M365 Governance
Add-on per user

Microsoft 365 governance.Who can access what?

Conbool M365 Governance records permissions and sharing in SharePoint, OneDrive, Teams and Microsoft 365 groups, assesses them against 13 fixed rules and fixes findings on request with a dry run and approval by a second person.

File contents are never readChanges only with a second personData centres in Germany

The starting point

Sharing happens every day. Nobody sees the total.

Microsoft 365 makes sharing easy. Nobody takes it back on their own.

How sharing builds up

A link for the tax adviser, a guest in the project team, a library opened to “Everyone” to get things done. Each decision made sense. Over the years they add up to an inventory that no admin console shows on one page.

What M365 Governance does with it

A scan records sites, libraries, OneDrives, groups, teams, guests and every single permission. Fixed rules turn them into findings with a severity. You see the most severe first and decide what gets cleaned up.

Microsoft 365 Copilot and search show a user everything they are allowed to access. Whatever is shared too widely becomes easy to find. Anyone rolling out Copilot should know their sharing first.

13 fixed rules

What counts as risky sharing is defined.

Each rule checks exactly one condition on a permission or an object. The open findings produce a score from 0 to 100.

Links

  • Anonymous link with write access. Anyone with the link can edit without signing in.
  • Link for anyone without sign-in. The link opens the item without an account.
  • Link without expiry date. The share stays until someone removes it.
  • Organisation-wide link in a confidential object. All staff can reach content in an area using the Confidential template.

External and Everyone

  • Grant to Everyone. All accounts are entitled, depending on settings including external ones.
  • Grant to a freemail address. The recipient is a private mailbox rather than a business account.
  • Direct grant to an external address. Trusted domains can be excluded.

Guests and teams

  • Guests gain access through a group. Nested groups are included.
  • Guest in a team without guests. Applies where the template excludes guests in teams.
  • Public team. Anyone in the company can join and read along.

Ownership and structure

  • No owner. Nobody is responsible for the object any more.
  • Only one owner. If that person leaves, the object is orphaned.
  • Many unique permission scopes. Inheritance is broken so often that the overview is lost.

The rules judge names, types and counts. What a file contains is neither read nor assessed.

What is covered

Five areas, one view.

Each area has its own pitfalls. That is why they are listed one by one.

SharePoint permissions at a glance

Sites and document libraries with their permissions, down to the single item with its own share. Each permission shows recipient, role, expiry and the kind of share.

  • Items with broken inheritance are counted and reported
  • Sharing links and direct grants shown separately
  • Grants to Everyone and to external addresses per site

View and manage OneDrive sharing

Personal storage is where most sharing happens and the least reviewing. M365 Governance lists the shares of all OneDrives in the same list as SharePoint.

  • Links for anyone, for the organisation and for specific people
  • External domains and addresses with the most grants
  • Links without an expiry date as a separate finding

Teams and Microsoft 365 groups

Every team comes with a group and a site. Owners, guests and visibility are recorded, plus the members of a group that something is shared with.

  • Teams without an owner or with only one owner
  • Public teams that anyone in the company can join
  • Guests in teams where none are intended

Guest users in Microsoft 365

Guests stay in the directory long after the project has ended. The scan shows what a guest can access, directly and through groups.

  • Guests in teams where none are intended
  • Access through groups, nested groups included
  • Breakdown by external domain and by address

Tenant settings against a baseline

Ten controls from four areas compared with the Conbool Basis baseline. Each control shows the expected and the actual value. The check reads and changes nothing.

  • SharePoint and OneDrive, guests and applications
  • Sign-in: multi-factor for administrators, legacy protocols
  • Number of global administrators

Features

From finding to decision.

Six things that turn a list of permissions into a working tool.

Score from 0 to 100 with trend

100 means no open findings. The trend shows whether the inventory is improving or growing back. Findings carry one of four severities, from Low to Critical, with the most severe on top.

Three templates

Standard, Strict and Confidential. Plus custom rules and limits, also for single sites, teams or name patterns.

Exceptions with a reason

An intended share is recorded as an exception, with a justification and an optional end date.

All permissions in one list

Filter by recipient type, search by name or path, summary by external domains and addresses. Group members can be expanded in place. Export as CSV.

Report as PDF

Score, findings, exceptions and tenant settings in one document, as of the time of retrieval.

Scheduled scan with notification

Daily or weekly. New critical and high findings, new deviations in tenant settings and a failed scan are reported. The inventory at activation counts as known.

Remediation

Clean up without breaking anything.

No change without a dry run and no execution without a second person.

1

Choose rule and action

Remove the share, set an expiry date or reduce direct grants to read access.

2

Dry run

The run shows every entry that would change and gives the reason for each one skipped. Nothing is changed.

3

Approval by a second person

Whoever requested the run cannot approve it. Rejecting is just as possible.

4

Execution

The change takes effect in Microsoft 365 immediately. Every entry ends with a result: done, no longer present or failed.

Tenant settings

Ten controls against the Conbool Basis baseline.

Sharing happens where the tenant allows it. That is why the settings belong to the same review.

SharePoint and OneDrive

  • No sharing for anyone without sign-in
  • External users may not reshare
  • Legacy protocols in SharePoint off
  • Invited address must match the account

Guests and applications

  • Only administrators and guest inviters invite
  • Users do not consent to applications themselves
  • Users do not register applications

Sign-in

  • Multi-factor for administrators
  • Legacy protocols blocked at sign-in

Administrators

  • Two to four global administrators

Each control ends as Met, Deviating or Not checked. Nothing is changed in the tenant, you make the change in Microsoft 365 yourself.

The difference

The auditor's question: who has access?

The same situation, played through twice.

Without an overview

  • The answer is assembled site by site in several admin consoles or from home-grown scripts.
  • Nobody knows which of the many shares is a risk and which is intended.
  • Clean-up is done by hand and may hit the wrong share.
  • After the clean-up the inventory grows back unnoticed.

With Conbool M365 Governance

  • One list of all permissions with filter, search and CSV export.
  • 13 rules assess every share, intended ones appear in the report as exceptions with a reason.
  • A dry run shows every entry beforehand, a second person approves.
  • The scheduled scan reports new critical and high findings.

For IT service providers and MSPs

All tenants side by side.

The partner view shows score, open findings and deviations of all managed tenants in one table.

Greatest need for action first

The order follows the need, not the alphabet. You see at once where a conversation with the customer is due.

The same baseline for every tenant

The tenant setting controls apply equally to all. Deviations are shown per tenant and per control.

In the same portal

M365 Governance sits in the partner portal next to MailGuard, Archive and 365 Backup. One login, one tenant list.

Billing per user

Licences are booked in the partner portal and allocated to tenants, as with the other products.

Access

What the connection reads and what it does not.

A tool that reviews permissions has to account for its own.

  • Nothing is read without the consent of a global administrator.
  • The first application requests full control of sites and uses it for reading only.
  • File contents are never read. Names, paths, recipients and roles are recorded.
  • Remediation runs through a second application with its own consent. Without it the product stays read-only.
  • Operated in German data centres, contract with a vendor based in Hamburg.

How to start

Three steps to the first finding

No agent, no software on servers or workstations.

1

Grant consent

A global administrator consents to the application in the portal. Nothing changes in the tenant.

2

Start the scan

The scan records sites, libraries, OneDrives, groups, guests and permissions. After that it can run on a schedule.

3

Work through findings

Choose a template, look at the most severe findings, record exceptions and clean up the rest with a dry run.

The duration of the first scan depends on the number of sites and permissions.

Frequently asked questions

What is Microsoft 365 governance?

The rules and controls for who may access what in Microsoft 365 and how content is shared. Conbool M365 Governance covers the part that can be measured: permissions, sharing, guests, ownership and tenant settings.

Does Conbool read file contents?

No. Objects, names, paths, recipients and roles are recorded. The content of a file is not opened, classified or stored. The product is therefore not a data loss prevention solution.

Which permissions does the connection need?

A global administrator grants consent once for an application with Microsoft Graph application permissions. It requests full control of sites because item-level permissions cannot be read otherwise, and uses it for reading only. If a role is missing, the affected check remains marked as not checked.

Does the product change anything in the tenant?

Only on explicit request. Remediation needs a second application with its own consent, a dry run and approval by a second person. Three actions are available: remove the share, set an expiry date, reduce a direct grant to read access. Tenant settings are checked but not changed.

Does this help when rolling out Microsoft 365 Copilot?

Yes, as preparation. Copilot works with the permissions of the respective user, so overshared content becomes easier to find. M365 Governance shows those shares and helps to clean them up before the rollout. It does not intervene in Copilot itself.

Does it replace Microsoft Secure Score or a CIS benchmark?

No. The tenant settings comprise ten controls of the Conbool Basis baseline and are not a complete benchmark. The focus is on what configuration assessments do not show: the single share, the single guest and the object without an owner.

Can it document an access concept?

The PDF report shows the score, open findings, recorded exceptions with their justification and the tenant settings as of the time of retrieval. It documents the actual state in Microsoft 365. The concept itself, meaning who should have which rights, is yours to define.

Does the product cover Exchange and mailbox permissions?

No. SharePoint, OneDrive, Teams, Microsoft 365 groups and guests are covered. Mailbox permissions and licence management are out of scope.

How is M365 Governance licensed?

Per user, as an add-on and independent of the suites. Partners book in the partner portal and allocate licences to their tenants.

Who is the partner view for?

For IT service providers and managed service providers looking after several Microsoft 365 tenants. It shows score, open findings, deviations and the last scan per tenant, with the tenant needing the most action first.

Know who can access what

We show M365 Governance on your own tenant: from the first scan to the first finding fixed.