How-to guides
Step-by-step guides for governing Microsoft 365 and the AI tools around it, from Copilot, SharePoint, and the Power Platform to Claude, OpenAI, Gemini, and AI coding assistants.
How does tenant sprawl in Microsoft 365 impact governance efficiency?
Tenant sprawl does not just clutter Microsoft 365. It quietly taxes governance efficiency by forcing IT to spend more time locating and cleaning up resources than reviewing them under policy. Here is how to measure the drag and reverse it.
Read guide Featured guidesHow to build EU AI Act evidence across your AI tools
How to produce the documentation the EU AI Act expects across every AI system you use, Microsoft Copilot and non-Microsoft tools alike: a per-tool record of what it does, the data it touches, who owns it, and when it was last reviewed.
Read guide Featured guidesHow to control Microsoft Teams sprawl
A repeatable process for bringing Microsoft Teams and their connected sites and groups back under control: inventory everything, find inactive and ownerless teams, attach ownership and expiry, and review on a cadence.
Read guide Featured guidesHow to control shadow AI
A process for finding the AI tools that IT and security have not sanctioned, assessing what they can reach, and bringing the ones that earn their place under the same inventory, ownership, and review as approved tools.
Read guide Featured guidesHow to detect and fix SharePoint oversharing
A repeatable process for finding SharePoint content that is reachable by more people than intended, prioritizing by sensitivity, and closing the access before it becomes an incident or a Copilot exposure.
Read guide Featured guidesHow to govern AI coding assistants
How to bring AI coding assistants like GitHub Copilot, Cursor, and Windsurf under the same inventory-and-oversight model as the rest of your AI stack, covering repo access, ownership, and review.
Read guide Featured guidesHow to govern AI tools beyond Microsoft Copilot
How to extend a single governance model, inventory, ownership, risk classification, and access review, across every AI tool your teams use, not just the Microsoft ones.
Read guide Featured guidesHow to govern Microsoft Copilot agents
A step-by-step approach to keeping every Copilot Studio and Microsoft 365 agent inventoried, owned, and risk-assessed, so agent creation does not turn into ungoverned sprawl and data exposure.
Read guide Featured guidesHow to govern the Power Platform
How to govern Power Apps, Power Automate, and Power BI as one connected low-code estate rather than three separate tools: inventory, ownership, environment and connector sprawl control, and access review.
Read guide Featured guidesHow to inventory the AI tools in use across your organization
A step-by-step approach to building a continuous inventory of every AI assistant, agent, and LLM tool in use across the organization, spanning Microsoft Copilot and the non-Microsoft tools teams adopt alongside it.
Read guide Featured guidesHow to monitor data loss prevention across Microsoft 365
How to treat data loss prevention as continuous monitoring rather than a one-time policy setup, watching for the oversharing, external access, and misconfiguration that let sensitive data slip across Microsoft 365.
Read guide Featured guidesHow to prepare for NIS2 in Microsoft 365
How to align a Microsoft 365 estate with the NIS2 Directive by treating readiness as an evidence problem: map requirements to controls, baseline access and configuration, and capture durable records an auditor can follow.
Read guide Featured guidesHow to prepare Microsoft 365 for a Copilot rollout
A readiness process for getting a Microsoft 365 tenant into a state where Copilot can be deployed without surfacing data users should not see: baseline exposure, fix oversharing, apply labels, validate, then expand.
Read guide Featured guidesHow to produce DORA audit evidence in Microsoft 365
A process for producing the documented, retained evidence DORA expects from a Microsoft 365 estate: map requirements to controls, capture configuration baselines, retain access and change logs, and package it for auditors.
Read guide Featured guidesHow to reclaim unused Microsoft 365 Copilot licenses
A practical, repeatable process for finding Microsoft 365 Copilot seats that go unused after assignment and reclaiming them, so the recurring bill stays aligned with actual usage.
Read guide Featured guidesHow to run recurring access reviews across Microsoft 365 and AI tools
How to run owner-led access reviews on a fixed cadence across Microsoft 365 and the AI tools your teams use, so access stays aligned with need and you can prove it was reviewed.
Read guide ServiceNowHow to govern Security in ServiceNow
Detect, review, and remediate Security issues in ServiceNow, using pre-built controls like ServiceNow AI agent is live and callable.
Read guide AnthropicHow to govern Costs in Anthropic
Detect, review, and remediate Costs issues in Anthropic, using pre-built controls like Claude Code user exceeds the costs limit.
Read guide Entra IDHow to govern Security in Entra ID
Detect, review, and remediate Security issues in Entra ID, using pre-built controls like Enterprise applications that use SharePoint Online permissions.
Read guide OpenAIHow to govern OpenAI
Keep OpenAI under continuous governance, from detecting risk to remediating it with an audit trail. Rencore covers OpenAI with 32 policies, 11 reports, and 8 automations.
Read guide SnowflakeHow to govern Inventory in Snowflake
Detect, review, and remediate Inventory issues in Snowflake, using pre-built controls like Snowflake Account.
Read guide TeamsHow to govern Adoption in Teams
Detect, review, and remediate Adoption issues in Teams, using pre-built controls like New Teams.
Read guide ServiceNowHow to govern ServiceNow
Keep ServiceNow under continuous governance, from detecting risk to remediating it with an audit trail. Rencore covers ServiceNow with 38 policies, 14 reports, and 6 automations.
Read guide Power BIHow to govern Inventory in Power BI
Detect, review, and remediate Inventory issues in Power BI, using pre-built controls like Workspace.
Read guide BoxHow to govern Security in Box
Detect, review, and remediate Security issues in Box, using pre-built controls like User exempt from login verification.
Read guide WindsurfHow to govern Security in Windsurf
Detect, review, and remediate Security issues in Windsurf, using pre-built controls like Windsurf member is an admin.
Read guide ExchangeHow to govern Exchange
Keep Exchange under continuous governance, from detecting risk to remediating it with an audit trail. Rencore covers Exchange with 31 policies, 14 reports, and 15 automations.
Read guide Agent Governance ToolkitHow to govern Inventory in Agent Governance Toolkit
Detect, review, and remediate Inventory issues in Agent Governance Toolkit, using pre-built controls like AGT Agent.
Read guide CursorHow to govern Operation in Cursor
Detect, review, and remediate Operation issues in Cursor, using pre-built controls like Cursor MCP server is actively invoked.
Read guide GitHub CopilotHow to govern Inventory in GitHub Copilot
Detect, review, and remediate Inventory issues in GitHub Copilot, using pre-built controls like GitHub Copilot Organization.
Read guide Vercel v0How to govern Costs in Vercel v0
Detect, review, and remediate Costs issues in Vercel v0, using pre-built controls like Vercel v0 Scope exceeds the 30-day credit limit.
Read guide Microsoft 365How to govern Costs in Microsoft 365
Detect, review, and remediate Costs issues in Microsoft 365, using pre-built controls like Users with Power Platform Premium License.
Read guide Agent Governance ToolkitHow to govern Security in Agent Governance Toolkit
Detect, review, and remediate Security issues in Agent Governance Toolkit, using pre-built controls like Prompt injection detected in last 24h.
Read guide Azure DevOpsHow to govern Azure DevOps
Keep Azure DevOps under continuous governance, from detecting risk to remediating it with an audit trail. Rencore covers Azure DevOps with 15 policies, 3 reports, and 3 automations.
Read guide AWS BedrockHow to govern Operation in AWS Bedrock
Detect, review, and remediate Operation issues in AWS Bedrock, using pre-built controls like Agent is live and callable.
Read guide Microsoft 365How to govern Provisioning in Microsoft 365
Detect, review, and remediate Provisioning issues in Microsoft 365, using pre-built controls like Private M365 Group.
Read guide ConfluenceHow to govern Sprawl in Confluence
Detect, review, and remediate Sprawl issues in Confluence, using pre-built controls like Stale Confluence page (365+ days).
Read guide Power AppsHow to govern Inventory in Power Apps
Detect, review, and remediate Inventory issues in Power Apps, using pre-built controls like Environment.
Read guide TeamsHow to govern Sprawl in Teams
Detect, review, and remediate Sprawl issues in Teams, using pre-built controls like Teams with very few users.
Read guide BoxHow to govern External Access in Box
Detect, review, and remediate External Access issues in Box, using pre-built controls like Shared link is open to anyone.
Read guide ConfluenceHow to govern Security in Confluence
Detect, review, and remediate Security issues in Confluence, using pre-built controls like Space is publicly reachable (anonymous access).
Read guide ExchangeHow to govern Operation in Exchange
Detect, review, and remediate Operation issues in Exchange, using pre-built controls like Mailboxes near storage quota.
Read guide SalesforceHow to govern Security in Salesforce
Detect, review, and remediate Security issues in Salesforce, using pre-built controls like Salesforce agent is active and callable.
Read guide Google WorkspaceHow to govern Google Workspace
Keep Google Workspace under continuous governance, from detecting risk to remediating it with an audit trail. Rencore covers Google Workspace with 28 policies, 12 reports, and 5 automations.
Read guide CursorHow to govern Cursor
Keep Cursor under continuous governance, from detecting risk to remediating it with an audit trail. Rencore covers Cursor with 26 policies, 3 reports, and 5 automations.
Read guide BoxHow to govern Sprawl in Box
Detect, review, and remediate Sprawl issues in Box, using pre-built controls like Folder inactive for over a year.
Read guide IntuneHow to govern Security in Intune
Detect, review, and remediate Security issues in Intune, using pre-built controls like Device is registered and reachable.
Read guide GitHub CopilotHow to govern Operation in GitHub Copilot
Detect, review, and remediate Operation issues in GitHub Copilot, using pre-built controls like Copilot seat is actively in use.
Read guide