What It Delivers
Sensitivity Label Deployment
A practical label taxonomy deployed across M365 โ not the six-tier compliance architecture that nobody uses, but a scheme your organisation will actually apply. Labels flow through email, Teams, SharePoint, and Office applications. Classification becomes a signal every downstream control can act on.
Retention Policies for All M365 Workloads
Retention configured for Exchange, SharePoint, OneDrive, Teams messages, and Teams meeting recordings. Regulatory minimums met. Over-retained data that creates unnecessary eDiscovery scope identified and scheduled for deletion. Retention gaps that expose you to "we don't have it" responses closed.
DLP Policies
Data Loss Prevention policies targeting your actual regulated data โ payment card numbers, national IDs, health data, or proprietary classifications โ with alert-before-block staged deployment. Auto-forward to external addresses blocked. "Anyone with the link" sharing scoped or removed.
eDiscovery Readiness
Content search scope validated, custodian identification process documented, legal hold workflow tested. If you receive a regulatory request or litigation hold tomorrow, you can respond without improvising under pressure.
Teams Governance and Guest Access Controls
Teams lifecycle policy deployed so abandoned Teams do not accumulate as forgotten data stores. Guest access permissions tightened. External sharing settings reconciled across tenant, site, and Teams channel levels โ the three layers that routinely disagree and produce unexpected exposure.
Standards Alignment
This module produces direct compliance evidence for NIS2 Article 21 (data security, access control), DORA Article 9 (ICT security policies โ data classification and handling), GDPR Articles 5 and 25 (data minimisation, privacy by design), and ISO 27001 A.5.12โA.5.13 (classification, labelling). External auditors receive the retention logs, sensitivity label reports, and DLP policy documentation as artefacts โ not manual screenshots.
Scope and Prerequisites
| Duration | 45โ90 days |
| Environment | M365 E3+ |
| Prerequisites | Module 2 (Identity) completed โ guest access and external sharing controls depend on a clean identity baseline |
| Natural follow-on | Module 7 (Recovery) to ensure retained data is backed up independently of Microsoft’s native retention |
Make your data flows visible
Every share is a copy of your blast radius handed to a party you do not fully control. Module 4 makes that visible and governable.