Case study
A Microsoft 365 governance framework for 50+ business units
Designed the classification, retention, and permission model that keeps a 50+ business-unit Microsoft 365 estate from drifting.
M365 governance — framework design and rollout · 2022 – Present
- Microsoft 365
- SharePoint Online
- Sensitivity labels
- Retention policies
- Power Automate
- Audit logs
Context
Microsoft 365 estates drift. Sites get created for a project and outlive it, permissions get granted in a hurry and never revoked, and documents that should have been archived years ago sit in active libraries. At this scale, more than fifty business units, drift isn’t an accident. It’s the default if nothing pushes back against it.
Challenge
Governance frameworks tend to fail one of two ways: strict enough that people route around them, or loose enough that they change nothing. I needed one that made the compliant path the easy path, and that didn’t depend on anybody remembering a policy document.
Approach
The framework rests on three layers. Classification comes first: a data classification and labelling scheme that maps business sensitivity onto sensitivity labels, so a document’s handling rules travel with the document instead of living in someone’s head.
Information lifecycle comes second. Retention and archiving policies are tied to classification, so content ages out on a schedule instead of by request. I automated the enforcement with Power Automate rather than leaving it to site owners, because a policy only holds if it doesn’t depend on someone remembering it, and across fifty business units, somebody always forgets.
Permission management comes third: compliance-based access controls and a provisioning process that grants access by role rather than by individual request. New sites arrive pre-governed instead of being retrofitted later.
Power BI dashboards sit on top of the audit logs, so compliance and audit teams can answer their own questions about who has access to what, and what’s due for retention.
Outcome
The framework now covers 50+ business units with standardised permission, archiving, and retention policies. Governance is built into how sites get provisioned, rather than added afterward as a review. Sites arrive compliant from day one, instead of getting fixed once someone notices they aren’t.