Microsoft Solutions Partner

SharePoint structures that IT defines. End users use them, but cannot change them.

Site provisioning, templates, information architecture and sharing settings centrally defined by IT. End users have no Site Collection Admin rights and cannot change structures after the fact. Self-hosted in your Azure tenant.

SharePoint Governance - site overview

What SharePoint Governance is

What is SharePoint governance?

SharePoint governance is the set of rules and controls IT uses to decide how SharePoint sites are created, structured and shared - so structure, permissions and sharing do not drift over time. Valprovia enforces those rules technically: IT defines structure and sharing centrally, end users have no Site Collection Admin rights, and everything runs self-hosted in your own Azure tenant.

Trusted by

Geberit
Dr. Oetker
Stadtsparkasse München
Lenzing
Horváth

Part of the Valprovia Governance module

SharePoint Governance is not a separate product

You buy the Governance module. Period. SharePoint Governance is one of two application views of it - the other is Microsoft Teams Governance. Same templates, same permissions, same lifecycle rules. One license, two views, no double pricing.

Information architecture that has nothing to do with the original plan after 12 months

IT defines site templates, library structures, metadata schemas and permission models - and watches end users override them. Every site creator becomes Site Collection Administrator, permission inheritance gets broken, permissions are granted directly to individuals instead of security groups, external sharing links stay "forgotten". A 5,000-user tenant without provisioning controls generates 200–500 ungoverned sites in the first year - which nobody can audit later. The moment Microsoft Copilot enters the picture, missing governance turns into data leakage.

How Valprovia SharePoint Governance works

Governance-first SharePoint architecture. Technically enforced, not just documented.

Valprovia is the provisioning and governance layer between IT architects and SharePoint Online. Sites come exclusively from IT-defined templates - hub affiliation, library structure, metadata schema, permission model, sensitivity label and sharing settings are part of the template definition. Permissions are granted via Azure AD security groups, never directly to individual users.

Site Collection Administrator rights are technically revoked from end users - permission inheritance cannot be broken, sharing settings cannot be overridden. Your information architecture in month 24 looks exactly like it did in month 1. Self-hosted in your Azure tenant.

Provisioning

Site requests with classification, approval and IT sign-off. No self-service sprawl.

End users request sites through Valprovia instead of directly in SharePoint. Mandatory fields: business purpose, owner and deputy, data classification, lifecycle period, compliance requirements. IT approves or rejects, Valprovia provisions compliant to the template. Self-service site creation in the SharePoint admin center stays disabled.

SharePoint Site Provisioning Workflow
Information Architecture

Hub topology, site designs and navigation defined centrally by IT - and not overridable

IT architects define hub sites, sub-topologies, site designs, navigation structures and term store hierarchies. Valprovia enforces these structures on every new site automatically and keeps them consistent - end users cannot rebuild the IA afterwards, not even as site owners.

SharePoint Information Architecture
Permissions

Permissions only via Azure AD security groups. Direct grants technically blocked.

Valprovia enforces the best-practice model technically: three AD groups per site (Owner, Member, Visitor), permissions exclusively via group memberships. Direct grants to individual users and broken inheritance are technically impossible. After 12 months you still have an auditable permission model - no permission sprawl.

SharePoint Permission Model via AD Groups
Sharing

External sharing locked per sensitivity label. Anonymous links only where IT permits.

Sharing rules are defined IT-centrally per site, library and sensitivity label. External domains run via allowlist, external guests have automatic expiry dates. Anonymous links are disabled by default and only available where IT has enabled them for a specific classification. Audit trail included.

SharePoint Sharing Control
Lifecycle

Inactive sites into retention hold - and out of the search index

Lifecycle policies per site classification: inactivity detection, owner re-attestation, automatic read-only, exclusion from search and Copilot index, archive in retention hold and deletion after compliance deadline. External access and anonymous links are cleaned up during the lifecycle process.

SharePoint Site Lifecycle and Retention
How we're different

Valprovia vs SharePoint reporting tools

We enforce technically. Others show you what already went wrong.

Capability Valprovia Competitors
Site provisioning with classification and IT approval (no self-service)
Permissions exclusively via Azure AD security groups (direct grants technically blocked)
External sharing locked per sensitivity label (anonymous links only where IT permits)
Hub topology and information architecture not overridable (not even by site owners)
Lifecycle incl. exclusion from search and Copilot index (retention hold and audit trail)
Self-hosted inside your own Azure tenant (no third-party cloud, no CLOUD Act exposure)

IT architects design - Valprovia enforces. Reporting tools tell you what is already broken. Consulting frameworks stay on paper. Valprovia is the technical enforcement layer between IT architecture and SharePoint Online.

What else lives inside the module

The same module covers Microsoft Teams Governance - the second application view on the same templates, permissions and lifecycle rules.

Made in Germany

SharePoint Governance - Made in Germany

Made in Germany

German-language docs and support

German UI, German documentation, support and onboarding in German. No language barriers in operations.

GDPR-compliant

GDPR via tenant isolation

Valprovia runs as a single-tenant instance in your Azure tenant - your data never leaves your environment. No multi-tenant SaaS, no data replication to third parties.

Self-hosted

In your Azure tenant, not in our cloud

Valprovia is deployed inside your Azure tenant. Your data stays in your environment - no shadow copies, no third-party data sharing, no CLOUD Act exposure.

Pricing

Public pricing. Volume tiers. No "Contact Sales" wall.

Volume-based. Public pricing - no "Contact Sales" funnel. Drag the slider to see your reference price.

Live calculation
Your tenant size
users
250 5,000 10,000 15,000 20,000

Standard

2,03 per user/month
at 1,000 users

Core governance for any Microsoft Teams tenant

  • Provisioning from IT templates with approval workflows
  • Automatic lifecycle - read-only or deletion by rules
  • End-user self-service via AD groups

Professional

3,64 per user/month
at 1,000 users

Includes all Standard features

  • External user management with NDA & expiration dates
  • Recurring member access reviews
  • Advanced archiving & provisioning

Enterprise

Most Popular
6,07 per user/month
at 1,000 users

Includes all Standard & Professional features

  • Advanced template management & bulk updates
  • Full channel management (Standard/Private/Shared)
  • AD Group Sync & role-based permissions
Customer stories

What organisations running Valprovia say

With Valprovia as a partner, we were able to find an elegant Microsoft 365 governance solution for our clients so that they can now keep their workspaces in Microsoft 365 in sync.

2 FTE saved per 1,000 users
Mario Pufahl
Mario Pufahl
Chief Sales Officer
DIGITALL

The decision for Valprovia was easy for us because we immediately recognized the added value via drastically reducing administrative activities through Valprovia governance module.

95% less effort for workspace provisioning
Rainer Schulz
Rainer Schulz
Head of IT Services
Horváth
Free resource

The ultimate Microsoft 365 Governance Guide

What can a governance solution actually do for your organization? Our guide walks through the architecture, controls, and lifecycle policies that make Teams & SharePoint enterprise-ready - in 38 pages, no fluff.

  • Governance maturity self-assessment for IT leads
  • Reference architecture for Teams + SharePoint at scale
  • Adaptable lifecycle & external-access policy templates
Download the Guide
38 pages PDF · 4.2 MB
VALPROVIA
Microsoft 365 Governance

The ultimate
Governance Guide

August2026
Microsoft Teams
SharePoint
OneDrive
Valprovia

Frequently asked questions about SharePoint Governance

Answers to SharePoint-specific topics - provisioning, information architecture, permissions, sharing, orphaned sites. Module-wide questions (setup, pricing, migration) on the Governance module page.

  • What is Valprovia SharePoint Governance?

    Valprovia SharePoint Governance is the SharePoint application view of the Valprovia Governance module. It revokes Site Collection Administrator rights from end users, enforces templates for site creation, controls sharing settings, preserves permission inheritance technically and automates the site lifecycle - all self-hosted in your Microsoft 365 tenant.

  • How is Valprovia different from other SharePoint governance vendors?

    Most governance tools are reporting-oriented: they surface problems (oversharing, broken inheritance, orphaned sites, anonymous links) that IT then has to fix manually - a reactive clean-up approach. Valprovia prevents these problems proactively through technical enforcement: Site Collection Admin rights are locked from end users by default, and standards are enforced at provisioning time rather than reported after the fact. Because the rights are technically revoked, the enforcement cannot be bypassed. Result: significantly less IT overhead for governance tasks.

  • How does site provisioning work under Valprovia?

    End users request sites through Valprovia instead of directly in the SharePoint admin center. Every request includes business purpose, owner and deputy, data classification, lifecycle period and compliance requirements. IT approves or rejects, Valprovia provisions compliant to the stored template - including hub affiliation, library structure, permission model and sensitivity label. Self-service site creation in the SharePoint admin center stays disabled.

  • How does Valprovia fit into an existing information architecture?

    IT architects define hub topology, site designs, navigation structures and term store hierarchies in Valprovia. These structures are enforced automatically on every new site and cannot be overridden afterwards - not even by site owners. Existing information architecture can be imported via the Migration Tool (Enterprise tier) and placed under Valprovia governance, without rebuilding sites.

  • How does Valprovia prevent oversharing on SharePoint sites?

    Sharing settings are technically locked: external guests, anonymous links and permission changes can only be enabled through IT-defined templates and allowlists. End users cannot bypass these settings. Sensitivity labels are assigned automatically at site creation and cannot be changed afterwards. Controlled sharing also keeps Microsoft 365 Copilot from surfacing content that was shared too broadly - a prerequisite for rolling Copilot out safely.

  • What happens to orphaned SharePoint sites?

    Valprovia identifies inactive sites automatically by defined rules (owner activity, access, date) and runs them through a lifecycle: owner re-attestation → read-only → archive → deletion. External access and anonymous links are cleaned up during the archive process. Content remains recoverable according to the retention policy.

  • Do I need separate licenses for Teams and SharePoint Governance?

    No. Valprovia Governance is one module that covers both platforms together. One license per user, three tiers (Standard, Professional, Enterprise). Buying Teams Governance automatically includes SharePoint Governance - and vice versa.

  • How does permission inheritance work under Valprovia?

    Valprovia preserves permission inheritance technically: end users cannot "break" it, not even as Site Collection Administrator (a role they no longer hold technically). Granular custom roles (Read-Only, Contributor, External Partner) are defined IT-centrally and enforced automatically - no manual permission audits anymore.

SharePoint without Site Collection Admins - shown in 30 minutes

Bring your site backlog. We show how the provisioning workflow classifies requests, how the permission model runs through Azure AD security groups, and how the IA kicks in on every new site automatically. Including a pricing proposal for your tenant size.