0:00–0:20
Review
0:20–0:35
Tenant tidy
0:35–1:40
Assessment
1:40–2:00
Debrief
0:00 – 0:20Review · 20 min
Week 5 consolidation — the complete Teams governance stack
Connect five days of Teams work into one governance picture.
- The Teams governance stack — draw on board: Architecture (M365 Group → SharePoint/Exchange/OneNote) → Policies (cascade: direct → group → global; 5 policy types) → Guest access (B2B guest accounts, org-wide settings, per-team settings) → External access (federation, chat/call only) → Meetings (lobby, recording, storage, expiry). Ask: "Which layer would catch a guest accessing content they shouldn't? Which layer governs what a Finance user can do in a meeting?"
- Incident investigation methodology — the systematic approach for Teams governance incidents: start with Teams Admin Centre → Teams list (who is in which team?), check guest users in Entra ID (what accounts exist?), check recording storage in SharePoint/OneDrive (what has been recorded and where is it?), check sharing on specific files (has anything been shared externally?), check meeting policies (what policy governs the affected user?). This is the methodology for the assessment.
- 5 minutes open Q&A — concepts only
Instructor note: Pre-seed the assessment scenario before class: (1) add a guest account to the HR team (where guests should not be — HR data is sensitive), either by inviting a real external address or by using the lab partner's account if still present. (2) In the IT Department team, start a channel meeting recording and then share the recording file externally with an "Anyone with the link" sharing link. Students must find both issues using the tools covered this week and remediate them.
0:20 – 0:35Tenant tidy · 15 min
Final self-audit before the assessment window opens
- All five department teams present in Teams Admin Centre — IT, Finance, HR, Sales, Lakeview Logistics (main)
- IT Management private channel exists in the IT Department team
- LL — Finance Messaging policy active — Priya Nair's effective messaging policy confirmed
- LL — Executive Meetings policy assigned to Sarah Chen and Marcus Webb
- Global meeting policy — recording On, anonymous join Off, expiry 120 days
- Guest access enabled in org-wide settings
- Lab Journal entries complete for Days 1–4
Assessment boundary: At 0:35 no further tenant changes are permitted unless directed by the assessment sheet. The instructor's pre-seeded issues are now live in the tenant.
0:35 – 1:40Assessment · 65 min
Week 5 assessment — the Lakeview Logistics Teams governance incident
Two concurrent governance incidents have been reported. Students investigate both, remediate both, design a governance control to prevent recurrence, and provide written analysis.
| Section | What is assessed | Marks |
| Section A — Investigation | Students locate the guest in the wrong team (HR) using the Teams Admin Centre and Entra ID, and locate the externally-shared meeting recording using SharePoint Manage access. Both require specific navigation paths that test whether students know where to look. | 25 pts |
| Section B — Remediation | Remove the guest from the HR team, verify the guest Entra ID account still exists (and decide whether to delete it), revoke the external sharing link on the recording file, and verify both access vectors are closed. | 25 pts |
| Section C — Policy design | Given the two breach types, design and implement one governance control that would prevent recurrence. Three options: guest access review, meeting recording policy tightening, or a Teams governance audit procedure. Students must implement their choice in the tenant. | 25 pts |
| Section D — Written analysis | Two written questions: explain how the guest ended up in HR and why Teams/SharePoint controls did not catch it earlier; analyse the recording sharing incident and whether the recording expiry policy would have eventually resolved it. | 25 pts |
Instructor note: Section A requires navigating to Teams Admin Centre → HR team → Members (to find the guest) and to the IT Department SharePoint site → Recordings folder → the recording file → Manage access (to find the external link). Both are specific paths students must know — they cannot be guessed. Section C's three options all produce defensible answers; marks are for implementation quality and reasoning, not for choosing a specific option.
1:40 – 2:00Debrief · 20 min
Assessment debrief & Week 6 preview
- Walk through Section A — show the HR team Members path in the Teams Admin Centre and the Manage access path on the recording file. These are the two navigation paths that distinguish students who understand the system from those who are guessing.
- Ask: "The recording expiry is set to 120 days. If no one had reported this incident, would the external sharing link have eventually become harmless?" — answer: the link would still work until the file was deleted at day 120; anyone with the link could access it during that window. Expiry closes the issue eventually but is not a detection or prevention mechanism.
- Discuss Section C governance designs — surface the range. Which control would have prevented the guest getting into HR? Which would have caught the recording sharing earlier? Which is the most operationally sustainable?
- Ask: "Looking at the full five-week M365 stack — identity, email, SharePoint, Teams — what is the single weakest governance point at Lakeview Logistics right now?" — open-ended synthesis question, no wrong answer, prime Week 6 thinking
- Week 6 preview: Endpoint management — Intune device enrolment, compliance policies, Autopilot, app deployment, and Known Folder Move (the KFM deployment planned in Lab 4-D Bonus B now gets implemented). The devices that all these users and guests are signing in from are the next governance layer.
Assessment rubric — marking guidance
| Criterion | Full marks | Partial | No marks |
| Section A | Both issues found via correct paths, navigation documented, findings described accurately | One found correctly, one found via wrong path or not found | Neither found |
| Section B | Both access vectors closed, verification performed for each, guest account decision documented with reasoning | One remediated and verified, one partial | Neither remediated |
| Section C | Governance gap correctly identified, appropriate control chosen, implemented in tenant, reasoning explained clearly | Gap identified, control chosen but not implemented or poorly reasoned | Gap not identified |
| Section D | Both questions answered with accurate technical content, expiry analysis correctly identifies the 120-day window risk | One answered well, one partial | Both incorrect or not attempted |
Learning outcomes — by end of Week 5, students can…
Audit Teams membershipFind guests in teams using the Teams Admin Centre and trace their Entra ID accounts
Audit recording accessLocate meeting recordings in SharePoint and inspect external sharing via Manage access
Remediate guest incidentsRemove guests from teams and manage their Entra ID accounts
Remediate recording incidentsRevoke external sharing links on recording files
Design governance controlsIdentify the root cause of a Teams incident and implement a preventive control