All Guides
Microsoft 365

Why Does Microsoft 365 Feel Messy?

Too many admins, no Conditional Access, SharePoint full of orphan sites, Teams sprawl, licences nobody tracks. This guide covers the most common M365 governance failures and how to fix them.

Last updated 4 October 20268 min read

Overview

Microsoft 365 environments expand faster than most IT teams can realistically manage without structured governance and lifecycle controls, so a tenant that was tidy at go-live drifts into sprawl within months as staff create teams, sites and groups with no owner, no expiry and no review. ShareGate, managing data sprawl in Microsoft 365.

The visible symptom is sprawl: forty teams whose names begin with Project, three of them for the same project, a team created for a two-week bid dormant for eighteen months that still contains the client pricing, and twelve teams with no owner because the owner left. None of that is a Teams defect; it is what happens when a tool with frictionless creation meets an organisation that never decided what happens after creation. VirtoSoftware, Microsoft Teams Governance 2026.

Microsoft 365 rewards discipline. Left alone, a tenant accumulates ghost admins, forgotten Teams, abandoned SharePoint sites, duplicate files, oversharing, unused licences, and no Conditional Access. It still works, but every task gets harder over time.

Symptoms of a Messy Tenant

The costs that show up on a balance sheet are the audit finding when a regulator asks who had access to a data set and nobody can answer, the eDiscovery bill for searching hundreds of teams because nobody can rule any out, the offboarding gap where a departed employee keeps a team running with no owner, and the slow tax on everyone time when finding the current version of anything takes four attempts. VirtoSoftware, Microsoft Teams Governance 2026.

Staff cannot find the right file in SharePoint
Hundreds of Teams, half unused
Nobody knows who owns half the sites
Files shared anyone with the link everywhere
10 plus Global Admins
No Conditional Access policies
Ex-staff accounts still active
Licences assigned to nobody
Email rules forwarding to personal inboxes
Guest users from three years ago still present

Root Causes

A Microsoft 365 group with no clear owner in Entra ID is the single most common data-sprawl marker, because nobody is accountable for reviewing membership, retiring the workspace when the work ends, or answering a request to remove a departed guest. Self-service creation is useful, but it only works when ownership and lifecycle follow it. ShareGate, managing data sprawl in Microsoft 365.

Self-service everything

Default tenant lets any user create a Team, site, or group. Sprawl starts on day one.

No information architecture

SharePoint designed by whoever clicked New Site. No hub sites, no templates.

No offboarding discipline

Accounts persist, licences stay assigned, delegated access lingers.

Admin creep

Every minor issue becomes a new Global Admin. Review never happens.

No Conditional Access at all

Defaults protect little. Without CA, MFA and device compliance are not enforced uniformly.

External sharing wide open

Default allows anyone with the link. Files leak everywhere.

Practical Fixes (In Order)

Microsoft distinguishes Microsoft 365 Groups, Teams, security groups, mail-enabled security groups and distribution lists because they solve different problems. A cleanup that starts by applying the right object to the right job, rather than deleting everything with low activity, avoids removing a contract library that sits behind a quiet team. Microsoft Learn, compare groups in Microsoft 365.

1

Audit admins

Global Admins down to 2 to 4 plus break-glass. Use PIM for just-in-time elevation.

2

Apply the Conditional Access baseline

MFA for all, block legacy auth, require compliant devices. See the Security Baseline.

3

Clean user and guest accounts

Disable dormant users, remove stale guests, offboard properly.

4

Rationalise Teams and SharePoint

Archive inactive Teams, delete abandoned sites, appoint owners for the rest.

5

Tighten external sharing

Default to specific people, not anyone-with-the-link. Expiry dates on sharing links.

6

Licence audit

Remove licences from terminated users, right-size plans, review Business vs Enterprise mix.

7

Enable unified audit log and alerts

Suspicious inbox rules, impossible travel, external forwarding.

8

Publish an information architecture

Hub sites per division, naming convention for Teams and sites, templates for common cases.

Ongoing Governance

Microsoft 365 group expiration policies automatically renew groups in use and prompt owners to review inactive ones, with a deleted-group restore window so a mistaken expiry is recoverable. Piloting the policy with owned workspaces and verifying the renewal notices reach the right people before broadening its scope prevents accidental loss of seasonal work. Microsoft Learn, Microsoft 365 group expiration.

Quarterly admin role review
Monthly licence reconciliation
Automated offboarding workflow
Expiry dates on all external sharing
Teams and site lifecycle policy (auto-archive after inactivity)
Information sensitivity labels on confidential content
Access reviews for privileged roles (Entra ID P2)

Common Mistakes

Inventorying inactive teams and implementing lifecycle policies reduces both the compliance risk of unmanaged access and the storage cost of abandoned content, but only when the inventory includes ownership, content sensitivity and record obligations. A blanket deletion of anything older than a threshold removes the quiet-but-required work alongside the genuinely abandoned. Netwrix, managing Microsoft Teams sprawl.

Trying to fix it all at once

Prioritise. Admin and Conditional Access first. Information architecture is a longer programme.

Deleting old Teams without communication

Staff lose reference material. Archive first, delete after a cooling-off period.

Locking down everything immediately

Breaks workflows overnight. Phased rollout of controls, with communication.

No named owner for the tenant

Without an accountable person, entropy wins. Assign a tenant owner.

Skipping the audit log

Without it, you cannot investigate or prove compliance. Enable first, retain 12 months plus.

Related: M365 Security Baseline, Offboarding Guide, SharePoint IA Guide, M365 Licensing Guide.

Common questions

How do you clean up a messy Microsoft 365 tenant?
Start with an admin audit to cut Global Admins to two to four plus break-glass accounts, apply the Conditional Access baseline for MFA and device compliance, then rationalise Teams and SharePoint, tighten external sharing defaults, and run a licence audit to remove unused seats.
How many Global Admins should a Microsoft 365 tenant have?
Two to four permanent Global Admins plus break-glass accounts, with just-in-time elevation through Entra ID Privileged Identity Management for anyone else who needs admin access rather than standing admin rights.
How do you stop Microsoft Teams sprawl?
Restrict Team creation to group owners, apply naming conventions such as PRJ or DEPT prefixes, set expiration policies on inactive Microsoft 365 Groups, and archive Teams that have been unused for 180 days so owners get a renewal prompt.
What is SharePoint information architecture and why does it matter?
Information architecture is how you organise sites and documents so people can find what they need: fewer hub sites, metadata over folders, and permissions granted at the site level. Most businesses need 5 to 10 SharePoint sites, not 50.
How often should you audit Microsoft 365 licences?
Run a monthly reconciliation against active staff to catch licences still assigned to departed users, and a full quarterly review to right-size plans and check the Business versus Enterprise mix for waste.
How do you govern external guest access in Microsoft 365?
Set the default sharing level to specific people rather than anyone-with-the-link, put expiry dates on all sharing links, and run guest access reviews every 90 days to remove stale guests from completed projects.

Clean Up Your M365 Tenant

We run M365 tenant audits, fix identity and Conditional Access, rationalise SharePoint and Teams, and set up governance that stays tidy.