SharePoint for accountancy firms is bought as a storage decision and lived with as a security one. A practice signs up for Microsoft 365, the old file server gets copied into a document library, and within eighteen months the same firm is holding every client’s identity documents, bank statements, payroll records and tax computations in a system nobody has ever configured. The files are safer than they were on a cupboard server. The permissions around them are usually worse.

That gap matters more in accountancy than in almost any other small business. A practice holds the personal data of people who are not its clients, the financial records of businesses that are, and the anti-money laundering evidence that a supervisor can ask to see at any time. Getting SharePoint for accountancy firms right is therefore a compliance exercise with a collaboration tool attached, not the other way round. This guide covers the site architecture, the permission model, the sharing settings, the labels, the retention rules and the recovery layers that a UK practice actually needs.

Everything below is written against Microsoft’s own current documentation and UK list pricing, with a worked example based on a forty-one person, three-office practice. If your firm is still on a file server, the companion guides to SharePoint migration cost and file server to SharePoint migration cover the move itself. This one covers what you build once the data has landed.

Why SharePoint for Accountancy Firms Is a Security Question, Not a Storage One

sharepoint for accountancy firms secure client document management b2 cloud three rounded bumps

The file server habits that arrive with SharePoint for accountancy firms

Most practices arrive in SharePoint for accountancy firms carrying a folder tree that was designed around a mapped drive. There is a folder per client, a folder per year inside it, and a permission set that was last reviewed when someone left in 2019. Copying that structure into a document library preserves every one of its weaknesses and adds a new one: the contents are now reachable from any browser in the world, subject only to whatever sign-in controls the practice has configured.

The reason SharePoint for accountancy firms so often ends up over-permissioned is that nothing in the migration forces a decision. A file copy tool will happily reproduce a share where “Domain Users” had modify rights on the whole client tree. Nobody notices, because the experience for staff is identical to the one they had before.

What a breach actually costs a UK practice

The Cyber Security Breaches Survey 2025/2026, published on 30 April 2026, found that 43% of UK businesses had identified a breach or attack in the previous twelve months. The rate climbs sharply with size: 42% of micro businesses, 46% of small businesses, 65% of medium businesses and 69% of large businesses. Only 47% of businesses had two-factor authentication in place.

UK businesses identifying a breach or attack in the last 12 months, by size (CSBS 2025/2026)
Micro (1–9 staff) — 42%
Small (10–49 staff) — 46%
Medium (50–249 staff) — 65%
Large (250+ staff) — 69%
Bars scaled to the highest figure in the series (69%).

Most firms running SharePoint for accountancy firms sit in the micro and small bands, where the headline rate looks reassuring. It is not, because the survey counts identified breaches, and a firm with no audit review and no alerting identifies very few.

The regulator’s view of client records

The Information Commissioner’s Office fined DPP Law £60,000 after a cyber attack in which a large volume of sensitive legal data was exfiltrated. The parallel for an accountancy practice is exact: the regulator’s concern is not that an attack happened but that basic controls were missing. Cybersecurity failings of that kind are almost always configuration failings rather than technology failings, which is precisely why SharePoint for accountancy firms deserves a deliberate build rather than a default one.

Where SharePoint for accountancy firms fits in this series

This is the ninth article in our accountancy series. It assumes the identity layer is already in place. If it is not, start with the Microsoft 365 security checklist for accountancy firms and the Conditional Access policy baseline, then come back here for the document layer.

What SharePoint for Accountancy Firms Actually Has to Protect

sharepoint for accountancy firms secure client document management c notebook binding holes

Before designing anything, list what SharePoint for accountancy firms will hold. The exercise takes an afternoon and it changes the architecture, because the seven categories below have genuinely different sharing, retention and access requirements. Treating them as one pile is the root cause of most of the problems in this guide.

Client permanent files

Incorporation documents, share registers, memorandums and articles, historic accounts, correspondence with Companies House. These change rarely, are referenced for years, and are the files most likely to be requested by a client who left in 2021 and came back in 2026. They need long retention and low churn.

Current-year working papers

Trial balances, lead schedules, journals, reconciliations, review notes. These change daily during a job, are worked on by two or three people, and become read-only the moment the file is signed off. Versioning matters here more than anywhere else in the practice.

Anti-money laundering evidence

Identity documents, proof of address, beneficial ownership records, risk assessments, source-of-funds notes. Regulation 40 of the Money Laundering Regulations 2017 requires these to be kept for five years from the end of the business relationship. They are also the single most damaging category to lose control of, because they are copies of somebody’s passport.

Payroll and personal data

Payslips, P60s, starter and leaver forms, pension records, bank details for net pay. This is special-category-adjacent personal data belonging to people who have no relationship with the practice at all, and it is the category most often left in a general client folder where the whole team can read it.

Tax computations and HMRC correspondence

Returns, computations, agent authorisations, HMRC letters, enquiry correspondence. Sensitive, time-bound, and increasingly subject to agent access requirements that assume the practice can prove who touched what.

Engagement letters and fee data

Letters of engagement, scope schedules, fee quotes, write-offs, WIP reports. Commercially sensitive within the firm as well as outside it. Partners routinely want this restricted from junior staff, which is exactly the kind of requirement that folder-level permissions handle badly.

The practice’s own records

HR files, partnership agreements, PII policies, supplier contracts, its own accounts. This should never live in the client estate, and in a well-built SharePoint for accountancy firms deployment it never does.

CategoryTypical churnExternal sharingRetention driver
Client permanent filesVery lowOccasional, read-onlyClient relationship life
Current-year working papersVery highNeverProfessional standards
AML evidenceLowNeverMLR 2017 reg 40 — five years
Payroll and personal dataMonthlyRestricted, per clientEmployment and tax law
Tax and HMRC correspondenceSeasonalRestricted, per clientEnquiry windows
Engagement letters and feesLowSigned copies onlyContract life plus limitation
Practice’s own recordsLowNeverInternal policy

The Site Architecture Behind SharePoint for Accountancy Firms

sharepoint for accountancy firms secure client document management d divider cards row tabs

Why one site per client does not scale

The instinct in SharePoint for accountancy firms is to give every client its own site. Microsoft will let you: the limit is two million sites per organisation. The problem is not the ceiling, it is the administration. A practice with 1,180 active clients would be running 1,180 sharing settings, 1,180 sensitivity labels, 1,180 permission sets and 1,180 retention scopes, and every new client would require a provisioning step that somebody has to remember.

Worse, Data Loss Prevention in Microsoft Purview can only be scoped to up to 100 individual SharePoint sites per policy. A site-per-client model puts you past that ceiling on day one, and the only way back is administrative units or an all-sites policy that you cannot tune.

The seven-site model for SharePoint for accountancy firms

A far better shape for SharePoint for accountancy firms is a small number of sites separated by sensitivity and audience, with the client identity carried as metadata rather than as a site boundary. Seven sites covers almost every general practice.

Client documents

The main working site in SharePoint for accountancy firms. One library, every client, every year, separated by columns and views rather than by top-level folders. This is where the accounts, bookkeeping and tax work happens.

Anti-money laundering

A separate site with external sharing turned off entirely, restricted access control applied, and a five-year retention label published to it. Keeping AML evidence out of the general client site is the single highest-value architectural decision in the whole build.

Payroll

A separate site because the audience is different: payroll staff plus one nominated contact per client, and nobody else. Payroll is also the category most likely to trigger a DLP match, so isolating it makes the policy far easier to tune.

Client portal

The only site with external sharing enabled, and even then set to New and existing guests rather than Anyone. Deliverables are copied here for signature or collection; nothing is worked on here.

Practice management

Engagement letters, fee schedules, WIP, client acceptance. Partner and manager audience only.

Firm administration

HR, insurance, partnership documents, supplier contracts, the practice’s own accounts. Completely separate from the client estate.

Knowledge and templates

Checklists, letter templates, standard working papers, technical updates. Read for everyone, write for a small group. This is the one site where broad access is correct.

SiteAudienceExternal sharingContainer labelUnmanaged devices
Client documentsAll fee earnersOnly people in your organizationConfidentialLimited web-only
Anti-money launderingMLRO plus nominated staffOnly people in your organizationHighly ConfidentialBlock
PayrollPayroll teamOnly people in your organizationHighly ConfidentialBlock
Client portalClient-facing staff plus guestsNew and existing guestsConfidential — externalLimited web-only
Practice managementPartners and managersOnly people in your organizationConfidentialLimited web-only
Firm administrationPartners and practice managerOnly people in your organizationHighly ConfidentialBlock
Knowledge and templatesEveryoneOnly people in your organizationGeneralFull access

Hub sites and navigation in SharePoint for accountancy firms

Associate the seven sites with a single hub so staff get one navigation bar and one scoped search. Microsoft allows up to 2,000 hub sites per organisation, and all navigation types are limited to 500 child links at each level, so a practice will never come close to either ceiling. One hub is the right answer.

Naming conventions that survive a partner change

Name sites in SharePoint for accountancy firms for function, never for people. A site called “Client Documents” outlives three managing partners; a site called “Sarah’s Clients” creates an orphan the moment Sarah retires. The same rule applies to the Microsoft 365 groups behind them.

Why subsites are the wrong tool in SharePoint for accountancy firms

SharePoint supports 2,000 subsites per site collection, and Microsoft explicitly recommends creating sites and organising them into hubs instead. Subsites inherit permissions in ways that are hard to reason about later, and they cannot be moved. A SharePoint for accountancy firms build should contain none.

Libraries and Metadata in SharePoint for Accountancy Firms

sharepoint for accountancy firms secure client document management e2 wall three square openings

The client column that anchors SharePoint for accountancy firms

Create a managed metadata column in SharePoint for accountancy firms, populated from a term set of active clients. Every document in the client documents library carries it. The term store supports one million terms, so a practice with 1,180 clients uses roughly a tenth of one percent of the ceiling.

The year column

A simple choice column for the accounting period is the second pillar of SharePoint for accountancy firms. This is what makes “show me everything for this client, this year” a two-click view rather than a folder dive, and it is what lets retention rules key off a period rather than a file date.

The document type column

Accounts, tax return, bookkeeping, correspondence, permanent, AML, payroll. Seven values in SharePoint for accountancy firms, no more. Long option lists never get used consistently and become worse than no metadata at all.

Views instead of folders in SharePoint for accountancy firms

Once the three columns exist, build views: My open jobs, This client all years, Year-end pack, Awaiting review. Staff stop navigating and start filtering. This is the change that makes SharePoint for accountancy firms feel faster than the file server rather than slower.

The 5,000-item list view threshold

SharePoint for accountancy firms inherits a list view threshold of 5,000 items, and administrators cannot raise it. This is the single most common complaint after a migration, and it is entirely avoidable: index the columns you filter on, and make sure every default view has a filter that returns fewer than 5,000 rows. The library itself can hold far more.

How many items a library can actually hold

A list in SharePoint for accountancy firms can hold up to 30 million items and a library up to 30 million files and folders. A practice will never reach that. What it will reach, if it uses folders, is the point at which no view returns quickly, which is why metadata is a performance decision as much as a usability one.

ColumnTypeIndexedWhy it exists
ClientManaged metadataYesReplaces the top-level folder
PeriodChoiceYesReplaces the year folder and drives retention
Document typeChoiceYesDrives views and auto-labelling
StatusChoiceNoDraft, in review, signed off
OwnerPersonNoAccountability, not permission

Permissions: The Model SharePoint for Accountancy Firms Should Use

sharepoint for accountancy firms secure client document management f rocket cone nose three fins

Groups, not people, across SharePoint for accountancy firms

Every permission in SharePoint for accountancy firms should be granted to a Microsoft 365 group or an Entra security group, never to an individual. Individual grants are invisible in a group listing, survive a leaver process, and are the reason permission reviews in most practices are meaningless. This rule costs nothing to adopt on day one and is painful to retrofit later.

The three permission levels you actually need

Most firms building SharePoint for accountancy firms need only three: Read for people who consume, Contribute for people who produce, and Full Control for two named administrators. Edit and Design are rarely the right answer, and Full Control on a client library should never be held by more than a handful of people.

Unique permissions and where they go wrong

SharePoint for accountancy firms supports up to 50,000 unique permission scopes per list or library, but Microsoft’s recommended general limit is 5,000. Every folder or file where somebody clicks “stop inheriting permissions” creates one. A practice that manages access per client folder will pass the recommended limit long before it passes the supported one, and performance degrades on the way.

The 100,000-item inheritance wall

When a list, library or folder contains more than 100,000 items, you cannot break permission inheritance on it, and you cannot reinherit permissions on it either. You can still break inheritance on individual items inside it. A large client library that has grown for a decade can therefore reach a state where the permission model you want is no longer available to you.

Restricted access control in SharePoint for accountancy firms

Restricted access control limits a site in SharePoint for accountancy firms to members of specified Microsoft 365 groups or Entra security groups. Users not in the group cannot reach the site or its content even if they had prior permissions or a shared link. You can configure up to 10 groups per site, and the policy is honoured in organisation-wide search and in Microsoft Copilot responses.

Why restricted access control is the right tool for AML

Belt and braces is exactly right for anti-money laundering evidence in SharePoint for accountancy firms. Permissions say who is allowed in; restricted access control says who is allowed in at all, and it catches the case where an old direct grant or a forgotten sharing link would otherwise still work. Note that a user needs both the content permission and group membership.

The sharing gap you must close

By default, sharing a site or its content does not follow the restricted access control policy. That is a deliberate Microsoft default and a poor one for SharePoint for accountancy firms. Close it with Set-SPOTenant -AllowSharingOutsideRestrictedAccessControlGroups $false, which blocks sharing with anyone outside the control group.

GroupClient documentsAMLPayrollPractice management
PartnersContributeReadReadContribute
ManagersContributeNoneNoneContribute
Qualified staffContributeNoneNoneNone
Tax teamContributeNoneNoneNone
Payroll teamReadNoneContributeNone
MLRO and deputiesReadContributeNoneRead
Administrators (2 named)Full ControlFull ControlFull ControlFull Control

External Sharing in SharePoint for Accountancy Firms and the Client Portal

External sharing is on by default

Microsoft states plainly that external sharing is turned on by default for your entire SharePoint and OneDrive environment, and recommends turning it off globally before people start using sites. Very few firms running SharePoint for accountancy firms have ever read that sentence. Checking it is the fastest security win available in any SharePoint for accountancy firms review.

The four sharing settings SharePoint for accountancy firms chooses between

SharePoint for accountancy firms has four levels to choose from. Anyone allows links that work without authentication. New and existing guests requires recipients to sign in with a work, school or Microsoft account, or to enter a verification code. Existing guests allows sharing only with guests already in your directory. Only people in your organization turns external sharing off.

Site-level overrides and the most-restrictive rule

Sharing settings in SharePoint for accountancy firms exist at both organisation and site level. To allow external sharing on any site you must allow it at the organisation level, then restrict it per site. Where the two disagree, the most restrictive value always applies, and OneDrive can be the same as or more restrictive than SharePoint, never more permissive.

Why a practice should set the tenant to guests, not Anyone

The pragmatic setting for SharePoint for accountancy firms is New and existing guests at the organisation level, with every site except the client portal set to Only people in your organization. That gives you an authenticated audit trail for every external recipient while keeping the blast radius to a single site.

Anyone links and why they are dangerous here

Anyone links in SharePoint for accountancy firms are unauthenticated. Anybody who receives one, forwards one, or finds one in an email thread can open the file, and you cannot track who has access or who has accessed it. There is a second, less-known problem: Anyone links are not affected by conditional access policies that block or limit unmanaged devices. Microsoft’s own guidance is to disable Anyone links for every site where you enable those policies.

If SharePoint for accountancy firms must allow Anyone links

Restrict them inside SharePoint for accountancy firms. You can require all Anyone links to expire within a specified maximum number of days, and you can restrict them to View permission only. If you shorten the expiry period, existing links update to the shorter setting; if you lengthen it, existing links keep their current expiry.

Guest expiry and verification codes for SharePoint for accountancy firms

Two settings deserve to be turned on in every SharePoint for accountancy firms build. Guest access to a site or OneDrive will expire automatically after this many days puts a clock on every guest. People who use a verification code must reauthenticate after this many days forces recipients who stayed signed in to prove they still control the mailbox they redeemed the invitation with.

Domain restrictions

SharePoint for accountancy firms can limit external sharing to a list of allowed domains, or block specific ones, up to a maximum of 5,000 domains. For a practice with a stable set of referral partners, solicitors and lenders, an allow-list is realistic and dramatically narrows the exposure of the client portal.

Turning sharing off does not remove guests

If you turn off external sharing for the organisation and later turn it back on, guests regain access. If you know sharing was previously in use on specific sites and you do not want those guests back, turn it off for those sites first. When you do restrict or disable sharing, guests typically lose access within one hour.

SettingWho can receive contentAudit trailRight for a practice?
AnyoneAnyone with the link, no sign-inNoneNo
New and existing guestsAnyone who signs in or enters a codeFullYes — tenant default
Existing guestsGuests already in the directoryFullOptional for the portal
Only people in your organizationStaff onlyFullYes — every site but the portal

Sensitivity Labels Across SharePoint for Accountancy Firms

Container labels versus file labels

Sensitivity labels in SharePoint for accountancy firms come in two flavours that people constantly conflate. A container label applies to a SharePoint site, a Microsoft 365 group or a Teams team, and controls privacy, external user access, access from unmanaged devices and the default sharing link. A file label applies to a document and can carry encryption that travels with the file wherever it goes.

Why a practice needs both

A container label stops the wrong people getting into the AML site. A file label stops a payroll spreadsheet being readable after somebody emails it to a personal address. Neither substitutes for the other, and a mature SharePoint for accountancy firms build uses both.

A four-label scheme for SharePoint for accountancy firms

Four labels is enough for SharePoint for accountancy firms: General for templates and internal notices, Confidential for client work, Confidential — external for anything deliberately shared with a client, and Highly Confidential for AML, payroll and firm administration. More than four and staff stop reading the names.

Default labels on a document library

You can set a default sensitivity label on a document library through Library settings, which applies to new and unlabelled files. On the AML and payroll libraries this means every file is labelled correctly without anyone remembering to do it, which is the only labelling scheme that survives a busy January.

What labels do that permissions cannot

Permissions in SharePoint for accountancy firms stop at the boundary of the tenant. Encryption from a sensitivity label does not: a labelled file that leaves in an email attachment, on a USB stick or through a personal cloud sync is still unreadable to anyone outside the permitted group. For a practice worried about a leaver taking the client base, that difference is the whole argument.

LabelApplied toEncryptionGuest accessUnmanaged devices
GeneralTemplates, knowledge siteNoNot allowedFull access
ConfidentialClient documents, practice managementNoNot allowedLimited web-only
Confidential — externalClient portal, signed deliverablesOptionalAllowedLimited web-only
Highly ConfidentialAML, payroll, firm administrationYesNot allowedBlock

Data Loss Prevention Across SharePoint for Accountancy Firms

What DLP can actually do in SharePoint

For SharePoint and OneDrive, Microsoft Purview DLP supports one main action: restrict access or encrypt the content. The options are block everyone, block only people outside your organisation, or block access for specific external domains or users. Microsoft is explicit that documents are proactively blocked right after detection of sensitive information, regardless of whether the document has been shared, for all guests, while internal users continue to have access.

The sensitive information types that matter in a practice

For SharePoint for accountancy firms, start with UK National Insurance number, UK passport number, UK driver’s licence number, credit card number, IBAN and SWIFT code, and EU or UK bank account number. Those six catch the overwhelming majority of genuinely dangerous content in an accountancy estate.

The 100-site scoping limit

DLP supports scoping policies to up to 100 individual SharePoint sites. With the seven-site model that is a non-issue. With a site-per-client model it is a hard wall, which is one more reason the architecture in this guide is shaped the way it is.

Other limits worth knowing

A tenant supports a maximum of 600 DLP rules, each rule and each policy is capped at 100 KB, and DLP scans the first two million characters of a file and the first three levels of nesting. None of these constrain a practice, but they explain why an over-engineered policy set eventually fails to save.

Start SharePoint for accountancy firms policies in simulation mode

Every DLP policy in SharePoint for accountancy firms should run in simulation first. A policy that blocks guest access to anything containing a bank account number will match your own remittance advices, your bank feeds and half of your payroll library. Simulation shows you that before your clients do.

PolicyScopeDetectsAction
Identity documentsAll sitesPassport, driver’s licence, NI numberBlock external
Bank detailsAll sitesAccount number, IBAN, SWIFTBlock external
Card dataAll sitesCredit card numberBlock everyone, notify
AML lockdownAML siteRetention label “AML five year”Block external
Payroll lockdownPayroll siteSensitivity label “Highly Confidential”Block external

Retention, MLR Regulation 40 and Disposal in SharePoint for Accountancy Firms

What the law requires of SharePoint for accountancy firms

Regulation 40 of the Money Laundering Regulations 2017 requires a relevant person to keep copies of the documents and information obtained to satisfy customer due diligence for five years. ICAEW guidance puts the same requirement plainly: customer due diligence records must be kept for five years following the end of the business relationship. Record keeping under the regulations is not subject to the risk-based approach, so there is no room for a judgement call about how much to keep.

Retention policies, retention labels and records

Microsoft Purview offers SharePoint for accountancy firms three levels. A retention policy applies to a location and retains everything in it. A retention label applies to an item and can be published for users to apply or auto-applied by a query. A label can also mark an item as a record or a regulatory record, which blocks deletion outright. The behaviour differs sharply, and picking the wrong one is the most common retention mistake in SharePoint for accountancy firms.

How each behaves when a file is edited or deleted

Under a retention policy, both editing and deleting an item create a copy in the Preservation Hold library. Under a standard retention label, editing does not create a copy but deleting does. Under a label that marks items as records, editing an unlocked item creates a copy while editing a locked item and deleting are both blocked. Under a regulatory record label, editing and deleting are always blocked.

The Preservation Hold library

SharePoint for accountancy firms creates a hidden Preservation Hold library on any site subject to retention. Microsoft is explicit that it is not designed to be used interactively, and that editing, deleting or moving the files inside it, or changing their labels, is unsupported. Reach the content through eDiscovery instead.

The thirty-seven day disposal clock

A timer job runs periodically on the Preservation Hold library. For content that has been there more than 30 days, the job compares it against the retention queries and deletes anything past its period. That job runs every seven days, so together with the 30-day minimum it can take up to 37 days for content to leave the Preservation Hold library. Plan disposal reporting around that window, not around the label’s expiry date.

Where deleted content actually goes

Expired content moves to the second-stage recycle bin and is permanently deleted at the end of 93 days. Microsoft notes that it no longer permanently deletes content directly from the Preservation Hold library, precisely to prevent inadvertent data loss. A 93-day retention period spans both the first-stage and second-stage recycle bins, and the recycle bin is not indexed, so eDiscovery cannot search it.

A retention scheme for SharePoint for accountancy firms

Publish four retention labels across SharePoint for accountancy firms. AML five year auto-applied by document type on the AML site. Client records seven year on the client documents site. Payroll six year on the payroll site. Practice records on firm administration. Auto-apply by the document type column wherever possible, because manual labelling in a practice does not survive January.

Retention overrides versioning

This catches people out in SharePoint for accountancy firms. For items subject to a retention policy or an eDiscovery hold, the versioning limits on the document library are ignored until the retention period is reached or the hold is released. Old versions are not automatically purged and users cannot delete versions. Retention labels behave differently: when there is no policy or hold, versioning limits are honoured, though users still cannot delete versions.

MechanismCopy on editCopy on deleteDeletion blocked?Use it for
Retention policyYesYesNoWhole-site floors
Standard retention labelNoYesConfigurableAML, payroll, client records
Label marking a recordYes (unlocked)BlockedYesSigned accounts, filed returns
Regulatory recordBlockedBlockedAlwaysRarely needed in practice

Versioning, Recycle Bins and Ransomware Recovery in SharePoint for Accountancy Firms

Automatic versus manual version limits in SharePoint for accountancy firms

Version history limits in SharePoint for accountancy firms can be set at organisation, site or library level, and a site or library can break inheritance from the organisation default. There are two modes. The Automatic setting is Microsoft’s recommendation and optimises storage using a time-based thinning schedule. The Manual setting lets an administrator set a major version count, optionally with an expiration period.

What the numbers actually are

Under the Automatic setting, users have access to a maximum of 500 versions created within the last 30 days. Under Manual, the interface will not accept a value below 100 major versions or an expiration below 30 days, though public APIs can set lower values. Microsoft warns that anything below those floors risks inadvertent data loss. The absolute ceiling is 50,000 major versions and 511 minor versions.

Trimmed versions do not go to the recycle bin

This is the detail that matters most for SharePoint for accountancy firms. When versions exceed the limits set on a library, they are marked for permanent deletion, and that workflow bypasses the recycle bin entirely. The same is true of a scheduled trim job. Only versions a user deletes from a file’s version history go to the site recycle bin.

The ninety-three day recycle bin in SharePoint for accountancy firms

Deleted items in SharePoint for accountancy firms pass through a first-stage recycle bin visible to users and a second-stage recycle bin visible only to site collection administrators. A 93-day retention period spans both. At the end of 93 days the document is permanently deleted wherever it sits. Plan on the assumption that anything deleted more than three months ago is gone unless retention or backup caught it.

Restoring a library after a ransomware event

SharePoint’s Restore this library feature rolls a library back to a point in the last 30 days using version history, which is why version limits are a security control and not a storage setting. If your library keeps 500 versions from the last 30 days, you have a rollback path. If somebody trimmed versions to save space, you may not.

How long each recovery layer holds a deleted client file (days)
Automatic version window — 30 days
Preservation Hold purge cycle — up to 37 days
Recycle bin, both stages combined — 93 days
Microsoft 365 Backup restore points — 365 days
Bars scaled to the longest window in the series (365 days).

The sync client is part of your ransomware exposure

Microsoft recommends syncing no more than 300,000 files in a single OneDrive or team site library, and notes the same performance issues arise at 300,000 items across all libraries a user is syncing. A machine with a large synced library is also a machine that can encrypt a large synced library, which is a good reason to prefer browser and Teams access over sync for client work.

LibraryVersion settingSync allowed?Why
Client documentsAutomaticNoRollback path plus reduced endpoint exposure
Anti-money launderingAutomaticNoBlocked at device level anyway
PayrollAutomaticNoPersonal data must not leave the service
Client portalManual, 100 versionsNoCopies only, low value history
Knowledge and templatesAutomaticYesNon-sensitive, offline access useful

Devices: Where SharePoint for Accountancy Firms Lets Documents Land

The three unmanaged-device options in SharePoint for accountancy firms

An administrator of SharePoint for accountancy firms can allow full access, allow limited web-only access, or block access outright for devices that are neither hybrid-joined nor compliant in Intune. The control can target all users or specific security groups, and all sites or specific sites. It relies on Microsoft Entra Conditional Access underneath.

What limited web-only access actually blocks

Users of SharePoint for accountancy firms on unmanaged devices get browser-only access with no ability to download, print or sync files, and no access through apps including the Office desktop applications. You can additionally choose whether editing in the browser is allowed. Blocked users see an explicit message: access denied due to organisation policy from an untrusted device.

The advanced switches worth knowing

-AllowEditing $false prevents editing Office files in the browser. -ReadOnlyForUnmanagedDevices $true makes the whole site read-only. -LimitedAccessFileType OfficeOnlineFilesOnly restricts preview to Office files only, which is more secure but does block PDFs. The default, WebPreviewableFiles, is more usable but Microsoft warns it can cause unexpected access-denied errors on PDFs and images.

The Anyone-link hole in the policy

Microsoft states it directly: Anyone links are not affected by these policies, and people holding one can download the item. For every site where you enable device restrictions in SharePoint for accountancy firms, disable Anyone links on that site as well, or the control is decorative.

Do it at the Microsoft 365 level, not just SharePoint

Microsoft’s own guidance is that a policy affecting all Microsoft 365 services gives better security and a better experience. Block SharePoint alone and a user on an unmanaged device can still read a Teams chat but loses the Files tab, which produces confusing support calls. Target the Office 365 cloud app in Conditional Access instead.

Give SharePoint for accountancy firms time, and check legacy apps

Changes can take up to 24 hours to take effect and will not affect users already signed in from unmanaged devices. Microsoft also recommends blocking apps that do not use modern authentication, because those apps cannot enforce device-based restrictions and can bypass the policy entirely.

OptionDownloadPrintSyncDesktop apps
Allow full accessYesYesYesYes
Allow limited, web-only accessNoNoNoNo
Block accessNo access at all

Copilot, Search and Oversharing in SharePoint for Accountancy Firms

Why an AI assistant exposes permission debt

Microsoft 365 Copilot answers using content in SharePoint for accountancy firms that the signed-in user already has permission to read. That sounds safe until you remember what the permission model in most practices actually says. A junior with read access to a library containing partner remuneration will not find it by browsing, but they may well be handed it by an assistant that was asked a reasonable question.

Restricted Content Discovery

Restricted Content Discovery limits how content from specific sites appears in organisation-wide search results and Copilot responses, and removes AI entry points such as the Copilot button and AI action menus from those sites. It is explicitly designed as a temporary governance control while permissions are reviewed. It does not change permissions and does not remove content from the search index.

What it does not do

Microsoft is careful here, and so should you be. Restricted Content Discovery affects discoverability, not authorisation. A user with permission can still open the document directly or through a link. It also does not affect searches originating from site context, and it cannot be applied to OneDrive.

How long it takes to take effect

Index update latency depends on site size. Microsoft states that for sites with more than 500,000 items an update to Restricted Content Discovery could take more than a week to process fully and be reflected in search and Copilot experiences. Turn it on before the Copilot pilot, not during it.

Restricted access control does more

Where Restricted Content Discovery hides, restricted access control blocks. It is honoured in organisation-wide search and Copilot experiences too, and users denied by the policy cannot view that content in either. For the AML site in SharePoint for accountancy firms, that is the control you want.

A phased Copilot approach for SharePoint for accountancy firms

Review permissions with the Data Access Governance reports, apply Restricted Content Discovery to anything questionable, pilot Copilot with a small group, then lift the restriction site by site as each one is cleared. Our guide to Microsoft 365 Copilot security before rollout covers the wider readiness work.

The Hard Limits on SharePoint for Accountancy Firms

Storage entitlement arithmetic for SharePoint for accountancy firms

Every tenant running SharePoint for accountancy firms gets 1 TB plus 10 GB per licence purchased. Storage is calculated in binary gigabytes. Extra storage can be bought in 1 GB increments and is genuinely unlimited, but Microsoft warns that a tenant operating above its storage limit risks being put into read-only mode, meaning users cannot add or modify content.

The site ceiling nobody reaches

Maximum storage per site collection in SharePoint for accountancy firms is 25 TB, and a site that reaches it enters read-only mode until content is deleted or moved. A practice will not get there. Watch the tenant total instead, because that is the number that actually bites.

File size and path length

The file upload limit in SharePoint for accountancy firms is 250 GB per file, and 250 MB for a file attached to a list item. Multi-file ZIP downloads are capped at 20 GB. The one that genuinely trips up an accountancy migration is the path limit: the entire decoded file path, including the file name, cannot exceed 400 characters.

Lists, libraries and subsites

There is a combined limit of 2,000 lists and libraries per site collection, and 2,000 subsites per site collection. Neither constrains the seven-site model, and both are excellent reasons not to build the site-per-client alternative.

Permission scopes and groups

A user can belong to 5,000 groups per site collection, each group can have 5,000 users, and there can be up to 10,000 groups per site collection. Unique permission scopes are supported to 50,000 per list or library but recommended at 5,000.

Holds and compliance policy counts

There is a maximum of 13 holds when all SharePoint or OneDrive sites are automatically included, and 2,600 when specific locations are included or excluded. Holds, retention policies, DLP policies, information barriers and sensitivity labels together count towards a 10,000 per tenant maximum.

LimitValueWhat happens in a practice
Tenant storage1 TB + 10 GB per licenceRead-only risk if exceeded
List view threshold5,000 itemsViews break; index and filter
Items per list or library30 millionNever reached
Break inheritance blocked above100,000 itemsOld client libraries lose flexibility
Unique permission scopes50,000 supported / 5,000 recommendedPer-folder security hits this
File path length400 charactersMigration failures
Sync recommendation300,000 filesPerformance and ransomware exposure
DLP site scoping100 sites per policyKills the site-per-client model
Restricted access control groups10 per siteAmple for seven sites

Backup: Where SharePoint for Accountancy Firms Still Needs More

Retention is not backup in SharePoint for accountancy firms

Retention in SharePoint for accountancy firms keeps things you were going to delete. Backup gets things back that were destroyed. They overlap enough to be confused and differ enough to matter: retention will not restore a library that a compromised account systematically encrypted, and the recycle bin runs out at 93 days. Our comparison of Microsoft 365 data retention versus backup sets out the distinction in full.

Microsoft 365 Backup

Microsoft’s first-party option is a pay-as-you-go service billed through Azure at a list price of $0.15 per GB per month of protected content. Restores are free, and the restore point frequency does not materially change the cost. There are no additional Azure API or storage charges beyond the backup usage itself.

What counts towards the bill

Charging is based on the user-facing size of protected sites and mailboxes plus the deleted and versioned data held for recovery. Microsoft’s own worked example: a 1 GB site with 0.5 GB in its second-stage recycle bin, plus a 1 GB mailbox with a 1 GB online archive, is billed as 3.5 GB. Deleted content keeps costing until the backup retention period lapses.

Third-party backup

An independent backup product still has advantages: a separate control plane, a separate credential set, and export outside Microsoft’s estate. For a practice whose professional indemnity insurer asks about recovery capability, that separation is often the deciding factor rather than the price.

Microsoft 365 Archive for old client years

Archive is a different lever. Archived SharePoint storage is billed at $0.05 per GB per month, and only when archived plus active storage exceeds the tenant’s licensed capacity. Reactivation fees were eliminated on 31 March 2025, though re-archiving newly reactivated content is restricted for a four-month period. For a practice with fifteen years of dormant client sites, that is a real saving.

What SharePoint for accountancy firms should actually do about backup

Turn on Microsoft 365 Backup for the client documents, AML and payroll sites at minimum. Keep versioning on Automatic everywhere. Leave the recycle bins alone. Test a restore once a quarter and write down how long it took, because the number you will be asked for after an incident is time to recover, not whether a backup existed.

Auditing SharePoint for Accountancy Firms and Proving What Happened

The audit events that matter in SharePoint for accountancy firms

Purview logs SharePoint for accountancy firms version history limit changes at organisation, site and library level, version deletions and bulk version deletions, restricted access control changes including the site admin’s justification, and Restricted Content Discovery enable and disable events with justifications. Those are the events a supervisory review will ask about.

Access reviews and the leaver problem

The hardest question in any practice is not who has access today but who kept access after they moved teams. Reviewing group membership quarterly, with the group owner rather than IT signing it off, catches more than any technical control. It also makes the permission model in SharePoint for accountancy firms defensible rather than merely documented.

Data Access Governance reports

Use the sites-protected report and the access-denials report that ship with restricted access control. The denials report returns the most recent 100 events from the past 28 days interactively, and up to 10,000 denials if you download it. A denial report full of legitimate staff is a permission design problem, not a policy problem.

eDiscovery and the recycle bin blind spot

Content in the recycle bin is not indexed and therefore cannot be found by an eDiscovery search or placed on hold. If a matter is live, act before the 93 days run out, and apply the hold to the site rather than assuming deleted items are recoverable.

Prove the disposal, not just the retention

Supervisors ask two questions about records: can you produce them, and can you show you destroyed them when you said you would. Disposition review answers the second. Configure it on the AML and payroll labels so a named person signs off each disposal batch and the sign-off itself is logged.

What SharePoint for Accountancy Firms Costs

The base licence behind SharePoint for accountancy firms

Every plan that includes SharePoint for accountancy firms gets the same storage entitlement and the same core service. UK list prices, annual commitment and excluding VAT, run Business Basic at £5.40, Business Standard at £10.80, Business Premium at £16.90, E3 at £33.50 and E5 at £51.60 per user per month. Business plans are capped at 300 users, which is well above the size of almost every UK practice.

What Business Premium already includes

Business Premium is the sensible base for SharePoint for accountancy firms. It carries Entra ID P1, so Conditional Access and device-based restrictions are available. It carries Intune, so devices can be made compliant. It carries basic Purview information protection, so sensitivity labels are available.

What the add-on suites add

Since 1 October 2025 Microsoft has sold two Business Premium add-ons relevant to SharePoint for accountancy firms. The Microsoft Defender Suite and the Microsoft Purview Suite are each £7.70 per user per month, or £11.50 for both, each requiring a Business Premium base licence and capped at 300 seats. The Purview Suite is the one that matters here: it adds full data loss prevention including endpoint, insider risk, premium audit, premium eDiscovery, data lifecycle management and records management.

Where SharePoint Advanced Management sits

Restricted access control and Restricted Content Discovery are SharePoint Advanced Management features. SAM is included with E5 and available as an add-on, and Restricted Content Discovery additionally expects a Microsoft Copilot licence. A Business Premium practice that wants those specific controls needs to price the add-on rather than assume it is included.

Consumption costs on top

Two consumption meters can appear against SharePoint for accountancy firms. Microsoft 365 Backup at $0.15 per GB per month of protected content, and Microsoft 365 Archive at $0.05 per GB per month, the latter charged only above the licensed storage quota. Both are billed pay-as-you-go through an Azure subscription.

Plan or add-onUK list, per user per monthConditional AccessFull DLPSharePoint Advanced Management
Business Basic£5.40NoNoNo
Business Standard£10.80NoNoNo
Business Premium£16.90YesNoNo
Business Premium + Purview Suite£24.60YesYesNo
Business Premium + both suites£28.40YesYesNo
Microsoft 365 E3£33.50YesPartialAdd-on
Microsoft 365 E5£51.60YesYesIncluded

SharePoint for Accountancy Firms: A Forty-One Person Worked Example

The practice

The firm behind this SharePoint for accountancy firms build has seven partners, eighteen qualified and part-qualified staff, six in tax and ten in administration and payroll: 41 named people across three offices. Add nine shared mailboxes and four service accounts and the tenant carries 54 identities. The client list runs to 1,180 active clients, and the old file server held roughly 640 GB of client data.

The storage picture

The tenant behind SharePoint for accountancy firms is entitled to 1 TB plus 10 GB per licence. With 41 licences that is 1,024 GB plus 410 GB, or 1,434 GB in total. The existing 640 GB of client data uses 45% of it, which leaves comfortable headroom for a decade of growth before the archive conversation becomes necessary.

The licence cost of SharePoint for accountancy firms

At £16.90 per user per month, 41 SharePoint for accountancy firms licences cost £692.90 a month, or £8,314.80 a year, which is £202.80 per person. Adding the Purview Suite at £7.70 takes the monthly figure to £1,008.60 and the annual figure to £12,103.20. Taking both suites at £11.50 takes it to £1,164.40 a month and £13,972.80 a year.

The comparison that matters

E3 for the same 41 people is £16,482 a year and E5 is £25,387.20. Business Premium with both add-on suites lands at £13,972.80, which is £2,509.20 below E3 and £11,414.40 below E5 while delivering the data protection controls this guide relies on.

Annual Microsoft 365 cost for 41 people, each option scaled against E5
Business Premium — £8,314.80
+ Purview Suite — £12,103.20
+ both suites — £13,972.80
Microsoft 365 E3 — £16,482.00
Microsoft 365 E5 — £25,387.20
Bars scaled to the most expensive option in the series (E5 at £25,387.20).

The backup bill

If the practice protects 640 GB of client data with Microsoft 365 Backup at $0.15 per GB per month, that is $96 a month, or $1,152 a year. Protecting only the AML and payroll sites, say 120 GB, costs $18 a month or $216 a year. Restores are free either way.

Putting the number in proportion

The Purview Suite for this practice costs £3,788.40 a year on top of the base licence. Across 252 working days that is £15.03 a day. The Information Commissioner’s Office penalty against DPP Law was £60,000, which is close to sixteen years of that spend.

How many years of each control a single £60,000 penalty would fund, for 41 people
Purview Suite alone, £3,788.40/yr — 15.8 years
Both add-on suites, £5,658.00/yr — 10.6 years
The whole Business Premium base, £8,314.80/yr — 7.2 years
Bars scaled to the longest period in the series (15.8 years).

The Thirty-Day Build Calendar for SharePoint for Accountancy Firms

Week one: decide what SharePoint for accountancy firms must hold

Seven tasks. Inventory what SharePoint for accountancy firms will actually hold against the seven categories. Confirm the tenant-level external sharing setting and write down what it is today. Read the current site inventory. Agree the seven-site model with the partners. Create the Entra security groups. Build the client term set. Choose the four sensitivity labels.

Week two: build the estate

Nine tasks. Create the seven SharePoint for accountancy firms sites and the hub. Create the libraries and the four columns. Index the three filtered columns. Build the standard views. Publish the sensitivity labels and set container labels on each site. Set the default library labels on AML and payroll. Set per-site external sharing. Configure guest expiry. Set version limits to Automatic.

Week three: protect and restrict

Eight tasks. Enable site-level access restriction across SharePoint for accountancy firms. Apply restricted access control to the AML, payroll and firm administration sites. Turn off sharing outside the control groups. Configure unmanaged-device access per site. Disable Anyone links on every restricted site. Publish the four retention labels. Configure auto-apply rules. Run the DLP policies in simulation.

Week four: migrate, verify and hand over

Seven tasks. Migrate the client data into SharePoint for accountancy firms. Run a path-length report and fix anything over 400 characters. Enable Microsoft 365 Backup on the three critical sites. Turn the DLP policies on. Run the access-denials report and fix legitimate blocks. Train staff on views rather than folders. Book the first quarterly access review.

Cumulative build tasks completed, of 31 total
End of week one — 7 of 31
End of week two — 16 of 31
End of week three — 24 of 31
End of week four — 31 of 31
Bars scaled to the full task count (31).
WeekThemeTasksOwnerEvidence produced
OneDecide and measure7Partner plus IT providerData inventory, site plan
TwoBuild the estate9IT providerSite and label configuration export
ThreeProtect and restrict8IT provider plus MLROPolicy list, simulation report
FourMigrate and hand over7IT provider plus practice managerMigration log, denials report

Migrating Into SharePoint for Accountancy Firms Without Breaking Trust

Decide what never enters SharePoint for accountancy firms

The cheapest migration into SharePoint for accountancy firms is the one that carries less. Duplicate scans, superseded drafts, personal files, and client years beyond the retention period should be archived or deleted rather than moved. Every gigabyte you leave behind is a gigabyte you never have to permission, label, retain or back up.

Fix the path lengths before you move

The 400-character limit in SharePoint for accountancy firms counts the whole decoded path including the file name. A file server folder tree that already runs deep will produce failures, and they are far cheaper to fix in a report than in a cutover. Run the length report during discovery, not on migration night.

Map permissions to groups, not to people

Take the NTFS permissions, discard them, and rebuild SharePoint for accountancy firms against the group model. Practices that translate share permissions one for one end up recreating exactly the sprawl they were trying to escape. This is the single decision that determines whether SharePoint for accountancy firms is better than the file server or merely newer.

Move into SharePoint for accountancy firms in the right order

Knowledge and templates first, because nobody minds if it breaks. Then practice management. Then client documents by office or by partner group. AML and payroll last, when the restrictive controls are already proven. The client portal is created empty and never migrated into.

Do not migrate into folders you plan to delete

If the destination is metadata-driven, do not stage the data in a folder tree and promise to tidy it later. It will not get tidied. Map the client and period columns during the migration itself, even if it slows the run.

Retire the old share properly

Set the old file server share to read-only on the SharePoint for accountancy firms cutover day rather than deleting it, and keep it for the enquiry period agreed with the partners. Then decommission it, and record that you did. A live legacy share is a second copy of every client record with none of the controls described in this guide.

Mistakes That Undo SharePoint for Accountancy Firms

Leaving external sharing at the default

External sharing is on by default across the whole SharePoint for accountancy firms environment. A practice that never checked it has an estate where any member of staff can create a link for a person outside the firm. This is the first thing to check and the fastest to fix.

Using Anyone links for client deliverables

They are unauthenticated, untrackable, forwardable, and exempt from the unmanaged-device policies you carefully configured. If a client genuinely cannot sign in, use a verification code rather than an anonymous link.

Building one site per client

It looks tidy and it breaks DLP scoping at 100 sites, multiplies every policy by the size of the client list, and guarantees inconsistency. Metadata scales; site sprawl does not.

Managing access with folder permissions

Every broken inheritance is a unique permission scope, and the recommended limit is 5,000 per library. Above 100,000 items you cannot break or reinherit at all. Use separate sites for separate audiences instead.

Trimming version history to save storage

Versions in SharePoint for accountancy firms removed by a limit change or a trim job bypass the recycle bin and cannot be recovered. Storage is cheap; a library you cannot roll back after an incident is not.

Assuming retention is backup

Retention will not rebuild a SharePoint for accountancy firms library after mass encryption, and the recycle bin ends at 93 days. Decide deliberately whether you are covered, and test a restore.

Putting AML evidence in the client folder

It is the highest-risk category in SharePoint for accountancy firms and the easiest to isolate. A separate site, restricted access control, no external sharing and a five-year label costs an afternoon.

Granting permissions to individuals

Individual grants in SharePoint for accountancy firms are invisible in a group review and survive leaver processes. Groups only, without exception.

Turning on Copilot before reviewing permissions

An assistant surfaces what a SharePoint for accountancy firms permission model actually says rather than what people assume it says. Review first, or apply Restricted Content Discovery while you do.

Never reviewing access to SharePoint for accountancy firms again

In SharePoint for accountancy firms the build is not the control; the review is. A quarterly membership review signed off by the group owner is what makes the whole design hold together over five years.

Frequently Asked Questions About SharePoint for Accountancy Firms

Is SharePoint secure enough for client tax and AML records?

Yes, provided SharePoint for accountancy firms is configured. The service offers stronger access control, auditing, retention and recovery than any file server a small practice could run. What it does not do is configure itself, and the defaults are collaboration-friendly rather than practice-friendly.

Do we need Microsoft 365 E5?

Almost never for SharePoint for accountancy firms. Business Premium plus the Purview Suite delivers the data protection controls in this guide for £24.60 per user per month against E5 at £51.60. The exception is a practice that specifically needs SharePoint Advanced Management features, which are included with E5.

Should each client have their own site?

No. Use metadata for client identity in SharePoint for accountancy firms and reserve sites for genuinely different audiences and sensitivity levels. Beyond the administrative burden, DLP can only be scoped to 100 sites per policy.

Can we give clients access without buying them licences?

Yes. Guests can view and edit documents through the browser without a licence, and can act on a site according to the permission level you grant. They need a licence only for capabilities such as their own OneDrive storage or building a Power Automate flow.

How long does SharePoint keep a deleted file?

In SharePoint for accountancy firms a 93-day retention period spans the first-stage and second-stage recycle bins, after which the file is permanently deleted. Retention labels and policies override that, and versions removed by a library limit or a trim job skip the recycle bin entirely.

What happens when we run out of storage?

The tenant gets 1 TB plus 10 GB per licence. Extra storage can be bought in 1 GB increments. If a tenant keeps operating above its limit, Microsoft warns the environment risks going read-only, meaning nobody can add or change content.

Why do our views break at 5,000 items?

That is the list view threshold, and administrators cannot change it in SharePoint Online. Index the columns SharePoint for accountancy firms filters on and make sure every default view returns fewer than 5,000 rows. The library itself can hold up to 30 million items.

Can we stop staff downloading client files at home?

Yes. Set unmanaged-device access to limited web-only, which removes download, print, sync and desktop app access while keeping browser access. Remember that Anyone links bypass this, so disable them on those sites.

Does Copilot read our whole client library?

It answers using content the signed-in user already has permission to read, which is exactly why permission review comes before rollout. Restricted Content Discovery and restricted access control both keep specified sites out of Copilot responses.

How often should we review permissions?

Review SharePoint for accountancy firms quarterly, with the group owner signing off rather than IT. Pair it with the access-denials report, which shows the most recent 100 denials from the past 28 days interactively and up to 10,000 if downloaded.

Who should build SharePoint for accountancy firms?

Someone who will still be answerable for it in three years. Most practices use their managed IT services provider for the build and keep the review cycle in-house. If you want a second opinion on an existing estate, our team offers a fixed-scope review of any SharePoint for accountancy firms deployment.

References and Further Reading

SharePoint limits – Microsoft Service Descriptions

Overview of external sharing in SharePoint and OneDrive

Manage sharing settings for SharePoint and OneDrive

Change the external sharing setting for a site

Restrict SharePoint site access with Microsoft 365 and Entra security groups

Restrict discovery of SharePoint sites and content

Control access from unmanaged devices

Use app-enforced restrictions with Conditional Access

Version history limits for document libraries and OneDrive

Set default organisation version history limits

Change version history limits for a site

Learn about retention for SharePoint and OneDrive

Learn about retention policies and retention labels

Learn about records management in Microsoft Purview

Disposition of content in Microsoft Purview

Data Loss Prevention policy reference

Learn about data loss prevention

Learn about sensitivity labels

Use sensitivity labels to protect groups and sites

Enable sensitivity labels for files in SharePoint and OneDrive

Microsoft Purview audit log activities

Microsoft Purview eDiscovery solutions

Pricing model for Microsoft 365 Backup

Overview of Microsoft 365 Backup

Pricing model for Microsoft 365 Archive

Overview of Microsoft 365 Archive

Data access governance reports in SharePoint

Prerequisites for SharePoint Advanced Management

Planning your SharePoint hub sites

Introduction to managed metadata in SharePoint

Manage large lists and libraries in SharePoint

Restore a shared library in SharePoint

Money Laundering Regulations 2017, regulation 40 – record keeping

ICAEW – Money Laundering Regulations 2017

ICAEW – Anti-money laundering for smaller practices

ICAEW – What is required of an AML supervised firm

ICO – A guide to data security

ICO – Personal data breach reporting

Cyber Security Breaches Survey 2025/2026

NCSC – Small business guide to response and recovery

NCSC – Cyber Action Toolkit for small businesses

IASME – Cyber Essentials

Microsoft 365 for business – UK plans and pricing

Microsoft 365 enterprise plans and pricing – UK

Microsoft Purview service description

Microsoft 365 Copilot licensing requirements

Set up secure collaboration with Microsoft 365

Policy recommendations for securing SharePoint sites and files