Microsoft 365 governance that keeps up with your users, and with AI

Microsoft 365 governance means clear rules, a live inventory, daily checks and records that keep Teams, SharePoint, OneDrive, Exchange, Planner, Viva Engage, Loop and Microsoft Entra ID in order. A tool applies them every day, not a policy document. Neptune selects that tool, puts it in place in your tenant, trains your team and supports you.

Native tools

Why native admin tools are not enough?

Microsoft's own tools are the foundation, and we keep them in place. Each one sets the rules for its own service. Microsoft 365 governance tools follow those rules up every day, across services, with the people who own the content.

Microsoft toolWhat it does wellWhat a governance layer adds
Microsoft 365, Teams and SharePoint admin centres Settings and reports for each service, managed by your admins. One inventory of teams, sites, guests, apps, flows and agents, with the links between them and the owner, activity and risk of each.
Microsoft Purview Classifies and protects data with sensitivity labels. Finds where labels or sharing rules are missing and asks the right owner to fix it, with a record of the decision.
Microsoft Entra ID Manages identities and guest access. Links people and guests to the workspaces they can reach, so access is reviewed in Teams by the people who own the content.
Administrative units in Microsoft Entra ID Limit roles such as Helpdesk, User or License Administrator to the users and groups of one country or subsidiary. Rules stay central while each subsidiary or country admin works only on their own scope, with the inventory, findings and reports for their part of the tenant.
SharePoint Advanced Management Flags inactive or ownerless sites, asks owners to confirm them, then sets them to read-only or archives them. Its reports show where sites may be overshared. The same lifecycle rules for every object, not only sites, and oversharing tracked in Teams, Power BI and Power Platform as well.
Power Platform admin center Data policies control which connectors agents may use, Managed Environments limit how widely they are shared, and the inventory lists agents, apps and flows. Daily checks on every app, flow and agent, ranked by severity and sent to its owner.
Agent Registry and Microsoft Agent 365 Lists every agent in one registry, including agents with no Microsoft Entra identity. Agent 365, generally available and licensed per user, adds access and security controls for agents that have one. A named owner, a review date and lifecycle rules for each agent, governed together with the teams, sites and permissions it uses.

The native tools stay in place: we configure them and build on them.

Part A

Microsoft 365 governance

Six areas of Teams and SharePoint governance where native settings leave you with manual follow-up. For each one: what we cover, and how we deliver it with you.

Teams and groups lifecycle

Every team stays owned, used and up to date.

Teams are created for a project and stay long after it ends, sometimes with a single owner who has left. Old teams keep their members, files and apps, and clutter search and AI answers. Rules check ownership and activity every day, and the owner confirms before a team is archived or removed.

What it covers

  • Teams without an owner, or with only one
  • Unused channels and tabs
  • Apps installed in each team
  • Expiry and archiving after the owner confirms
  • Templates and naming rules for new teams

How we deliver it

  • We map today's teams and agree the rules with you.
  • Lifecycle rules run in your tenant, switched on in waves.
  • Owners get a plain-language request, not a ticket.
  • Your admins receive a monthly lifecycle report.

Teams lifecycle

Active teams
1,240
Teams without an owner
38
Inactive for 90 days
214
Archived this quarter
61
Example data, for illustration only

SharePoint and OneDrive

Know who can open what, across every site.

Over the years, sites collect sharing links, external shares and missing labels. Microsoft Copilot (formerly Microsoft 365 Copilot) only shows people content they can already open, so overshared content becomes easier to find. Daily checks flag sites without a sensitivity label, "Anyone" links without expiry and sites left unused, and send each finding to the site owner.

What it covers

  • Sites without a sensitivity label
  • "Anyone" links without expiry
  • External sharing, site by site
  • Unused sites and the storage they hold
  • OneDrive handover for leavers

How we deliver it

  • We rank oversharing by risk and fix the worst first, with site owners.
  • Default settings that prevent the next overshare.
  • Site owners review access on a schedule.
  • Reports show the trend, site by site.

Sensitivity label coverage

71%

Sites with a label

  • Confidential 312 sites
  • Internal 1,040 sites
  • No label yet 548 sites
Example data, for illustration only

Guest and external access

Every guest has a sponsor and an end date.

Guests are invited for one project and keep their access long after it ends. Some invitations are never accepted but stay open. Rules flag guests inactive for 90 days and open invitations, then each sponsor or owner decides: keep or remove. Every decision is recorded.

What it covers

  • Guests inactive for 90 days or more
  • Invitations never accepted
  • A sponsor and an end date for each guest
  • Teams guest access reviewed by owners
  • Shared channels and cross-tenant access

How we deliver it

  • An inventory of every guest, with last sign-in.
  • Review campaigns sent to sponsors, with reminders.
  • Removal once the owner decides, recorded for audit.
  • A clear report for your security team.

Guest access review

  • Agency partner Keep
  • Former contractor Remove
  • Audit firm Awaiting owner
  • Supplier account Keep
Example data, for illustration only

Policies and compliance reporting

See where you stand on your policies, without building reports by hand.

Policies exist on paper, but checking them across every team and site by hand does not hold up. The rules you switch on are checked every day, findings are ranked by severity and a six-month trend shows progress. Evidence is exported on a schedule for audit.

What it covers

  • Rules you switch on or off
  • Daily checks across services
  • Findings ranked by severity
  • A six-month trend
  • Scheduled evidence exports

How we deliver it

  • A policy baseline agreed with your security team.
  • Scheduled reports to the people who need them.
  • An alert when a key setting changes.

Findings by rule

  • High 42
  • Medium 155
  • Low 260
  • "Anyone" link without expiry 42 High
  • Team without an owner 38 Medium
  • Guest inactive for 90 days 117 Medium
  • Site without a label 260 Low
Example data, for illustration only

Licence optimisation

Pay for the licences people actually use.

Licences stay assigned to people who left, changed role or never sign in, and renewals then pay for seats nobody uses. We compare assigned and active licences by plan and by department, using Microsoft Entra ID attributes, and free seats for reuse before you buy more.

What it covers

  • Assigned and active licences
  • Disabled accounts that keep a licence
  • No sign-in for 90 days
  • Usage by department, from Entra ID
  • Overlapping plans and add-ons

How we deliver it

  • Usage measured over the last 90 days.
  • A reclaim plan before each renewal.
  • Reclaim rules that run automatically.

Assigned and active, by plan

  • Plan 1: Assigned 100, Active 72
  • Plan 2: Assigned 46, Active 30
  • Add-ons: Assigned 28, Active 12
Example data, for illustration only

Copilot readiness

Switch on Copilot without surfacing what should stay private.

Copilot answers from what each person can already open. The readiness assessment is the first step of the rollout: the tool's first inventory shows oversharing, missing labels and stale content, and the fixes start there.

What it covers

  • Oversharing and risky links
  • Sensitivity labels on sites in Copilot scope
  • Stale content and content without an owner

How we deliver it

  • A first inventory as step one of the rollout.
  • Fixes for the top risks, with site owners.
  • A pilot group, trained on its own data.

Copilot readiness

3 of 5 steps

  • Oversharing fixed
  • Labels in place
  • Pilot group chosen
  • Pilot training
  • Adoption reporting
Example data, for illustration only

How it works

How governance runs in your tenant

Fast and done right: tested starting rules, a rollout in waves and runbooks your team keeps.

  1. Step 1

    Connect

    The governance tool is registered as an app in Microsoft Entra ID, with admin consent. We review its scope with your security team.

  2. Step 2

    Inventory

    A first inventory of teams, sites, guests, licences and agents, reviewed with you to agree priorities.

  3. Step 3

    Enforce

    Rules are switched on in waves, and owners are told what changes and why.

  4. Step 4

    Prove

    Scheduled reports and a trend over time for IT, security and audit.

FAQ

Governance questions, answered.

What is Microsoft 365 governance?

Microsoft 365 governance, sometimes called M365 or Office 365 governance, is the set of rules, inventory, checks and records that decide who can create teams and sites, who can share what, how long guests keep access and which licences are in use. A governance tool applies them every day across Microsoft 365, rather than leaving them in a policy document.

How do Microsoft 365 governance tools differ from the admin centres, Purview and Entra ID?

The Microsoft 365, Teams and SharePoint admin centres manage settings service by service. Microsoft Purview classifies and protects data, Microsoft Entra ID manages identities and guest access, and Microsoft's agent registry lists your agents. A governance tool works across all of them: it keeps one inventory of teams, sites, guests and agents, checks your rules every day and asks the owner to act, with a record of each decision. We keep the native tools in place and build on them.

We are getting Microsoft Agent 365. Do we still need a governance layer?

Agent 365 is Microsoft's control plane for agents, and we build on it. Its registry lists every agent, including those with no Microsoft Entra identity, and its access and security controls apply to agents that have one. A governance layer adds the follow-up: a named owner and a review date for each agent, rules that also cover the teams, sites and data the agent uses, and clean-up when it is no longer needed. Our guide Microsoft Agent 365 explained covers what it includes and what you still decide.

Which Microsoft 365 services are covered?

Teams, SharePoint, OneDrive, Exchange, Planner, Viva Engage, Loop and Microsoft Entra ID, plus Microsoft Copilot and the agents built in Copilot Studio, in SharePoint and in Power Platform. We agree with you which services and rules come first.

Can each country or subsidiary manage its own part of the tenant?

Yes. Rules stay central while each subsidiary or country admin works only on their own scope. A segment is defined by Microsoft Entra ID attributes such as country or company, and admins assigned to it see only its inventory, findings and reports. Microsoft's administrative units still decide who can change which accounts. Our guide to Microsoft 365 administrative units explains where native delegation stops.

How are unused teams and SharePoint sites cleaned up?

Rules flag teams and sites with no recent activity, and teams left without an owner. The owner is asked to keep, archive or delete, and nothing is removed without that decision. Archiving follows a documented runbook, and each decision is recorded, so SharePoint governance does not depend on someone remembering to look.

How should Teams guest access be reviewed?

Every guest gets a sponsor and an end date. Guests inactive for a period you set, for example 90 days, and invitations that were never accepted are flagged. On a schedule, the owner of each team or site decides to keep or remove each guest. Microsoft Entra ID still manages the guest accounts; the governance tool runs the reviews and keeps the decisions.

Where should we start if everything feels urgent?

With the first inventory of your tenant. Findings are ranked by risk, so the first rules target what matters most, often guest access and oversharing. We agree the order with you.

Will governance rules slow our users down?

Not if they are designed with them in mind. We agree the rules with you, automate what can run on its own and keep requests short. Owners get plain-language requests instead of tickets, so most users simply notice that their spaces stay tidy.

Who keeps the rules up to date after the project?

Your team, with our help when you want it. The rules are documented and your admins are trained on them. We stay reachable after go-live, adjust the setup when your needs change and keep pace with Microsoft updates.

Talk to us about your tenant.

Tell us what worries you most today. We will explain which tool fits your tenant and how we would put it in place with your team.