Back to Top

 

 

m365-family-of-apps

 

The steps and interface descriptions in this guide reflect Microsoft 365 as it works at KAUST today. Microsoft updates these tools regularly, so the screens you see may look slightly different over time. The underlying concepts and permissions model described here remain consistent.

How these tools fit together

OneDrive, SharePoint, Microsoft Teams, and Microsoft Planner are not four separate products. They are four different interfaces built on top of a shared membership layer called a Microsoft 365 Group. Understanding how they connect is the most important thing in this guide.

The Microsoft 365 Group: the invisible backbone

When a Team, a SharePoint team site, or a Planner board is created, Microsoft quietly creates a Microsoft 365 Group underneath it. The Group holds the membership list. The SharePoint site, Teams workspace, Planner board, and shared Outlook mailbox all look at that same list to decide who gets access.

Add someone to the Group or Team and they get access to the SharePoint site, Planner board, and Teams workspace all at once. This is the most common source of accidental oversharing at KAUST.

OneDrive
OneDrive
SharePoint
SharePoint
Teams
Microsoft Teams
Planner
Microsoft Planner

Good Practices

Good data governance across OneDrive, SharePoint, Teams, and Planner comes down to consistent habits applied at the right moments.

When someone joins your team

Add them through Teams, not directly through SharePoint. Adding through Teams updates their access to SharePoint, Planner, and the Teams workspace simultaneously. If they only need read-only access to a site without full Team membership, add them to the SharePoint Visitors group directly.

When someone changes role or moves to a new team

Their access from their previous role does not update automatically. Review what they had access to and remove or adjust anything that no longer fits. For private channels they were in, remove them separately. For SharePoint sites added directly, check and update those too.

When a project ends

Take five minutes to review the Team and SharePoint site membership. Remove anyone involved on a temporary basis. Check whether the Team is still actively needed or should be archived. Teams that sit unused with active membership and open permissions are a governance risk.

When adding external collaborators

Before adding a guest to a Team, review what is in the connected SharePoint site. Restricted content needs to be in a library with separate permissions before the guest arrives. For one-time meetings, send a meeting link rather than adding the person to the Team.

When deciding where to store files

Ask whether the file belongs to you as an individual or to the team. Personal drafts go in OneDrive. Team-owned, long-term content goes in SharePoint or a Teams channel. Files shared in a chat stay in the sender's OneDrive and are at risk if that person leaves.

When reviewing permissions

Use Check Permissions in SharePoint to verify what a specific person can access. Use the Shared by Me view in OneDrive to see everything you have actively shared. Do both periodically, not only when something goes wrong.

When content is sensitive or Restricted

Keep Restricted content out of general document libraries. Create a dedicated library, break inheritance so it has its own separate permissions, and assign access only to the people who genuinely need it. Do not scatter sensitive files across a general library and try to protect them individually. If external sharing of Restricted content is ever needed, consult IT first.

The general principle

Use the most restrictive option that still lets the work get done. If Specific People works, use it instead of People in KAUST. If a channel post works, use it instead of a chat. If read-only works, use it instead of edit. Access should reflect genuine need, not convenience at the point of granting it.