Guides

How-to guides

Step-by-step guides for governing Microsoft 365 and the AI tools around it, from Copilot, SharePoint, and the Power Platform to Claude, OpenAI, Gemini, and AI coding assistants.

Featured guides

How does tenant sprawl in Microsoft 365 impact governance efficiency?

Tenant sprawl does not just clutter Microsoft 365. It quietly taxes governance efficiency by forcing IT to spend more time locating and cleaning up resources than reviewing them under policy. Here is how to measure the drag and reverse it.

Read guide
Featured guides

How to build EU AI Act evidence across your AI tools

How to produce the documentation the EU AI Act expects across every AI system you use, Microsoft Copilot and non-Microsoft tools alike: a per-tool record of what it does, the data it touches, who owns it, and when it was last reviewed.

Read guide
Featured guides

How to control Microsoft Teams sprawl

A repeatable process for bringing Microsoft Teams and their connected sites and groups back under control: inventory everything, find inactive and ownerless teams, attach ownership and expiry, and review on a cadence.

Read guide
Featured guides

How to control shadow AI

A process for finding the AI tools that IT and security have not sanctioned, assessing what they can reach, and bringing the ones that earn their place under the same inventory, ownership, and review as approved tools.

Read guide
Featured guides

How to detect and fix SharePoint oversharing

A repeatable process for finding SharePoint content that is reachable by more people than intended, prioritizing by sensitivity, and closing the access before it becomes an incident or a Copilot exposure.

Read guide
Featured guides

How to govern AI coding assistants

How to bring AI coding assistants like GitHub Copilot, Cursor, and Windsurf under the same inventory-and-oversight model as the rest of your AI stack, covering repo access, ownership, and review.

Read guide
Featured guides

How to govern AI tools beyond Microsoft Copilot

How to extend a single governance model, inventory, ownership, risk classification, and access review, across every AI tool your teams use, not just the Microsoft ones.

Read guide
Featured guides

How to govern Microsoft Copilot agents

A step-by-step approach to keeping every Copilot Studio and Microsoft 365 agent inventoried, owned, and risk-assessed, so agent creation does not turn into ungoverned sprawl and data exposure.

Read guide
Featured guides

How to govern the Power Platform

How to govern Power Apps, Power Automate, and Power BI as one connected low-code estate rather than three separate tools: inventory, ownership, environment and connector sprawl control, and access review.

Read guide
Featured guides

How to inventory the AI tools in use across your organization

A step-by-step approach to building a continuous inventory of every AI assistant, agent, and LLM tool in use across the organization, spanning Microsoft Copilot and the non-Microsoft tools teams adopt alongside it.

Read guide
Featured guides

How to monitor data loss prevention across Microsoft 365

How to treat data loss prevention as continuous monitoring rather than a one-time policy setup, watching for the oversharing, external access, and misconfiguration that let sensitive data slip across Microsoft 365.

Read guide
Featured guides

How to prepare for NIS2 in Microsoft 365

How to align a Microsoft 365 estate with the NIS2 Directive by treating readiness as an evidence problem: map requirements to controls, baseline access and configuration, and capture durable records an auditor can follow.

Read guide
Featured guides

How to prepare Microsoft 365 for a Copilot rollout

A readiness process for getting a Microsoft 365 tenant into a state where Copilot can be deployed without surfacing data users should not see: baseline exposure, fix oversharing, apply labels, validate, then expand.

Read guide
Featured guides

How to produce DORA audit evidence in Microsoft 365

A process for producing the documented, retained evidence DORA expects from a Microsoft 365 estate: map requirements to controls, capture configuration baselines, retain access and change logs, and package it for auditors.

Read guide
Featured guides

How to reclaim unused Microsoft 365 Copilot licenses

A practical, repeatable process for finding Microsoft 365 Copilot seats that go unused after assignment and reclaiming them, so the recurring bill stays aligned with actual usage.

Read guide
Featured guides

How to run recurring access reviews across Microsoft 365 and AI tools

How to run owner-led access reviews on a fixed cadence across Microsoft 365 and the AI tools your teams use, so access stays aligned with need and you can prove it was reviewed.

Read guide
ServiceNow

How to govern Security in ServiceNow

Detect, review, and remediate Security issues in ServiceNow, using pre-built controls like ServiceNow AI agent is live and callable.

Read guide
Anthropic

How to govern Costs in Anthropic

Detect, review, and remediate Costs issues in Anthropic, using pre-built controls like Claude Code user exceeds the costs limit.

Read guide
Entra ID

How to govern Security in Entra ID

Detect, review, and remediate Security issues in Entra ID, using pre-built controls like Enterprise applications that use SharePoint Online permissions.

Read guide
OpenAI

How to govern OpenAI

Keep OpenAI under continuous governance, from detecting risk to remediating it with an audit trail. Rencore covers OpenAI with 32 policies, 11 reports, and 8 automations.

Read guide
Snowflake

How to govern Inventory in Snowflake

Detect, review, and remediate Inventory issues in Snowflake, using pre-built controls like Snowflake Account.

Read guide
Teams

How to govern Adoption in Teams

Detect, review, and remediate Adoption issues in Teams, using pre-built controls like New Teams.

Read guide
ServiceNow

How to govern ServiceNow

Keep ServiceNow under continuous governance, from detecting risk to remediating it with an audit trail. Rencore covers ServiceNow with 38 policies, 14 reports, and 6 automations.

Read guide
Power BI

How to govern Inventory in Power BI

Detect, review, and remediate Inventory issues in Power BI, using pre-built controls like Workspace.

Read guide
Box

How to govern Security in Box

Detect, review, and remediate Security issues in Box, using pre-built controls like User exempt from login verification.

Read guide
Windsurf

How to govern Security in Windsurf

Detect, review, and remediate Security issues in Windsurf, using pre-built controls like Windsurf member is an admin.

Read guide
Exchange

How to govern Exchange

Keep Exchange under continuous governance, from detecting risk to remediating it with an audit trail. Rencore covers Exchange with 31 policies, 14 reports, and 15 automations.

Read guide
Agent Governance Toolkit

How to govern Inventory in Agent Governance Toolkit

Detect, review, and remediate Inventory issues in Agent Governance Toolkit, using pre-built controls like AGT Agent.

Read guide
Cursor

How to govern Operation in Cursor

Detect, review, and remediate Operation issues in Cursor, using pre-built controls like Cursor MCP server is actively invoked.

Read guide
GitHub Copilot

How to govern Inventory in GitHub Copilot

Detect, review, and remediate Inventory issues in GitHub Copilot, using pre-built controls like GitHub Copilot Organization.

Read guide
Vercel v0

How to govern Costs in Vercel v0

Detect, review, and remediate Costs issues in Vercel v0, using pre-built controls like Vercel v0 Scope exceeds the 30-day credit limit.

Read guide
Microsoft 365

How to govern Costs in Microsoft 365

Detect, review, and remediate Costs issues in Microsoft 365, using pre-built controls like Users with Power Platform Premium License.

Read guide
Agent Governance Toolkit

How to govern Security in Agent Governance Toolkit

Detect, review, and remediate Security issues in Agent Governance Toolkit, using pre-built controls like Prompt injection detected in last 24h.

Read guide
Azure DevOps

How to govern Azure DevOps

Keep Azure DevOps under continuous governance, from detecting risk to remediating it with an audit trail. Rencore covers Azure DevOps with 15 policies, 3 reports, and 3 automations.

Read guide
AWS Bedrock

How to govern Operation in AWS Bedrock

Detect, review, and remediate Operation issues in AWS Bedrock, using pre-built controls like Agent is live and callable.

Read guide
Microsoft 365

How to govern Provisioning in Microsoft 365

Detect, review, and remediate Provisioning issues in Microsoft 365, using pre-built controls like Private M365 Group.

Read guide
Confluence

How to govern Sprawl in Confluence

Detect, review, and remediate Sprawl issues in Confluence, using pre-built controls like Stale Confluence page (365+ days).

Read guide
Power Apps

How to govern Inventory in Power Apps

Detect, review, and remediate Inventory issues in Power Apps, using pre-built controls like Environment.

Read guide
Teams

How to govern Sprawl in Teams

Detect, review, and remediate Sprawl issues in Teams, using pre-built controls like Teams with very few users.

Read guide
Box

How to govern External Access in Box

Detect, review, and remediate External Access issues in Box, using pre-built controls like Shared link is open to anyone.

Read guide
Confluence

How to govern Security in Confluence

Detect, review, and remediate Security issues in Confluence, using pre-built controls like Space is publicly reachable (anonymous access).

Read guide
Exchange

How to govern Operation in Exchange

Detect, review, and remediate Operation issues in Exchange, using pre-built controls like Mailboxes near storage quota.

Read guide
Salesforce

How to govern Security in Salesforce

Detect, review, and remediate Security issues in Salesforce, using pre-built controls like Salesforce agent is active and callable.

Read guide
Google Workspace

How to govern Google Workspace

Keep Google Workspace under continuous governance, from detecting risk to remediating it with an audit trail. Rencore covers Google Workspace with 28 policies, 12 reports, and 5 automations.

Read guide
Cursor

How to govern Cursor

Keep Cursor under continuous governance, from detecting risk to remediating it with an audit trail. Rencore covers Cursor with 26 policies, 3 reports, and 5 automations.

Read guide
Box

How to govern Sprawl in Box

Detect, review, and remediate Sprawl issues in Box, using pre-built controls like Folder inactive for over a year.

Read guide
Intune

How to govern Security in Intune

Detect, review, and remediate Security issues in Intune, using pre-built controls like Device is registered and reachable.

Read guide
GitHub Copilot

How to govern Operation in GitHub Copilot

Detect, review, and remediate Operation issues in GitHub Copilot, using pre-built controls like Copilot seat is actively in use.

Read guide