Skip to main content
Dig IT Solutions logo

Microsoft 365 & Cloud

Cloud governance for SMEs: why setup is not the end and what to review every quarter

Cloud systems drift without ongoing governance. The eight areas a business of up to 250 people must keep reviewing, plus a quarterly checklist and who owns each.

By Dig IT SolutionsUpdated 8 September 20269 min read

Short answer

Cloud governance is the set of rules, owners and regular reviews that keep a cloud environment secure, tidy and affordable after migration. For an SME it covers identity and access, naming and structure, licensing, data retention, security posture, cost, documentation and change control, reviewed quarterly by a named owner rather than left to drift.

A cloud migration has a clear finish line. The last mailbox moves, the old file server is switched off and the project is signed off. What follows has no finish line at all. Accounts, permissions, files, licences and settings keep changing as the business changes, and without someone steering, a tenant that was clean on day one is cluttered, leaky and more expensive by year two. This guide sets out what governance means for a business of up to 250 people, what to review and how often.

Why setup is only the start

The first phase of any move to Microsoft 365, Google Workspace or a hosted server is about migration and access: creating users, moving data, connecting devices, applying basic security and testing that everything works. At that point the environment matches its design, because nobody has touched it yet.

Then the business carries on. Staff join and leave. A department buys a new application. Someone shares a folder with a supplier and forgets. A temporary admin account created for a project stays live. Each change is small and reasonable. Together, over a year, they move the environment a long way from where it started. The NCSC cloud security guidance is built around the same point: the provider secures the platform, and the customer remains responsible for how it is configured and used.

Cloud platforms do not manage themselves. What they do is make change easy, which is exactly why oversight has to be continuous.

What happens when cloud sprawls without a plan

Sprawl is what an unmanaged cloud environment looks like after 18 months. It shows up in predictable ways:

  • Loss of visibility. Marketing uses one tool, finance another, operations a third. Nobody can list every system that holds company data, so nobody can say who has access to it.
  • Rising cost. Licences for leavers, a duplicate survey tool, a virtual machine left running after a test. Each is a small line on a bill that nobody reads closely.
  • Security gaps. Different platforms with different login rules, MFA on some and not others, external sharing links that never expire. Shadow IT, where teams adopt tools without approval, adds systems that were never secured at all.
  • Fragmented data. Customer details in the CRM, the mailing platform and a spreadsheet, each slightly different. Reports disagree and people stop trusting them.
  • Reactive support. IT time goes on access requests and "which version is right" questions instead of improvement.
  • Technical debt. Every quick fix adds a dependency. Eventually a simple change, such as moving a shared mailbox, breaks three things nobody knew were connected.

Growth makes all of this worse, because what a team of eight could hold in their heads, a team of forty cannot.

Why staff feel less organised after moving

A common complaint six months after a migration is that the business feels less organised than it did with a server in the cupboard. That is rarely the technology. It is what the move removed and what was not put in its place.

A file server imposed structure by accident. There was one place for files, a folder tree everyone learned, and access limited by being in the office. The cloud takes that away: files can live in OneDrive, Teams channels, SharePoint sites, email attachments and chat, all editable by several people at once. Without a deliberate digital structure to replace the physical one, people choose whatever is easiest in the moment and the estate fragments.

Two other causes are common. Migrations that lift and shift an already messy folder structure simply move the mess somewhere with more users. And ownership blurs: when everyone can edit a document, nobody is responsible for keeping it current. The fix is not a new tool but a few written rules about where things live and who owns them, which is what the rest of this guide describes. Our SharePoint and Teams service exists largely to put that structure back.

The eight areas of ongoing governance

1. Identity and access

Accounts and permissions drift faster than anything else. Governance here means a joiners, movers and leavers process that is actually followed, multi-factor authentication enforced for every account with no exceptions, admin roles held by a small named group using separate accounts, and a quarterly review of who has access to what. Guest and external sharing need the same attention: every external user should have a current reason to be there. A documented onboarding and offboarding process does most of the heavy lifting.

2. Naming and structure

Decide, in writing, how Teams, SharePoint sites, channels and folders are named and who can create them. A short standard (department, purpose, year, for example) prevents four different "Projects" sites appearing in a year. Limit the number of places a type of document can live: contracts in one library, HR files in another with restricted access, working documents in the relevant Team. Search is a backup for structure, not a replacement for it.

3. Licensing

Every licence should have a named person and a reason. Review assigned licences against active sign-ins, remove leavers, convert mailboxes that only need to be kept into shared mailboxes, and check tiers. Field staff on a full desktop plan and finance staff without the security features of Premium are both common. Microsoft's published UK list prices are on its plan comparison page, and the gap between tiers is large enough that mismatches add up over a year.

4. Data lifecycle and retention

Decide how long different kinds of data are kept and what happens at the end. UK GDPR expects organisations to keep personal data no longer than necessary, and the ICO guidance for organisations sets out what that means in practice. In Microsoft 365 that translates into retention policies, an archive procedure for finished projects and a rule for what happens to a leaver's files and mailbox.

Backup belongs here too. Microsoft 365 does not include backup in the sense most people mean. Deleted items and mailboxes are recoverable only inside retention and recycle-bin windows, so a third-party Microsoft 365 backup is recommended and should be tested, not just running. Our article on whether Microsoft 365 includes backup covers what Microsoft's own retention does and does not protect.

5. Security posture

Security settings that were right at migration age quickly. Governance means checking, on a schedule, that MFA is still enforced, Conditional Access rules still reflect where staff work, external sharing defaults have not been loosened, devices are still compliant and encrypted, and the alerts Microsoft generates are being read by someone. The GOV.UK Cyber Security Breaches Survey consistently finds phishing to be the most common attack on UK businesses, and most successful phishing ends in an account without MFA or with permissions broader than it needed.

6. Cost review

Read the bill. Monthly for anything usage-based (hosted servers, storage, Azure resources), quarterly for per-user subscriptions. Look for licences with no sign-ins, resources with no owner, storage growing faster than headcount, and third-party subscriptions that duplicate something already included. Cloud is cost-effective when someone is watching and expensive when nobody is.

7. Documentation

Write down how the environment is built: tenant settings, admin accounts and where their credentials are held, the naming standard, the licence policy, the retention rules, the backup schedule, network diagrams and the list of third-party systems. If the person who set it up left tomorrow, could someone else pick it up? If the answer is no, the business depends on an individual rather than a system.

8. Change control

Not a bureaucracy, just a habit. Changes to security settings, sharing policies, admin roles and integrations get proposed, approved by the owner, made, and recorded. It takes minutes, and it is the difference between knowing why a setting is the way it is and guessing.

A quarterly governance checklist

AreaCheck every quarterOwner
Identity and accessLeavers removed, MFA coverage complete, admin roles reviewed, guest accounts justifiedIT lead or provider
Naming and structureNew Teams and sites follow the standard, orphaned or duplicate sites archivedOffice or operations manager with IT
LicensingLicences reconciled against active users and the HR list, tiers match rolesFinance with IT
Data lifecycleRetention policies applied, finished projects archived, leaver data handledIT lead with data owners
Security postureConditional Access, sharing settings, device compliance and alert handling reviewedIT lead or provider
Cost reviewBills read, unused resources removed, duplicate subscriptions cancelledFinance with IT
DocumentationRunbook and admin list updated for the quarter's changesIT lead or provider
Change controlChange log reviewed, unapproved changes investigatedIT lead
BackupRestore test completed and recordedIT lead or provider

Monthly, someone should also check backup job results, read security alerts and process joiners and leavers. Annually, review the whole framework against how the business has changed.

Who does what in a business of up to 250 people

Governance fails most often because everyone assumes someone else owns it. In a small business the roles look like this:

  • Executive sponsor (MD, FD or operations director): approves the policies, funds the reviews and is accountable for the risk. This is not a technical role.
  • IT owner: the internal IT lead, or the managed provider where there is no internal IT. Runs the quarterly checks, keeps the documentation and makes the changes.
  • Data owners: a named person per department who decides what their team's data is, who should see it and how long it is kept. In a 20-person firm that may be two people. In an 80-person firm it might be six.
  • Finance: reconciles licences and subscriptions against the bill and the payroll.
  • Every manager: follows the joiners and leavers process and the naming standard, and tells IT before buying a new tool.

For businesses without an internal IT lead, a vCIO or IT strategy arrangement provides the review cadence and the board-level conversation without hiring a full-time role. The point is a named person and a date in the diary, not a job title.

Governance in a hybrid estate

Governance is not only for businesses that have gone fully cloud. Mr Plant Hire, a multi-depot plant and tool hire business established in 1981, runs Microsoft 365 with SharePoint for inter-company document sharing alongside Windows servers that still have a job to do, with local and cloud backup across both. Supporting that environment for over 15 years has meant applying the same disciplines of access reviews, structure, licence checks and tested backups across cloud and on-premise as one estate. The Mr Plant Hire case study shows how that works in practice.

What to do next

If nobody in the business can say when access, licences and sharing settings were last reviewed, that is the answer. An IT health check looks at identity, security configuration, licensing, backup and how SharePoint and Teams are structured, and gives you a prioritised list to start the first quarterly review from.

Frequently asked questions

What is cloud governance?
Cloud governance is the set of policies, named owners and scheduled reviews that control how a cloud environment is used after it has been set up. For a small business it covers who has access to what, how files and Teams are named and structured, which licences are assigned and why, how long data is kept, how security settings are maintained, how spend is reviewed, what is documented and how changes are approved.
How often should a small business review its cloud environment?
Monthly for the operational items: backup job results, security alerts, joiners and leavers, and any usage-based bills. Quarterly for the structured review: access and admin roles, licences against active users, sharing settings, device compliance, naming standards, documentation and a restore test. Annually, step back and check whether the whole framework still matches how the business has changed.
Who should own cloud governance in a business of up to 250 people?
A director should sponsor it and be accountable for the risk, but the day-to-day owner is the internal IT lead or, where there is none, the managed IT provider. Each department needs a named data owner who decides who should see their team's information and how long it is kept, and finance should reconcile licences and subscriptions. The essential ingredient is a named person and a date in the diary.
Why does our business feel less organised since moving to the cloud?
Because the old file server imposed structure by accident: one place for files, one folder tree, access limited to the office. The cloud removes those boundaries, so files can live in OneDrive, Teams, SharePoint, email and chat, edited by anyone. Without written rules about where things live and who owns them, people choose whatever is easiest and the estate fragments. The fix is structure and ownership, not another tool.
Does Microsoft 365 include backup?
Not in the sense most businesses mean. Microsoft keeps deleted items and mailboxes only within retention and recycle-bin windows, and its own terms recommend that customers arrange backup for their data. A malicious deletion, ransomware or a leaver's account being removed can outrun those windows. A third-party Microsoft 365 backup, with restores tested on a schedule, belongs in every governance plan.
Is cloud governance the same as managed IT support?
No, but they overlap. Managed IT support is the operational service of running and supporting the environment: helpdesk, patching, monitoring, backup. Governance is the framework of rules, owners and reviews that decides how the environment should be used and checks that it still is. A good managed provider delivers much of the governance work, but the business still has to own the decisions.
What is the biggest cloud governance risk for a small business?
Access that nobody reviews. Leavers whose accounts stay active, admin rights granted for a project and never removed, external sharing links that never expire and accounts without multi-factor authentication are the most common causes of both data loss and successful phishing attacks. A quarterly access review with a working joiners and leavers process removes most of that risk at very little cost.

Next step

Talk to an engineer, not a sales script

Tell us what is not working, or what you are planning, and we will give you a straight view on what it would take to fix.

WhatsApp us