SharePoint, Purview and Teams, Managed Across Every Client Tenant

Table of Contents

Augmentt now manages Microsoft Purview, SharePoint and OneDrive sharing, and Microsoft Teams policy across every client tenant you have connected. That includes DLP for Microsoft 365 Copilot. All of it is live today.

  • Microsoft Purview. Verify DLP policies and sensitivity labels across every tenant, including DLP for Microsoft 365 Copilot, and deploy a baseline where a tenant has none.
  • SharePoint and OneDrive. Audit sharing controls against the CIS Microsoft 365 Benchmark on every tenant and remediate a loose setting in a click.
  • Microsoft Teams. Manage meetings, messaging, app permissions, channels and external access, with the org-wide security settings on one screen.

That is three more Microsoft 365 workloads managed the way your team already manages Conditional Access and Intune in Augmentt. Same tenant connections and the same permission model, so there is nothing new to onboard.

The question your clients started asking

Your clients are turning on Microsoft 365 Copilot. Some of them told you first. Some of them did not. Either way the question lands on your desk within a few weeks. Is our data safe with AI?

It is a fair question and a hard one to answer. Copilot is a very capable search and retrieval engine, and the first place it looks is whatever is sitting in SharePoint and OneDrive. If that content was never classified and no data loss prevention policy is in place, Copilot will surface things to people who were never meant to see them, and it will do it fast.

Answering that across a book of business has meant opening one client’s Purview portal, checking, closing it, and opening the next one. No screen existed that could tell you which of your clients had data protection turned on.

Microsoft left this one open

Microsoft 365 Lighthouse was supposed to be the multi-tenant view for partners. It does a reasonable job on identity and threat protection. It does not reach Microsoft Purview, and it does not reach Teams policy.

So two of the three areas your clients ask about most, Purview DLP and Teams policy, have had no cross-tenant tooling behind them at all. The third, SharePoint and OneDrive sharing, has meant checking each tenant by hand.

The defaults do not help. Data protection ships turned off. Collaboration ships wide open, with external federation on, guest access broad, and anyone able to create a team. A client does not have to make a mistake to be exposed. They only have to leave things alone.

What shipped today

Microsoft Purview, including Copilot. Verify whether DLP policies are enabled in every tenant, whether that protection extends into Teams, and whether sensitivity label policies are published. DLP for Microsoft 365 Copilot is part of the DLP policies you manage here. Where a tenant has nothing, deploy a baseline data-protection configuration from Augmentt instead of sending a technician into the client’s Purview portal.

A baseline gets a tenant to a sane starting point. DLP and labeling still need tuning to each organization’s own data, so the part that pays off first is knowing where all of your clients stand and being able to show it.

SharePoint and OneDrive sharing. Augmentt audits the sharing controls against the CIS Microsoft 365 Benchmark on every tenant. External and guest sharing scope, link-sharing defaults, trusted-domain and security-group allowlists, modern authentication, Azure AD B2B integration, and blocking downloads of malware-infected files. Where the control is a setting, fix it from Augmentt in a click. Where it needs a curated list of approved domains or security groups, manage that list here too. If a client loosens something later, you find out.

Microsoft Teams policy. Teams is where client collaboration happens, and it has become a real attack surface, with external users used to phish and socially engineer staff. Manage the policies that shape how Teams behaves: meetings, messaging, app permissions and setup, channels, and external access. View a tenant’s policies, adjust them, assign them to the right users or groups, and create or remove policies without leaving Augmentt. A consolidated settings page puts the org-wide controls that matter most for security on one screen with a single save: guest access, external federation, guest meeting and messaging, and who can create teams.

Why the standard behind it matters

Every check maps back to the CIS Microsoft 365 Benchmark, alongside the HIPAA, CMMC, NIST CSF and Essential Eight mappings already in Augmentt. That matters for two conversations you are going to have.

The first is with an auditor or an insurer. When someone asks for evidence of a control, the answer comes from the same place your team configured it. There is no parallel spreadsheet to keep, and no gap between what was set and what actually gets reported.

The second is about licensing. Some of these controls need premium Microsoft licensing, and Augmentt shows which ones a client’s current licensing covers. So when you tell a client they need Business Premium, you can point at the exact control they do not have today. Most partners already have a portion of their base on premium and get value from this on day one. For the rest, you have something concrete to put in front of them.

Available today

SharePoint and OneDrive sharing controls, Purview DLP and sensitivity labels including Copilot, and Teams policy management are live for every Augmentt partner as of today, across every tenant you have connected. The full control list and the setup steps are in the Help Center.

See it on your own tenants. Start a trial, or book time with our team and we will walk your environment with you.

Author
Gavin Garbutt
Co-Founder & Chairman of Augmentt

FAQ

Using our GDAP tool & Magic Link, setting up is easy! You can integrate with your CSP partner portal in minutes
Augmentt uses a combination of Microsoft Secure Score best practices as well as industry standards such as NIST & CIS. You can use the out of box templates to get started right away and even build your own custom templates to match your client requirements.
Out of box, Augmentt comes pre-configured to not be noisy. Very few Microsoft alerts are critical in nature so you will be receiving tickets for account breaches and not minor user log related events. That said, everything is customizable and you can turn alerts on & off to match your clients’ needs.
No. You can choose to schedule alerts to any stakeholder you want and at the frequency you want or manually download reports when you need them.
Regardless of how MFA is managed across your tenants, we have you covered. Augmentt supports Conditional Access Policies, Security Defaults, Entra ID per user (Legacy) MFA as well as 3rd party MFA services like DUO.
No. You can use Augmentt to monitor and manage all clients regardless of their licensing. For environments with no premium licensing you can still provide alerts and monitoring for account breaches and configure security best practices. For environments with premium licensing, you can leverage Microsoft’s premium alerts and premium security configurations such as Conditional Access Policies.
Augmentt is one of the few vendors SOC 2 Type II, and GDPR compliant.
Site licenses to make sure you can deliver standardized service across all clients very affordably.

SUBSCRIBE for more resources

Related Content

Policy Sprawl Is Killing MSP Efficiency
Policy sprawl is quietly draining your margins, creating security gaps, and eroding client trust. The good news? Standardization is the cure.
Does Microsoft Secure Score Tell the Whole Story?
Do you have a complete understanding of your security? See why MSPs need to understand the role licensing plays in Secure Score results.
Top 10 M365 Security Best Practices for MSPs
Here are the top M365 security best practices to help you enhance protection, ensure compliance, and stay ahead of emerging threats.