Pre-Session Homework: SharePoint Admin
This page lists the 14 control(s) you are responsible for as SharePoint Admin. Please review each control and bring the requested evidence to your assessment session.
For the full assessment experience, see the Readiness Assessment.
Control 1.14 — Data Minimization and Agent Scope Control
Security · Zone 1, Zone 2, Zone 3
Pass criteria: Each agent has a documented grounding inventory with zone-based justification, narrowed SharePoint scopes, public web grounding disabled for Zone 3 NPI agents, and active scope-drift monitoring.
Verify in: See control documentation.
Full control documentation · Portal walkthrough
Control 1.15 — Encryption: Data in Transit and at Rest
Security · Zone 1, Zone 2, Zone 3
Pass criteria: SSL Labs grade A/A+ on all public tenant endpoints (TLS 1.2+ only, no weak ciphers); Customer Key DEPs in Active state for Exchange Online and SharePoint/OneDrive workloads (Zone 2/3) with Key Vaults hardened (soft delete + purge protection enabled, >=90-day retention, wrapKey/unwrapKey/get access only); Power Platform CMK applied to every Managed Environment hosting agents (Zone 2/3); Double Key Encryption label published to MNPI scope and cryptographic isolation validated in a non-production tenant (Zone 3); key rotation within zone cadence (annual Zone 2, quarterly Zone 3) with dual-control approval records; and rehearsed Customer Key revocation runbook with dated non-production test (Zone 3).
Verify in: See control documentation.
Full control documentation · Portal walkthrough
Control 1.16 — Information Rights Management (IRM) for Documents
Security · Zone 1, Zone 2, Zone 3
Pass criteria: Zone 1: IRM is optional — no IRM evidence required for a Zone 1 pass. Zone 2/3: Azure RMS reports Enabled (Get-AipService); at least one IRM-enabled sensitivity label is published with Assign permissions now and encryption configured (not content marking only); IRM enabled on every SharePoint agent knowledge-source library with zone-appropriate content expiration (Zone 2: 180-day; Zone 3: 90-day); IRM-enabled sensitivity label configured in Purview with zone-appropriate offline-access limit (Zone 2: 14-day; Zone 3: 7-day); agent service identity scoped to Viewer in label permissions (not Co-Author or Co-Owner); document tracking events confirmed in Purview within expected latency; super-user group membership restricted to named compliance personnel; and Zone 3: dynamic watermark with viewer email, auto-labeling deployed for all FSI-relevant sensitive information types.
Verify in: See control documentation.
Full control documentation · Portal walkthrough
Control 1.3 — SharePoint Content Governance and Permissions
Security · Zone 1, Zone 2, Zone 3
Pass criteria: External sharing restricted; Everyone groups removed from agent knowledge sites; container sensitivity labels applied; SAM RAC/RCD enabled and quarterly access reviews active for Zone 3.
Verify in: See control documentation.
Full control documentation · Portal walkthrough
Control 2.13 — Documentation and Record Keeping
Management · Zone 1, Zone 2, Zone 3
Verify in: See control documentation.
Full control documentation · Portal walkthrough
Control 2.16 — RAG Source Integrity Validation
Management · Zone 2, Zone 3
Verify in: See control documentation.
Full control documentation · Portal walkthrough
Control 4.1 — SharePoint Information Access Governance (IAG) / Restricted Content Discovery
SharePoint · Zone 1, Zone 2, Zone 3
Verify in: See control documentation.
Full control documentation · Portal walkthrough
Control 4.2 — Site Access Reviews and Certification
SharePoint · Zone 1, Zone 2, Zone 3
Verify in: See control documentation.
Full control documentation · Portal walkthrough
Control 4.3 — Site and Document Retention Management
SharePoint · Zone 1, Zone 2, Zone 3
Verify in: See control documentation.
Full control documentation · Portal walkthrough
Control 4.4 — Guest and External User Access Controls
SharePoint · Zone 1, Zone 2, Zone 3
Verify in: See control documentation.
Full control documentation · Portal walkthrough
Control 4.5 — SharePoint Security and Compliance Monitoring
SharePoint · Zone 2, Zone 3
Verify in: See control documentation.
Full control documentation · Portal walkthrough
Control 4.6 — Grounding Scope Governance
SharePoint · Zone 1, Zone 2, Zone 3
Verify in: See control documentation.
Full control documentation · Portal walkthrough
Control 4.7 — Microsoft 365 Copilot Data Governance
SharePoint · Zone 1, Zone 2, Zone 3
Verify in: See control documentation.
Full control documentation · Portal walkthrough
Control 4.8 — Item-Level Permission Scanning for Agent Knowledge Sources
SharePoint · Zone 1, Zone 2, Zone 3
Verify in: See control documentation.
Full control documentation · Portal walkthrough
Generated from assessment/manifest/controls.json by scripts/generate_homework_pages.py. Edit the manifest, then re-run.