Microsoft 365 Governance Glossary
The core terms around Microsoft 365 governance, Teams, SharePoint, access reviews, integration and archiving - explained clearly and concisely. Each term links to the matching Valprovia solution.
What is Microsoft 365 governance?
Microsoft 365 governance is the set of rules, processes and controls that define how Teams, SharePoint sites, groups and access are created, structured, shared and retired in Microsoft 365. The goal is to keep structure, permissions and sharing consistent over time and to prevent sprawl. Valprovia enforces these rules technically - applied at provisioning time rather than reported after the fact. The terms below explain the key concepts behind it.
Terms from A to Z
Grouped by topic. Click a linked term to reach its detailed page.
Governance - core terms
- Microsoft Teams Governance
- The rules and controls that define how Microsoft Teams are created, structured, shared and retired. Valprovia enforces these rules technically instead of just reporting on them.
- Preventive governance
- An approach where rules are technically enforced at provisioning time, so sprawl never occurs in the first place - unlike reactive reporting tools that only surface problems after the fact.
- Sprawl
- The uncontrolled growth of teams, groups and sites without consistent structure, ownership or lifecycle - one of the core challenges that governance prevents.
- Orphaned team
- A Microsoft team with no active accountable owner, e.g. after the original owner has left the company. Leads to unclear accountability and security gaps.
Provisioning & self-service
- Provisioning
- The automated, template-based creation of standardized Microsoft 365 workspaces - SharePoint sites, Teams and document sets - including naming conventions, permissions and metadata.
- Template
- A blueprint that standardizes a workspace's entire configuration: naming conventions, permissions, preconfigured channels, metadata and lifecycle rules.
- PnP provisioning
- PnP provisioning is a template format following the open PnP provisioning schema (XML) that fully configures SharePoint sites during creation - libraries, lists, content types, navigation and branding.
- Self-service
- Self-service is the ability for authorized end users to create workspaces themselves via a wizard - they only see approved templates, and depending on configuration an approval workflow applies.
- Approval workflow
- An approval process placed ahead of workspace creation: a request is reviewed and approved before the workspace is provisioned.
Permissions & external collaboration
- Permission drift
- The gradual divergence of access rights as users accumulate more and more permissions over time without those being reviewed.
- Oversharing
- Excessive or unintentional sharing of content, giving more people access than intended - a common risk in grown SharePoint environments.
- Site collection admin
- The highest permission level within a SharePoint site collection. Valprovia runs governance without granting end users these rights (least privilege).
- Security group
- A group in Active Directory, Azure AD or Entra ID used to control memberships and access in bulk. Managing Teams memberships natively via security groups hits limits that governance closes.
- Guest access
- Guest access refers to users outside your own organization invited to teams or sites. Governance manages this access on a time-limited, rule-based basis.
Lifecycle & archiving
- Lifecycle management
- The orderly handling of workspaces across their entire lifecycle - automatically detecting inactive teams and sites, archiving them by rule and deleting them in an orderly way.
- Valprovia Archive (blob offload)
- A separate module that offloads inactive SharePoint files to the customer's Azure Blob Storage to cut Microsoft 365 storage cost - a different concept from read-only lifecycle archiving.
- Retention label
- A label that defines how long content is retained and when it is deleted - to meet compliance and retention requirements.
Access reviews
- Access review
- A recurring review of whether existing access rights to Teams, SharePoint and Entra ID are still justified - regular recertification forces a cleanup.
- Single point of contact (SPOC)
- A clearly named, accountable contact per workspace. They are the addressee for access review campaigns and ensure unambiguous owner accountability so no team is left without a responsible owner.
- Recertification
- The process where accountable people actively confirm or revoke existing access - the core of an access review campaign.
- Least privilege
- The principle of granting each user only the rights they actually need. Valprovia runs in operation without standing global admin rights.
- Entra ID
- Microsoft's identity and access service (formerly Azure Active Directory), used to manage users, groups and permissions across Microsoft 365.
Integration, Archive & Headless
- Dynamics 365 ↔ Microsoft 365 integration
- The synchronization of metadata and permissions between Dynamics 365 and Microsoft 365. Valprovia syncs change-driven - triggered by a change in D365, not on fixed intervals.
- Sensitivity label
- A label that defines the protection needs of content (e.g. confidential, internal) and triggers protection such as encryption or access restrictions.
- MCP server
- A Model Context Protocol server that exposes Valprovia's governance capabilities programmatically - governance as an interface, usable by automation and agents.
- Copilot agent
- A governance agent for Microsoft 365 Copilot through which governance tasks can be run directly from Copilot - a product feature, not an AI-consulting topic.
Frequently asked questions about Microsoft 365 governance terms
-
What is the difference between Teams governance and SharePoint governance?
Both describe rules and controls for Microsoft 365 but differ in scope: Teams governance controls how Microsoft Teams are created, structured and retired; SharePoint governance controls site structure, information architecture and sharing of SharePoint sites. In practice they overlap, because every team owns a SharePoint site - the same governance platform covers both.
-
What is the difference between Teams archiving and Valprovia Archive?
Teams/SharePoint archiving sets a workspace to read-only to decommission it in an orderly way - a lifecycle topic. Valprovia Archive is a separate module that offloads inactive files to Azure Blob Storage to cut storage cost. Both contain the word "archive" but are different concepts.
-
What does preventive governance mean?
Preventive governance enforces rules technically at provisioning time, so sprawl never occurs in the first place. Reactive reporting tools, by contrast, only surface problems after they have already happened.
-
Does governance require standing global admin rights?
No. Valprovia runs governance on a least-privilege basis and operates without standing global admin rights - end users are never given site collection admin rights.
Governance that puts these terms into practice
See how Valprovia enforces Microsoft 365 governance technically - in your own tenant. Talk to one of our experts.