At UQ, we have a responsibility to handle UQ data, information and records according to the requirements outlined in the Data Handling Procedure.

We need to take action to secure internal documents in line with relevant UQ procedures and our information security classifications to ensure we do not have avoidable data breaches.

While Microsoft 365 provides a secure, cloud-based platform for storing and sharing files, we need to ensure that it is only accessible to authorised individuals.

1. Restrict access to documents

We can control who has access to files in Microsoft 365 by the way that it is stored and shared.

Files only shared with individuals and distribution lists (people you specify) do not require action. 
A distribution list is a way to group together several email addresses, often done to represent a team.

For any file shared using the People in The University of Queensland, consider whether the document(s) should be available to both staff and students or if students should not have access to the document(s).

Staff and students can access the document(s)

  • Share the document(s) using the People in The University of Queensland option.

Students should not have access to the document(s)

  • Remove the link
  • Re-share the file as needed to individuals or groups