Microsoft 365 governance.Who can access what?
Conbool M365 Governance records permissions and sharing in SharePoint, OneDrive, Teams and Microsoft 365 groups, assesses them against 13 fixed rules and fixes findings on request with a dry run and approval by a second person.
The starting point
Sharing happens every day. Nobody sees the total.
Microsoft 365 makes sharing easy. Nobody takes it back on their own.
How sharing builds up
A link for the tax adviser, a guest in the project team, a library opened to “Everyone” to get things done. Each decision made sense. Over the years they add up to an inventory that no admin console shows on one page.
What M365 Governance does with it
A scan records sites, libraries, OneDrives, groups, teams, guests and every single permission. Fixed rules turn them into findings with a severity. You see the most severe first and decide what gets cleaned up.
Microsoft 365 Copilot and search show a user everything they are allowed to access. Whatever is shared too widely becomes easy to find. Anyone rolling out Copilot should know their sharing first.
13 fixed rules
What counts as risky sharing is defined.
Each rule checks exactly one condition on a permission or an object. The open findings produce a score from 0 to 100.
Links
- Anonymous link with write access. Anyone with the link can edit without signing in.
- Link for anyone without sign-in. The link opens the item without an account.
- Link without expiry date. The share stays until someone removes it.
- Organisation-wide link in a confidential object. All staff can reach content in an area using the Confidential template.
External and Everyone
- Grant to Everyone. All accounts are entitled, depending on settings including external ones.
- Grant to a freemail address. The recipient is a private mailbox rather than a business account.
- Direct grant to an external address. Trusted domains can be excluded.
Guests and teams
- Guests gain access through a group. Nested groups are included.
- Guest in a team without guests. Applies where the template excludes guests in teams.
- Public team. Anyone in the company can join and read along.
Ownership and structure
- No owner. Nobody is responsible for the object any more.
- Only one owner. If that person leaves, the object is orphaned.
- Many unique permission scopes. Inheritance is broken so often that the overview is lost.
The rules judge names, types and counts. What a file contains is neither read nor assessed.
What is covered
Five areas, one view.
Each area has its own pitfalls. That is why they are listed one by one.
View and manage OneDrive sharing
Personal storage is where most sharing happens and the least reviewing. M365 Governance lists the shares of all OneDrives in the same list as SharePoint.
- Links for anyone, for the organisation and for specific people
- External domains and addresses with the most grants
- Links without an expiry date as a separate finding
Teams and Microsoft 365 groups
Every team comes with a group and a site. Owners, guests and visibility are recorded, plus the members of a group that something is shared with.
- Teams without an owner or with only one owner
- Public teams that anyone in the company can join
- Guests in teams where none are intended
Guest users in Microsoft 365
Guests stay in the directory long after the project has ended. The scan shows what a guest can access, directly and through groups.
- Guests in teams where none are intended
- Access through groups, nested groups included
- Breakdown by external domain and by address
Tenant settings against a baseline
Ten controls from four areas compared with the Conbool Basis baseline. Each control shows the expected and the actual value. The check reads and changes nothing.
- SharePoint and OneDrive, guests and applications
- Sign-in: multi-factor for administrators, legacy protocols
- Number of global administrators
Features
From finding to decision.
Six things that turn a list of permissions into a working tool.
Score from 0 to 100 with trend
100 means no open findings. The trend shows whether the inventory is improving or growing back. Findings carry one of four severities, from Low to Critical, with the most severe on top.
Three templates
Standard, Strict and Confidential. Plus custom rules and limits, also for single sites, teams or name patterns.
Exceptions with a reason
An intended share is recorded as an exception, with a justification and an optional end date.
All permissions in one list
Filter by recipient type, search by name or path, summary by external domains and addresses. Group members can be expanded in place. Export as CSV.
Report as PDF
Score, findings, exceptions and tenant settings in one document, as of the time of retrieval.
Scheduled scan with notification
Daily or weekly. New critical and high findings, new deviations in tenant settings and a failed scan are reported. The inventory at activation counts as known.
Remediation
Clean up without breaking anything.
No change without a dry run and no execution without a second person.
Choose rule and action
Remove the share, set an expiry date or reduce direct grants to read access.
Dry run
The run shows every entry that would change and gives the reason for each one skipped. Nothing is changed.
Approval by a second person
Whoever requested the run cannot approve it. Rejecting is just as possible.
Execution
The change takes effect in Microsoft 365 immediately. Every entry ends with a result: done, no longer present or failed.
Tenant settings
Ten controls against the Conbool Basis baseline.
Sharing happens where the tenant allows it. That is why the settings belong to the same review.
SharePoint and OneDrive
- No sharing for anyone without sign-in
- External users may not reshare
- Legacy protocols in SharePoint off
- Invited address must match the account
Guests and applications
- Only administrators and guest inviters invite
- Users do not consent to applications themselves
- Users do not register applications
Sign-in
- Multi-factor for administrators
- Legacy protocols blocked at sign-in
Administrators
- Two to four global administrators
Each control ends as Met, Deviating or Not checked. Nothing is changed in the tenant, you make the change in Microsoft 365 yourself.
The difference
The auditor's question: who has access?
The same situation, played through twice.
Without an overview
- The answer is assembled site by site in several admin consoles or from home-grown scripts.
- Nobody knows which of the many shares is a risk and which is intended.
- Clean-up is done by hand and may hit the wrong share.
- After the clean-up the inventory grows back unnoticed.
With Conbool M365 Governance
- One list of all permissions with filter, search and CSV export.
- 13 rules assess every share, intended ones appear in the report as exceptions with a reason.
- A dry run shows every entry beforehand, a second person approves.
- The scheduled scan reports new critical and high findings.
For IT service providers and MSPs
All tenants side by side.
The partner view shows score, open findings and deviations of all managed tenants in one table.
Greatest need for action first
The order follows the need, not the alphabet. You see at once where a conversation with the customer is due.
The same baseline for every tenant
The tenant setting controls apply equally to all. Deviations are shown per tenant and per control.
In the same portal
M365 Governance sits in the partner portal next to MailGuard, Archive and 365 Backup. One login, one tenant list.
Billing per user
Licences are booked in the partner portal and allocated to tenants, as with the other products.
Access
What the connection reads and what it does not.
A tool that reviews permissions has to account for its own.
- Nothing is read without the consent of a global administrator.
- The first application requests full control of sites and uses it for reading only.
- File contents are never read. Names, paths, recipients and roles are recorded.
- Remediation runs through a second application with its own consent. Without it the product stays read-only.
- Operated in German data centres, contract with a vendor based in Hamburg.
How to start
Three steps to the first finding
No agent, no software on servers or workstations.
Grant consent
A global administrator consents to the application in the portal. Nothing changes in the tenant.
Start the scan
The scan records sites, libraries, OneDrives, groups, guests and permissions. After that it can run on a schedule.
Work through findings
Choose a template, look at the most severe findings, record exceptions and clean up the rest with a dry run.
The duration of the first scan depends on the number of sites and permissions.
Frequently asked questions
What is Microsoft 365 governance?
The rules and controls for who may access what in Microsoft 365 and how content is shared. Conbool M365 Governance covers the part that can be measured: permissions, sharing, guests, ownership and tenant settings.
Does Conbool read file contents?
No. Objects, names, paths, recipients and roles are recorded. The content of a file is not opened, classified or stored. The product is therefore not a data loss prevention solution.
Which permissions does the connection need?
A global administrator grants consent once for an application with Microsoft Graph application permissions. It requests full control of sites because item-level permissions cannot be read otherwise, and uses it for reading only. If a role is missing, the affected check remains marked as not checked.
Does the product change anything in the tenant?
Only on explicit request. Remediation needs a second application with its own consent, a dry run and approval by a second person. Three actions are available: remove the share, set an expiry date, reduce a direct grant to read access. Tenant settings are checked but not changed.
Does this help when rolling out Microsoft 365 Copilot?
Yes, as preparation. Copilot works with the permissions of the respective user, so overshared content becomes easier to find. M365 Governance shows those shares and helps to clean them up before the rollout. It does not intervene in Copilot itself.
Does it replace Microsoft Secure Score or a CIS benchmark?
No. The tenant settings comprise ten controls of the Conbool Basis baseline and are not a complete benchmark. The focus is on what configuration assessments do not show: the single share, the single guest and the object without an owner.
Can it document an access concept?
The PDF report shows the score, open findings, recorded exceptions with their justification and the tenant settings as of the time of retrieval. It documents the actual state in Microsoft 365. The concept itself, meaning who should have which rights, is yours to define.
Does the product cover Exchange and mailbox permissions?
No. SharePoint, OneDrive, Teams, Microsoft 365 groups and guests are covered. Mailbox permissions and licence management are out of scope.
How is M365 Governance licensed?
Per user, as an add-on and independent of the suites. Partners book in the partner portal and allocate licences to their tenants.
Who is the partner view for?
For IT service providers and managed service providers looking after several Microsoft 365 tenants. It shows score, open findings, deviations and the last scan per tenant, with the tenant needing the most action first.
Related
More pages on permissions and security in Microsoft 365.
SharePoint-Berechtigungen verwalten
Alle Berechtigungen aus SharePoint und OneDrive in einer Liste.
Learn moreCopilot und Oversharing
Zu weite Freigaben finden, bevor Copilot eingeführt wird.
Learn moreMicrosoft-365-Sicherheitscheck
Mandanteneinstellungen gegen eine Vorlage, dazu der Bestand an Freigaben.
Learn moreMicrosoft 365 Backup
Acht Quellen in einem Zeitplan, Rückholung einzelner Elemente.
Learn moreMicrosoft 365 E-Mail-Sicherheit
Schutz des Mailwegs vor Exchange Online.
Learn moreVergleich mit Hornetsecurity
Conbool und Hornetsecurity im Überblick.
Learn moreKnow who can access what
We show M365 Governance on your own tenant: from the first scan to the first finding fixed.