You may have already read our article Sharing sensitive information within a team: whose responsibility is it?. Did you recognize yourself in some of those behaviours? Client files sent by email, confidential data in open Teams channels, people using external tools without anyone knowing. The question now is no longer whether your team is sharing sensitive information in a risky way. It’s how to put guardrails around it, concretely, by working with your IT department.
Protecting sensitive information is one of the challenges many managers face. To better understand how this issue fits into a broader set of Microsoft 365-related practices, we recommend starting with our complete guide to Microsoft 365 adoption for team leaders, which is the starting point for exploring the different issues covered.
The difference between having Microsoft 365 and having rules
Microsoft 365 already provides what you need to govern the sharing of sensitive information. SharePoint lets you share a link with specific permissions instead of sending a file as an attachment. Teams lets you create private channels for discussions that contain confidential information. Microsoft Purview lets you classify a document as confidential and automatically restrict sharing.
But no one has defined the usage rules for your team. When you share a quote with an external partner, do you send the file as an attachment via Outlook or a SharePoint link with permissions? When someone talks about payroll data in Teams, does it go in the general channel or in a private channel? When a member of your team wants to use an AI tool to draft an email, can they copy and paste customer data into it?
Without clear answers to these questions, everyone does what’s easiest. And “easiest” is not enough to protect your sensitive information.
According to a CoreView study, 44% of Microsoft 365 licenses are underused or poorly sized in businesses.. Grav-ITI helps teams govern information sharing and implement data governance tailored to their needs.
Governing your team’s sharing behaviours is your responsibility
Two things are often confused: protecting the IT environment and governing sharing behaviours within a team.
Protecting the Microsoft 365 environment is the IT department’s role. Configuring access, firewalls, updates, permissions. These are part of the basic conditions for you to be able to do your work.
Governing day-to-day information sharing is the team leader’s responsibility. Deciding what types of information can be sent by email. Clarifying which Teams channels are appropriate for which types of data. Defining what can and cannot be copied into an external tool.
But your colleagues in IT can’t monitor or know how each person in each team shares information day to day. You can. You know who sends what, through which channel, and to whom. You’re in the best position to define the sharing rules and make sure they’re followed.
To improve the protection of sensitive information in your team and make it a real lever for the business, the first step is to clearly understand the current situation. That’s why we prepared a Microsoft 365 self-assessment for managers that helps you identify where your team stands today, what the main risks are related to sharing confidential data in Microsoft 365, and what initial improvements can be considered.
Three actions to provide clear direction for sharing sensitive information
A good team leader doesn’t react after an incident. They take the lead. They assume it’s their responsibility instead of waiting for IT to handle it. They lead by example by changing their own sharing behaviours. And they create a space where people can say “I didn’t know it was risky” without being blamed.
In practical terms, that translates into three actions.
1. Observe to see what’s being shared and how.
Take a week to observe how sensitive information circulates within your team. Not to monitor. To understand.
- What types of files are being sent by email instead of via SharePoint?
- Which Teams channels contain information that shouldn’t be visible to everyone?
- Are members of your team using external tools to work with company data?
You can also ask your IT department to show you the usage reports for Microsoft 365. These reports show who uses what and how. It’s free, it’s already included in your license, and it gives you a concrete picture. The fact that you’re the one requesting this information, rather than waiting for it to be sent to you, is already an act of leadership.
“For the protection of sensitive information to be better governed, leadership commitment is essential. Read the article Governing the sharing of sensitive data in Microsoft 365 to get the support you need.”
2. Define the rules with your IT department.
Based on this picture, you’ll be able to define three or four clear rules for sharing sensitive information for your team, in collaboration with your IT colleagues.
- Files that contain customer data, pricing, or margins are shared via a SharePoint link with permissions, not as an email attachment.
- Discussions involving payroll data, financial information, or HR files take place in a private Teams channel, not in the general channel.
- No company data should be copied into an external AI tool or a free file-sharing tool.
- Each new person who joins the team receives these rules on their first day.
The IT department’s role here is to help you put in place what supports these rules in the environment. For example, setting up a private Teams channel for your team, adjusting SharePoint permissions, or enabling Microsoft Purview sensitivity labels so certain documents are automatically protected. But the rules are yours to carry. And you set the example by applying them first.
Microsoft 365 protects sensitive data through three complementary layers applied in order: classify, protect, monitor. Here’s how it works in practice.

3. Repeat so habits stick.
This is the step most people skip, and that’s exactly why nothing changes after a good intention. You don’t change a team’s habits with a Monday-morning email. You change them by revisiting the rules every week, in a team meeting, for two or three minutes. What’s working. What’s getting in the way. What are we adjusting.
This is also where your role as a leader makes the difference. If someone sent a file by email out of habit, you don’t blame them. You remind them of the rule and show them how to do it differently. After two weeks, the new habits start to stick. After a month, people stop wondering.
To better support team members, you first need to structure information in your M365 environment. A Microsoft 365 audit gives you an objective view of your current practices and maps out the roadmap needed so your digital tools become real performance drivers, rather than sources of uncertainty.
What a Microsoft 365 audit reveals about your team’s habits
Before defining your rules, or to validate what you’ve put in place, a Microsoft 365 audit gives you an objective picture of the situation—not based on what colleagues think they do, but on what actually happens in the environment.
A Microsoft 365 audit concretely analyzes which tools are used, how data flows, and where current practices create risks. You get a clear view of blind spots: unnoticed external sharing, Teams channels that are too open, behaviours that bypass sensitivity labels without anyone realizing it.
This is exactly the kind of information that makes it possible to move from a conversation about good habits to a structured discussion with senior management to address the issue.
Is it really my role to define sharing rules, or is that IT’s role?
The two roles are distinct. Your IT department configures the environment—access, permissions, sensitivity labels. You govern your team’s day-to-day behaviours. No one in IT knows that your team sends quotes as attachments instead of SharePoint links. You do. That’s why defining and enforcing sharing rules is your responsibility, in collaboration with your IT colleagues.
Where should I start if my team has never had clear rules?
Start by observing before correcting. Take a week to look at how sensitive information circulates within your team—what channels, what tools, what types of files. You can also ask your IT department for Microsoft 365 usage reports, which are included in your license at no extra cost. This picture gives you a concrete basis to define three or four priority rules, rather than starting from a theoretical list that no one will follow.
How do I convince my colleagues to change their habits if it makes their lives harder?
Resistance almost always comes from not understanding why the change is necessary. If you explain the real risk—a customer file sent by email can’t be revoked, an open Teams channel gives access to colleagues who don’t need to see the information—people adjust. The other lever is you. If you apply the rules first in your own communications, your team follows. Behaviour change doesn’t start with a Monday-morning email; it starts with example.
Microsoft 365 is already in place in our organization. Aren’t we already protected?
Having the tools is not the same as having active protection. Microsoft 365 provides the capabilities—SharePoint, Purview labels, private Teams channels—but those capabilities are only effective if they’re configured and used properly. 70% of organizations underuse their Microsoft 365 environment due to a lack of support. The tools are there; what’s missing is governance of their use at the team level.
Is a Microsoft 365 audit only for large enterprises?
No. A Microsoft 365 audit is particularly useful for SMEs, precisely because internal resources to analyze sharing practices are often limited. It provides an objective picture of the situation without tying up your IT department for weeks. For a manager who wants to escalate the issue to senior management, it’s also what turns a concern into a documented case with data, clear impact, and a prioritized action plan.
And now, what results can you expect?
When everyone on your team knows what can be shared, with whom, and through which channel, it shows immediately. A department director no longer has to wonder whether their financial data is floating around in an open Teams channel. A customer file sent to a partner goes through SharePoint with the right permissions instead of travelling by email with no protection at all.
New people joining the team learn the right habits from the start instead of repeating the wrong ones. IT can focus on what it does best instead of reacting to incidents that could have been avoided. And you, as a team leader, move from “I hope no one messes up” to “my team knows how to do it.”
Next step: Assess your team’s situation with an effective self-assessment tool
Our team wanted to offer you a simple diagnostic tool to help you identify the issues that have the biggest impact on your day-to-day and your team’s, including the sharing of sensitive information.
70% of businesses underuse their Microsoft 365 tools due to a lack of support
Grav-ITI helps teams govern information sharing and implement data governance tailored to their needs. Our team, certified Microsoft Solutions Partner, works in collaboration with your IT department. The approach begins with a discovery meeting to understand your situation, followed by a process-oriented analysis and a concrete, prioritized action plan tailored to your pace.
You can discover our services or learn more about our team.
Protecting sensitive information is one of the challenges many managers face. To better understand how this issue fits into a broader set of Microsoft 365-related practices, we recommend starting with our complete guide to adopting Microsoft 365 tools for team leaders, which is the starting point for exploring the different issues covered.