Customer:
A global manufacturer with operations in over 40 countries and a workforce of approximately 40,000 users in Microsoft 365. Its products serve diverse industries, including automotive, construction, and packaging.
Problem:
The company had Microsoft 365 E3 license when Infotechtion did an analysis of the current situation in Microsoft 365 with the following findings:
- Information is not classified making it difficult to ensure information confidentiality, integrity, and availability
- Lack of classification of sensitive information makes it difficult to protect it against insider risks, successful phishing, and GenAI solutions like Microsoft 365 Copilot
- Privacy data are often stored forever in personal and shared workspaces leading to non-compliance to GDPR requirements for data minimalization and storage limitation
- Records that are required by law to be retained, that document business decisions, or ensures business continuity are not governed to ensure authenticity, integrity, and reliability making it difficult to trust them
- Records stored in personal workspaces are lost when employees leave the company leading to lack of documentation
- A growing volume of information will lead to higher storage and ediscovery costs, but also more search clutter for employees trying to find information
Goals:
Infotechtion established then a business case for change and for buying Microsoft 365 E5 add-on license for 40,000 users. Once the company procured the required licenses from Microsoft, a project was established with the following goals:
- Improve data security due to security classification of files and emails with information protection and data loss prevention
- Reduce cost of storage since we only keep what we need
- Reduce e-discovery costs due to less time being spent analysing irrelevant information
- Easier for users to discover relevant information due to less search results clutter of redundant, obsolete, and trivial information
- Easier for users to know if they can trust the information they find due to record authenticity, reliability, and integrity
- More efficient digital workplace due to better knowledge sharing and reuse
- Reduce compliance risk by not overstoring privacy data
- More value from Microsoft Copilot and similar GenAI tools due improved security and less redundant, obsolete, and redundant information (garbage in/garbage out)
Solution:
Success required the following deliverables by Infotechtion:
- Establish governance model
- Support CISO with improving security classification model to only three levels: Public, Internal, Confidential
- Identified sensitive data that must be classified and protected according to new security classification model
- Established a big-bucket record retention schedule to ensure the company keep what they need in Microsoft 365
- Established non-record deletion policies for Microsoft 365, e.g., Teams chat in personal workspaces deleted after 6 months, but not channel messages since this is shared workspaces.
- Implemented Microsoft Purview Information Protection and Data Loss Prevention:
- Content sensitivity labels classify and protect Microsoft Teams and SharePoint sites and ensure all stored files automatically get the correct sensitivity label with default labelling for all workspaces
- Default content sensitivity label classify files and emails in Microsoft Office and Outlook/Exchange
- Automatic classification based on Sensitive Information Types (SITs) and Trainable Classifiers (machine learning)
- Data Loss Prevention with real-time policy tips guides users handle sensitive information correctly with the correct sensitivity label
- Implemented Microsoft Purview Data Lifecycle Management / Records Management:
- Records/documentation is classified manually and automatic with Record Labels in Microsoft Teams and SharePoint
- Automatic classification based on Sensitive Information Types (SITs) and Trainable Classifiers (machine learning)
- Non-record deletion policies automatically delete redundant, obsolete, and trivial information
- Established change management with metrics and KPIs to help the users:
- Store information in the correct location
- Ensure the information is labelled correctly
- Share links in emails instead of attachments
Next steps:
Please feel free to contact us if you want us to demonstrate the value of Microsoft Purview to any of your customers but also explain how we use Infotechtion templates to quickly ensure a successful implementation.