Exercise - Set up and audit a governed SharePoint site

Completed

Relecloud's Finance team needs a governed site of its own, and you need to see the tenant's broader sharing exposure before Copilot rolls out company-wide. You've just learned how site permissions, external sharing settings, and data access governance reports fit together—apply all three yourself.

Important

Prerequisites for this exercise:

  • SharePoint admin center access at admin.microsoft.com/sharepoint with SharePoint Administrator (or Global Administrator) permissions.
  • A test tenant with at least one existing site preseeded with broad "Anyone" or "Everyone except external users" sharing—fresh sandbox tenants don't organically show oversharing signals, so you may need to seed one before you can see the report light up.
  • Three test user accounts you can add as owner, member, and visitor of the new site.

If your tenant doesn't have SharePoint Advanced Management for the data access governance reports, complete Tasks 1 and 2, then read through Task 3 to see what the report surfaces.

Task 1: Create the Finance site with the right permissions

  1. Sign in to the SharePoint admin center at admin.microsoft.com/sharepoint, then select Sites > Active sites > Create.
  2. Choose Team site—Finance collaborates internally, so the team site's Microsoft 365 group membership fits better than a communication site.
  3. Name the site Relecloud Finance, set the primary owner to your Finance lead account, and select Next > Finish.
  4. Once the site appears in Active sites, open it and select Membership. Add a second account as Site owner, add a member to the Site member group, and add a visitor to Site visitor.
  5. Confirm all three groups show the right users. This is the least-privileged split you learned in Unit 2—everyone on the site now has exactly the access they need, and no more.

Task 2: Configure external sharing at the org and site level

  1. Back in the SharePoint admin center, select Policies > Sharing.
  2. Set the organization-level SharePoint sharing to New and existing guests (or match your tenant's real governance target—don't leave it on Anyone if you can avoid it).
  3. Select Save, then return to Sites > Active sites, select the Finance site, and open its Settings tab.
  4. Under External sharing, restrict the site to Only people in your organization—this overrides the org-level ceiling for the Finance site specifically, because Copilot grounding for Finance content shouldn't surface to any external user.
  5. Confirm: the site now sits below the tenant's sharing ceiling. That's what "tenant sets the ceiling, site sets its own floor" means in practice.

Task 3: Run a site permissions report to find the oversharing

  1. In the SharePoint admin center, select Reports > Data access governance.
  2. Select the Site permissions report, then select Run report.
  3. When the report finishes, sort by Sharing links – Anyone or Users with access to surface the sites with the widest exposure.
  4. Open the top overshared site the report surfaces. Note its sharing links and its user count—this is exactly what Copilot would use as grounding context if a user in that scope asked a question that hit this site's content.
  5. Reflect: you now have (a) a properly governed new site, (b) a Copilot-safe sharing ceiling on it, and (c) a shortlist of preexisting sites you'll need to remediate before Copilot goes live. You'll act on that shortlist in the next exercise.