Course 02 · Available now
Eight modules on the governance controls every SharePoint tenant needs before scaling Copilot. Tenant + site external sharing, sharing link defaults, container labels on sites, site lifecycle policies, Restricted Content Discovery (RCD), Data Access Governance (DAG) reports, permission scope limits, and modern flat information architecture.
CA$99 one-time · lifetime access · verified against Microsoft Learn
Enrolment
Lifetime access · no subscription · no renewals
Bundle all 6 courses · CA$399 (once all six ship)
Why this course exists
SharePoint sites created quietly over five years now have their content surfaced in natural-language queries by anyone with a Copilot licence. Governance stopped being an admin nicety — it's the difference between a productive AI rollout and a data leak that ends a career.
This course teaches the eight parts of SharePoint governance that most tenants misconfigure. Tenant + site external sharing (with the group-connect gotcha most admins miss). Sharing link defaults (the one setting change with the largest oversharing impact). Container labels on sites (and the misconception that trips everyone up). Site lifecycle policies. Restricted Content Discovery — the modern replacement for the retiring Restricted SharePoint Search. Data Access Governance reports for proving oversharing to auditors. Permission scope limits before you break them. And modern flat IA vs classic hierarchical structures.
Every claim in the course cites its Microsoft Learn source. No war stories, no vendor speculation — just the SharePoint governance stack sourced from the documentation.
Curriculum
Each module includes written reference, callouts for the traps, tables for the sharing / labelling / scope limits, and a knowledge-check quiz. Complete all eight plus the final exam to earn CCSGP certification.
The four failure modes every SharePoint tenant has. What Copilot changed. The 5 tenant-level + 3 per-site decisions that shape everything else.
Tenant-level options (Anyone / New+existing guests / Existing guests / Only-in-org). Per-site overrides. Domain allow/block. The group-connect gotcha that silently loosens site sharing.
The three link types. Default-link tenant decision (one setting change with the largest oversharing impact). Anyone-link expiry + view-only constraints. The audit gap on Anyone links.
Container labels do NOT label items inside. What container labels DO control (privacy, external access, unmanaged devices, discoverability, shared channels). Shared-channel inheritance. Bulk apply via Set-SPOSite.
Three policy types: ownership, inactive site, attestation. Simulation vs active mode. Enforcement actions (read-only, archive). The overlap gotcha that suppresses notifications.
The modern replacement for retiring Restricted SharePoint Search. Discoverability control, not access control. Propagation latency that scales with site size (up to a week for 500k+ item sites). Why OneDrive is out of scope.
The five scenarios: sharing links, EEEU audit, labelled files, too-many-users baseline, direct-permission-per-user. Snapshot vs RecentActivity. Start-SPODataAccessGovernanceInsight cmdlet.
5,000 recommended / 50,000 hard scope limits. 100,000-item folder inheritance cap. Share folders not files. Modern flat IA vs classic hierarchical. Hub sites (up to 2,000 per tenant).
Eight modules · CCSGP certification exam · PDF certificate + LinkedIn credential · every claim citing its Microsoft Learn source. No subscription. No renewals.