Microsoft 365 & Cloud
Cloud governance for SMEs: why setup is not the end and what to review every quarter
Cloud systems drift without ongoing governance. The eight areas a business of up to 250 people must keep reviewing, plus a quarterly checklist and who owns each.
By Dig IT SolutionsUpdated 8 September 20269 min read
Short answer
Cloud governance is the set of rules, owners and regular reviews that keep a cloud environment secure, tidy and affordable after migration. For an SME it covers identity and access, naming and structure, licensing, data retention, security posture, cost, documentation and change control, reviewed quarterly by a named owner rather than left to drift.
A cloud migration has a clear finish line. The last mailbox moves, the old file server is switched off and the project is signed off. What follows has no finish line at all. Accounts, permissions, files, licences and settings keep changing as the business changes, and without someone steering, a tenant that was clean on day one is cluttered, leaky and more expensive by year two. This guide sets out what governance means for a business of up to 250 people, what to review and how often.
Why setup is only the start
The first phase of any move to Microsoft 365, Google Workspace or a hosted server is about migration and access: creating users, moving data, connecting devices, applying basic security and testing that everything works. At that point the environment matches its design, because nobody has touched it yet.
Then the business carries on. Staff join and leave. A department buys a new application. Someone shares a folder with a supplier and forgets. A temporary admin account created for a project stays live. Each change is small and reasonable. Together, over a year, they move the environment a long way from where it started. The NCSC cloud security guidance is built around the same point: the provider secures the platform, and the customer remains responsible for how it is configured and used.
Cloud platforms do not manage themselves. What they do is make change easy, which is exactly why oversight has to be continuous.
What happens when cloud sprawls without a plan
Sprawl is what an unmanaged cloud environment looks like after 18 months. It shows up in predictable ways:
- Loss of visibility. Marketing uses one tool, finance another, operations a third. Nobody can list every system that holds company data, so nobody can say who has access to it.
- Rising cost. Licences for leavers, a duplicate survey tool, a virtual machine left running after a test. Each is a small line on a bill that nobody reads closely.
- Security gaps. Different platforms with different login rules, MFA on some and not others, external sharing links that never expire. Shadow IT, where teams adopt tools without approval, adds systems that were never secured at all.
- Fragmented data. Customer details in the CRM, the mailing platform and a spreadsheet, each slightly different. Reports disagree and people stop trusting them.
- Reactive support. IT time goes on access requests and "which version is right" questions instead of improvement.
- Technical debt. Every quick fix adds a dependency. Eventually a simple change, such as moving a shared mailbox, breaks three things nobody knew were connected.
Growth makes all of this worse, because what a team of eight could hold in their heads, a team of forty cannot.
Why staff feel less organised after moving
A common complaint six months after a migration is that the business feels less organised than it did with a server in the cupboard. That is rarely the technology. It is what the move removed and what was not put in its place.
A file server imposed structure by accident. There was one place for files, a folder tree everyone learned, and access limited by being in the office. The cloud takes that away: files can live in OneDrive, Teams channels, SharePoint sites, email attachments and chat, all editable by several people at once. Without a deliberate digital structure to replace the physical one, people choose whatever is easiest in the moment and the estate fragments.
Two other causes are common. Migrations that lift and shift an already messy folder structure simply move the mess somewhere with more users. And ownership blurs: when everyone can edit a document, nobody is responsible for keeping it current. The fix is not a new tool but a few written rules about where things live and who owns them, which is what the rest of this guide describes. Our SharePoint and Teams service exists largely to put that structure back.
The eight areas of ongoing governance
1. Identity and access
Accounts and permissions drift faster than anything else. Governance here means a joiners, movers and leavers process that is actually followed, multi-factor authentication enforced for every account with no exceptions, admin roles held by a small named group using separate accounts, and a quarterly review of who has access to what. Guest and external sharing need the same attention: every external user should have a current reason to be there. A documented onboarding and offboarding process does most of the heavy lifting.
2. Naming and structure
Decide, in writing, how Teams, SharePoint sites, channels and folders are named and who can create them. A short standard (department, purpose, year, for example) prevents four different "Projects" sites appearing in a year. Limit the number of places a type of document can live: contracts in one library, HR files in another with restricted access, working documents in the relevant Team. Search is a backup for structure, not a replacement for it.
3. Licensing
Every licence should have a named person and a reason. Review assigned licences against active sign-ins, remove leavers, convert mailboxes that only need to be kept into shared mailboxes, and check tiers. Field staff on a full desktop plan and finance staff without the security features of Premium are both common. Microsoft's published UK list prices are on its plan comparison page, and the gap between tiers is large enough that mismatches add up over a year.
4. Data lifecycle and retention
Decide how long different kinds of data are kept and what happens at the end. UK GDPR expects organisations to keep personal data no longer than necessary, and the ICO guidance for organisations sets out what that means in practice. In Microsoft 365 that translates into retention policies, an archive procedure for finished projects and a rule for what happens to a leaver's files and mailbox.
Backup belongs here too. Microsoft 365 does not include backup in the sense most people mean. Deleted items and mailboxes are recoverable only inside retention and recycle-bin windows, so a third-party Microsoft 365 backup is recommended and should be tested, not just running. Our article on whether Microsoft 365 includes backup covers what Microsoft's own retention does and does not protect.
5. Security posture
Security settings that were right at migration age quickly. Governance means checking, on a schedule, that MFA is still enforced, Conditional Access rules still reflect where staff work, external sharing defaults have not been loosened, devices are still compliant and encrypted, and the alerts Microsoft generates are being read by someone. The GOV.UK Cyber Security Breaches Survey consistently finds phishing to be the most common attack on UK businesses, and most successful phishing ends in an account without MFA or with permissions broader than it needed.
6. Cost review
Read the bill. Monthly for anything usage-based (hosted servers, storage, Azure resources), quarterly for per-user subscriptions. Look for licences with no sign-ins, resources with no owner, storage growing faster than headcount, and third-party subscriptions that duplicate something already included. Cloud is cost-effective when someone is watching and expensive when nobody is.
7. Documentation
Write down how the environment is built: tenant settings, admin accounts and where their credentials are held, the naming standard, the licence policy, the retention rules, the backup schedule, network diagrams and the list of third-party systems. If the person who set it up left tomorrow, could someone else pick it up? If the answer is no, the business depends on an individual rather than a system.
8. Change control
Not a bureaucracy, just a habit. Changes to security settings, sharing policies, admin roles and integrations get proposed, approved by the owner, made, and recorded. It takes minutes, and it is the difference between knowing why a setting is the way it is and guessing.
A quarterly governance checklist
| Area | Check every quarter | Owner |
|---|---|---|
| Identity and access | Leavers removed, MFA coverage complete, admin roles reviewed, guest accounts justified | IT lead or provider |
| Naming and structure | New Teams and sites follow the standard, orphaned or duplicate sites archived | Office or operations manager with IT |
| Licensing | Licences reconciled against active users and the HR list, tiers match roles | Finance with IT |
| Data lifecycle | Retention policies applied, finished projects archived, leaver data handled | IT lead with data owners |
| Security posture | Conditional Access, sharing settings, device compliance and alert handling reviewed | IT lead or provider |
| Cost review | Bills read, unused resources removed, duplicate subscriptions cancelled | Finance with IT |
| Documentation | Runbook and admin list updated for the quarter's changes | IT lead or provider |
| Change control | Change log reviewed, unapproved changes investigated | IT lead |
| Backup | Restore test completed and recorded | IT lead or provider |
Monthly, someone should also check backup job results, read security alerts and process joiners and leavers. Annually, review the whole framework against how the business has changed.
Who does what in a business of up to 250 people
Governance fails most often because everyone assumes someone else owns it. In a small business the roles look like this:
- Executive sponsor (MD, FD or operations director): approves the policies, funds the reviews and is accountable for the risk. This is not a technical role.
- IT owner: the internal IT lead, or the managed provider where there is no internal IT. Runs the quarterly checks, keeps the documentation and makes the changes.
- Data owners: a named person per department who decides what their team's data is, who should see it and how long it is kept. In a 20-person firm that may be two people. In an 80-person firm it might be six.
- Finance: reconciles licences and subscriptions against the bill and the payroll.
- Every manager: follows the joiners and leavers process and the naming standard, and tells IT before buying a new tool.
For businesses without an internal IT lead, a vCIO or IT strategy arrangement provides the review cadence and the board-level conversation without hiring a full-time role. The point is a named person and a date in the diary, not a job title.
Governance in a hybrid estate
Governance is not only for businesses that have gone fully cloud. Mr Plant Hire, a multi-depot plant and tool hire business established in 1981, runs Microsoft 365 with SharePoint for inter-company document sharing alongside Windows servers that still have a job to do, with local and cloud backup across both. Supporting that environment for over 15 years has meant applying the same disciplines of access reviews, structure, licence checks and tested backups across cloud and on-premise as one estate. The Mr Plant Hire case study shows how that works in practice.
What to do next
If nobody in the business can say when access, licences and sharing settings were last reviewed, that is the answer. An IT health check looks at identity, security configuration, licensing, backup and how SharePoint and Teams are structured, and gives you a prioritised list to start the first quarterly review from.

