Skip to content

Pre-Session Homework: SharePoint Admin

This page lists the 14 control(s) you are responsible for as SharePoint Admin. Please review each control and bring the requested evidence to your assessment session.

For the full assessment experience, see the Readiness Assessment.


Control 1.14 — Data Minimization and Agent Scope Control

Security · Zone 1, Zone 2, Zone 3

Pass criteria: Each agent has a documented grounding inventory with zone-based justification, narrowed SharePoint scopes, public web grounding disabled for Zone 3 NPI agents, and active scope-drift monitoring.

Verify in: See control documentation.

Full control documentation · Portal walkthrough

Control 1.15 — Encryption: Data in Transit and at Rest

Security · Zone 1, Zone 2, Zone 3

Pass criteria: SSL Labs grade A/A+ on all public tenant endpoints (TLS 1.2+ only, no weak ciphers); Customer Key DEPs in Active state for Exchange Online and SharePoint/OneDrive workloads (Zone 2/3) with Key Vaults hardened (soft delete + purge protection enabled, >=90-day retention, wrapKey/unwrapKey/get access only); Power Platform CMK applied to every Managed Environment hosting agents (Zone 2/3); Double Key Encryption label published to MNPI scope and cryptographic isolation validated in a non-production tenant (Zone 3); key rotation within zone cadence (annual Zone 2, quarterly Zone 3) with dual-control approval records; and rehearsed Customer Key revocation runbook with dated non-production test (Zone 3).

Verify in: See control documentation.

Full control documentation · Portal walkthrough

Control 1.16 — Information Rights Management (IRM) for Documents

Security · Zone 1, Zone 2, Zone 3

Pass criteria: Zone 1: IRM is optional — no IRM evidence required for a Zone 1 pass. Zone 2/3: Azure RMS reports Enabled (Get-AipService); at least one IRM-enabled sensitivity label is published with Assign permissions now and encryption configured (not content marking only); IRM enabled on every SharePoint agent knowledge-source library with zone-appropriate content expiration (Zone 2: 180-day; Zone 3: 90-day); IRM-enabled sensitivity label configured in Purview with zone-appropriate offline-access limit (Zone 2: 14-day; Zone 3: 7-day); agent service identity scoped to Viewer in label permissions (not Co-Author or Co-Owner); document tracking events confirmed in Purview within expected latency; super-user group membership restricted to named compliance personnel; and Zone 3: dynamic watermark with viewer email, auto-labeling deployed for all FSI-relevant sensitive information types.

Verify in: See control documentation.

Full control documentation · Portal walkthrough

Control 1.3 — SharePoint Content Governance and Permissions

Security · Zone 1, Zone 2, Zone 3

Pass criteria: External sharing restricted; Everyone groups removed from agent knowledge sites; container sensitivity labels applied; SAM RAC/RCD enabled and quarterly access reviews active for Zone 3.

Verify in: See control documentation.

Full control documentation · Portal walkthrough

Control 2.13 — Documentation and Record Keeping

Management · Zone 1, Zone 2, Zone 3

Verify in: See control documentation.

Full control documentation · Portal walkthrough

Control 2.16 — RAG Source Integrity Validation

Management · Zone 2, Zone 3

Verify in: See control documentation.

Full control documentation · Portal walkthrough

Control 4.1 — SharePoint Information Access Governance (IAG) / Restricted Content Discovery

SharePoint · Zone 1, Zone 2, Zone 3

Verify in: See control documentation.

Full control documentation · Portal walkthrough

Control 4.2 — Site Access Reviews and Certification

SharePoint · Zone 1, Zone 2, Zone 3

Verify in: See control documentation.

Full control documentation · Portal walkthrough

Control 4.3 — Site and Document Retention Management

SharePoint · Zone 1, Zone 2, Zone 3

Verify in: See control documentation.

Full control documentation · Portal walkthrough

Control 4.4 — Guest and External User Access Controls

SharePoint · Zone 1, Zone 2, Zone 3

Verify in: See control documentation.

Full control documentation · Portal walkthrough

Control 4.5 — SharePoint Security and Compliance Monitoring

SharePoint · Zone 2, Zone 3

Verify in: See control documentation.

Full control documentation · Portal walkthrough

Control 4.6 — Grounding Scope Governance

SharePoint · Zone 1, Zone 2, Zone 3

Verify in: See control documentation.

Full control documentation · Portal walkthrough

Control 4.7 — Microsoft 365 Copilot Data Governance

SharePoint · Zone 1, Zone 2, Zone 3

Verify in: See control documentation.

Full control documentation · Portal walkthrough

Control 4.8 — Item-Level Permission Scanning for Agent Knowledge Sources

SharePoint · Zone 1, Zone 2, Zone 3

Verify in: See control documentation.

Full control documentation · Portal walkthrough


Generated from assessment/manifest/controls.json by scripts/generate_homework_pages.py. Edit the manifest, then re-run.