It arrives attached to a customer security questionnaire, a Cyber Essentials renewal or an ISO deadline, and it has a date on it. We find out who can actually reach what across your Microsoft 365, and hand you the evidence to send back.
This is not a failure of your IT. The reporting that answers the question is a paid add-on, and the plan most organisations your size are on cannot buy into it.
Who has access to our data, how is that access reviewed, what is shared outside the organisation, and how would you evidence any of it.
In SharePoint Advanced Management: permission state reports, sharing links reports, and site access reviews. It needs an E1, E3 or E5 base, and then a Copilot licence or the SAM Plan 1 add-on on top.
Business Premium and Business Standard do not qualify. If you are on Business Premium, the reporting you are being asked for is not something you can switch on.
We produce the equivalent from the Graph API and PnP, across the whole estate in one pass, with the exceptions named and counted rather than described.
We build AI and data systems for organisations that cannot put their data in a public cloud. Most of the work is the assurance around them rather than the models themselves: impact assessments, audit trails that hold up when somebody checks them, and the evidence an assessor will actually accept.
We have taken organisations through ISO certification, which means assembling evidence for an auditor rather than only asking for it. That is the difference between evidence that holds and evidence that falls over when somebody actually looks.
The same collection and the same pack, against our own Microsoft 365, before it goes anywhere near a client. If you want to know how we would treat your data, ask what we found in ours.
We do not sell IT support and the pack does not comment on whoever does. If you have a managed service provider, they keep the relationship.
If the answer is that you can already evidence it, that is a fine answer and it costs you one email.