The request sounds harmless: “Can we clean up Microsoft 365?”

Then someone discovers that an old Team still receives form submissions, a SharePoint site contains the only approved contract template, and a department’s “shared folder” actually belongs to an employee’s OneDrive. Deleting first and investigating later can turn clutter into an outage.

A safe Microsoft 365 cleanup is not a mass-deletion exercise. It is a controlled process for deciding which workspaces are official, who owns them, who should have access, where important files belong, and what can be archived or removed without interrupting work.

Inventory the Environment Before Changing It

Begin with an inventory of:

  • Microsoft 365 groups and Teams;
  • SharePoint sites, including sites connected to Teams;
  • site owners and administrators;
  • last meaningful activity;
  • internal members and external guests;
  • storage use and high-value libraries;
  • sensitivity or retention requirements;
  • business process, application, or automation dependencies.

Do not treat the “last modified” date on one file as the only activity signal. A workspace may support Teams messages, meetings, a shared mailbox, forms, Power Automate flows, or an application connection.

Microsoft’s current SharePoint site lifecycle management guidance distinguishes ownership, inactivity, and periodic attestation as separate questions. That is a useful cleanup model even when a tenant does not license the automated policy features:

  1. Does the site have accountable owners?
  2. Is it being used?
  3. Does the business still attest that it is needed?

Export the inventory before making changes and keep it as the cleanup control list.

Classify Every Workspace

Use a small number of decisions that employees and administrators can understand.

| Classification | Meaning | Typical action | |—|—|—| | Active and official | Supports current work and has an owner | Retain, document, and correct access | | Active but misplaced | Work is current, but files or membership are in the wrong location | Move carefully and communicate | | Inactive but required | No current activity, but retention or reference value remains | Archive or make read-only | | Duplicate | Another workspace is the approved source | Migrate unique content, then archive | | Ownerless or unknown | Purpose or accountability cannot be confirmed | Investigate; do not delete automatically | | Obsolete | No operational, legal, retention, or reference need remains | Approve deletion and record it |

“Inactive” and “safe to delete” are not synonyms. Microsoft’s inactive-site policy documentation uses owner notification, attestation, reporting, and staged enforcement rather than treating inactivity as immediate deletion.

For smaller tenants, the same control can be maintained with an inventory, named reviewers, and documented decisions.

Trace One Real Document Before Designing the Cleanup

A document trail often reveals the operating problem more clearly than a site list.

Imagine a sales proposal that begins as an email attachment. One employee saves it to OneDrive, another uploads a copy to a Team, and a manager later creates a SharePoint library for approved proposals. Three versions now exist, and no one knows which location is authoritative.

The cleanup decision should answer:

  • Where should a proposal be created?
  • Which workspace owns the final version?
  • Who can edit, approve, and share it?
  • When does it become a record?
  • What happens to copies in personal storage and email?

The solution is not simply “move everything to SharePoint.” It is to define the official path, migrate the authoritative version, preserve needed history, and teach the team how the path works.

This also clarifies the difference between OneDrive and a team-owned workspace. OneDrive is appropriate for an individual’s working files. Content that must survive role changes or be operated by a group should normally live in an appropriately managed shared location.

Fix Ownership Before Permissions

Every retained Team or SharePoint site should have a business owner who can answer:

  • What work belongs here?
  • Who should be a member?
  • Is external sharing permitted?
  • Which content is sensitive?
  • When should the workspace be reviewed or retired?

Where practical, assign at least two responsible owners to avoid dependence on one employee. Separate business ownership from technical administration: an administrator can change permissions, but the business owner should decide who needs access.

An ownerless site should enter an investigation queue. Look for connected groups, active members, linked automations, embedded forms, recent sharing, and business records before deciding its future.

Review Access in Layers

Permissions become difficult to explain when access is granted through a mixture of Teams membership, Microsoft 365 groups, SharePoint groups, direct user permissions, sharing links, and guests.

Review access in this order:

  1. Owners and administrators: confirm named people and remove unnecessary privilege.
  2. Members: verify that group membership matches the workspace purpose.
  3. Guests: confirm sponsor, business need, and expected end date.
  4. Sharing links: identify anonymous or organization-wide links that exceed the need.
  5. Direct permissions: replace one-off access with managed groups where possible.
  6. Exceptions: document access that cannot yet be simplified.

Do not remove access solely because an account looks unfamiliar. Confirm whether it belongs to a vendor, automation, service integration, or legal hold before acting.

Where the review exposes stale administrator rights, departed users, or unmanaged devices, treat those findings through a separate access and identity review instead of hiding them inside a workspace-deletion decision.

Move Content With a Cutover Plan

When content must move, use a migration sequence:

  1. identify the source and authoritative destination;
  2. inventory permissions, links, metadata, versions, and dependencies;
  3. remediate unsupported names, structures, or access patterns;
  4. test a representative pilot;
  5. communicate the destination and cutover time;
  6. move or synchronize content;
  7. make the old location read-only where possible;
  8. validate access, links, workflows, and search;
  9. retain a rollback path until acceptance is complete.

Microsoft’s file-share migration guidance likewise separates assessment, remediation, preparation, pilot migration, cutover, and user onboarding. Cleanup should use the same discipline even when both the source and destination are already inside Microsoft 365.

Archive Before You Delete

Archive a workspace when its content is still needed but active collaboration has ended. The archive decision should record:

  • business owner;
  • reason for retention;
  • access model;
  • archive date;
  • retention or legal constraint;
  • planned review or deletion date;
  • location of any exported dependency documentation.

Deletion requires stronger evidence. Confirm that no retention requirement, automation, application, shared mailbox, form, notebook, meeting artifact, or unique file depends on the workspace. Record the approver and recovery window.

Define the Clean State

A cleanup is complete when the environment is easier to operate, not when the site count reaches an arbitrary target.

The business should be able to answer:

  • Which workspaces are official?
  • Who owns each one?
  • Where do shared documents belong?
  • Which guests and sharing links remain?
  • Which workspaces are archived, and why?
  • Which exceptions still need attention?

Ongoing provisioning and lifecycle rules belong in Microsoft 365 governance. The cleanup establishes the trustworthy baseline that those rules will maintain.

If your tenant has grown without consistent ownership or structure, VesperTek can help inventory the environment and design a controlled Microsoft 365 optimization plan. Contact VesperTek to scope the first cleanup workstream.

Sources and Further Reading