FIELD NOTE / M365 / GOVERNANCE
Microsoft 365 governance starts with boundaries, not more settings
A tenant can have hundreds of configured settings and still be poorly governed. Governance begins when the organisation can explain who may decide, what they control, and how anyone can verify the decision.
The settings-list failure
Microsoft 365 exposes controls across Entra ID, SharePoint, Teams, Purview, Power Platform, Defender and Graph. Copying every control into a spreadsheet produces volume, not governance. Settings interact, product defaults change, and a technically valid configuration can still lack an accountable owner.
The useful question is not “Is this feature enabled?” It is “What risk or operating outcome does this decision control, who owns it, and where is the evidence?”
Six boundaries that matter
- Identity: who can authenticate, administer and grant application access.
- Information: where content belongs, who owns it and how long it remains.
- Collaboration: where external people may participate and under whose sponsorship.
- Platform: where apps and flows are built, tested, released and supported.
- Automation: which identities may observe, propose or change tenant state.
- Assurance: which evidence proves controls still operate.
A useful minimum baseline
Start with inventories that can drive action: privileged roles and application permissions; production sites, teams and environments; external access; retention and sensitivity policy; solution ownership; and recovery procedures. Each item needs an owner and review date.
That baseline should close expired access, abandoned applications and unsupported flows. A monthly report that changes nothing is only monitoring.
Separate related controls
Sensitivity, retention, records management and DLP are often discussed as though one label can solve all four. They answer different questions: how information should be handled, how long it must remain, when it becomes a formal record, and where sensitive data may move. Coordinate them, but keep each decision explicit.
Governance that survives staff change
The final test is continuity. Can another administrator explain the reason for the control, find its owner, see the current exception set and recover the service? If not, the tenant depends on personal memory. The goal is not maximal documentation; it is enough controlled evidence for the next person to operate safely.