Upload
others
View
3
Download
0
Embed Size (px)
Citation preview
A Strategic Approach to Leveraging Office 365 as a Records Repository for
the Enterprise
Tim Shinkle and Marcus Getzendanner
Millican & Associates, Inc.
Agenda
1. ERM strategy and lessons learned.
2. High level overview of O365 components and approach.
3. Privacy, alerts, notifications and eDiscovery.
4. Clean up and migration strategy.
5. Demonstration1. Auto-site provisioning with ERM baked-in.
2. End user drag and drop.
3. RM disposition process.
4. IT/RM configuration components.
Millican & Associates, Inc.11/18/2019 2
ERM Strategy
Office 365
Inventory & File Plans
File Share Clean up and
Migration
Develop a better understanding of the records landscape and file plans.
Clean up, manage in-place or migrate legacy shares and third-party repositories to controlled repositories such as O365.
Leverage Security & Compliance features for automating records and privacy policies in SharePoint, OneDrive, Exchange and Teams.
Millican & Associates, Inc.11/18/2019 3
Lessons Learned
• Microsoft O365 has become the de facto repository for unstructured electronic records.
• O365 can automate ERM end-to-end with minimal impact to the business user
• Additional license costs and hybrid IT/RM roles are required for proper configuration and support.
• Third party software can add value by further automating the out-of-the-box ERM features of O365 minimizing the time, cost and effort.
Millican & Associates, Inc.11/18/2019 4
High Level Overview of O365 Components
• OneDrive (Replaces home drive – Record copies, drafts, etc..)
• SharePoint Online (ECM and Collaboration – Document records repository*)
• Teams (Replaces “Skype for Business” and ties together communication and content apps in a single collaborative workspace)
• Exchange Online (Email – Communication records repository)
• Power Apps and Flow – (Replaces tools like SharePoint Designer and MS Access. Flow connectors can capture third party social media and automate e-forms and business logic across O365 platform)
* Consider long-term strategy for inactive records in a less expensive longer-term storage location.
Millican & Associates, Inc.11/18/2019 5
O365 ERM Approach Summary
1. All O365 apps have RM configurations baked-in with records management using (Microsoft Patterns and Practices or PnP).
2. Map file plans to O365 (SharePoint, OneDrive, Teams) using auto-site provisioning to auto generate and configure sites.
3. Email and Team communications follow a role-based approach (e.g. Capstone) using Retention Policies (not Labels) inherited from the content container (e.g. mailbox).
4. Retention Label queries are used to capture and process records automatically with no end user intervention. (Note: Requires E(G)3+Advanced Data Governance or E(G)5 license)
Millican & Associates, Inc.11/18/2019 6
Use Cases - Administration
Role: IT, Hybrid IT/RM SME
1. Configure Label policies.
2. Publish Labels.
3. Update or Remove Labels.
4. Automate the application of Labels.
5. Build out templates and auto-site provisioning.
Role: RM SME, RM Liaison
1. Monitor use of Labels for their group (role-based security boundaries).
2. Run disposition reporting.
3. Perform disposition processing (delete or transfer).
4. Apply holds.
Millican & Associates, Inc.11/18/2019 7
Use Cases – Business
Role: SME and Power User
1. Define taxonomy and configurations for their group.
2. Configure content repositories (e.g. SharePoint sites).
3. Review records for final disposal (as needed).
4. Support use of O365 apps for their group.
Role: Knowledge Worker
1. Create and share content in O365 apps (OneDrive, SharePoint, Teams, Exchange).
2. Create and close projects.
3. Finalize documents.
4. Review records for final disposal (as needed).
Millican & Associates, Inc.11/18/2019 8
Taxonomy (SharePoint Online)
Transaction
(Site, Library, Folder or Record –
Document or Document Set)
Activity
(Collection, Subsite, Library, Folder, Doc
Set or Record)
Function
(Hub Site, Site Collection, Site,
Subsite or Library)
Program
(Hub Site, Site Collection or Site)
OCIO
Policy
RM
Privacy
ITService
Operations…
Retention Label(As needed)
Operations
Projects
Retention Label(As needed)
Millican & Associates, Inc.11/18/2019 9
Label Mapping To Record Series
Record Series
(Each record series map to one label)
Labels
(A label for each retention rule to one or
more record series)
Destroy 7 Years after event or inactive period (GRS 1.1 item 080, GRS
2.3 item 012, ..)
GRS 1.1 item 080
7 years after final action
GRS 2.3 item 012
7 years after case is closed
Best Practice: Map organization retention schedules to a minimum set of Labels based on similar retention rules. This reduces how many labels need to be created and maintained.
Millican & Associates, Inc.11/18/2019 10
Label Mapping to Label Policy
Label Policy
(Each label is applied to records by one or more label
policies)
Labels
(Each label has a retention rule)
Destroy 7 Years after even or inactive period
Label policy 1, Label policy 2, ..
Label policy 1
{Search query 1}
Label policy 2
{Search query 2}
Best Practice: Use a minimal set of label polices to apply labels to records using search queries (i.e. Auto-apply a label) where each query can service one or many records series (GRS or agency retention schedule items). This reduces the number of queries need to apply labels to records across O365.
Millican & Associates, Inc.11/18/2019 11
Labels and Label Policies
Labels define the rules Policies apply the labels to content
Millican & Associates, Inc.11/18/2019 12
Sensitivity Labels
Millican & Associates, Inc.11/18/2019 13
Retention Policies
Label Policies
Retention Policies
Millican & Associates, Inc.11/18/2019 14
High Level Overview of O365 Components
O365 App Retention Label and Label Policy (Content and subject based retention)
Retention Policy(Containers and role-based retention)
OneDrive
SharePoint
Teams
Exchange
Millican & Associates, Inc.11/18/2019 15
Teams
• Teams conversations are stored in Exchange Online mailboxes
• Messages are deleted from all relevant storage locations: mailboxes, substrate, and chat service.
• Teams files are stored in OneDrive for Business and SharePoint.
Millican & Associates, Inc.11/18/2019 16
Dashboards
Millican & Associates, Inc.11/18/2019 17
Compliance Manager (GDPR)
Millican & Associates, Inc.11/18/2019 18
Alerts – E.g. Email notifications
Millican & Associates, Inc.11/18/2019 19
Audit Trails – Audit Log Search Page
Millican & Associates, Inc.11/18/2019 20
Advanced eDiscovery
Note: Advanced eDiscovery requires an Office 365 E3 with the Advanced Compliance add-on or an E5 subscription for your organization.
Millican & Associates, Inc.11/18/2019 21
Flow – Integrate & Automate Workflows
Millican & Associates, Inc.11/18/2019 22
Clean Up and Migration
Clean Up (e.g. Tier5Data Seek tool) SharePoint Migration Tool
Millican & Associates, Inc.11/18/2019 23
Demo1. Auto-site provisioning with ERM baked-in.
2. End user drag and drop.
3. RM disposition process.
4. IT/RM configuration components.
Millican & Associates, Inc.11/18/2019 24