Try For Free
Microsoft 365 provisioning

Self-service Microsoft 365 provisioning, without losing control

Every Team, SharePoint site and Microsoft 365 group your people create is an asset someone has to own, secure and eventually retire. Governed provisioning lets anyone request a workspace from a template you control, with an owner, a naming standard, the right sensitivity label and an approval step applied before anything is created, so self-service never turns into sprawl.

The provisioning templates screen in Rencore Governance, listing 24 workspace templates with their active state and their in-progress and completed request counts.

Trusted by the world’s leading organizations

  • MAPAL
  • bam
  • VDL
  • Wacker
  • Grundfos
  • Amgen
  • Lufthansa
  • thyssenkrupp
  • Sunrise
  • Pattern

Where ungoverned creation goes wrong

Left to the native create button, a Microsoft 365 tenant grows its fastest-moving assets outside every standard, and the cost lands later:

Anyone can create anything

Any licensed user spins up a Team, a Microsoft 365 group or a site in seconds, with no owner named and no standard applied.

No owner, no accountability

Workspaces launch without a responsible owner, so no one is answerable for their access, the data they hold, or their end of life.

Naming and access drift from day one

Without a template, every new workspace picks its own name, visibility and sharing, and the estate fragments before anyone governs it.

Sprawl starts at creation

Ungoverned Teams, sites and groups are the sprawl you clean up later. The cheapest place to stop it is the moment of creation.

Put self-service inside guardrails

Rencore puts control at the point of creation: people keep self-service, and every workspace arrives with an owner, a name, a sensitivity label and the approvals you require. It complements Microsoft 365 native creation and hands each new workspace to lifecycle governance. For the capability screen by screen, see the provisioning feature and the Rencore app for Microsoft Teams.

Templates

Creation starts from a template you control

People request a department, project or community workspace from a gallery you curate, or start from a governed Teams, SharePoint, Planner or Viva Engage template. Content, visibility and the multi-geo location live in the template, so self-service stays inside the rules IT sets.

The provisioning template list in Rencore Governance: eight workspace templates including Planner Board, Department Team and Standard Team, each with an active toggle, whether it is recommended, and its in-progress and completed request counts.
Owners and naming

An owner and a name on every workspace, before it exists

The request captures the owner, a naming standard and the right sensitivity label up front. Nothing is created without someone accountable for it, so orphaned Teams and sites never enter the tenant in the first place.

The Request a Team form in the Rencore app for Microsoft Teams, with a team name, a description, a Private team type and a Confidential sensitivity label selected.
Approval

Approval routes to the people you name

Each template carries its own approvers, deadlines and triggers. A request routes to the right approver before anything is provisioned, so creation stays self-service for the requester and controlled for IT.

Step 1 of the Rencore Governance provisioning template builder, with the Template Settings, Provisioning Settings and Approval steps across the top and the title and description of a Communication Site template being edited.
Lifecycle handoff

Every request tracked, then handed to lifecycle

See every provisioning request, its template, status, requester and time in one place. Each governed workspace passes straight into lifecycle governance, so ownership, access reviews and retirement continue after creation.

All provisioning requests in Rencore Governance: five requests for subsidiary, project, cost centre, Copilot licence and Planner board templates, each showing its template, a Completed status, the requester and the creation time.

What governed provisioning gives you

Each control at creation ladders to a board pillar.

  • Guardrails, not gatekeeping Efficiency

    People self-serve; IT sets the rules once, in the template.

  • Every workspace owned Risk

    A named owner and an end of life on every Team, site and group.

  • One naming and sharing standard Efficiency

    New workspaces follow your naming and visibility from creation.

  • Sprawl stopped at the source Cost

    Fewer orphaned, duplicate and empty workspaces to clean up later.

Guardrails without gatekeeping: self-service that IT can stand behind.

Rencore complements Microsoft 365. Native creation stays available to your admins; Rencore adds the template, owner, naming and approval controls around it and hands each workspace to lifecycle governance. It does not replace Microsoft.

Trusted by security, IT, and platform leaders

Security, IT, and platform leaders use Rencore to see their Microsoft estate, cut cost and risk, and roll out Copilot and agents on a governed foundation.

  • With Rencore's scalable automation solutions, organizations can not only meet current challenges but also prepare themselves for future technological advancements.
    Case Study
    Philipp Widmer Philipp Widmer Head of Platform Services Universitätsspital Basel
  • 26% vs 3%

    Organizations that govern Microsoft 365 well realize significant Copilot value 26% of the time, versus 3% for those that do not.

    Gartner, 2025 Microsoft 365 Copilot Survey
  • As we continue to expand our cloud capabilities, the foundation laid by Rencore Governance will undoubtedly play a crucial role in ensuring that each step forward is taken with confidence, security, and compliance in mind.
    Case Study
    Claude Bisdorff Claude Bisdorff Head of IT Systems Ville de Luxembourg
  • 116%

    ROI from Microsoft 365 Copilot once the program is adopted and governed, in Forrester’s Total Economic Impact study.

    Forrester Total Economic Impact
  • I currently estimate that we save around €80k per year by freeing up our IT admin team to do the work that counts.
    Case Study
    Undisclosed Undisclosed Former Lead O365 Competence Center Royal BAM
  • 71%

    of enterprises name security and governance among their top challenges to deploying Microsoft 365 Copilot.

    Gartner
  • Rencore's centralized governance tool excelled at ensuring secure data in Microsoft 365 and minimizing the risk of unauthorized access.
    Case Study
    Greg Bowles Greg Bowles IT Operations Manager Specialist Risk Group
  • 150,000+

    AI agents in use at the average Fortune 500 company by 2028. Agent sprawl is the next sprawl.

    Gartner
  • With Rencore Governance we are able to reduce manual governance activities, improve our service quality and generate valuable insights across our Microsoft service stack.
    Undisclosed Undisclosed Head of AI & Process Automation Wacker Chemie AG

Frequently asked questions

What is governed self-service provisioning in Microsoft 365?
It lets people request a new Microsoft 365 workspace, a Team, a SharePoint site, a group, a Planner plan or a Viva Engage community, from a template you control, and applies an owner, a naming standard, the right sensitivity label and an approval step before anything is created. Self-service stays fast for the requester while creation stays inside the rules IT sets, which is the difference between provisioning and letting anyone create anything.
Does this replace the native Microsoft 365 create experience?
No. Rencore complements Microsoft 365 and never replaces it. Your admins keep the native create experience; Rencore adds the template, owner, naming and approval controls around it and hands each new workspace to lifecycle governance. Coverage is generally available today for Microsoft 365, Teams, SharePoint, Planner and Viva Engage.
How does governed provisioning stop workspace sprawl?
Sprawl starts at creation, so that is where it is cheapest to stop. Every workspace request arrives with a named owner, a naming standard and the approvals you require, and each created workspace passes straight to lifecycle governance for ongoing access reviews and retirement. You prevent the orphaned, duplicate and unnamed Teams and sites at the source instead of cleaning them up months later.
What can people request, and who approves it?
People can request a department, project or community workspace from a gallery you curate, or start from a governed Teams, SharePoint, Planner or Viva Engage template. Each template carries its own approvers, deadlines and triggers, so a request routes to the people you name before it is provisioned. You decide which templates exist and what each one enforces.

Make workspace creation your first control point

Start with the template gallery: let people request the workspaces they need, with owners, naming, sensitivity and approval built in, so nothing enters your tenant ungoverned.

The provisioning request template gallery in the Rencore app for Microsoft Teams: nine templates including Private M365 Group, Community Team, Confidential Team, Department Team, Project Team, Standard Team, Communication Site, Intranet Site and Planner Board, each with a Request button and tags for its type and visibility.