Augmentt Update: Teams Settings Go Templatable, and Purview Ships a Curated Policy Library

Table of Contents

A new healthcare client signs, and someone on your team has to stand up HIPAA-ready DLP, retention, and sensitivity label policies for them by hand. A week later, a different client wants Teams locked down so outsiders can’t message staff or spin up new teams, and you’re rebuilding that same policy from scratch for the fifth tenant this month. None of it is hard. It’s just the kind of work that never gets faster no matter how many times you do it.

Here’s what shipped.

SharePoint Settings Are Now Fully Configurable, and Templatable

SharePoint settings inside Augmentt now cover more ground, and every one of them can be saved as a template. Notifications, page creation and commenting, and the full sharing block (external sharing for SharePoint and OneDrive, resharing, allowed domains, guest access expiration, link permissions) are all here in one screen instead of scattered across the SharePoint admin center. Build the configuration once, save it as a template, and apply it to the next tenant instead of clicking through the same settings again. System Users permission controls who on your team can view or change them.

Augmentt SharePoint settings screen showing notification, page, and sharing controls for a client tenant

Teams Policies Add App Setup and Event Settings, and Get Templatable

Teams policy management picks up two policy types it was missing: App Setup and Event Settings, alongside the existing Meeting, Messaging, Channels, and External Access policies. That’s six policy types you can now mix into a single baseline and push out as one deployable unit, instead of assigning each policy type separately.

Augmentt Teams Policies screen showing counts for Meeting, Messaging, Events, Channels, External Access, and App Setup policies

Creating a template works the same way it does elsewhere in Augmentt: pick Settings Template from the Create New menu and it’s ready to reuse on the next tenant.

Create New menu in Augmentt showing Policy Template, Settings Template, and Baseline options

Teams settings themselves are templatable now too, and System Users permission extends to Teams the same way it already covers Purview and SharePoint: Disabled, Read-only, or Manage, set per user.

Augmentt System Users permission toggle rows for Purview, Teams, and SharePoint, each set to Disabled, Read-only, or Manage

Purview Gets a Curated Information Protection Library

A new library of Augmentt-curated Information Protection templates deploys straight from the Templates tab and covers all three Purview surfaces: DLP, retention, and sensitivity labels.

On DLP, the library gives you regional and vertical starting points: UK, AU, EU, and CA PII, HIPAA PHI, FERPA, GLBA, and Microsoft’s own built-in US PII policy. Every one of them defaults to detect-and-notify, so nothing starts out blocking mail or file access on day one. You decide whether to switch a policy to enforce at deploy time.

Augmentt Data Loss Prevention templates screen listing curated policies including FERPA education records and GLBA financial privacy

On retention, you get the standard duration schedules (1, 3, 7, and 10 years) plus the HIPAA 6-year and SOX 5-year schedules already built. On sensitivity labels, there’s a standard set (Public, Internal, Confidential) plus vertical labels for PHI, attorney-client privileged material, and education records. None of this replaces the tuning a client’s own data needs, but it means nobody on your team is building a FERPA DLP policy from a blank screen.

One more Purview change in this release: you can now change a DLP policy’s evaluation priority directly from the policies table, without opening the policy itself.

Augmentt Data Loss Prevention policies table with an editable Priority column

New Compliance Audit Checks

Five checks joined the Compliance Audit library this release:

  • Comprehensive attachment-filtering policy
  • Zero-hour auto purge for Microsoft Teams
  • Notifications for internal users sending malware
  • Restrict third-party storage services
  • Restrict shared bookings pages

Secure Score Gets Its Own Filter

The assessment view now has a Secure Score filter card that narrows the list down to just the checks that pull a Microsoft Secure Score, so you’re not scrolling past framework checks that don’t touch it. Augmentt also mapped more checks to Secure Score this release, which means more of the posture work you’re already doing shows up as points on the score.

Augmentt assessment view with Secure Score, Augmentt Quick Baseline, CIS M365, and CMMC compliance cards

AI Risk Report Improvements

Three changes landed in the AI Risk Report based on partner feedback: you can now open the full employee detail view from any user table in the report, service principal permissions reflect the unique permissions actually granted instead of raw assignment records, and the report’s scoring details are more accurate. Thanks to everyone who sent in feedback on this one.

Where to Find It

SharePoint settings and templates live under Secure > SharePoint. Teams policies and templates are under Secure > Teams. The new Purview library sits on the Templates tab inside Secure > Purview > Data Loss Prevention (retention and sensitivity label templates are on their respective tabs in the same Purview section), and DLP policy priority is a column on the Policies tab right next to it. Secure Score’s new filter is on the assessment view under Security Posture, and the AI Risk Report lives in Reports. System Users permissions for all of this are managed under Configuration.

Author
Gavin Garbutt
Co-Founder & Chairman of Augmentt

FAQ

Using our GDAP tool & Magic Link, setting up is easy! You can integrate with your CSP partner portal in minutes
Augmentt uses a combination of Microsoft Secure Score best practices as well as industry standards such as NIST & CIS. You can use the out of box templates to get started right away and even build your own custom templates to match your client requirements.
Out of box, Augmentt comes pre-configured to not be noisy. Very few Microsoft alerts are critical in nature so you will be receiving tickets for account breaches and not minor user log related events. That said, everything is customizable and you can turn alerts on & off to match your clients’ needs.
No. You can choose to schedule alerts to any stakeholder you want and at the frequency you want or manually download reports when you need them.
Regardless of how MFA is managed across your tenants, we have you covered. Augmentt supports Conditional Access Policies, Security Defaults, Entra ID per user (Legacy) MFA as well as 3rd party MFA services like DUO.
No. You can use Augmentt to monitor and manage all clients regardless of their licensing. For environments with no premium licensing you can still provide alerts and monitoring for account breaches and configure security best practices. For environments with premium licensing, you can leverage Microsoft’s premium alerts and premium security configurations such as Conditional Access Policies.
Augmentt is one of the few vendors SOC 2 Type II, and GDPR compliant.
Site licenses to make sure you can deliver standardized service across all clients very affordably.

SUBSCRIBE for more resources

Related Content

Policy Sprawl Is Killing MSP Efficiency
Policy sprawl is quietly draining your margins, creating security gaps, and eroding client trust. The good news? Standardization is the cure.
Does Microsoft Secure Score Tell the Whole Story?
Do you have a complete understanding of your security? See why MSPs need to understand the role licensing plays in Secure Score results.
Top 10 M365 Security Best Practices for MSPs
Here are the top M365 security best practices to help you enhance protection, ensure compliance, and stay ahead of emerging threats.