Skip to content

SharePoint Vitality Check.

A questionnaire across 18 areas that shows you where your SharePoint Online is under control, and where risk or unrealised value is building up.

The output includes a GAP analysis against target maturity and the foundation for a structured improvement roadmap.

For smaller organisations (up to 100 users) the questionnaire automatically simplifies — a portion of advanced enterprise questions become optional, so you only answer what makes sense for your size.

After submission we'll be in touch within 2 business days with a suggested next step.

Time to complete: 15–20 minutes
Rating scale Each question has five options. Pick the one that most accurately reflects your current state.
L0
Ad hoc
Nothing is defined; everything is handled "when there is time".
L1
Reactive
Basic rules exist, but they are only enforced once a problem appears.
L2
Proactive
Policy is documented, owners are aware of it, some things are automated.
L3
Optimised
Fully automated, measurable, continuously improved.
N/A
Don't know / Not applicable
I cannot judge this question, or it does not apply to our environment.
  1. 1 Identification
  2. 2 Foundation
  3. 3 Structure
  4. 4 Trust
  5. 5 Experience
  6. 6 Copilot
  7. 7 Operations
  8. 8 People
  9. 9 Migration, KPIs
  10. 10 Closing
Step 1 of 10

Identification and customer context

A few basics about your organisation. They help us interpret your answers correctly and benchmark them against target maturity for organisations of your size.

Step 2 of 10

Foundation

Foundation

1. Vision, strategy and governance leadership

Without a vision and a steering team, the governance plan disintegrates into isolated IT settings. This section measures whether a strategic frame exists and who decides about SPO.

1.1 Is there a documented vision / strategy for SharePoint Online?
1.2 Is there a steering committee / governance committee for M365 and SPO?
1.3 Are decision rights clear — who decides, and how do you escalate conflicts?
Foundation

2. Roles and responsibilities

When nobody is accountable, sites end up without an owner, permissions sprawl, and content goes stale.

2.1 Do Site Owners have clearly defined responsibilities?
2.2 Is there a RACI matrix for the key processes (provisioning, sharing, retention, incidents)?
2.3 How many tenant-level admins (Global Admin, SharePoint Admin) do you have, and is least-privilege applied?
Foundation

3. Policies, standards and guidance

A policy is a binding rule; guidance is a recommendation. Without distinguishing the two and publishing them, users get lost.

3.1 Is there a consolidated governance plan, and is it published so that users can find it?
3.2 Do you have naming conventions for sites, M365 Groups, Teams and files?
3.3 Is there a process for exceptions to your policies?
Step 3 of 10

Structure

Structure

4. Information architecture

Without good IA users "cannot find anything", search breaks down and Copilot returns nonsense.

4.1 Do you have a defined global navigation (App Bar) and home site?
4.2 Do you have a hub site strategy (HR, Finance, IT, business units, projects…)?
4.3 Do you use taxonomy and managed metadata (term store, content types)?
Structure

5. Provisioning and site lifecycle

Uncontrolled site creation and forgotten sites are the largest source of content sprawl and security risk.

5.1 How does a new SharePoint site or M365 Group / Team come into existence?
5.2 Have you enabled the M365 Groups Expiration Policy?
5.3 Do you use SAM Site Lifecycle Management policies (inactive site, ownership, attestation)?
5.4 Do you have a defined process for site archival and decommissioning?
Structure

6. Content management

Bad content management = broken search, duplicates, stale information for Copilot.

6.1 Do users have clear rules on where to store what (OneDrive vs. SharePoint vs. Teams chat vs. e-mail)?
6.2 Do you use content types and structured metadata in libraries?
6.3 Have you set a versioning policy in libraries?
Step 4 of 10

Trust

Trust

7. Security, identity and permissions

Permissions tend to sprawl. Broken inheritance + EEEU + direct sharing = an attack surface that Copilot makes visible.

7.1 Are permissions managed exclusively through groups (Microsoft Entra security groups, M365 Groups), or are they assigned directly to users?
7.2 Do you have visibility into sites with broken permission inheritance, EEEU sharing and Anyone links?
7.3 Do you have Conditional Access policies for SharePoint Online?
7.4 Do you run regular Site Access Reviews?
Trust

8. External sharing and B2B collaboration

External sharing is the most visible risk and the most common business need. The goal is not to ban it, but to target it.

8.1 What is the tenant-level external sharing setting in SPO?
8.2 What is the default sharing link type, and is it restricted?
8.3 Do you restrict sharing by domain or security group?
8.4 Do guests (B2B) have automatic expiry?
Trust

9. Information protection, compliance and retention

GDPR, NIS2, sector regulations — they all touch SPO data. Without retention you either delete things you must not, or you keep things forever.

9.1 Do you have a defined data classification (e.g. Public / Internal / Confidential / Restricted)?
9.2 How deeply are sensitivity labels deployed in SPO/OneDrive?
9.3 Do you have retention policies for SharePoint, OneDrive and Teams?
9.4 Do you have active DLP policies for SPO/OneDrive (and Copilot if applicable)?
9.5 Are you ready for eDiscovery and audit (legal hold, search, export)?
Step 5 of 10

Experience

Experience

10. Search and discoverability

Search is the largest entry point into content and the foundation for Copilot. What search cannot find, Copilot cannot use.

10.1 Is Microsoft Search consciously configured (start page, scopes, verticals)?
10.2 Do you maintain promoted results / bookmarks / acronyms / Q&A?
10.3 Do you track search analytics (top queries, no-result queries) and use them to improve?
Experience

11. UX, branding and accessibility

A consistent look builds trust and reduces cognitive load. Accessibility is often a legal requirement.

11.1 Do you have consistent brand standards applied to the intranet and SP sites?
11.2 Do you use site templates / site designs to standardise new sites?
11.3 Do you test accessibility (WCAG 2.1/2.2 AA) of intranet pages and templates?
11.4 Do you support multilingual content (multi-language pages, translation workflow)?
Experience

12. Customisation, development and Power Platform

Customisation unlocks value, but without governance Power Platform turns into shadow IT.

12.1 Is there a customisation policy (what is allowed: configuration / branding / no-code / SPFx / pro-code)?
12.2 Do you have governance for Power Platform (environments, DLP policies, maker role)?
12.3 Do you have visibility into which non-Microsoft applications access SPO content?
Step 6 of 10

Copilot

Value

13. Microsoft 365 Copilot and Agent governance

Copilot exposes everything that was "security through obscurity". Without preparation: blocked rollout or an incident. _This section is only relevant if you have Copilot or are planning to._

13.1 Have you run a Copilot readiness assessment (Content Management Assessment in SAM, or DSPM Data Risk Assessment in Purview)?
13.2 Do you use Restricted Content Discovery (RCD) or Restricted SharePoint Search (RSS) for sensitive sites?
13.3 Do you govern SharePoint agents (who can build them, on which data, monitoring)?
Step 7 of 10

Operations

Operations

14. Monitoring, audit and reporting

What is not measured cannot be managed. Without audit you cannot investigate an incident or prove compliance.

14.1 How regularly do you watch native admin reports (SPO Admin Center, M365 Usage)?
14.2 Do you use SAM Data Access Governance reports (sharing links, permissions, EEEU, sensitivity labels)?
14.3 Do you stream audit logs (Purview Audit) into SIEM (Sentinel) or another security tool?
14.4 Do you have a governance KPI dashboard (e.g. in Power BI, or directly in M365)?
Operations

15. Backup, recovery and business continuity

Microsoft protects the platform, not user-caused losses. The 93-day recycle bin is not enough for most compliance scenarios.

15.1 What backup strategy do you have for SPO/OneDrive/Teams?
15.2 Do you have defined RPO (Recovery Point Objective) and RTO (Recovery Time Objective)?
15.3 Do you run regular DR tests (disaster recovery)?
15.4 Do you have a defined process for what happens to a leaving employee's OneDrive?
Step 8 of 10

People

People

16. Adoption, training and support

Without adoption, even the best governance plan is useless. Adoption is the governance "last mile".

16.1 Do you have an adoption strategy with defined scenarios and success criteria?
16.2 Is there a champions network (a network of business ambassadors)?
16.3 Is there regular training for Site Owners?
16.4 Do you measure adoption metrics and use them to iterate?
Step 9 of 10

Migration, KPIs

Operations

17. Migration and platform evolution

Migration is an opportunity (and a requirement) for a governance reset. The platform evolves; the governance plan has to keep up.

17.1 Do you still have file shares, on-prem SharePoint or other systems to migrate into SPO?
17.2 Is somebody actively watching the Microsoft 365 Roadmap and Message Center?
17.3 Do you have a tenant or selected users in Targeted release for piloting new features?
Value

18. Measurement, KPIs and continuous improvement

KPIs give you the arguments for investment, prove value, and show where the governance plan diverges from reality.

18.1 Do you have a defined set of governance KPIs (health, adoption, compliance, value)?
18.2 Is there a quarterly governance review (committee + KPIs + roadmap)?
18.3 Do you have an active user feedback loop (surveys, focus groups, Site Owner sentiment)?
Step 10 of 10

Closing and priorities

The last step. A short summary of what you filled in, plus your specific pain points and the horizon for our collaboration.

Within what horizon do you want to see the first results? *
Do you consent to us contacting you for a follow-up workshop on the results? *
Do you have documents you would like to share? (governance plan, IA map, sharing report…) Optional. Paste a link to a shared file (SharePoint, OneDrive, Box, Google Drive). No file upload — links only.

Your answers contain sensitive information about your organisation. We store them in a private repository only the EasyPortal 365 team can access. Read more in our privacy policy. Privacy policy →

Get in touch