A SharePoint governance plan survives an audit when every policy statement maps to a native control, a configuration artifact and a log entry. EPC Group publishes the full table of contents, the RACI, the nine policy decisions, and the control-to-evidence mapping — before you buy a governance tool.
Last updated: 2026-07-31
EPC Group is a Houston-based Microsoft consulting firm operating since 1997, with six Microsoft Solutions Partner designations and 216+ M&A tenant migrations covering 1.83M users. Governed Microsoft AI, Data & Cloud — since 1997.
Key facts
- SharePoint Advanced Management (SAM) is included with a Microsoft 365 Copilot licence. One assigned Copilot licence gives admins site ownership, inactive site and attestation policies, data access governance reports, restricted access control and restricted content discovery.
- Audit (Standard) retains 180 days. Audit (Premium) retains Microsoft Entra ID, Exchange, OneDrive and SharePoint records for one year, and up to 10 years with the add-on licence.
- Microsoft 365 group expiration is a real deletion. An unrenewed group is deleted one day after expiry, restorable for 30 days — a window that is not configurable. Owners are notified at 30, 15 and 1 day.
- Site lifecycle policies never delete a site. The ceiling is read-only, then archive to Microsoft 365 Archive after 3, 6, 9 or 12 months.
- Restricted access control accepts up to 10 groups per site, and a user needs both content permission and control-group membership.
- Restricted SharePoint Search is retiring — new enablement is blocked from 31 July 2026. Restricted Content Discovery replaces it.
- External sharing is on by default; site settings can only tighten the organisation setting, and OneDrive can never exceed SharePoint.
- Boundaries that constrain governance: 25 TB per site, 2 million sites per organisation, 2,000 hub sites, tenant allocation of 1 TB + 10 GB per licence.
Quick facts
| Question | Answer |
|---|---|
| Minimum viable plan | 9 policy decisions, a RACI, an evidence register, a review cadence |
| Third-party tool first? | No. Establish native SAM and Purview coverage, then buy the residual gap |
| What licence includes SAM | Microsoft 365 Copilot, or the SAM Plan 1 add-on, on an eligible base plan |
| Default audit retention | 180 days (Standard); 1 year for SharePoint/Entra/Exchange/OneDrive (Premium) |
| Site lifecycle enforcement ceiling | Read-only, then archive — never automatic deletion |
| Group expiration minimum lifetime | 30 days; deleted group restorable for 30 days |
| Max external sharing domains in the allow/block list | 5,000 |
| Restricted access control groups per site | 10 |
| Who owns the plan | Business owner accountable; SharePoint admin responsible |
| Review cadence | Monthly operational, quarterly policy, annual full review |
| The artifact auditors ask for first | The RACI, then the evidence register |
The Governance Evidence Chain
Most SharePoint governance plans fail an audit for the same reason: they are written as intentions. "We restrict external sharing." "Sites have two owners." An auditor does not accept an intention — they ask the follow-up questions, and the plan cannot answer them.
The Governance Evidence Chain is EPC Group's model for governance that survives the follow-up. Every policy line carries all six links, in order. A line missing any link is an aspiration, not a control.
| Link | The question it answers | Example |
|---|---|---|
| 1 — Decision | What did we decide, in one sentence, with a number? | "Every site has a minimum of two owners." |
| 2 — Scope | Which sites, users, data classes? | "All sites except OneDrive and archived sites." |
| 3 — Native control | Which Microsoft feature enforces it? | Site ownership policy (SAM) |
| 4 — Configuration artifact | What proves it is configured as decided? | Exported policy definition from Site lifecycle management |
| 5 — Evidence source | What proves it operated over the period? | Policy execution report + change history report |
| 6 — Cadence and owner | Who reviews it, how often, what escalates? | SharePoint admin, monthly; exceptions to the board quarterly |
Two rules make this work. Write the chain before the prose — if you cannot fill links 3 to 5 you have found either a control gap or a genuine case for buying a tool. And build the evidence register as a table, because that is what an auditor asks for; converting narrative later costs a week.
The governance plan: complete table of contents
Adopt this as-is. It is ordered so the sections an auditor opens first come first, and so each produces an artifact rather than a paragraph.
Part 1 — Mandate
1.1 Purpose, scope and out-of-scope systems · 1.2 Regulatory and contractual drivers, named individually · 1.3 Governance board: membership, quorum, decision rights, escalation · 1.4 RACI · 1.5 Definitions and site taxonomy
Part 2 — Policy decisions (each in Governance Evidence Chain format)
2.1 Site creation and provisioning · 2.2 Naming and the site catalogue · 2.3 External sharing · 2.4 Guest access and lifecycle · 2.5 Ownership and orphan prevention · 2.6 Site lifecycle: inactivity, attestation, archive · 2.7 Sensitivity labels on containers · 2.8 Retention and records · 2.9 Storage allocation and quota
Part 3 — Access and permissions
3.1 Permission model and standard groups · 3.2 Prohibited patterns (Everyone Except External Users on sensitive sites, item-level uniques at scale) · 3.3 Access review process and frequency · 3.4 Restricted access control and restricted content discovery: criteria for applying and removing · 3.5 Privileged admin access and the roles model
Part 4 — Content standards
4.1 Information architecture: hubs, sites, libraries, metadata · 4.2 Version history policy · 4.3 Managed metadata and term store ownership · 4.4 Prohibited content classes
Part 5 — AI and Copilot readiness
5.1 Oversharing remediation gate criteria before Copilot enablement · 5.2 Agent creation policy and agent inventory · 5.3 Restricted content discovery scope and exit criteria
Part 6 — Operations
6.1 Request, approval and exception process with SLAs · 6.2 Monitoring: which report, which frequency, which threshold · 6.3 Incident and escalation runbook · 6.4 Training and site owner enablement
Part 7 — Evidence and assurance
7.1 Control-to-evidence register · 7.2 Audit log configuration and retention decision · 7.3 Review cadence and change log · 7.4 Attestation records
Appendices — policy configuration exports, PowerShell baseline scripts, site catalogue, exception register.
Part 7 separates a plan that survives an audit from one that does not. Most published templates stop at Part 6.
The governance RACI
One accountable owner per row. Not two. Governance decays fastest where "IT" and "the business" are both accountable for the same decision.
| Decision area | SharePoint Admin | M365 / Entra Admin | Security | Compliance | Site Owner | Business Owner |
|---|---|---|---|---|---|---|
| Site creation policy | R | C | C | I | I | A |
| Naming policy and catalogue | R | C | I | I | C | A |
| External sharing (org level) | R | C | A | C | I | C |
| External sharing (site level) | C | I | C | I | R | A |
| Guest access and expiry | C | R | A | C | I | I |
| Site ownership policy | R | C | I | I | A own site | C |
| Inactivity and attestation | R | I | I | C | A own site | C |
| Sensitivity labels on containers | C | C | C | R | I | A |
| Retention policies and labels | I | I | C | R | I | A |
| Storage allocation and quota | R | C | I | I | I | A |
| Restricted access control | R | C | A | C | C | I |
| Restricted content discovery | R | I | A | C | C | I |
| Audit log configuration and retention | C | C | C | R/A | I | I |
| Admin role assignment | C | R | A | I | I | I |
| Access reviews | C | C | C | A | R | C |
| Copilot readiness gate | R | C | C | C | C | A |
| Exception approval | C | I | C | C | I | A |
| Plan review and change control | R | I | C | C | I | A |
Two notes an auditor will test. Site owners are accountable for their own site's ownership and attestation — which is why lifecycle policies send an actionable "certify site" button to owners, not to a central queue. And security owns organisation-level sharing while the business owner owns it at site level; held by the same person, you have no segregation of duties on the platform's highest-risk control.
The nine policy decisions
This table replaces four pages of narrative: the decision, the native control that enforces it, and the constraint most organisations discover too late.
| # | Decision | Options | Native control | The constraint you will hit |
|---|---|---|---|---|
| 1 | Site creation | Open · request-based · admins only | Settings → Site creation | Turning it off does not stop Microsoft 365 group or Teams creation, and every group creates a site. Restrict group creation too |
| 2 | Naming | Free · prefix/suffix · blocked-word list | Microsoft 365 Groups naming policy | Governs groups only. Non-group communication sites need a separate provisioning process |
| 3 | External sharing | Anyone · new and existing guests · existing guests · organisation only | Sharing page + per-site setting | Sites can only tighten the org setting; OneDrive can never exceed SharePoint. Domain allow/block caps at 5,000 |
| 4 | Guest access | Expiry period · verification-code reauth · guests sharing items they don't own · who may share externally | More external sharing settings + Entra external collaboration | Entra guest-invite and domain lists interact with SharePoint's. Configure both, or the policy is not what you think |
| 5 | Ownership | Minimum owner count · owners vs site admins · notification recipients | Site ownership policy (SAM) | Simulation or active mode. Notifications use Outlook Actionable Messages — verify Outlook version support first |
| 6 | Lifecycle | Inactivity threshold · attestation frequency · enforcement action | Inactive site + attestation policies (SAM) | Enforcement tops out at read-only then archive after 3/6/9/12 months, never deletion. Same-type policies suppress each other's notifications for 30 days |
| 7 | Sensitivity labels | Privacy · external user access · external sharing · unmanaged devices · conditional access · private team discoverability | Purview labels scoped to Groups & sites | The container label does not apply to items inside it, and external-sharing label settings hand owners a previously admin-only control |
| 8 | Retention | Retention policy (container) · retention label (item) · records · disposition review | Purview Data Lifecycle and Records Management | Policies apply at site level; labels per item, travelling within the tenant. Holds count against a 10,000-per-tenant ceiling |
| 9 | Storage | Automatic · manual per-site quota | SharePoint admin center storage limits | 25 TB per site; tenant pool is 1 TB + 10 GB per licence. Sustained over-limit risks read-only mode |
Two cross-cutting decisions belong alongside these. Group expiration — lifetime in days (minimum 30), with activity-based auto-renewal across Outlook, SharePoint, Teams and Viva Engage — requires Entra ID P1 or P2 licences held for members of every affected group, and only one policy per tenant is supported. And admin roles: assign SharePoint Administrator and the newer SharePoint Advanced Management Administrator rather than Global Administrator, and note that neither has automatic access to every site — they can grant themselves access, and that action is auditable. Our Microsoft 365 E3 vs E5 comparison covers which controls you already licence.
Control-to-audit-evidence mapping
This is the table Syskit, ShareGate and SharePointMaven do not publish. Hand it to an auditor and the conversation takes 40 minutes, not three days.
| Policy statement | Enforcing control | Configuration evidence | Operating evidence |
|---|---|---|---|
| Only approved roles create sites | Site creation setting + group creation restriction | Settings → Site creation export; Entra group creation setting | Change history report; audit log site-creation events |
| External sharing limited to approved partners | Org sharing level + domain allow list + per-site settings | Sharing page export; Get-SPOTenant sharing properties | Sharing links report (DAG); audit log sharing events |
| Guests expire after N days | Guest access expiration setting | Sharing settings; Entra external collaboration settings | Guest expiry events; Entra sign-in and audit logs |
| Every site has ≥2 owners | Site ownership policy (SAM) | Policy definition in Site lifecycle management | Policy execution report, per run |
| Sites confirm business need annually | Site attestation policy (SAM) | Policy definition and notification schedule | Attestation responses in the execution report |
| Inactive sites are archived, not abandoned | Inactive site policy + Microsoft 365 Archive | Policy definition with enforcement action and read-only duration | Execution report; archive status per site |
| Sensitive sites are restricted to a named group | Restricted access control (SAM) | Site settings showing restricted access and control groups | Change history report; audit log |
| High-risk sites excluded from Copilot and search | Restricted content discovery (SAM) | RestrictContentOrgWideSearch value; RCD tenant report | Audit events for enabling/disabling RCD, with justification text |
| Confidential sites block downloads | Block download policy (SAM) | Policy definition | Audit log file-access events |
| Container classification is enforced | Sensitivity labels scoped to Groups & sites | Label definitions and publishing policies | Label application and change events |
| Content is retained for the required period | Purview retention policies and labels | Policy and label definitions with locations and durations | Disposition review records; proof of disposition |
| Oversharing is measured and remediated | DAG reports + site access review | Report generation schedule | EEEU, permission state and sharing links reports; review outcomes |
| Admin access is least-privilege | Entra role assignments | Role assignment export | Entra audit logs; recent admin actions panel |
| All of the above is logged and retained | Purview Audit (Standard/Premium) | Audit configuration and retention policies | The unified audit log — Purview portal, Search-UnifiedAuditLog, Audit Search Graph API, or the Office 365 Management Activity API |
The last row is load-bearing. Decide audit retention deliberately: 180 days on Standard, one year for SharePoint, OneDrive, Exchange and Entra on Premium, or up to 10 years with the add-on licence and an explicit policy — which is not retroactive and cannot recover logs generated before it existed. If your regulator requires seven years, decide now, not at the audit. Our SOC 2 compliance guide for Microsoft 365 maps this to a formal control set.
Native versus third-party: what you already own
Both vendor guides ranking on this query sell governance software. Neither can lead with this table, so we will.
| Capability | Native control | Licence | Where a third-party tool genuinely adds value |
|---|---|---|---|
| Ownerless site detection | Site ownership policy | SAM | Cross-workload ownership in one view |
| Inactive site detection and archive | Inactive site policy + Microsoft 365 Archive | SAM | Disposition workflows with approval chains |
| Periodic business-need confirmation | Site attestation policy | SAM | Attestation across non-Microsoft repositories |
| Oversharing discovery | DAG reports, EEEU insights, permission state and sharing links reports | SAM | Trending beyond native report windows |
| Site-level access lockdown | Restricted access control | SAM | Nothing native is missing |
| Excluding sites from Copilot and search | Restricted content discovery | SAM | Nothing native is missing |
| Delegated remediation to site owners | Site access review | SAM | Ticketing integration, SLA tracking |
| Change tracking | Change history report; recent admin actions | SAM | Longer retention, cross-tenant comparison |
| App and agent visibility | Enterprise app insights; agent insights | SAM | Third-party app risk scoring |
| Classification and container protection | Sensitivity labels for Groups & sites | Purview | Non-Microsoft repositories |
| Retention, records, disposition | Purview Data Lifecycle and Records Management | Purview | Physical records, non-Microsoft systems |
| Group lifecycle | Microsoft 365 group expiration policy | Entra ID P1/P2 | Approval workflow on renewal |
| Provisioning with metadata and approval | Site creation controls; site designs and scripts | Included | Approval routing, chargeback, CMDB |
| Audit evidence | Purview Audit (Standard/Premium) | Included / E5 / add-on | Long-term SIEM archive and correlation |
The honest summary: for a Microsoft-only estate with a Copilot licence, native controls cover the great majority of a governance plan. Third-party value is in workflow, cross-platform scope, longer-horizon reporting and delegated operations at very large scale — not in the controls themselves. Establish native coverage, run the plan for a quarter, then buy against a residual gap you can name. That sequence also gives you a business case instead of a vendor's. Our view on enterprise Microsoft consulting firms and the CFO conversation on AI governance work the buying side.
Governance review cadence
A plan without a cadence is a document. Publish this table inside the plan.
| Frequency | What is reviewed | Owner | Output |
|---|---|---|---|
| Weekly | Exception queue; new external sharing on sensitive sites; failed policy executions | SharePoint admin | Exception log entry |
| Monthly | Lifecycle policy execution reports; ownerless sites; storage against tenant pool; DAG reports | SharePoint admin | Operational report to the governance board |
| Quarterly | Policy decisions 1–9 re-affirmed; access reviews for sensitive sites; admin role assignments; label and retention coverage; roadmap items affecting the plan | Governance board | Signed change log, updated plan version |
| Semi-annual | Guest population and expiry outcomes; restricted-discovery scope and what to release; agent and app inventory | Security + SharePoint admin | Remediation backlog |
| Annual | Full plan review; regulatory driver re-validation; audit evidence dry run; RACI re-confirmed | Business owner | Re-issued plan, dated |
Two disciplines matter more than frequency. Re-confirm the RACI with named individuals, not role titles — the commonest failure is an accountable owner who left 14 months ago. And run an evidence dry run annually: pull every artifact in the register as if the auditor asked today, and time it. Whatever takes longest is your real gap.
What breaks — failure modes
| Symptom | Root cause | Fix |
|---|---|---|
| Sprawl continues after site creation is locked down | Turning off SharePoint site creation does not stop group or Teams creation, and every group creates a site | Restrict who can create Microsoft 365 groups too; scope creation rights with a security group |
| A live Team disappears | An unrenewed group expired and was deleted one day later | Restore within 30 days — the window is not configurable. Rely on activity-based auto-renewal and set the alternate notification email for ownerless groups |
| Owners never respond to lifecycle notifications | Outlook Actionable Messages do not render in unsupported clients, or a same-type policy suppressed the email for 30 days | Verify Outlook version requirements; avoid overlapping scopes; customise sender and copy (needs a custom domain) |
| Sites are "certified" but still abandoned | Clicking the site URL in the notification is not activity, and read actions within an hour of that visit are excluded | Pair the inactive site policy with an attestation policy so the owner must confirm business need |
| External sharing is tighter in policy than in practice | Entra external collaboration settings and domain lists can permit invitations SharePoint appears to block | Configure Entra and SharePoint together, and evidence both |
| Site owners change sharing settings you thought were locked | A published sensitivity label with external sharing settings extends that control to site owners | Do not configure external sharing or authentication context on container labels unless you intend owners to have them |
| A restricted site is still reachable | Restricted access control needs both content permission and control-group membership; changing one alone does nothing | Audit both. Configure shared and private channel sites separately — they are separate site collections |
| Content still appears in Copilot after restricting discovery | Restricted content discovery must propagate across indexing systems; large sites take longer | Allow propagation time; verify the RestrictContentOrgWideSearch value and the tenant RCD report |
| Copilot answers thin out after a governance push | Restricted content discovery applied too broadly reduces content available to search and Copilot | Use RCD as a temporary control with documented per-site exit criteria, reviewed semi-annually |
| The tenant goes read-only | Sustained operation above the 1 TB + 10 GB per licence allocation | Archive inactive sites, empty recycle bins on schedule, buy storage, monitor monthly |
| Auditor asks for evidence older than your logs | Audit (Standard) retains 180 days; longer tiers need the right licence and, at 10 years, a non-retroactive policy | Decide the audit retention tier while authoring the plan, not during the audit |
| Permission changes fail on large libraries | Inheritance cannot be broken or reinherited above 100,000 items; unique permissions recommended below 5,000 | Restructure into multiple libraries; rebuild access with groups, not item-level permissions |
What changed in 2026
- Restricted SharePoint Search is retiring. From 31 July 2026 new enablement is blocked. Restricted Content Discovery replaces it as a temporary, per-site control with an exit path — not a permanent posture.
- Site lifecycle management consolidated into three policy types — ownership, inactivity and attestation — each with simulation and active modes, each escalating to read-only and then archive through Microsoft 365 Archive.
- SAM became a Copilot entitlement, not just an add-on. One assigned Microsoft 365 Copilot licence gives administrators the SAM governance surface across commercial, GCC, GCC-High and DoD. Restricted site creation by apps remains Plan 1 add-on only.
- A dedicated SharePoint Advanced Management Administrator role lets you delegate SAM operations without the full SharePoint Administrator role — a direct answer to the most common least-privilege finding on this platform.
- Agent governance became a first-class governance object. Agent insights and agent access reports identify where agents were created and what they can reach, and content governance policies can be applied directly from those reports. A plan with no agent section is a 2024 plan. Our Copilot pricing and licensing guide and Copilot vs ChatGPT for enterprise cover the choices upstream of it.
Where to go next
If your plan cannot produce a control-to-evidence register on demand, it will not survive an audit — and it is probably failing to stop sprawl too. EPC Group builds the plan, RACI and evidence register against your existing licences first, and names the residual gap before anyone quotes you for a tool. Start with SharePoint consulting or data governance consulting.
Related: EPC Group · SharePoint migration services · My Sites in SharePoint · SharePoint vs Google Drive · Box vs SharePoint · Microsoft 365 E3 vs E5 · Teams Premium features · Microsoft Frontier Company
Frequently asked questions
What should a SharePoint governance plan contain?
Seven parts: mandate and RACI, nine policy decisions, access and permissions, content standards, AI and Copilot readiness, operations, and evidence and assurance. The last part — a control-to-evidence register, an audit retention decision and a review cadence — makes the plan auditable rather than aspirational.
Do I need a third-party governance tool for SharePoint?
Usually not first. SharePoint Advanced Management covers ownership, inactivity, attestation, oversharing reporting, restricted access control and restricted content discovery, and ships with a Microsoft 365 Copilot licence. Purview covers classification, retention, records and audit. Establish native coverage, run it a quarter, then buy against a gap you can name.
Who should own SharePoint governance?
A business owner is accountable for the plan; the SharePoint administrator operates it. Security is accountable for organisation-level external sharing and admin role assignment; compliance for retention, labels and audit configuration. Site owners are accountable for their own site's ownership and attestation.
How do inactive site policies actually work?
The policy evaluates activity across SharePoint and connected workloads including Teams, Exchange and Viva Engage. When a site crosses the threshold, owners receive monthly notifications for three months. If nobody certifies it, the enforcement action applies: nothing, read-only, or read-only for 3, 6, 9 or 12 months then archiving through Microsoft 365 Archive. Policies never delete a site directly.
Will a Microsoft 365 group expiration policy delete active Teams?
It should not. Groups with recent activity in Outlook, SharePoint, Teams or Viva Engage renew automatically about 35 days before expiry, and owners of unrenewed groups are notified at 30, 15 and 1 day. A group that still expires is deleted one day later and restorable for 30 days — a window that is not configurable.
What is the difference between restricted access control and restricted content discovery?
Restricted access control limits who can open a site at all — a user needs both content permission and membership of one of up to 10 specified groups. Restricted content discovery changes no permissions; it stops content surfacing in organisation-wide search and Copilot responses and removes AI entry points, as a temporary measure during a permissions review.
How long are SharePoint audit logs kept?
Audit (Standard) retains 180 days. Audit (Premium) retains Microsoft Entra ID, Exchange, OneDrive and SharePoint records for one year, with other workloads at 180 days unless you create a retention policy. Ten-year retention needs a per-user add-on licence and an explicit, non-retroactive policy.
How often should the governance plan be reviewed?
Weekly for the exception queue, monthly for policy execution reports and storage, quarterly for the nine policy decisions and admin roles, semi-annually for guest population and restricted-discovery scope, annually for a full re-issue with a named-individual RACI and an evidence dry run.
What is the single most common SharePoint governance failure?
Locking down site creation while leaving Microsoft 365 group and Teams creation open. Every group creates a site, so sprawl continues unchanged while the governance board believes the control is in place. Restrict both, evidence both.
Sources and verification
- Microsoft Learn — SharePoint governance overview
- Microsoft Learn — What is SharePoint Advanced Management?
- Microsoft Learn — SharePoint Advanced Management features in Microsoft 365 Copilot licenses
- Microsoft Learn — Prerequisites for SharePoint Advanced Management
- Microsoft Learn — SharePoint site lifecycle management
- Microsoft Learn — Create a SharePoint site ownership policy
- Microsoft Learn — Manage inactive sites by using inactive site policies
- Microsoft Learn — Request recurring site attestations for SharePoint sites
- Microsoft Learn — Restrict SharePoint site access with Microsoft 365 groups and Microsoft Entra security groups
- Microsoft Learn — Restrict discovery of SharePoint sites and content
- Microsoft Learn — Curate the allow list for Restricted SharePoint Search (retirement notice)
- Microsoft Learn — Data access governance reports for SharePoint sites
- Microsoft Learn — Manage sharing settings for SharePoint and OneDrive
- Microsoft Learn — Overview of external sharing in SharePoint and OneDrive
- Microsoft Learn — Change the sharing settings for a site
- Microsoft Learn — Plan sharing and collaboration options in SharePoint and OneDrive
- Microsoft Learn — Manage site creation in SharePoint
- Microsoft Learn — About the SharePoint Administrator role in Microsoft 365
- Microsoft Learn — About administrator roles in the Microsoft 365 admin center
- Microsoft Learn — Configure the expiration policy for Microsoft 365 groups
- Microsoft Learn — Use sensitivity labels to protect collaborative workspaces (groups and sites)
- Microsoft Learn — Learn about sensitivity labels
- Microsoft Learn — Learn about retention policies and retention labels
- Microsoft Learn — Learn about data lifecycle management
- Microsoft Learn — Learn about auditing solutions in Microsoft Purview
- Microsoft Learn — Manage audit log retention policies
- Microsoft Learn — Search the audit log
- Microsoft Learn — SharePoint limits (service description)
- Microsoft Learn — Get ready for Microsoft 365 Copilot and agents with SharePoint Advanced Management
- Microsoft Learn — Microsoft 365 Archive overview
- Microsoft Learn — Manage access to agents in SharePoint
- Microsoft Learn — Sharing and permissions in the SharePoint modern experience
