scenarios
and target a
critical mass of
users for rapid
value
Define your
path to secure
your data for
compliance
and peace of
mind
Copilot for Microsoft 365 implementation
Copilot
implementation
Sponsor
Scenarios
Security
Copilot essentials
checklist
User Enablement
Prepare organization and employees for the AI
transformation journey
Workstreams support each other for maximum value and ROI
Technical Readiness
Address technical deployment and optimization,
including governance, security, compliance, and
management
Leadership journey
1
6
2
3
5
3
4
Data flow ( = all requests are encrypted via HTTPS)
User prompts from Microsoft 365 Apps are sent to Copilot
Copilot accesses Graph and Semantic Index for pre-processing
Copilot sends modified prompt to Large Language Model (LLM)
Copilot receives LLM response
Copilot accesses Graph and Semantic Index for post-processing
Copilot sends the response, and app command back to Microsoft 365 Apps
1
2
3
4
5
6
Microsoft 365 Trust Boundary
Customer’s Microsoft 365 Tenant
Semantic
Index
Azure
OpenAI
RAI
Azure Open AI
instance is
maintained by
Microsoft. Open
AI has no access
to the data or the
model.
RAI is performed
on input prompt
and output results
Customer data is
not stored or used
to train the model
Improve your data quality with Data Lifecycle
Management
8
• Restrict access
• Delete
redundant,
obsolete, or
trivial (ROT) data
• Access
permissions
• Sharing links
• Naming
conventions
• Metadata
Create
Store
and Use
Archive
Delete
Technical considerations for compliance
and security of deployment
Copilot for Microsoft 365 basic architecture
6
2
3
5
3
4
Microsoft 365 Service
Boundary
Customer Microsoft 365 Tenant
Semantic
Index
Azure
OpenAI
RAI
Azure OpenAI
instance is
maintained by
Microsoft. OpenAI
has no access to the
data or the model.
RAI is performed on
input prompt and
output results
Prompts, responses, and data
accessed through Microsoft
Graph aren't used to train
foundation models
1
Data flow (lock) = all requests are encrypted via HTTPS and wss://)
1 User prompts from Microsoft 365 Apps are sent to Copilot
2 Copilot accesses Graph and Semantic Index for pre-processing
3 Copilot sends modified prompt to Large Language Model
4 Copilot receives LLM response
5 Copilot accesses Graph and Semantic Index for post-processing
6 Copilot sends the response, and app command back to Microsoft 365 Apps
Microsoft’s approach to privacy
You control
your data
You know
where your
data is located
We secure
your data at rest
and in transit
We defend
your data
Common questions
we hear from
customers
How do we know our data is secure?
When will we be able to audit Copilot usage?
What can I do to avoid overexposing our data?
Where is my data processed?
Copilot for Microsoft 365
Built on Microsoft’s comprehensive approach
Security Compliance Privacy Responsible AI
Microsoft 365 Copilot: How to boost your productivity with AI. Part two: Data security and governance | IntraTeam event | April 2024
1. Understand
your current
risks and data
security
readiness
Most data stored outside Microsoft 365
and users work in email
3rd Party data
storage
Ungoverned - access Ungoverned – no access
Location hidden from scope –
Excluded
SharePoint
Your
OneDrive
Others
OneDrives
Use of OneDrive increases but emailing files
not sharing files - no adoption or training
Ungoverned - access Ungoverned – no access
Location hidden from scope –
Excluded
Your
OneDrive
SharePoint
3rd Party data
storage
Your
OneDrive
Others
OneDrives
Pioneers create ungoverned Teams & Sites
Ungoverned - access Ungoverned – no access
Location hidden from scope –
Excluded
Your
OneDrive
Others
OneDrives
SharePoint
3rd Party data
storage
3rd Party
data
storage
We create public Teams with default configuration
Ungoverned - access Ungoverned – no access
Location hidden from scope –
Excluded
Others
OneDrives
Your
OneDrive
3rd Party
data
storage
SPO
There is ungoverned file sharing
Ungoverned - access Ungoverned – no access
Location hidden from scope –
Excluded
Others
OneDrives
Your
OneDrive
3rd party data is migrated into Microsoft 365
- increasing sprawl
3rd
party
Your
OneDrive
Ungoverned - access Ungoverned – no access
Location hidden from scope –
Excluded
Govern Access - Admins added as owner of all
groups, Teams & sites by default
SPO
Your
OneDrive
Ungoverned - access Ungoverned – no access
Location hidden from scope –
Excluded
Govern groups, Teams and sites
Data Lifecycle management
Ungoverned - access
Ungoverned – no
access
Governed location –
No access
Governed location –
have access
Your
OneDrive
Copilot for Microsoft 365 Optimization Assessment
Data Security readiness
score
License profile Deployment path
0% - 66% Office 365 E3, Microsoft 365 Business
Standard/Premium, or higher
Core
67% - 100% Microsoft 365 E5 Best-in-Class
Determine your deployment path
Solution Assessment Program (microsoft.com)
2. Provide
“Just
enough
access”
5
If used,
disable
Restricted
SharePoint
Search
Apply appropriate Data Security controls
Get started quickly and continue to optimize along the way
*Restricted SharePoint Search will limit Copilot for Microsoft 365 experiences and organization-wide search. It is a temporary option which gives you time to address oversharing concerns while getting started on your Copilot journey.
4
OPTIMIZE
FURTHER
AS NEEDED
Core
Restrict data oversharing and data leaks with
manual labeling and policies
Required licenses:
Office 365 E3, Microsoft 365 Business
Standard/Premium, or higher
Best-In-Class
Prevent data oversharing, data leaks, and detect
non-compliant usage at scale with auto labeling and
policies
Required licenses:
Microsoft 365 E5; and
SPP-SharePoint Advanced Management
YES
3
Deploy Copilot
for Microsoft 365
2b
Enable
Restricted
SharePoint
Search*
NO
2a
Ready to
deploy?
Get started
Copilot for
Microsoft 365
Optimization
Assessment
Determine path
(26 questions; 30 minutes)
1
SPO
1. Temporary measure - Restricted SharePoint Search
Ungoverned - access
Ungoverned – no
access
Governed location –
No access
Governed location –
have access
Your
OneDrive
Add up to 100 sites
Frequently visited
sites
Your OneDrive
Shared files with you
& you have accessed
This disables
organization-wide search
No impact on Purview
e.g. DLP
2. User adoption so users know they can
revoke access to their shared OneDrive files
Your
OneDrive
Ungoverned - access
Ungoverned – no
access
Governed location –
No access
Governed location –
have access
Relies on user
adoption
SPO
3. Convert Public workspaces to Private
workspaces
Ungoverned - access
Ungoverned – no
access
Governed location –
No access
Governed location –
have access
Your
OneDrive
All users in the
tenant can access
content in Public
Groups
Use Container
sensitivity labels to
restrict Public Teams
being created
Identify Viva
Engage/ Teams that
need to be Public e.g All
staff or social
SPO
4. Regularly review workspace membership
Ungoverned - access
Ungoverned – no
access
Governed location –
No access
Governed location –
have access
Your
OneDrive
Manual reviews
Dynamic groups
(Entra ID P1)
Entra ID
Groups/Teams/Viva
Engage Access
Reviews (Entra ID P2
licence)
SAM reviews for Sites
SPO
5. Implement workspace provisioning controls
and sensitivity labels
Ungoverned - access
Ungoverned – no
access
Governed location –
No access
Governed location –
have access
Your
OneDrive
Container
sensitivity labels to
control access
permissions
Build or Buy e.g.
Orchestry
6. Govern Teams - Use private/shared
channels to restrict access
Ungoverned - access
Ungoverned – no
access
Governed location –
No access
Governed location –
have access
SPO
Your
OneDrive
Control who can
create
Shared channel
bi-directional config
SPO
7. Restrict who can share files and folders and
sharing links
Ungoverned - access
Ungoverned – no
access
Governed location –
No access
Governed location –
have access
Your
OneDrive
Use container
labels (feature
enabled via
PowerShell)
SPO
8. Govern Site Access - Block site access to non-
members
Ungoverned - access
Ungoverned – no
access
Governed location –
No access
Governed location –
have access
Your
OneDrive
SharePoint
Advanced
Management
licenses $3 PUPM
for all users
9. Govern Content - Use DLP and or encrypted
sensitivity labels to restrict access
Ungoverned - access
Ungoverned – no
access
Governed location –
No access
Governed location –
have access
Teams
SPO
Automated
labelling & default
label on Document
Library requires E5
IP&G licencing for all
users
SPO
10. Govern Content - Retention policies/labels
to keep what you need and delete the rest
Others
OneDrive
Teams
Teams
Ungoverned - access
Ungoverned – no
access
Governed location –
No access
Governed location –
have access
Automated
requires E5 IP&G
licencing for all
users
SPO Archive
SPO
11. Govern Content - Externally archive
inactive content
Others
OneDrive
Ungoverned - access
Ungoverned – no
access
Governed location –
No access
Governed location –
have access
Your
OneDrive
Microsoft now
has a SharePoint
archive service
Summary
User adoption
Container permissions
Review container membership
Protect content
Govern content lifecycle

More Related Content

PPSX
Preparing for Microsoft 365 Copilot - Best Practices for Governance and Data ...
PDF
Unlock the Potential of Microsoft 365 Copilot | Norwegian M365 User Group |...
PDF
Microsoft 365 Copilot data security and governance |Commsverse 2024 | June 2024
PDF
Deciphering Copilot Unravelling Data Security and Governance in Microsoft 365...
PDF
Copilot for Microsoft 365 data security and governance | Workplace Ninjas Den...
PDF
Ready Set Secure your Data |GRC User Group| Oct 2024.pdf
PPTX
Prepare your data for Microsoft Copilot with new tools
PDF
Microsoft 365 Copilot data security and governance with Notes | CollabDays B...
Preparing for Microsoft 365 Copilot - Best Practices for Governance and Data ...
Unlock the Potential of Microsoft 365 Copilot | Norwegian M365 User Group |...
Microsoft 365 Copilot data security and governance |Commsverse 2024 | June 2024
Deciphering Copilot Unravelling Data Security and Governance in Microsoft 365...
Copilot for Microsoft 365 data security and governance | Workplace Ninjas Den...
Ready Set Secure your Data |GRC User Group| Oct 2024.pdf
Prepare your data for Microsoft Copilot with new tools
Microsoft 365 Copilot data security and governance with Notes | CollabDays B...

Similar to Microsoft 365 Copilot: How to boost your productivity with AI. Part two: Data security and governance | IntraTeam event | April 2024 (20)

PPTX
Copilot-for-Microsoft-365-technical.pptx
PDF
Microsoft365-Copilot-Partner-Guide
PPTX
4_TechnicalReadinessGuide_CopilotforMicrosoft365.pptx
PPTX
Microsoft Information Protection: Your Security and Compliance Framework
PDF
May 2020 Microsoft 365 Need to Know Webinar
PPTX
Securing Team, SharePoint, and OneDrive in Microsoft 365 - M365VM
PPTX
Office 365 Saturday - Office 365 Security Best Practices
PPTX
Intelligent Security, Compliance and Privacy in Office 365
PPTX
Copy of Co pilot ai all about it.pptxxxxx
PPTX
Microsoft-365-Copilot-Adoption-Guide-Workbook.pptx
PPTX
Administrators guide to managing Microsoft 365 and collaboration workloads - ...
PPTX
SC-900 Capabilities of Microsoft Compliance Solutions
PPTX
St. Louis SharePoint User Group - Security and Compliance in O365 for SharePo...
PPTX
B2 - The History of Content Security: Part 2 - Adam Levithan
PPTX
Securing SharePoint & OneDrive in Office 365
PPTX
Safely Enabling Office 365
PPTX
Secure and govern your data with Microsoft Purview
PDF
Office 365 Security, Privacy and Compliance - SMB Nation 2015
PPTX
HSPUG presentation - Advanced Data Governance
PDF
Microsoft Office 365 Security and Compliance
Copilot-for-Microsoft-365-technical.pptx
Microsoft365-Copilot-Partner-Guide
4_TechnicalReadinessGuide_CopilotforMicrosoft365.pptx
Microsoft Information Protection: Your Security and Compliance Framework
May 2020 Microsoft 365 Need to Know Webinar
Securing Team, SharePoint, and OneDrive in Microsoft 365 - M365VM
Office 365 Saturday - Office 365 Security Best Practices
Intelligent Security, Compliance and Privacy in Office 365
Copy of Co pilot ai all about it.pptxxxxx
Microsoft-365-Copilot-Adoption-Guide-Workbook.pptx
Administrators guide to managing Microsoft 365 and collaboration workloads - ...
SC-900 Capabilities of Microsoft Compliance Solutions
St. Louis SharePoint User Group - Security and Compliance in O365 for SharePo...
B2 - The History of Content Security: Part 2 - Adam Levithan
Securing SharePoint & OneDrive in Office 365
Safely Enabling Office 365
Secure and govern your data with Microsoft Purview
Office 365 Security, Privacy and Compliance - SMB Nation 2015
HSPUG presentation - Advanced Data Governance
Microsoft Office 365 Security and Compliance
Ad

More from Nikki Chapple (20)

PDF
Protecting Your Sensitive Data with Microsoft Purview - IRMS 2025
PDF
Measuring Microsoft 365 Copilot and Gen AI Success
PDF
Measuring Copilot and Gen AI Success with Viva Insights and Purview
PDF
Microsoft 365 Copilot data quality with semantic index and how Topics plays...
PDF
Microsoft Viva and Copilot Governance | M365 ReVival | Feb 2024
PDF
Real World Governance Risk and Compliance | European Collaboration Summit | M...
PDF
Microsoft 365 Copilot: How to boost your productivity with AI. Part one: Adop...
PDF
Cracking the Code- Expert Tips for Mastering GRC | CollabDays Bletchley | Sep...
PDF
Microsoft Viva Security and Privacy | CollabDays Bletchley | Sept 23
PDF
Demystifying security and privacy in Viva | Commsverse | June 2023
PDF
Demystifying security and compliance in Viva | European Collaboration Summit ...
PDF
Real World Governance Risk and Compliance | European Collaboration Summit 2023
PDF
Dont let governance risk and compliance be a roll of the device | Modern Wor...
PDF
Dont let governance risk and compliance be a roll of the dice | ESPC22 | De...
PDF
Microsoft Viva governance and compliance implications | Viva Explorers Commun...
PDF
Implementing Microsoft Teams Lifecycle Governance to Stop Team Sprawl M365C...
PDF
Governance, Risk and Compliance and you | CollabDays Bletchley Park 2022
PDF
Build a Teams creation workflow using Power Automate | ESPC 22 Microsoft Team...
PDF
Implementing Microsoft Teams lifecycle governance to stop Team sprawl | MN Mi...
PDF
Microsoft 365 Governance Risk and Compliance Maturity model | MM4M365 practit...
Protecting Your Sensitive Data with Microsoft Purview - IRMS 2025
Measuring Microsoft 365 Copilot and Gen AI Success
Measuring Copilot and Gen AI Success with Viva Insights and Purview
Microsoft 365 Copilot data quality with semantic index and how Topics plays...
Microsoft Viva and Copilot Governance | M365 ReVival | Feb 2024
Real World Governance Risk and Compliance | European Collaboration Summit | M...
Microsoft 365 Copilot: How to boost your productivity with AI. Part one: Adop...
Cracking the Code- Expert Tips for Mastering GRC | CollabDays Bletchley | Sep...
Microsoft Viva Security and Privacy | CollabDays Bletchley | Sept 23
Demystifying security and privacy in Viva | Commsverse | June 2023
Demystifying security and compliance in Viva | European Collaboration Summit ...
Real World Governance Risk and Compliance | European Collaboration Summit 2023
Dont let governance risk and compliance be a roll of the device | Modern Wor...
Dont let governance risk and compliance be a roll of the dice | ESPC22 | De...
Microsoft Viva governance and compliance implications | Viva Explorers Commun...
Implementing Microsoft Teams Lifecycle Governance to Stop Team Sprawl M365C...
Governance, Risk and Compliance and you | CollabDays Bletchley Park 2022
Build a Teams creation workflow using Power Automate | ESPC 22 Microsoft Team...
Implementing Microsoft Teams lifecycle governance to stop Team sprawl | MN Mi...
Microsoft 365 Governance Risk and Compliance Maturity model | MM4M365 practit...
Ad

Recently uploaded (20)

PPTX
sap open course for s4hana steps from ECC to s4
PDF
Unlocking AI with Model Context Protocol (MCP)
PPTX
Cloud computing and distributed systems.
DOCX
The AUB Centre for AI in Media Proposal.docx
PPTX
Programs and apps: productivity, graphics, security and other tools
PPT
“AI and Expert System Decision Support & Business Intelligence Systems”
PDF
TokAI - TikTok AI Agent : The First AI Application That Analyzes 10,000+ Vira...
PPTX
Detection-First SIEM: Rule Types, Dashboards, and Threat-Informed Strategy
PDF
Profit Center Accounting in SAP S/4HANA, S4F28 Col11
PDF
Advanced methodologies resolving dimensionality complications for autism neur...
PDF
Build a system with the filesystem maintained by OSTree @ COSCUP 2025
PDF
Building Integrated photovoltaic BIPV_UPV.pdf
PDF
Network Security Unit 5.pdf for BCA BBA.
PPTX
Big Data Technologies - Introduction.pptx
PPTX
ACSFv1EN-58255 AWS Academy Cloud Security Foundations.pptx
PPTX
20250228 LYD VKU AI Blended-Learning.pptx
PDF
NewMind AI Weekly Chronicles - August'25 Week I
PDF
Machine learning based COVID-19 study performance prediction
PDF
How UI/UX Design Impacts User Retention in Mobile Apps.pdf
PDF
Optimiser vos workloads AI/ML sur Amazon EC2 et AWS Graviton
sap open course for s4hana steps from ECC to s4
Unlocking AI with Model Context Protocol (MCP)
Cloud computing and distributed systems.
The AUB Centre for AI in Media Proposal.docx
Programs and apps: productivity, graphics, security and other tools
“AI and Expert System Decision Support & Business Intelligence Systems”
TokAI - TikTok AI Agent : The First AI Application That Analyzes 10,000+ Vira...
Detection-First SIEM: Rule Types, Dashboards, and Threat-Informed Strategy
Profit Center Accounting in SAP S/4HANA, S4F28 Col11
Advanced methodologies resolving dimensionality complications for autism neur...
Build a system with the filesystem maintained by OSTree @ COSCUP 2025
Building Integrated photovoltaic BIPV_UPV.pdf
Network Security Unit 5.pdf for BCA BBA.
Big Data Technologies - Introduction.pptx
ACSFv1EN-58255 AWS Academy Cloud Security Foundations.pptx
20250228 LYD VKU AI Blended-Learning.pptx
NewMind AI Weekly Chronicles - August'25 Week I
Machine learning based COVID-19 study performance prediction
How UI/UX Design Impacts User Retention in Mobile Apps.pdf
Optimiser vos workloads AI/ML sur Amazon EC2 et AWS Graviton

Microsoft 365 Copilot: How to boost your productivity with AI. Part two: Data security and governance | IntraTeam event | April 2024

  • 2. Nikki Chapple Principal Cloud Architect nikkichapple @chapplenikki www.nikkichapple.com All Things M365 Compliance
  • 3. Agenda • The risks of not addressing data security and governance as part of your Microsoft 365 Copilot transformation • How to configure Microsoft 365 for “just enough access” to safeguard your sensitive data • How to improve data governance to deliver more accurate and relevant recommendations
  • 4. Big Data - A New Era 4
  • 5. Essentials for Copilot success Nominate and activate your Copilot executive sponsors, in partnership with your AI Council Define initial high value scenarios and target a critical mass of users for rapid value Define your path to secure your data for compliance and peace of mind
  • 6. Copilot for Microsoft 365 implementation Copilot implementation Sponsor Scenarios Security Copilot essentials checklist User Enablement Prepare organization and employees for the AI transformation journey Workstreams support each other for maximum value and ROI Technical Readiness Address technical deployment and optimization, including governance, security, compliance, and management Leadership journey
  • 7. 1 6 2 3 5 3 4 Data flow ( = all requests are encrypted via HTTPS) User prompts from Microsoft 365 Apps are sent to Copilot Copilot accesses Graph and Semantic Index for pre-processing Copilot sends modified prompt to Large Language Model (LLM) Copilot receives LLM response Copilot accesses Graph and Semantic Index for post-processing Copilot sends the response, and app command back to Microsoft 365 Apps 1 2 3 4 5 6 Microsoft 365 Trust Boundary Customer’s Microsoft 365 Tenant Semantic Index Azure OpenAI RAI Azure Open AI instance is maintained by Microsoft. Open AI has no access to the data or the model. RAI is performed on input prompt and output results Customer data is not stored or used to train the model
  • 8. Improve your data quality with Data Lifecycle Management 8 • Restrict access • Delete redundant, obsolete, or trivial (ROT) data • Access permissions • Sharing links • Naming conventions • Metadata Create Store and Use Archive Delete
  • 9. Technical considerations for compliance and security of deployment
  • 10. Copilot for Microsoft 365 basic architecture 6 2 3 5 3 4 Microsoft 365 Service Boundary Customer Microsoft 365 Tenant Semantic Index Azure OpenAI RAI Azure OpenAI instance is maintained by Microsoft. OpenAI has no access to the data or the model. RAI is performed on input prompt and output results Prompts, responses, and data accessed through Microsoft Graph aren't used to train foundation models 1 Data flow (lock) = all requests are encrypted via HTTPS and wss://) 1 User prompts from Microsoft 365 Apps are sent to Copilot 2 Copilot accesses Graph and Semantic Index for pre-processing 3 Copilot sends modified prompt to Large Language Model 4 Copilot receives LLM response 5 Copilot accesses Graph and Semantic Index for post-processing 6 Copilot sends the response, and app command back to Microsoft 365 Apps
  • 11. Microsoft’s approach to privacy You control your data You know where your data is located We secure your data at rest and in transit We defend your data
  • 12. Common questions we hear from customers How do we know our data is secure? When will we be able to audit Copilot usage? What can I do to avoid overexposing our data? Where is my data processed?
  • 13. Copilot for Microsoft 365 Built on Microsoft’s comprehensive approach Security Compliance Privacy Responsible AI
  • 15. 1. Understand your current risks and data security readiness
  • 16. Most data stored outside Microsoft 365 and users work in email 3rd Party data storage Ungoverned - access Ungoverned – no access Location hidden from scope – Excluded SharePoint Your OneDrive Others OneDrives
  • 17. Use of OneDrive increases but emailing files not sharing files - no adoption or training Ungoverned - access Ungoverned – no access Location hidden from scope – Excluded Your OneDrive SharePoint 3rd Party data storage Your OneDrive Others OneDrives
  • 18. Pioneers create ungoverned Teams & Sites Ungoverned - access Ungoverned – no access Location hidden from scope – Excluded Your OneDrive Others OneDrives SharePoint 3rd Party data storage
  • 19. 3rd Party data storage We create public Teams with default configuration Ungoverned - access Ungoverned – no access Location hidden from scope – Excluded Others OneDrives Your OneDrive
  • 20. 3rd Party data storage SPO There is ungoverned file sharing Ungoverned - access Ungoverned – no access Location hidden from scope – Excluded Others OneDrives Your OneDrive
  • 21. 3rd party data is migrated into Microsoft 365 - increasing sprawl 3rd party Your OneDrive Ungoverned - access Ungoverned – no access Location hidden from scope – Excluded
  • 22. Govern Access - Admins added as owner of all groups, Teams & sites by default SPO Your OneDrive Ungoverned - access Ungoverned – no access Location hidden from scope – Excluded
  • 23. Govern groups, Teams and sites Data Lifecycle management Ungoverned - access Ungoverned – no access Governed location – No access Governed location – have access Your OneDrive
  • 24. Copilot for Microsoft 365 Optimization Assessment Data Security readiness score License profile Deployment path 0% - 66% Office 365 E3, Microsoft 365 Business Standard/Premium, or higher Core 67% - 100% Microsoft 365 E5 Best-in-Class Determine your deployment path Solution Assessment Program (microsoft.com)
  • 26. 5 If used, disable Restricted SharePoint Search Apply appropriate Data Security controls Get started quickly and continue to optimize along the way *Restricted SharePoint Search will limit Copilot for Microsoft 365 experiences and organization-wide search. It is a temporary option which gives you time to address oversharing concerns while getting started on your Copilot journey. 4 OPTIMIZE FURTHER AS NEEDED Core Restrict data oversharing and data leaks with manual labeling and policies Required licenses: Office 365 E3, Microsoft 365 Business Standard/Premium, or higher Best-In-Class Prevent data oversharing, data leaks, and detect non-compliant usage at scale with auto labeling and policies Required licenses: Microsoft 365 E5; and SPP-SharePoint Advanced Management YES 3 Deploy Copilot for Microsoft 365 2b Enable Restricted SharePoint Search* NO 2a Ready to deploy? Get started Copilot for Microsoft 365 Optimization Assessment Determine path (26 questions; 30 minutes) 1
  • 27. SPO 1. Temporary measure - Restricted SharePoint Search Ungoverned - access Ungoverned – no access Governed location – No access Governed location – have access Your OneDrive Add up to 100 sites Frequently visited sites Your OneDrive Shared files with you & you have accessed This disables organization-wide search No impact on Purview e.g. DLP
  • 28. 2. User adoption so users know they can revoke access to their shared OneDrive files Your OneDrive Ungoverned - access Ungoverned – no access Governed location – No access Governed location – have access Relies on user adoption
  • 29. SPO 3. Convert Public workspaces to Private workspaces Ungoverned - access Ungoverned – no access Governed location – No access Governed location – have access Your OneDrive All users in the tenant can access content in Public Groups Use Container sensitivity labels to restrict Public Teams being created Identify Viva Engage/ Teams that need to be Public e.g All staff or social
  • 30. SPO 4. Regularly review workspace membership Ungoverned - access Ungoverned – no access Governed location – No access Governed location – have access Your OneDrive Manual reviews Dynamic groups (Entra ID P1) Entra ID Groups/Teams/Viva Engage Access Reviews (Entra ID P2 licence) SAM reviews for Sites
  • 31. SPO 5. Implement workspace provisioning controls and sensitivity labels Ungoverned - access Ungoverned – no access Governed location – No access Governed location – have access Your OneDrive Container sensitivity labels to control access permissions Build or Buy e.g. Orchestry
  • 32. 6. Govern Teams - Use private/shared channels to restrict access Ungoverned - access Ungoverned – no access Governed location – No access Governed location – have access SPO Your OneDrive Control who can create Shared channel bi-directional config
  • 33. SPO 7. Restrict who can share files and folders and sharing links Ungoverned - access Ungoverned – no access Governed location – No access Governed location – have access Your OneDrive Use container labels (feature enabled via PowerShell)
  • 34. SPO 8. Govern Site Access - Block site access to non- members Ungoverned - access Ungoverned – no access Governed location – No access Governed location – have access Your OneDrive SharePoint Advanced Management licenses $3 PUPM for all users
  • 35. 9. Govern Content - Use DLP and or encrypted sensitivity labels to restrict access Ungoverned - access Ungoverned – no access Governed location – No access Governed location – have access Teams SPO Automated labelling & default label on Document Library requires E5 IP&G licencing for all users
  • 36. SPO 10. Govern Content - Retention policies/labels to keep what you need and delete the rest Others OneDrive Teams Teams Ungoverned - access Ungoverned – no access Governed location – No access Governed location – have access Automated requires E5 IP&G licencing for all users
  • 37. SPO Archive SPO 11. Govern Content - Externally archive inactive content Others OneDrive Ungoverned - access Ungoverned – no access Governed location – No access Governed location – have access Your OneDrive Microsoft now has a SharePoint archive service
  • 38. Summary User adoption Container permissions Review container membership Protect content Govern content lifecycle