Remediation settings: SharePoint & OneDrive Management policies

  • Last update on February 7th, 2024

The table below provides an overview of the Sharepoint Out-of-the-Box policies, what type of remediation action they are set to execute, and which remediation settings you can configure.

Policy Remediation action What you can configure
Inactive SharePoint sites
  1. Send attestation to a specified recipient (optional)
  2. Execute the action "Delete SharePoint site"
  • Change the recipient of the attestation to either the site owners, a custom address, or choose not to send the attestation
  • Insert an additional message
  • Set time-out days (min: 1 day – max: 180 days)
  • Enable/disable the email alert if the workflow fails
  • Schedule the recurrence of the remediation action
SharePoint sites with anonymous sharing
  1. Send attestation to a specified recipient (optional)
  2. Execute the action "Manage SharePoint external sharing" to disable external and anonymous sharing
  • Change the recipient of the attestation to either the site owners, a custom address, or choose not to send the attestation
  • Insert an additional message
  • Set time-out days (min: 1 day – max: 180 days)
  • Enable/disable the email alert if the workflow fails
  • Schedule the recurrence of the remediation action
SharePoint sites with anonymous sharing and a certain sensitivity label
  1. Send attestation to a specified recipient (optional)
  2. Execute the action "Manage SharePoint external sharing" to disable external and anonymous sharing
  • Change the recipient of the attestation to either the site owners, a custom address, or choose not to send the attestation
  • Insert an additional message
  • Set time-out days (min: 1 day – max: 180 days)
  • Enable/disable the email alert if the workflow fails
  • Schedule the recurrence of the remediation action
SharePoint sites with anonymous sharing and no expiration policy
  1. Send attestation to a specified recipient (optional)
  2. Execute the action "Set expiration policy for anonymous links" to set a customizable expiration policy
  • Change the recipient of the attestation to either the site owners, a custom address, or choose not to send the attestation
  • Insert an additional message
  • Set time-out days (min: 1 day – max: 180 days)
  • Define the number of days after which the links expire
  • Enable/disable the email alert if the workflow fails
  • Schedule the recurrence of the remediation action
SharePoint sites with external sharing and no expiration policy
  1. Send attestation to a specified recipient (optional)
  2. Execute the action "Set expiration policy for external links" to set a customizable expiration policy
  • Change the recipient of the attestation to either the site owners, a custom address, or choose not to send the attestation
  • Define the number of days after which the links expire
  • Enable/disable the email alert if the workflow fails
  • Schedule the recurrence of the remediation action
SharePoint sites with files shared externally
  1. Generate a report containing the list of SharePoint sites that have been shared externally in the last 30 days
  2. Send the report to the designated recipients
  • Define when to send the report
  • Choose the report format (Excel, CSV, PDF)
  • Insert an additional message
  • Choose the report recipient(s)
  • Schedule the recurrence of the remediation action
SharePoint external invitations alert
  1. Send a notification to a custom email whenever a new event related to external invitations and access requests is recorded 

     
  • Choose the alert recipient(s)
OneDrive with files shared externally
  1. Generate a report containing the list of OneDrive accounts that have been sharing files externally in the last 30 days
  2. Send the report to the designated recipients
  • Define when to send the report
  • Choose the report format (Excel, CSV, PDF)
  • Insert an additional message
  • Choose the report recipient(s)
  • Schedule the recurrence of the remediation action