SharePoint for accountancy firms is bought as a storage decision and lived with as a security one. A practice signs up for Microsoft 365, the old file server gets copied into a document library, and within eighteen months the same firm is holding every client’s identity documents, bank statements, payroll records and tax computations in a system nobody has ever configured. The files are safer than they were on a cupboard server. The permissions around them are usually worse.
That gap matters more in accountancy than in almost any other small business. A practice holds the personal data of people who are not its clients, the financial records of businesses that are, and the anti-money laundering evidence that a supervisor can ask to see at any time. Getting SharePoint for accountancy firms right is therefore a compliance exercise with a collaboration tool attached, not the other way round. This guide covers the site architecture, the permission model, the sharing settings, the labels, the retention rules and the recovery layers that a UK practice actually needs.
Everything below is written against Microsoft’s own current documentation and UK list pricing, with a worked example based on a forty-one person, three-office practice. If your firm is still on a file server, the companion guides to SharePoint migration cost and file server to SharePoint migration cover the move itself. This one covers what you build once the data has landed.
Table of contents
- Why SharePoint for Accountancy Firms Is a Security Question, Not a Storage One
- What SharePoint for Accountancy Firms Actually Has to Protect
- The Site Architecture Behind SharePoint for Accountancy Firms
- Libraries and Metadata in SharePoint for Accountancy Firms
- Permissions: The Model SharePoint for Accountancy Firms Should Use
- External Sharing in SharePoint for Accountancy Firms and the Client Portal
- Sensitivity Labels Across SharePoint for Accountancy Firms
- Data Loss Prevention Across SharePoint for Accountancy Firms
- Retention, MLR Regulation 40 and Disposal in SharePoint for Accountancy Firms
- Versioning, Recycle Bins and Ransomware Recovery in SharePoint for Accountancy Firms
- Devices: Where SharePoint for Accountancy Firms Lets Documents Land
- Copilot, Search and Oversharing in SharePoint for Accountancy Firms
- The Hard Limits on SharePoint for Accountancy Firms
- Backup: Where SharePoint for Accountancy Firms Still Needs More
- Auditing SharePoint for Accountancy Firms and Proving What Happened
- What SharePoint for Accountancy Firms Costs
- SharePoint for Accountancy Firms: A Forty-One Person Worked Example
- The Thirty-Day Build Calendar for SharePoint for Accountancy Firms
- Migrating Into SharePoint for Accountancy Firms Without Breaking Trust
- Mistakes That Undo SharePoint for Accountancy Firms
- Frequently Asked Questions About SharePoint for Accountancy Firms
- References and Further Reading
Why SharePoint for Accountancy Firms Is a Security Question, Not a Storage One
The file server habits that arrive with SharePoint for accountancy firms
Most practices arrive in SharePoint for accountancy firms carrying a folder tree that was designed around a mapped drive. There is a folder per client, a folder per year inside it, and a permission set that was last reviewed when someone left in 2019. Copying that structure into a document library preserves every one of its weaknesses and adds a new one: the contents are now reachable from any browser in the world, subject only to whatever sign-in controls the practice has configured.
The reason SharePoint for accountancy firms so often ends up over-permissioned is that nothing in the migration forces a decision. A file copy tool will happily reproduce a share where “Domain Users” had modify rights on the whole client tree. Nobody notices, because the experience for staff is identical to the one they had before.
What a breach actually costs a UK practice
The Cyber Security Breaches Survey 2025/2026, published on 30 April 2026, found that 43% of UK businesses had identified a breach or attack in the previous twelve months. The rate climbs sharply with size: 42% of micro businesses, 46% of small businesses, 65% of medium businesses and 69% of large businesses. Only 47% of businesses had two-factor authentication in place.
Most firms running SharePoint for accountancy firms sit in the micro and small bands, where the headline rate looks reassuring. It is not, because the survey counts identified breaches, and a firm with no audit review and no alerting identifies very few.
The regulator’s view of client records
The Information Commissioner’s Office fined DPP Law £60,000 after a cyber attack in which a large volume of sensitive legal data was exfiltrated. The parallel for an accountancy practice is exact: the regulator’s concern is not that an attack happened but that basic controls were missing. Cybersecurity failings of that kind are almost always configuration failings rather than technology failings, which is precisely why SharePoint for accountancy firms deserves a deliberate build rather than a default one.
Where SharePoint for accountancy firms fits in this series
This is the ninth article in our accountancy series. It assumes the identity layer is already in place. If it is not, start with the Microsoft 365 security checklist for accountancy firms and the Conditional Access policy baseline, then come back here for the document layer.
What SharePoint for Accountancy Firms Actually Has to Protect
Before designing anything, list what SharePoint for accountancy firms will hold. The exercise takes an afternoon and it changes the architecture, because the seven categories below have genuinely different sharing, retention and access requirements. Treating them as one pile is the root cause of most of the problems in this guide.
Client permanent files
Incorporation documents, share registers, memorandums and articles, historic accounts, correspondence with Companies House. These change rarely, are referenced for years, and are the files most likely to be requested by a client who left in 2021 and came back in 2026. They need long retention and low churn.
Current-year working papers
Trial balances, lead schedules, journals, reconciliations, review notes. These change daily during a job, are worked on by two or three people, and become read-only the moment the file is signed off. Versioning matters here more than anywhere else in the practice.
Anti-money laundering evidence
Identity documents, proof of address, beneficial ownership records, risk assessments, source-of-funds notes. Regulation 40 of the Money Laundering Regulations 2017 requires these to be kept for five years from the end of the business relationship. They are also the single most damaging category to lose control of, because they are copies of somebody’s passport.
Payroll and personal data
Payslips, P60s, starter and leaver forms, pension records, bank details for net pay. This is special-category-adjacent personal data belonging to people who have no relationship with the practice at all, and it is the category most often left in a general client folder where the whole team can read it.
Tax computations and HMRC correspondence
Returns, computations, agent authorisations, HMRC letters, enquiry correspondence. Sensitive, time-bound, and increasingly subject to agent access requirements that assume the practice can prove who touched what.
Engagement letters and fee data
Letters of engagement, scope schedules, fee quotes, write-offs, WIP reports. Commercially sensitive within the firm as well as outside it. Partners routinely want this restricted from junior staff, which is exactly the kind of requirement that folder-level permissions handle badly.
The practice’s own records
HR files, partnership agreements, PII policies, supplier contracts, its own accounts. This should never live in the client estate, and in a well-built SharePoint for accountancy firms deployment it never does.
| Category | Typical churn | External sharing | Retention driver |
|---|---|---|---|
| Client permanent files | Very low | Occasional, read-only | Client relationship life |
| Current-year working papers | Very high | Never | Professional standards |
| AML evidence | Low | Never | MLR 2017 reg 40 — five years |
| Payroll and personal data | Monthly | Restricted, per client | Employment and tax law |
| Tax and HMRC correspondence | Seasonal | Restricted, per client | Enquiry windows |
| Engagement letters and fees | Low | Signed copies only | Contract life plus limitation |
| Practice’s own records | Low | Never | Internal policy |
The Site Architecture Behind SharePoint for Accountancy Firms
Why one site per client does not scale
The instinct in SharePoint for accountancy firms is to give every client its own site. Microsoft will let you: the limit is two million sites per organisation. The problem is not the ceiling, it is the administration. A practice with 1,180 active clients would be running 1,180 sharing settings, 1,180 sensitivity labels, 1,180 permission sets and 1,180 retention scopes, and every new client would require a provisioning step that somebody has to remember.
Worse, Data Loss Prevention in Microsoft Purview can only be scoped to up to 100 individual SharePoint sites per policy. A site-per-client model puts you past that ceiling on day one, and the only way back is administrative units or an all-sites policy that you cannot tune.
The seven-site model for SharePoint for accountancy firms
A far better shape for SharePoint for accountancy firms is a small number of sites separated by sensitivity and audience, with the client identity carried as metadata rather than as a site boundary. Seven sites covers almost every general practice.
Client documents
The main working site in SharePoint for accountancy firms. One library, every client, every year, separated by columns and views rather than by top-level folders. This is where the accounts, bookkeeping and tax work happens.
Anti-money laundering
A separate site with external sharing turned off entirely, restricted access control applied, and a five-year retention label published to it. Keeping AML evidence out of the general client site is the single highest-value architectural decision in the whole build.
Payroll
A separate site because the audience is different: payroll staff plus one nominated contact per client, and nobody else. Payroll is also the category most likely to trigger a DLP match, so isolating it makes the policy far easier to tune.
Client portal
The only site with external sharing enabled, and even then set to New and existing guests rather than Anyone. Deliverables are copied here for signature or collection; nothing is worked on here.
Practice management
Engagement letters, fee schedules, WIP, client acceptance. Partner and manager audience only.
Firm administration
HR, insurance, partnership documents, supplier contracts, the practice’s own accounts. Completely separate from the client estate.
Knowledge and templates
Checklists, letter templates, standard working papers, technical updates. Read for everyone, write for a small group. This is the one site where broad access is correct.
| Site | Audience | External sharing | Container label | Unmanaged devices |
|---|---|---|---|---|
| Client documents | All fee earners | Only people in your organization | Confidential | Limited web-only |
| Anti-money laundering | MLRO plus nominated staff | Only people in your organization | Highly Confidential | Block |
| Payroll | Payroll team | Only people in your organization | Highly Confidential | Block |
| Client portal | Client-facing staff plus guests | New and existing guests | Confidential — external | Limited web-only |
| Practice management | Partners and managers | Only people in your organization | Confidential | Limited web-only |
| Firm administration | Partners and practice manager | Only people in your organization | Highly Confidential | Block |
| Knowledge and templates | Everyone | Only people in your organization | General | Full access |
Hub sites and navigation in SharePoint for accountancy firms
Associate the seven sites with a single hub so staff get one navigation bar and one scoped search. Microsoft allows up to 2,000 hub sites per organisation, and all navigation types are limited to 500 child links at each level, so a practice will never come close to either ceiling. One hub is the right answer.
Naming conventions that survive a partner change
Name sites in SharePoint for accountancy firms for function, never for people. A site called “Client Documents” outlives three managing partners; a site called “Sarah’s Clients” creates an orphan the moment Sarah retires. The same rule applies to the Microsoft 365 groups behind them.
Why subsites are the wrong tool in SharePoint for accountancy firms
SharePoint supports 2,000 subsites per site collection, and Microsoft explicitly recommends creating sites and organising them into hubs instead. Subsites inherit permissions in ways that are hard to reason about later, and they cannot be moved. A SharePoint for accountancy firms build should contain none.
Libraries and Metadata in SharePoint for Accountancy Firms
The client column that anchors SharePoint for accountancy firms
Create a managed metadata column in SharePoint for accountancy firms, populated from a term set of active clients. Every document in the client documents library carries it. The term store supports one million terms, so a practice with 1,180 clients uses roughly a tenth of one percent of the ceiling.
The year column
A simple choice column for the accounting period is the second pillar of SharePoint for accountancy firms. This is what makes “show me everything for this client, this year” a two-click view rather than a folder dive, and it is what lets retention rules key off a period rather than a file date.
The document type column
Accounts, tax return, bookkeeping, correspondence, permanent, AML, payroll. Seven values in SharePoint for accountancy firms, no more. Long option lists never get used consistently and become worse than no metadata at all.
Views instead of folders in SharePoint for accountancy firms
Once the three columns exist, build views: My open jobs, This client all years, Year-end pack, Awaiting review. Staff stop navigating and start filtering. This is the change that makes SharePoint for accountancy firms feel faster than the file server rather than slower.
The 5,000-item list view threshold
SharePoint for accountancy firms inherits a list view threshold of 5,000 items, and administrators cannot raise it. This is the single most common complaint after a migration, and it is entirely avoidable: index the columns you filter on, and make sure every default view has a filter that returns fewer than 5,000 rows. The library itself can hold far more.
How many items a library can actually hold
A list in SharePoint for accountancy firms can hold up to 30 million items and a library up to 30 million files and folders. A practice will never reach that. What it will reach, if it uses folders, is the point at which no view returns quickly, which is why metadata is a performance decision as much as a usability one.
| Column | Type | Indexed | Why it exists |
|---|---|---|---|
| Client | Managed metadata | Yes | Replaces the top-level folder |
| Period | Choice | Yes | Replaces the year folder and drives retention |
| Document type | Choice | Yes | Drives views and auto-labelling |
| Status | Choice | No | Draft, in review, signed off |
| Owner | Person | No | Accountability, not permission |
Permissions: The Model SharePoint for Accountancy Firms Should Use
Groups, not people, across SharePoint for accountancy firms
Every permission in SharePoint for accountancy firms should be granted to a Microsoft 365 group or an Entra security group, never to an individual. Individual grants are invisible in a group listing, survive a leaver process, and are the reason permission reviews in most practices are meaningless. This rule costs nothing to adopt on day one and is painful to retrofit later.
The three permission levels you actually need
Most firms building SharePoint for accountancy firms need only three: Read for people who consume, Contribute for people who produce, and Full Control for two named administrators. Edit and Design are rarely the right answer, and Full Control on a client library should never be held by more than a handful of people.
Unique permissions and where they go wrong
SharePoint for accountancy firms supports up to 50,000 unique permission scopes per list or library, but Microsoft’s recommended general limit is 5,000. Every folder or file where somebody clicks “stop inheriting permissions” creates one. A practice that manages access per client folder will pass the recommended limit long before it passes the supported one, and performance degrades on the way.
The 100,000-item inheritance wall
When a list, library or folder contains more than 100,000 items, you cannot break permission inheritance on it, and you cannot reinherit permissions on it either. You can still break inheritance on individual items inside it. A large client library that has grown for a decade can therefore reach a state where the permission model you want is no longer available to you.
Restricted access control in SharePoint for accountancy firms
Restricted access control limits a site in SharePoint for accountancy firms to members of specified Microsoft 365 groups or Entra security groups. Users not in the group cannot reach the site or its content even if they had prior permissions or a shared link. You can configure up to 10 groups per site, and the policy is honoured in organisation-wide search and in Microsoft Copilot responses.
Why restricted access control is the right tool for AML
Belt and braces is exactly right for anti-money laundering evidence in SharePoint for accountancy firms. Permissions say who is allowed in; restricted access control says who is allowed in at all, and it catches the case where an old direct grant or a forgotten sharing link would otherwise still work. Note that a user needs both the content permission and group membership.
The sharing gap you must close
By default, sharing a site or its content does not follow the restricted access control policy. That is a deliberate Microsoft default and a poor one for SharePoint for accountancy firms. Close it with Set-SPOTenant -AllowSharingOutsideRestrictedAccessControlGroups $false, which blocks sharing with anyone outside the control group.
| Group | Client documents | AML | Payroll | Practice management |
|---|---|---|---|---|
| Partners | Contribute | Read | Read | Contribute |
| Managers | Contribute | None | None | Contribute |
| Qualified staff | Contribute | None | None | None |
| Tax team | Contribute | None | None | None |
| Payroll team | Read | None | Contribute | None |
| MLRO and deputies | Read | Contribute | None | Read |
| Administrators (2 named) | Full Control | Full Control | Full Control | Full Control |
External Sharing in SharePoint for Accountancy Firms and the Client Portal
External sharing is on by default
Microsoft states plainly that external sharing is turned on by default for your entire SharePoint and OneDrive environment, and recommends turning it off globally before people start using sites. Very few firms running SharePoint for accountancy firms have ever read that sentence. Checking it is the fastest security win available in any SharePoint for accountancy firms review.
The four sharing settings SharePoint for accountancy firms chooses between
SharePoint for accountancy firms has four levels to choose from. Anyone allows links that work without authentication. New and existing guests requires recipients to sign in with a work, school or Microsoft account, or to enter a verification code. Existing guests allows sharing only with guests already in your directory. Only people in your organization turns external sharing off.
Site-level overrides and the most-restrictive rule
Sharing settings in SharePoint for accountancy firms exist at both organisation and site level. To allow external sharing on any site you must allow it at the organisation level, then restrict it per site. Where the two disagree, the most restrictive value always applies, and OneDrive can be the same as or more restrictive than SharePoint, never more permissive.
Why a practice should set the tenant to guests, not Anyone
The pragmatic setting for SharePoint for accountancy firms is New and existing guests at the organisation level, with every site except the client portal set to Only people in your organization. That gives you an authenticated audit trail for every external recipient while keeping the blast radius to a single site.
Anyone links and why they are dangerous here
Anyone links in SharePoint for accountancy firms are unauthenticated. Anybody who receives one, forwards one, or finds one in an email thread can open the file, and you cannot track who has access or who has accessed it. There is a second, less-known problem: Anyone links are not affected by conditional access policies that block or limit unmanaged devices. Microsoft’s own guidance is to disable Anyone links for every site where you enable those policies.
If SharePoint for accountancy firms must allow Anyone links
Restrict them inside SharePoint for accountancy firms. You can require all Anyone links to expire within a specified maximum number of days, and you can restrict them to View permission only. If you shorten the expiry period, existing links update to the shorter setting; if you lengthen it, existing links keep their current expiry.
Guest expiry and verification codes for SharePoint for accountancy firms
Two settings deserve to be turned on in every SharePoint for accountancy firms build. Guest access to a site or OneDrive will expire automatically after this many days puts a clock on every guest. People who use a verification code must reauthenticate after this many days forces recipients who stayed signed in to prove they still control the mailbox they redeemed the invitation with.
Domain restrictions
SharePoint for accountancy firms can limit external sharing to a list of allowed domains, or block specific ones, up to a maximum of 5,000 domains. For a practice with a stable set of referral partners, solicitors and lenders, an allow-list is realistic and dramatically narrows the exposure of the client portal.
Turning sharing off does not remove guests
If you turn off external sharing for the organisation and later turn it back on, guests regain access. If you know sharing was previously in use on specific sites and you do not want those guests back, turn it off for those sites first. When you do restrict or disable sharing, guests typically lose access within one hour.
| Setting | Who can receive content | Audit trail | Right for a practice? |
|---|---|---|---|
| Anyone | Anyone with the link, no sign-in | None | No |
| New and existing guests | Anyone who signs in or enters a code | Full | Yes — tenant default |
| Existing guests | Guests already in the directory | Full | Optional for the portal |
| Only people in your organization | Staff only | Full | Yes — every site but the portal |
Sensitivity Labels Across SharePoint for Accountancy Firms
Container labels versus file labels
Sensitivity labels in SharePoint for accountancy firms come in two flavours that people constantly conflate. A container label applies to a SharePoint site, a Microsoft 365 group or a Teams team, and controls privacy, external user access, access from unmanaged devices and the default sharing link. A file label applies to a document and can carry encryption that travels with the file wherever it goes.
Why a practice needs both
A container label stops the wrong people getting into the AML site. A file label stops a payroll spreadsheet being readable after somebody emails it to a personal address. Neither substitutes for the other, and a mature SharePoint for accountancy firms build uses both.
A four-label scheme for SharePoint for accountancy firms
Four labels is enough for SharePoint for accountancy firms: General for templates and internal notices, Confidential for client work, Confidential — external for anything deliberately shared with a client, and Highly Confidential for AML, payroll and firm administration. More than four and staff stop reading the names.
Default labels on a document library
You can set a default sensitivity label on a document library through Library settings, which applies to new and unlabelled files. On the AML and payroll libraries this means every file is labelled correctly without anyone remembering to do it, which is the only labelling scheme that survives a busy January.
What labels do that permissions cannot
Permissions in SharePoint for accountancy firms stop at the boundary of the tenant. Encryption from a sensitivity label does not: a labelled file that leaves in an email attachment, on a USB stick or through a personal cloud sync is still unreadable to anyone outside the permitted group. For a practice worried about a leaver taking the client base, that difference is the whole argument.
| Label | Applied to | Encryption | Guest access | Unmanaged devices |
|---|---|---|---|---|
| General | Templates, knowledge site | No | Not allowed | Full access |
| Confidential | Client documents, practice management | No | Not allowed | Limited web-only |
| Confidential — external | Client portal, signed deliverables | Optional | Allowed | Limited web-only |
| Highly Confidential | AML, payroll, firm administration | Yes | Not allowed | Block |
Data Loss Prevention Across SharePoint for Accountancy Firms
What DLP can actually do in SharePoint
For SharePoint and OneDrive, Microsoft Purview DLP supports one main action: restrict access or encrypt the content. The options are block everyone, block only people outside your organisation, or block access for specific external domains or users. Microsoft is explicit that documents are proactively blocked right after detection of sensitive information, regardless of whether the document has been shared, for all guests, while internal users continue to have access.
The sensitive information types that matter in a practice
For SharePoint for accountancy firms, start with UK National Insurance number, UK passport number, UK driver’s licence number, credit card number, IBAN and SWIFT code, and EU or UK bank account number. Those six catch the overwhelming majority of genuinely dangerous content in an accountancy estate.
The 100-site scoping limit
DLP supports scoping policies to up to 100 individual SharePoint sites. With the seven-site model that is a non-issue. With a site-per-client model it is a hard wall, which is one more reason the architecture in this guide is shaped the way it is.
Other limits worth knowing
A tenant supports a maximum of 600 DLP rules, each rule and each policy is capped at 100 KB, and DLP scans the first two million characters of a file and the first three levels of nesting. None of these constrain a practice, but they explain why an over-engineered policy set eventually fails to save.
Start SharePoint for accountancy firms policies in simulation mode
Every DLP policy in SharePoint for accountancy firms should run in simulation first. A policy that blocks guest access to anything containing a bank account number will match your own remittance advices, your bank feeds and half of your payroll library. Simulation shows you that before your clients do.
| Policy | Scope | Detects | Action |
|---|---|---|---|
| Identity documents | All sites | Passport, driver’s licence, NI number | Block external |
| Bank details | All sites | Account number, IBAN, SWIFT | Block external |
| Card data | All sites | Credit card number | Block everyone, notify |
| AML lockdown | AML site | Retention label “AML five year” | Block external |
| Payroll lockdown | Payroll site | Sensitivity label “Highly Confidential” | Block external |
Retention, MLR Regulation 40 and Disposal in SharePoint for Accountancy Firms
What the law requires of SharePoint for accountancy firms
Regulation 40 of the Money Laundering Regulations 2017 requires a relevant person to keep copies of the documents and information obtained to satisfy customer due diligence for five years. ICAEW guidance puts the same requirement plainly: customer due diligence records must be kept for five years following the end of the business relationship. Record keeping under the regulations is not subject to the risk-based approach, so there is no room for a judgement call about how much to keep.
Retention policies, retention labels and records
Microsoft Purview offers SharePoint for accountancy firms three levels. A retention policy applies to a location and retains everything in it. A retention label applies to an item and can be published for users to apply or auto-applied by a query. A label can also mark an item as a record or a regulatory record, which blocks deletion outright. The behaviour differs sharply, and picking the wrong one is the most common retention mistake in SharePoint for accountancy firms.
How each behaves when a file is edited or deleted
Under a retention policy, both editing and deleting an item create a copy in the Preservation Hold library. Under a standard retention label, editing does not create a copy but deleting does. Under a label that marks items as records, editing an unlocked item creates a copy while editing a locked item and deleting are both blocked. Under a regulatory record label, editing and deleting are always blocked.
The Preservation Hold library
SharePoint for accountancy firms creates a hidden Preservation Hold library on any site subject to retention. Microsoft is explicit that it is not designed to be used interactively, and that editing, deleting or moving the files inside it, or changing their labels, is unsupported. Reach the content through eDiscovery instead.
The thirty-seven day disposal clock
A timer job runs periodically on the Preservation Hold library. For content that has been there more than 30 days, the job compares it against the retention queries and deletes anything past its period. That job runs every seven days, so together with the 30-day minimum it can take up to 37 days for content to leave the Preservation Hold library. Plan disposal reporting around that window, not around the label’s expiry date.
Where deleted content actually goes
Expired content moves to the second-stage recycle bin and is permanently deleted at the end of 93 days. Microsoft notes that it no longer permanently deletes content directly from the Preservation Hold library, precisely to prevent inadvertent data loss. A 93-day retention period spans both the first-stage and second-stage recycle bins, and the recycle bin is not indexed, so eDiscovery cannot search it.
A retention scheme for SharePoint for accountancy firms
Publish four retention labels across SharePoint for accountancy firms. AML five year auto-applied by document type on the AML site. Client records seven year on the client documents site. Payroll six year on the payroll site. Practice records on firm administration. Auto-apply by the document type column wherever possible, because manual labelling in a practice does not survive January.
Retention overrides versioning
This catches people out in SharePoint for accountancy firms. For items subject to a retention policy or an eDiscovery hold, the versioning limits on the document library are ignored until the retention period is reached or the hold is released. Old versions are not automatically purged and users cannot delete versions. Retention labels behave differently: when there is no policy or hold, versioning limits are honoured, though users still cannot delete versions.
| Mechanism | Copy on edit | Copy on delete | Deletion blocked? | Use it for |
|---|---|---|---|---|
| Retention policy | Yes | Yes | No | Whole-site floors |
| Standard retention label | No | Yes | Configurable | AML, payroll, client records |
| Label marking a record | Yes (unlocked) | Blocked | Yes | Signed accounts, filed returns |
| Regulatory record | Blocked | Blocked | Always | Rarely needed in practice |
Versioning, Recycle Bins and Ransomware Recovery in SharePoint for Accountancy Firms
Automatic versus manual version limits in SharePoint for accountancy firms
Version history limits in SharePoint for accountancy firms can be set at organisation, site or library level, and a site or library can break inheritance from the organisation default. There are two modes. The Automatic setting is Microsoft’s recommendation and optimises storage using a time-based thinning schedule. The Manual setting lets an administrator set a major version count, optionally with an expiration period.
What the numbers actually are
Under the Automatic setting, users have access to a maximum of 500 versions created within the last 30 days. Under Manual, the interface will not accept a value below 100 major versions or an expiration below 30 days, though public APIs can set lower values. Microsoft warns that anything below those floors risks inadvertent data loss. The absolute ceiling is 50,000 major versions and 511 minor versions.
Trimmed versions do not go to the recycle bin
This is the detail that matters most for SharePoint for accountancy firms. When versions exceed the limits set on a library, they are marked for permanent deletion, and that workflow bypasses the recycle bin entirely. The same is true of a scheduled trim job. Only versions a user deletes from a file’s version history go to the site recycle bin.
The ninety-three day recycle bin in SharePoint for accountancy firms
Deleted items in SharePoint for accountancy firms pass through a first-stage recycle bin visible to users and a second-stage recycle bin visible only to site collection administrators. A 93-day retention period spans both. At the end of 93 days the document is permanently deleted wherever it sits. Plan on the assumption that anything deleted more than three months ago is gone unless retention or backup caught it.
Restoring a library after a ransomware event
SharePoint’s Restore this library feature rolls a library back to a point in the last 30 days using version history, which is why version limits are a security control and not a storage setting. If your library keeps 500 versions from the last 30 days, you have a rollback path. If somebody trimmed versions to save space, you may not.
The sync client is part of your ransomware exposure
Microsoft recommends syncing no more than 300,000 files in a single OneDrive or team site library, and notes the same performance issues arise at 300,000 items across all libraries a user is syncing. A machine with a large synced library is also a machine that can encrypt a large synced library, which is a good reason to prefer browser and Teams access over sync for client work.
| Library | Version setting | Sync allowed? | Why |
|---|---|---|---|
| Client documents | Automatic | No | Rollback path plus reduced endpoint exposure |
| Anti-money laundering | Automatic | No | Blocked at device level anyway |
| Payroll | Automatic | No | Personal data must not leave the service |
| Client portal | Manual, 100 versions | No | Copies only, low value history |
| Knowledge and templates | Automatic | Yes | Non-sensitive, offline access useful |
Devices: Where SharePoint for Accountancy Firms Lets Documents Land
The three unmanaged-device options in SharePoint for accountancy firms
An administrator of SharePoint for accountancy firms can allow full access, allow limited web-only access, or block access outright for devices that are neither hybrid-joined nor compliant in Intune. The control can target all users or specific security groups, and all sites or specific sites. It relies on Microsoft Entra Conditional Access underneath.
What limited web-only access actually blocks
Users of SharePoint for accountancy firms on unmanaged devices get browser-only access with no ability to download, print or sync files, and no access through apps including the Office desktop applications. You can additionally choose whether editing in the browser is allowed. Blocked users see an explicit message: access denied due to organisation policy from an untrusted device.
The advanced switches worth knowing
-AllowEditing $false prevents editing Office files in the browser. -ReadOnlyForUnmanagedDevices $true makes the whole site read-only. -LimitedAccessFileType OfficeOnlineFilesOnly restricts preview to Office files only, which is more secure but does block PDFs. The default, WebPreviewableFiles, is more usable but Microsoft warns it can cause unexpected access-denied errors on PDFs and images.
The Anyone-link hole in the policy
Microsoft states it directly: Anyone links are not affected by these policies, and people holding one can download the item. For every site where you enable device restrictions in SharePoint for accountancy firms, disable Anyone links on that site as well, or the control is decorative.
Do it at the Microsoft 365 level, not just SharePoint
Microsoft’s own guidance is that a policy affecting all Microsoft 365 services gives better security and a better experience. Block SharePoint alone and a user on an unmanaged device can still read a Teams chat but loses the Files tab, which produces confusing support calls. Target the Office 365 cloud app in Conditional Access instead.
Give SharePoint for accountancy firms time, and check legacy apps
Changes can take up to 24 hours to take effect and will not affect users already signed in from unmanaged devices. Microsoft also recommends blocking apps that do not use modern authentication, because those apps cannot enforce device-based restrictions and can bypass the policy entirely.
| Option | Download | Sync | Desktop apps | |
|---|---|---|---|---|
| Allow full access | Yes | Yes | Yes | Yes |
| Allow limited, web-only access | No | No | No | No |
| Block access | No access at all | — | — | — |
Copilot, Search and Oversharing in SharePoint for Accountancy Firms
Why an AI assistant exposes permission debt
Microsoft 365 Copilot answers using content in SharePoint for accountancy firms that the signed-in user already has permission to read. That sounds safe until you remember what the permission model in most practices actually says. A junior with read access to a library containing partner remuneration will not find it by browsing, but they may well be handed it by an assistant that was asked a reasonable question.
Restricted Content Discovery
Restricted Content Discovery limits how content from specific sites appears in organisation-wide search results and Copilot responses, and removes AI entry points such as the Copilot button and AI action menus from those sites. It is explicitly designed as a temporary governance control while permissions are reviewed. It does not change permissions and does not remove content from the search index.
What it does not do
Microsoft is careful here, and so should you be. Restricted Content Discovery affects discoverability, not authorisation. A user with permission can still open the document directly or through a link. It also does not affect searches originating from site context, and it cannot be applied to OneDrive.
How long it takes to take effect
Index update latency depends on site size. Microsoft states that for sites with more than 500,000 items an update to Restricted Content Discovery could take more than a week to process fully and be reflected in search and Copilot experiences. Turn it on before the Copilot pilot, not during it.
Restricted access control does more
Where Restricted Content Discovery hides, restricted access control blocks. It is honoured in organisation-wide search and Copilot experiences too, and users denied by the policy cannot view that content in either. For the AML site in SharePoint for accountancy firms, that is the control you want.
A phased Copilot approach for SharePoint for accountancy firms
Review permissions with the Data Access Governance reports, apply Restricted Content Discovery to anything questionable, pilot Copilot with a small group, then lift the restriction site by site as each one is cleared. Our guide to Microsoft 365 Copilot security before rollout covers the wider readiness work.
The Hard Limits on SharePoint for Accountancy Firms
Storage entitlement arithmetic for SharePoint for accountancy firms
Every tenant running SharePoint for accountancy firms gets 1 TB plus 10 GB per licence purchased. Storage is calculated in binary gigabytes. Extra storage can be bought in 1 GB increments and is genuinely unlimited, but Microsoft warns that a tenant operating above its storage limit risks being put into read-only mode, meaning users cannot add or modify content.
The site ceiling nobody reaches
Maximum storage per site collection in SharePoint for accountancy firms is 25 TB, and a site that reaches it enters read-only mode until content is deleted or moved. A practice will not get there. Watch the tenant total instead, because that is the number that actually bites.
File size and path length
The file upload limit in SharePoint for accountancy firms is 250 GB per file, and 250 MB for a file attached to a list item. Multi-file ZIP downloads are capped at 20 GB. The one that genuinely trips up an accountancy migration is the path limit: the entire decoded file path, including the file name, cannot exceed 400 characters.
Lists, libraries and subsites
There is a combined limit of 2,000 lists and libraries per site collection, and 2,000 subsites per site collection. Neither constrains the seven-site model, and both are excellent reasons not to build the site-per-client alternative.
Permission scopes and groups
A user can belong to 5,000 groups per site collection, each group can have 5,000 users, and there can be up to 10,000 groups per site collection. Unique permission scopes are supported to 50,000 per list or library but recommended at 5,000.
Holds and compliance policy counts
There is a maximum of 13 holds when all SharePoint or OneDrive sites are automatically included, and 2,600 when specific locations are included or excluded. Holds, retention policies, DLP policies, information barriers and sensitivity labels together count towards a 10,000 per tenant maximum.
| Limit | Value | What happens in a practice |
|---|---|---|
| Tenant storage | 1 TB + 10 GB per licence | Read-only risk if exceeded |
| List view threshold | 5,000 items | Views break; index and filter |
| Items per list or library | 30 million | Never reached |
| Break inheritance blocked above | 100,000 items | Old client libraries lose flexibility |
| Unique permission scopes | 50,000 supported / 5,000 recommended | Per-folder security hits this |
| File path length | 400 characters | Migration failures |
| Sync recommendation | 300,000 files | Performance and ransomware exposure |
| DLP site scoping | 100 sites per policy | Kills the site-per-client model |
| Restricted access control groups | 10 per site | Ample for seven sites |
Backup: Where SharePoint for Accountancy Firms Still Needs More
Retention is not backup in SharePoint for accountancy firms
Retention in SharePoint for accountancy firms keeps things you were going to delete. Backup gets things back that were destroyed. They overlap enough to be confused and differ enough to matter: retention will not restore a library that a compromised account systematically encrypted, and the recycle bin runs out at 93 days. Our comparison of Microsoft 365 data retention versus backup sets out the distinction in full.
Microsoft 365 Backup
Microsoft’s first-party option is a pay-as-you-go service billed through Azure at a list price of $0.15 per GB per month of protected content. Restores are free, and the restore point frequency does not materially change the cost. There are no additional Azure API or storage charges beyond the backup usage itself.
What counts towards the bill
Charging is based on the user-facing size of protected sites and mailboxes plus the deleted and versioned data held for recovery. Microsoft’s own worked example: a 1 GB site with 0.5 GB in its second-stage recycle bin, plus a 1 GB mailbox with a 1 GB online archive, is billed as 3.5 GB. Deleted content keeps costing until the backup retention period lapses.
Third-party backup
An independent backup product still has advantages: a separate control plane, a separate credential set, and export outside Microsoft’s estate. For a practice whose professional indemnity insurer asks about recovery capability, that separation is often the deciding factor rather than the price.
Microsoft 365 Archive for old client years
Archive is a different lever. Archived SharePoint storage is billed at $0.05 per GB per month, and only when archived plus active storage exceeds the tenant’s licensed capacity. Reactivation fees were eliminated on 31 March 2025, though re-archiving newly reactivated content is restricted for a four-month period. For a practice with fifteen years of dormant client sites, that is a real saving.
What SharePoint for accountancy firms should actually do about backup
Turn on Microsoft 365 Backup for the client documents, AML and payroll sites at minimum. Keep versioning on Automatic everywhere. Leave the recycle bins alone. Test a restore once a quarter and write down how long it took, because the number you will be asked for after an incident is time to recover, not whether a backup existed.
Auditing SharePoint for Accountancy Firms and Proving What Happened
The audit events that matter in SharePoint for accountancy firms
Purview logs SharePoint for accountancy firms version history limit changes at organisation, site and library level, version deletions and bulk version deletions, restricted access control changes including the site admin’s justification, and Restricted Content Discovery enable and disable events with justifications. Those are the events a supervisory review will ask about.
Access reviews and the leaver problem
The hardest question in any practice is not who has access today but who kept access after they moved teams. Reviewing group membership quarterly, with the group owner rather than IT signing it off, catches more than any technical control. It also makes the permission model in SharePoint for accountancy firms defensible rather than merely documented.
Data Access Governance reports
Use the sites-protected report and the access-denials report that ship with restricted access control. The denials report returns the most recent 100 events from the past 28 days interactively, and up to 10,000 denials if you download it. A denial report full of legitimate staff is a permission design problem, not a policy problem.
eDiscovery and the recycle bin blind spot
Content in the recycle bin is not indexed and therefore cannot be found by an eDiscovery search or placed on hold. If a matter is live, act before the 93 days run out, and apply the hold to the site rather than assuming deleted items are recoverable.
Prove the disposal, not just the retention
Supervisors ask two questions about records: can you produce them, and can you show you destroyed them when you said you would. Disposition review answers the second. Configure it on the AML and payroll labels so a named person signs off each disposal batch and the sign-off itself is logged.
What SharePoint for Accountancy Firms Costs
The base licence behind SharePoint for accountancy firms
Every plan that includes SharePoint for accountancy firms gets the same storage entitlement and the same core service. UK list prices, annual commitment and excluding VAT, run Business Basic at £5.40, Business Standard at £10.80, Business Premium at £16.90, E3 at £33.50 and E5 at £51.60 per user per month. Business plans are capped at 300 users, which is well above the size of almost every UK practice.
What Business Premium already includes
Business Premium is the sensible base for SharePoint for accountancy firms. It carries Entra ID P1, so Conditional Access and device-based restrictions are available. It carries Intune, so devices can be made compliant. It carries basic Purview information protection, so sensitivity labels are available.
What the add-on suites add
Since 1 October 2025 Microsoft has sold two Business Premium add-ons relevant to SharePoint for accountancy firms. The Microsoft Defender Suite and the Microsoft Purview Suite are each £7.70 per user per month, or £11.50 for both, each requiring a Business Premium base licence and capped at 300 seats. The Purview Suite is the one that matters here: it adds full data loss prevention including endpoint, insider risk, premium audit, premium eDiscovery, data lifecycle management and records management.
Where SharePoint Advanced Management sits
Restricted access control and Restricted Content Discovery are SharePoint Advanced Management features. SAM is included with E5 and available as an add-on, and Restricted Content Discovery additionally expects a Microsoft Copilot licence. A Business Premium practice that wants those specific controls needs to price the add-on rather than assume it is included.
Consumption costs on top
Two consumption meters can appear against SharePoint for accountancy firms. Microsoft 365 Backup at $0.15 per GB per month of protected content, and Microsoft 365 Archive at $0.05 per GB per month, the latter charged only above the licensed storage quota. Both are billed pay-as-you-go through an Azure subscription.
| Plan or add-on | UK list, per user per month | Conditional Access | Full DLP | SharePoint Advanced Management |
|---|---|---|---|---|
| Business Basic | £5.40 | No | No | No |
| Business Standard | £10.80 | No | No | No |
| Business Premium | £16.90 | Yes | No | No |
| Business Premium + Purview Suite | £24.60 | Yes | Yes | No |
| Business Premium + both suites | £28.40 | Yes | Yes | No |
| Microsoft 365 E3 | £33.50 | Yes | Partial | Add-on |
| Microsoft 365 E5 | £51.60 | Yes | Yes | Included |
SharePoint for Accountancy Firms: A Forty-One Person Worked Example
The practice
The firm behind this SharePoint for accountancy firms build has seven partners, eighteen qualified and part-qualified staff, six in tax and ten in administration and payroll: 41 named people across three offices. Add nine shared mailboxes and four service accounts and the tenant carries 54 identities. The client list runs to 1,180 active clients, and the old file server held roughly 640 GB of client data.
The storage picture
The tenant behind SharePoint for accountancy firms is entitled to 1 TB plus 10 GB per licence. With 41 licences that is 1,024 GB plus 410 GB, or 1,434 GB in total. The existing 640 GB of client data uses 45% of it, which leaves comfortable headroom for a decade of growth before the archive conversation becomes necessary.
The licence cost of SharePoint for accountancy firms
At £16.90 per user per month, 41 SharePoint for accountancy firms licences cost £692.90 a month, or £8,314.80 a year, which is £202.80 per person. Adding the Purview Suite at £7.70 takes the monthly figure to £1,008.60 and the annual figure to £12,103.20. Taking both suites at £11.50 takes it to £1,164.40 a month and £13,972.80 a year.
The comparison that matters
E3 for the same 41 people is £16,482 a year and E5 is £25,387.20. Business Premium with both add-on suites lands at £13,972.80, which is £2,509.20 below E3 and £11,414.40 below E5 while delivering the data protection controls this guide relies on.
The backup bill
If the practice protects 640 GB of client data with Microsoft 365 Backup at $0.15 per GB per month, that is $96 a month, or $1,152 a year. Protecting only the AML and payroll sites, say 120 GB, costs $18 a month or $216 a year. Restores are free either way.
Putting the number in proportion
The Purview Suite for this practice costs £3,788.40 a year on top of the base licence. Across 252 working days that is £15.03 a day. The Information Commissioner’s Office penalty against DPP Law was £60,000, which is close to sixteen years of that spend.
The Thirty-Day Build Calendar for SharePoint for Accountancy Firms
Week one: decide what SharePoint for accountancy firms must hold
Seven tasks. Inventory what SharePoint for accountancy firms will actually hold against the seven categories. Confirm the tenant-level external sharing setting and write down what it is today. Read the current site inventory. Agree the seven-site model with the partners. Create the Entra security groups. Build the client term set. Choose the four sensitivity labels.
Week two: build the estate
Nine tasks. Create the seven SharePoint for accountancy firms sites and the hub. Create the libraries and the four columns. Index the three filtered columns. Build the standard views. Publish the sensitivity labels and set container labels on each site. Set the default library labels on AML and payroll. Set per-site external sharing. Configure guest expiry. Set version limits to Automatic.
Week three: protect and restrict
Eight tasks. Enable site-level access restriction across SharePoint for accountancy firms. Apply restricted access control to the AML, payroll and firm administration sites. Turn off sharing outside the control groups. Configure unmanaged-device access per site. Disable Anyone links on every restricted site. Publish the four retention labels. Configure auto-apply rules. Run the DLP policies in simulation.
Week four: migrate, verify and hand over
Seven tasks. Migrate the client data into SharePoint for accountancy firms. Run a path-length report and fix anything over 400 characters. Enable Microsoft 365 Backup on the three critical sites. Turn the DLP policies on. Run the access-denials report and fix legitimate blocks. Train staff on views rather than folders. Book the first quarterly access review.
| Week | Theme | Tasks | Owner | Evidence produced |
|---|---|---|---|---|
| One | Decide and measure | 7 | Partner plus IT provider | Data inventory, site plan |
| Two | Build the estate | 9 | IT provider | Site and label configuration export |
| Three | Protect and restrict | 8 | IT provider plus MLRO | Policy list, simulation report |
| Four | Migrate and hand over | 7 | IT provider plus practice manager | Migration log, denials report |
Migrating Into SharePoint for Accountancy Firms Without Breaking Trust
Decide what never enters SharePoint for accountancy firms
The cheapest migration into SharePoint for accountancy firms is the one that carries less. Duplicate scans, superseded drafts, personal files, and client years beyond the retention period should be archived or deleted rather than moved. Every gigabyte you leave behind is a gigabyte you never have to permission, label, retain or back up.
Fix the path lengths before you move
The 400-character limit in SharePoint for accountancy firms counts the whole decoded path including the file name. A file server folder tree that already runs deep will produce failures, and they are far cheaper to fix in a report than in a cutover. Run the length report during discovery, not on migration night.
Map permissions to groups, not to people
Take the NTFS permissions, discard them, and rebuild SharePoint for accountancy firms against the group model. Practices that translate share permissions one for one end up recreating exactly the sprawl they were trying to escape. This is the single decision that determines whether SharePoint for accountancy firms is better than the file server or merely newer.
Move into SharePoint for accountancy firms in the right order
Knowledge and templates first, because nobody minds if it breaks. Then practice management. Then client documents by office or by partner group. AML and payroll last, when the restrictive controls are already proven. The client portal is created empty and never migrated into.
Do not migrate into folders you plan to delete
If the destination is metadata-driven, do not stage the data in a folder tree and promise to tidy it later. It will not get tidied. Map the client and period columns during the migration itself, even if it slows the run.
Retire the old share properly
Set the old file server share to read-only on the SharePoint for accountancy firms cutover day rather than deleting it, and keep it for the enquiry period agreed with the partners. Then decommission it, and record that you did. A live legacy share is a second copy of every client record with none of the controls described in this guide.
Mistakes That Undo SharePoint for Accountancy Firms
Leaving external sharing at the default
External sharing is on by default across the whole SharePoint for accountancy firms environment. A practice that never checked it has an estate where any member of staff can create a link for a person outside the firm. This is the first thing to check and the fastest to fix.
Using Anyone links for client deliverables
They are unauthenticated, untrackable, forwardable, and exempt from the unmanaged-device policies you carefully configured. If a client genuinely cannot sign in, use a verification code rather than an anonymous link.
Building one site per client
It looks tidy and it breaks DLP scoping at 100 sites, multiplies every policy by the size of the client list, and guarantees inconsistency. Metadata scales; site sprawl does not.
Managing access with folder permissions
Every broken inheritance is a unique permission scope, and the recommended limit is 5,000 per library. Above 100,000 items you cannot break or reinherit at all. Use separate sites for separate audiences instead.
Trimming version history to save storage
Versions in SharePoint for accountancy firms removed by a limit change or a trim job bypass the recycle bin and cannot be recovered. Storage is cheap; a library you cannot roll back after an incident is not.
Assuming retention is backup
Retention will not rebuild a SharePoint for accountancy firms library after mass encryption, and the recycle bin ends at 93 days. Decide deliberately whether you are covered, and test a restore.
Putting AML evidence in the client folder
It is the highest-risk category in SharePoint for accountancy firms and the easiest to isolate. A separate site, restricted access control, no external sharing and a five-year label costs an afternoon.
Granting permissions to individuals
Individual grants in SharePoint for accountancy firms are invisible in a group review and survive leaver processes. Groups only, without exception.
Turning on Copilot before reviewing permissions
An assistant surfaces what a SharePoint for accountancy firms permission model actually says rather than what people assume it says. Review first, or apply Restricted Content Discovery while you do.
Never reviewing access to SharePoint for accountancy firms again
In SharePoint for accountancy firms the build is not the control; the review is. A quarterly membership review signed off by the group owner is what makes the whole design hold together over five years.
Frequently Asked Questions About SharePoint for Accountancy Firms
Is SharePoint secure enough for client tax and AML records?
Yes, provided SharePoint for accountancy firms is configured. The service offers stronger access control, auditing, retention and recovery than any file server a small practice could run. What it does not do is configure itself, and the defaults are collaboration-friendly rather than practice-friendly.
Do we need Microsoft 365 E5?
Almost never for SharePoint for accountancy firms. Business Premium plus the Purview Suite delivers the data protection controls in this guide for £24.60 per user per month against E5 at £51.60. The exception is a practice that specifically needs SharePoint Advanced Management features, which are included with E5.
Should each client have their own site?
No. Use metadata for client identity in SharePoint for accountancy firms and reserve sites for genuinely different audiences and sensitivity levels. Beyond the administrative burden, DLP can only be scoped to 100 sites per policy.
Can we give clients access without buying them licences?
Yes. Guests can view and edit documents through the browser without a licence, and can act on a site according to the permission level you grant. They need a licence only for capabilities such as their own OneDrive storage or building a Power Automate flow.
How long does SharePoint keep a deleted file?
In SharePoint for accountancy firms a 93-day retention period spans the first-stage and second-stage recycle bins, after which the file is permanently deleted. Retention labels and policies override that, and versions removed by a library limit or a trim job skip the recycle bin entirely.
What happens when we run out of storage?
The tenant gets 1 TB plus 10 GB per licence. Extra storage can be bought in 1 GB increments. If a tenant keeps operating above its limit, Microsoft warns the environment risks going read-only, meaning nobody can add or change content.
Why do our views break at 5,000 items?
That is the list view threshold, and administrators cannot change it in SharePoint Online. Index the columns SharePoint for accountancy firms filters on and make sure every default view returns fewer than 5,000 rows. The library itself can hold up to 30 million items.
Can we stop staff downloading client files at home?
Yes. Set unmanaged-device access to limited web-only, which removes download, print, sync and desktop app access while keeping browser access. Remember that Anyone links bypass this, so disable them on those sites.
Does Copilot read our whole client library?
It answers using content the signed-in user already has permission to read, which is exactly why permission review comes before rollout. Restricted Content Discovery and restricted access control both keep specified sites out of Copilot responses.
How often should we review permissions?
Review SharePoint for accountancy firms quarterly, with the group owner signing off rather than IT. Pair it with the access-denials report, which shows the most recent 100 denials from the past 28 days interactively and up to 10,000 if downloaded.
Who should build SharePoint for accountancy firms?
Someone who will still be answerable for it in three years. Most practices use their managed IT services provider for the build and keep the review cycle in-house. If you want a second opinion on an existing estate, our team offers a fixed-scope review of any SharePoint for accountancy firms deployment.
References and Further Reading
SharePoint limits – Microsoft Service Descriptions
Overview of external sharing in SharePoint and OneDrive
Manage sharing settings for SharePoint and OneDrive
Change the external sharing setting for a site
Restrict SharePoint site access with Microsoft 365 and Entra security groups
Restrict discovery of SharePoint sites and content
Control access from unmanaged devices
Use app-enforced restrictions with Conditional Access
Version history limits for document libraries and OneDrive
Set default organisation version history limits
Change version history limits for a site
Learn about retention for SharePoint and OneDrive
Learn about retention policies and retention labels
Learn about records management in Microsoft Purview
Disposition of content in Microsoft Purview
Data Loss Prevention policy reference
Learn about data loss prevention
Learn about sensitivity labels
Use sensitivity labels to protect groups and sites
Enable sensitivity labels for files in SharePoint and OneDrive
Microsoft Purview audit log activities
Microsoft Purview eDiscovery solutions
Pricing model for Microsoft 365 Backup
Overview of Microsoft 365 Backup
Pricing model for Microsoft 365 Archive
Overview of Microsoft 365 Archive
Data access governance reports in SharePoint
Prerequisites for SharePoint Advanced Management
Planning your SharePoint hub sites
Introduction to managed metadata in SharePoint
Manage large lists and libraries in SharePoint
Restore a shared library in SharePoint
Money Laundering Regulations 2017, regulation 40 – record keeping
ICAEW – Money Laundering Regulations 2017
ICAEW – Anti-money laundering for smaller practices
ICAEW – What is required of an AML supervised firm
ICO – A guide to data security
ICO – Personal data breach reporting
Cyber Security Breaches Survey 2025/2026
NCSC – Small business guide to response and recovery
NCSC – Cyber Action Toolkit for small businesses
Microsoft 365 for business – UK plans and pricing
Microsoft 365 enterprise plans and pricing – UK
Microsoft Purview service description
Microsoft 365 Copilot licensing requirements
Set up secure collaboration with Microsoft 365
Policy recommendations for securing SharePoint sites and files