0:00–0:20
Review
0:20–0:35
Tenant tidy
0:35–1:40
Assessment
1:40–2:00
Debrief
0:00 – 0:20Review · 20 min

Week 4 consolidation — the SharePoint and OneDrive governance stack

Connect four days of work into one governance picture. Not re-teaching — mapping the controls to the risks they address.

Instructor note: Before the session, pre-seed the assessment scenario in student tenants. The scenario involves two issues: (1) Marcus Webb (Operations Director) can read the Payroll Records library — he shouldn't be able to. A sharing link from Lab 4-B was not deleted and is still active. (2) An unknown user appears in the Sales site Members group — a guest account that was never properly governed. Students must find both using the tools covered this week.
0:20 – 0:35Tenant tidy · 15 min

Final self-audit before the assessment window opens

Assessment boundary: At 0:35 no further tenant changes are permitted unless directed by the assessment sheet. Students work from the current state of their tenant — plus any pre-seeded changes made by the instructor.
0:35 – 1:40Assessment · 65 min

Week 4 assessment — the Lakeview Logistics permissions breach

Students investigate a reported permissions breach, audit the permissions chain using the tools covered this week, remediate the misconfiguration, design a corrective governance policy, and provide a written analysis.

SectionWhat is assessedMarks
Section A — Permissions auditStudents use Check Permissions, the library permissions panel, and Manage access on a sharing link to identify how an unauthorised user has access to restricted content. Navigate specific paths and record findings.25 pts
Section B — RemediationStudents remove the access vector identified in Section A, verify the fix using Check Permissions, and confirm the restricted library is no longer accessible via the old route.25 pts
Section C — Governance designGiven the identified breach type, students design a governance improvement — a policy, process, or configuration change that would prevent this class of breach from occurring again. Includes implementing one specific technical control.25 pts
Section D — Written analysisTwo written questions requiring students to explain the permissions model, analyse the breach cause, and justify their governance recommendation. Closed-notes.25 pts
Instructor note: The scenario centres on Marcus Webb having read access to the Payroll Records library via an active sharing link that was created in Lab 4-B but never expired or was never deleted. Section A requires students to find this link via Manage access on the document, not via the library permissions panel (which won't show link-based access). Section C's governance improvement can be: enable mandatory link expiry (already done in Lab 4-C but students must apply the rationale), configure site access reviews, or implement a stricter sharing policy for the Finance site. All are valid — marks are for reasoning quality.
1:40 – 2:00Debrief · 20 min

Assessment debrief & Week 5 preview

Assessment rubric — marking guidance

CriterionFull marksPartialNo marks
Section ABoth access vectors identified, correct tool used for each (Check Permissions for library access, Manage access for link), navigation path recorded, finding described accuratelyOne vector found or both found but wrong tool/pathNeither vector found
Section BAccess removed, Check Permissions run after removal confirms no access, method of removal documentedAccess removed but not verified, or partially removedAccess not removed
Section CGovernance gap correctly identified based on the breach type, appropriate control selected, control implemented in the tenant, reasoning explainedGap identified but wrong control, or control not implementedGap not identified
Section DBoth questions answered directly with accurate technical content, inheritance model correctly described, governance recommendation justifiedOne answered well, one partial or one fundamentally wrongBoth incorrect or not attempted

Learning outcomes — by end of Week 4, students can…

Build site architectureCreate and connect hub sites and department team sites in the SharePoint admin centre
Investigate permissions breachesUse Check Permissions, the library permissions panel, and Manage access to trace how a user gained unintended access
Remediate access violationsRemove unauthorised access and verify the fix
Design governance controlsIdentify the root cause of a breach and implement a specific control to prevent recurrence
Govern OneDrive lifecycleConfigure retention, departure notifications, and access delegation for user departures
Week 5 →Week 4 Overview