Scope & packages
Packages for the architecture setup. The conceptual effort does not scale linearly with the number of users. You receive a binding fixed-price quote for your scope.
- Oversharing audit (SharePoint & Teams)
- Identification of “Anyone” links & orphaned data
- Basic permission concept (RBAC)
- Executive report on Copilot readiness
- Clean up Teams sprawl & guest access
- Everything in Essentials
- Microsoft Purview Information Protection (MIP)
- Rollout of sensitivity labels
- Data Loss Prevention (DLP) for finance & HR data
- Lifecycle & expiration rules for teams and groups
- Entra B2B cross-tenant access policies
- Everything in Corporate
- Automatic classification (auto-labeling)
- Endpoint DLP (USB and print restrictions)
- Complex lifecycle & retention policies
- Sensitivity labels for Teams & SharePoint containers
Technical details
Details for technical validation.
Discovery & Oversharing Analysis
In-depth analysis of the existing SharePoint and Teams architecture via the Graph API and PowerShell. I identify toxic permissions, broken inheritance and open sharing links before Copilot's Semantic Index indexes them.
- SharePoint Permission & Shadow IT Audit
- External Sharing & Guest Access Review
- Identification of High-Risk Workspaces
Information Protection (MIP & Labels)
Building the classification architecture in Microsoft Purview. I define the global label taxonomy and require users to classify documents in order to enforce need-to-know access cryptographically.
- MIP Sensitivity Label Taxonomy Design
- Label Enforcement & Default Classification Policies
- Encryption & Rights Management (RMS) Setup
Data Loss Prevention (DLP Baseline)
Implementation of hard guardrails against data exfiltration. I configure Purview DLP rules for Exchange, SharePoint and Teams to block the unauthorized export of PII (Swiss AHV numbers, credit cards) and intellectual property.
- DLP Policy Deployment (Cloud Services)
- Endpoint DLP Setup (Windows 11 Integration via Intune)
- Incident Routing & Alerting Configuration
Copilot Boundary Hardening
Securing Microsoft 365 Copilot access. I make sure that strict Conditional Access controls, app protection policies and Purview integration prevent the AI engine from being misused as a vector for internal data exfiltration.
- Semantic Index Hardening
- Copilot Web-Grounding & Agent Controls
- Restricted Content Discovery for sensitive SharePoint sites
Lifecycle & Container Management
Implementation of automated expiration policies. Inactive teams are validated by the owner or soft-deleted after a defined period (e.g., 180 days).
- M365 Group Expiration Policy Deployment
- Access Review Setup for Teams Owners
- Retention Policies for Teams Channel Messages
External Collaboration & B2B Setup
Securing the boundaries of your organization. I configure Entra ID cross-tenant access and enforce granular rules for guest access so that external partners remain isolated.
- Entra ID B2B Collaboration Hardening
- Guest Access Reviews & Auto-Expiration
- Teams Shared Channels (B2B Direct Connect) Setup
What is not included in this sprint:
- Prompt engineering & end-user training: I build the secure infrastructure for AI. Training on how to ask Copilot better questions is not part of the sprint.
- SharePoint data migrations: Moving local file servers (drive Z:) to the cloud is a separate project and not part of this readiness audit.
- Intranet build: Communication sites or HR portals are not part of the sprint; I secure the permission and data structure.
Benefits for your business
The ROI for management.
Frequently asked questions
Why not just assign Copilot licenses and get started?
Microsoft 365 Copilot respects your existing permissions. If your SharePoint contains broken inheritance or “Anyone” links, Copilot will find them. Without a prior audit, undetected permission errors can quickly lead to internal data leaks during the AI rollout (e.g., interns accessing salary lists).
Will DLP and labels block employees in their work?
No. I roll out Purview Data Loss Prevention (DLP) and sensitivity labels in audit mode first, analyze the telemetry and only enforce them once false positives have been eliminated. Legitimate data flow stays intact; only unauthorized exfiltration is strictly blocked.
Does this sprint include Copilot licenses or prompt training?
No. I am an engineer, not an AI coach. I build the technical security foundation (Zero Trust for data) so that you can roll out Copilot securely. Licenses and end-user training are not part of the sprint.
Do you also clean up the folder structure on the file server?
No. Migrating unstructured local data (file servers) to the cloud is a separate migration project. This sprint focuses on securing existing Microsoft 365 workloads (SharePoint, Teams, Exchange) for AI readiness.