Skip to main content

Policies: Workspace Types and Reviewers

Before applying the policies you've created or enabled in Syskit Point, it is useful to know which workspace the policies can be applied to, who can be selected as a reviewer, and who receives tasks and emails if the delegation option is enabled.

Below you can find details on:

  • Types of workspaces (Microsoft Teams, Microsoft 365 Groups, SharePoint Sites, etc.) supported by each policy
  • Delegation option availability for policies
  • Which users you can define as reviewers who complete tasks when the delegation option is enabled
  • Who are the users considered as workspace owners for each workspace type
warning

Please note the following:

  • Policies that do not have task delegation available do not have active tasks to resolve, there are no reviewers, and no e-mails are sent.
    • Syskit Point Administrators can monitor and complete actions for those policies on the Security & Compliance Checks screen when a vulnerability is detected.
  • For certain policies with task delegation enabled, when workspace owners don't resolve their tasks on time, you can select who the task will be reassigned to. If workspace owners do not complete the task, it will be reassigned to the reviewers you choose.
  • Policies that are user-centered do not have specific workspaces they can be applied to, as they are applied tenant-wide.
Policy NameWorkspace TypeTask DelegationReviewersReassign to
Blocked Users with Assigned LicensesTenant-WideNot availableNot applicableNot applicable
Inactive Guest UsersTenant-WideAvailableManager of Guest User, Syskit Point Administrators, Custom RecipientsNot available
Inactive WorkspacesMicrosoft Teams, Microsoft 365 Group, Viva Engage Community, SharePoint SiteAvailableWorkspace Owners or Site Admins (for nongroup connected sites)Not available
Minimum Number of OwnersMicrosoft Teams, Microsoft 365 Group, Viva Engage Community, SharePoint SiteAvailableWorkspace OwnersManager of Reviewer, Syskit Point Administrators, Custom Recipients
Maximum Number of OwnersMicrosoft Teams, Microsoft 365 Group, Viva Engage Community, SharePoint SiteAvailableWorkspace OwnersManager of Reviewer, Syskit Point Administrators, Custom Recipients
Orphaned WorkspacesMicrosoft Teams, Microsoft 365 Group, Viva Engage Community, SharePoint SiteAvailableWorkspace Members or Specific Users suggest new owners, Point Administrators or Custom recipients approve new ownersNot available
Tenant Storage LimitTenant-WideAvailableSyskit Point Administrators, Custom recipientsNot available
Orphaned UsersTenant-WideNot availableNot applicableNot applicable
Maximum Number of MembersMicrosoft Teams, Microsoft 365 Group, Viva Engage Community, SharePoint SiteNot AvailableNot applicableNot applicable
Workspaces with Shadow UsersMicrosoft Teams, Microsoft 365 Group, Viva Engage Community, SharePoint SiteNot AvailableNot applicableNot applicable
Private Workspaces Shared with EveryoneMicrosoft Teams, Microsoft 365 Group, SharePoint SiteNot AvailableNot applicableNot applicable
Workspaces Without a Sensitivity LabelMicrosoft Teams, Microsoft 365 Group, Viva Engage Community, SharePoint SiteNot AvailableNot applicableNot applicable
Workspace TypeWorkspace Owners
Microsoft TeamsOwners of the connected Microsoft 365 Group
Microsoft 365 GroupOwners of the connected Microsoft 365 Group
Viva Engage CommunityOwners of the connected Microsoft 365 Group
SharePoint SiteFor the Inactive Workspaces Policy, Site admins are cosidered workspace owners - this is due to the fact the Site admin role is needed in case reviewers want to delete the site in the assigned task
For Minimum Number of Owners, Maximum Number of Owners, and Orphaned Workspaces policies, users in the Owners SharePoint group are considered workspace owners - the Owners SharePoint group is created by default with the site creation and has the following naming pattern: <SharePointSiteName> Owners; for example, SharePoint Site named Sales has the Sales Owners SharePoint group
Remaining policies are either tenant-wide or have no delegation option, so the workspace ownership logic is not being used to define reviewers