By clicking “Accept”, you agree to the storing of cookies on your device to enhance site navigation, analyze site usage, and assist in our marketing efforts. View our Cookie Policy for more information.
Insights

Optimizing Governance for Continued Copilot Integration with SharePoint Advanced Management

10 mins
Optimizing Governance for Continued Copilot Integration with SharePoint Advanced Management

Enhancing Governance with SharePoint Advanced Management (SAM)

The importance of governance significantly increases after implementing Copilot in an organization, as it ensures that AI-driven processes continue to be secure, compliant, and effectively managed. Robust governance helps mitigate risks associated with data handling and user access, enhancing overall operational efficiency.

Implementing AI tools like Copilot in a tenant introduces several governance challenges, primarily because Copilot is a dynamic technology introduced into the M365 ecosystem. Some key issues on the horizon:

  • Content Sprawl: Organizing and managing large volumes of content across SharePoint and OneDrive can become overwhelming, leading to inefficiencies and data silos.
  • Oversharing: Without proper controls, sensitive information may be overshared, resulting in potential data breaches and compliance issues.
  • User Access Management: Monitoring and controlling user permissions and access to sensitive information is a complex task.
  • Inconsistent Governance Policies: The absence of standardized governance practices can lead to fragmented management and oversight.

Addressing these challenges is crucial for maintaining a secure and efficient collaboration environment.

Effective governance is crucial for managing SharePoint environments in today's dynamic business landscape. With the increasing complexities of content management and the advent of AI tools, organizations need robust solutions to ensure security, compliance, and efficiency. SharePoint Advanced Management (SAM) is a powerful tool to address these challenges, especially when used alongside Copilot.  

We recommendation that organizations explore the capabilities and benefits of SAM, use of AI Insights, and how they together elevate both your security posture and your Copilot experience.

SAM – What, Why

Microsoft SharePoint Premium - SharePoint Advanced Management is an add-on for Microsoft 365 that provides IT administrators with tools to enhance content governance during the Microsoft Copilot deployment.

As your organization is investing into Copilot Technical Readiness or managing content post-implementation, you can take advantage of its capabilities, such as:

  • prevent content sprawl
  • manage and monitor oversharing
  • streamline access management for SharePoint and OneDrive sites
  • lifecycle analysis through comprehensive reporting
A screenshot of a computerDescription automatically generated

These 3 key pillars for SharePoint Advanced Management help organizations to manage their environment:

  • Centralized Management: A unified platform to manage SharePoint environments, simplifying policy enforcement and compliance monitoring across all sites and OneDrive accounts, ensuring consistency and reducing administrative complexity.
  • Scalability: Enables governance practices to scale effectively, maintaining control and oversight while supporting organizational growth. It ensures that as your environment expands, governance remains efficient and adaptable to evolving needs.
  • Integration with Microsoft 365 Tools: Seamless integration with other Microsoft 365 tools enhances overall functionality and user experience.

SAM – Unlock the Potential for improved Governance

Content Oversharing Controls

Users frequently add content and collaborate with others. Whether intentionally or unintentionally, they may share content with a wider audience than necessary, potentially exposing data through Copilot. SAM implements robust measures to prevent unauthorized access and sharing of sensitive information through features such as:

✅ Data Access Governance (DAG) reports

DAG insights in the Admin Center can be utilized to identify and remediate overshared content. Below reports are generated against OneDrive and SharePoint sites.

  • Everyone except external users or EEEU report - Common cause of oversharing is users mistakenly sharing content with the EEEU group, which grants access to all users within the organization, except external users. With the EEEU report, you can now view a list of all sites shared with the EEEU group.  
A screenshot of a computerDescription automatically generated
  • Permission state report (Public Preview) - Offers a comprehensive view of site permissions across SharePoint, OneDrive, and files, aiding in the identification of potentially over-permissioned content within the tenant. Also allows admins to take corrective actions on these sites, ensuring that Copilot or search results are accessible only to authorized users.

✅ Site access reviews

Initiate access reviews with the owners of sites identified in the Permission State and EEEU reports. Prompt site owners to assess and confirm whether the current access patterns are expected or if any action is needed.

Screenshot that shows Initiate site access review for sites listed within DAG report

✅ Restrict discovery of SharePoint sites and content. (PowerShell only)

Set up policies to prevent search and Copilot from indexing certain sites, ensuring site access is maintained while keeping the site's content out of Copilot and organization-wide Search. These can be selectively applied to any site type.

Set-SPOSite –identity <site-url> -RestrictContentOrgWideSearch $true

✅ Setting up oversharing baseline with permissions-based report (PowerShell only)

The risk of data exposure grows with the number of users having access. Admins should assess sensitive data exposure by reviewing site and item permissions.  

Sharing links page

💡 Most organizations will have oversharing, though where you want to govern are sites that are sharing with a large number of users.  Generating a report based on the 'number of users', as one factor, helps to establish a baseline and track key contributors to potential 'oversharing.

Start-SPODataAccessGovernanceInsight -ReportEntity PermissionedUsers -ReportType Snapshot -Workload SharePoint -CountOfUsersMoreThan 100 -Name "ReportName"

Site Lifecycle Management

SAM streamlines the creation, maintenance, and archiving of SharePoint sites to ensure efficient use and governance through:

✅ Inactive sites policy (Preview)

A site that is active may eventually become inactive, potentially after several years. Copilot users could receive outdated results from inactive site content. The feature now allows the creation of policies that target specific site types that are inactive for a specified period. Site owners receive automated alerts and can choose to keep, delete, or archive these sites.

A screenshot of a computerDescription automatically generated

✅ Ownership management policy

Managing SharePoint sites owned by employees who leave or join the organization is crucial. Ownerless sites pose a risk of unauthorized data exposure through Copilot, as there is no designated owner to manage permissions and content. With this policy admins can set a minimum number of required owners per site (recommended 2).

A screenshot of a computerDescription automatically generated

Content Sprawl Controls

SAM manages and organizes content effectively to avoid cluttering and maintain a streamlined SharePoint environment, including:

✅ Restricted provisioning control (PowerShell only)

With the new Restricted Site Creation feature, you can manage which groups of users in your organization can create various types of sites. This policy can be controlled granularly for Team sites, Communication sites, or all sites.

Set-SPORestrictedSiteCreation -Enabled:$true

✅ Change History

These reports can increase visibility and let you monitor changes made to the SharePoint configuration across various levels of your organization.

Microsoft SharePoint Premium ...

As organizations continue to navigate the complexities of content management and AI integration, solutions like SAM become essential for robust governance. By enhancing security and compliance, improving content management, and reducing risks like content sprawl and oversharing through robust permissions, SAM ensures that Copilot operates within a controlled, regulated framework. This synergy allows IT admins and leaders to streamline governance, maintain data integrity, and optimize collaboration, ultimately enhancing the overall effectiveness of SharePoint environments and AI integration.

There are many more features on the roadmap, with additional updates expected to roll out over the next few months.  We would recommend building out a tactical roadmap to manage change within your organization.

Take the next step with experts today!
Case Study Details

Similar posts

Get our perspectives on the latest developments in technology and business.
Love the way you work. Together.
Next steps
Have a question, or just say hi. 🖐 Let's talk about your next big project.
Contact us
Popular insights
One of our goals is to help organizations build a better digital workplace experience.
Access knowledge center