0:00–0:20
Review
0:20–0:35
Tenant tidy
0:35–1:40
Assessment
1:40–2:00
Debrief
0:00 – 0:20Review · 20 min
Week 4 consolidation — the SharePoint and OneDrive governance stack
Connect four days of work into one governance picture. Not re-teaching — mapping the controls to the risks they address.
- The governance stack — draw on board: Site architecture (hub → dept sites) → Permissions model (site → library → item, inheritance, groups) → External sharing (4 tiers, tenant ceiling, site override) → OneDrive (personal storage, quota, departure lifecycle). Ask: "Which layer would catch accidental internal oversharing? Which layer controls external risk? Which layer governs what happens when someone leaves?"
- Permissions troubleshooting methodology — the systematic approach: start with Check Permissions (what access does this user have?), trace the inheritance chain (is this library inheriting from the site?), identify the group memberships involved (how is this user getting this access?), check for direct permissions (was this user granted access individually?), and check sharing links (is there an active link granting access?). This is the methodology for the assessment.
- 5 minutes open Q&A — concepts only
Instructor note: Before the session, pre-seed the assessment scenario in student tenants. The scenario involves two issues: (1) Marcus Webb (Operations Director) can read the Payroll Records library — he shouldn't be able to. A sharing link from Lab 4-B was not deleted and is still active. (2) An unknown user appears in the Sales site Members group — a guest account that was never properly governed. Students must find both using the tools covered this week.
0:20 – 0:35Tenant tidy · 15 min
Final self-audit before the assessment window opens
- All 6 SharePoint sites present in Active sites — Intranet (hub), Lakeview Logistics, IT, Finance, HR, Sales
- All sites associated to the Lakeview Logistics hub — confirmed in Active sites Hub column
- Finance and HR sites showing "Only people in your organisation" in the Sharing column
- Payroll Records library exists on the Finance site with broken inheritance
- Guest user from Day 3 visible in Entra ID Users filtered by Guest
- OneDrive retention set to 180 days — confirmed in OneDrive admin centre
- Lab Journal entries complete for Days 1–4
Assessment boundary: At 0:35 no further tenant changes are permitted unless directed by the assessment sheet. Students work from the current state of their tenant — plus any pre-seeded changes made by the instructor.
0:35 – 1:40Assessment · 65 min
Week 4 assessment — the Lakeview Logistics permissions breach
Students investigate a reported permissions breach, audit the permissions chain using the tools covered this week, remediate the misconfiguration, design a corrective governance policy, and provide a written analysis.
| Section | What is assessed | Marks |
| Section A — Permissions audit | Students use Check Permissions, the library permissions panel, and Manage access on a sharing link to identify how an unauthorised user has access to restricted content. Navigate specific paths and record findings. | 25 pts |
| Section B — Remediation | Students remove the access vector identified in Section A, verify the fix using Check Permissions, and confirm the restricted library is no longer accessible via the old route. | 25 pts |
| Section C — Governance design | Given the identified breach type, students design a governance improvement — a policy, process, or configuration change that would prevent this class of breach from occurring again. Includes implementing one specific technical control. | 25 pts |
| Section D — Written analysis | Two written questions requiring students to explain the permissions model, analyse the breach cause, and justify their governance recommendation. Closed-notes. | 25 pts |
Instructor note: The scenario centres on Marcus Webb having read access to the Payroll Records library via an active sharing link that was created in Lab 4-B but never expired or was never deleted. Section A requires students to find this link via Manage access on the document, not via the library permissions panel (which won't show link-based access). Section C's governance improvement can be: enable mandatory link expiry (already done in Lab 4-C but students must apply the rationale), configure site access reviews, or implement a stricter sharing policy for the Finance site. All are valid — marks are for reasoning quality.
1:40 – 2:00Debrief · 20 min
Assessment debrief & Week 5 preview
- Walk through Section A — the sharing link access vector. Show that Get-SPOSiteGroup and the library permissions panel do not reveal link-based access — only Manage access on the specific document does. This is the most important troubleshooting lesson of the week.
- Discuss Section C governance designs as a class — surface the range of approaches. Ask: "Which control would have prevented this breach entirely? Which would have limited the damage? Which would have detected it earlier?"
- Ask: "Looking back at the full Week 4 stack — sites, permissions, external sharing, OneDrive — what is the single control that would have the most impact on data governance at Lakeview Logistics if nothing else was in place?" — prime synthesis thinking
- Week 5 preview: Microsoft Teams administration — the collaboration layer that sits on top of the M365 Groups and SharePoint sites built this week. Students will configure Teams policies, manage channels and apps, control guest access in Teams, and understand the Teams → SharePoint → M365 Group relationship in full. The Week 2 CA policies enabled in Bonus B also now govern Teams sign-ins.
Assessment rubric — marking guidance
| Criterion | Full marks | Partial | No marks |
| Section A | Both access vectors identified, correct tool used for each (Check Permissions for library access, Manage access for link), navigation path recorded, finding described accurately | One vector found or both found but wrong tool/path | Neither vector found |
| Section B | Access removed, Check Permissions run after removal confirms no access, method of removal documented | Access removed but not verified, or partially removed | Access not removed |
| Section C | Governance gap correctly identified based on the breach type, appropriate control selected, control implemented in the tenant, reasoning explained | Gap identified but wrong control, or control not implemented | Gap not identified |
| Section D | Both questions answered directly with accurate technical content, inheritance model correctly described, governance recommendation justified | One answered well, one partial or one fundamentally wrong | Both incorrect or not attempted |
Learning outcomes — by end of Week 4, students can…
Build site architectureCreate and connect hub sites and department team sites in the SharePoint admin centre
Investigate permissions breachesUse Check Permissions, the library permissions panel, and Manage access to trace how a user gained unintended access
Remediate access violationsRemove unauthorised access and verify the fix
Design governance controlsIdentify the root cause of a breach and implement a specific control to prevent recurrence
Govern OneDrive lifecycleConfigure retention, departure notifications, and access delegation for user departures