About the Organization
This financial services organization is responsible for safeguarding sensitive financial, investor, and operational data across multiple entities. Leadership needed stronger data governance controls in Microsoft 365 — particularly within SharePoint and Teams — to reduce growing risk and demonstrate audit readiness.
The Challenge
Like many high-growth companies operating in fast-paced environments, the organization found itself adopting a “share first, govern later” approach to collaboration over time.
At the onset of their engagement with Macro, the firm’s IT environment featured:
- Over 200 SharePoint sites
- Millions of files
- Widespread internal and external sharing
- Limited visibility into who had ongoing access
When it came to sharing, convenience was increasingly taking precedence over security, with little monitoring. The result?
- Access creep accumulated
- Former users retained permissions
- Anonymous and broad sharing links persisted
- Regulatory and cyber insurance risk increased
Data governance — essential in a regulated financial services environment — became a time-intensive, one-person job. Quarterly access reviews were taking an IT admin an entire quarter to conduct. By generating scripts and exporting reports to parsing permissions manually and following up with users to validate access, the entire process was becoming unsustainable.
The Solution
Macro implemented a structured data governance framework for financial service firms, leveraging Microsoft 365 tools to automate oversight, reduce manual effort, and strengthen compliance.
1. Eliminate anonymous & uncontrolled sharing
Macro identified and removed anonymous and public SharePoint links, requiring authentication for all external access.
This immediately reduced uncontrolled exposure and limited the blast radius of a potential breach.
2. Automate Microsoft 365 access reviews
Instead of relying on one IT administrator to manually review permissions across hundreds of sites, Macro implemented automated, owner-based access reviews.
Key changes included:
- Shifting accountability where it belongs — with document and site owners
- Automating review prompts on a structured cadence
- Revoking unnecessary permissions automatically
- Logging review outcomes for audit documentation
An approach that once consumed thousands of hours annually now follows a repeatable, defensible process aligned with compliance requirements.
3. Implement Microsoft Purview & Data Loss Prevention (DLP)
Macro deployed Microsoft Purview data governance and compliance tools to enhance visibility and policy enforcement:
- Sensitivity labeling for financial and regulated data
- Automated classification and tagging
- Data Loss Prevention (DLP) policies to prevent inappropriate sharing
- Conditional controls on downloading or forwarding sensitive documents
When protected financial data is identified, policies now automatically restrict external sharing or enforce encryption, so governance is no longer dependent on user behavior alone.
4. Build an audit-ready governance framework
For regulated financial services organizations, governance must be proven. Macro’s implementation now supports:
- Clear audit trails of access decisions
- Automated review documentation
- Centralized reporting for compliance leadership
- Stronger preparation for regulatory and cyber insurance reviews
This was not a one-click deployment. The transformation required stakeholder alignment, communication, and a phased rollout — and it created a sustainable foundation for long-term Microsoft 365 governance.
— Brendan Thompson, Director of AI, Architecture and Engineering
The Results
Streamlined data access reviews and accountability
Quarterly access reviews no longer consume an entire quarter of one employee’s time. Governance is automated, structured, and owner-driven.
Reduced risk across millions of files
By removing anonymous sharing and enforcing least-privilege access, the organization significantly reduced its exposure to internal and external data risk.
Automated, defensible compliance
Access decisions are documented. Permissions are reviewed regularly. Oversight is continuous — not reactive.
A scalable data governance model
As the organization grows — through acquisitions, new hires, or structural changes — governance controls scale with it.
Planning to strengthen Microsoft 365 Governance? If your financial services organization relies on SharePoint and Microsoft 365 but still conducts largely manual data access reviews, we can help.
*We respect privacy requests from our clients.

