Identity and conditional access
In a cloud estate the security boundary is identity, not the network. Conditional access rules are built around device state, location and risk level, and privileged roles are granted for a limited time with approval.
- Privileged roles open on request and expire
- Break-glass accounts are exempt from rules and monitored
- Rule changes run in report mode first
- Legacy authentication methods are switched off
Collaboration and sharing governance
Team spaces open easily and close with difficulty. Without lifecycle rules, ownerless spaces accumulate and external sharing becomes invisible. Naming, ownership and duration are defined at the outset.
- Every space carries an owner and a renewal date
- External sharing is restricted by default
- Guest accounts are reviewed on a regular cycle
- An ownerless space is archived rather than deleted
Data location and retention
Where data is held and how long it is kept matters as much as configuration for compliance. Retention and destruction policies are translated into technical rules, and eDiscovery needs are considered from the start.
- Retention periods become technical rules, not intentions
- Region selection is recorded
- Sensitive content is marked through classification
- Destruction records can be shown during audit
Licensing and cost discipline
Licensing cost usually grows out of assignments nobody uses. Assignment is compared against real usage data, and a leaver's license is reclaimed automatically.
- Assignment is regularly reconciled with real usage
- The leaver process reclaims the license
- License tiers are matched to roles
- A usage report is prepared before renewal