Back to blogMicrosoft 365

Teams and SharePoint Sprawl: How to Clean It Up Without a Migration

8 min read

Every Microsoft 365 tenant that has been running for three years or more has the same problem. Somebody created a Team for a project that finished in 2024. Somebody else created a nearly identical one because they could not find the first. A departed staff member owns nine sites. There is a folder structure in one place, a flat document library in another, and three copies of the current price list, two of which are wrong.

Nobody planned this. It is the predictable result of a platform that lets any user create a collaboration space in about four seconds, running for a few years without governance.

The instinct is usually to propose a migration: design a clean structure, move everything, start again. That is expensive, disruptive, and in our experience frequently fails, because the underlying behaviour that produced the sprawl has not changed. Six months later you have a tidy new structure with a fresh layer of sprawl on top.

There is a better approach, and it does not require a migration.

First, understand what sprawl actually costs you

It is worth being specific, because "it is messy" is not a business case.

Security exposure grows with every unmanaged site. An orphaned SharePoint site with no owner still has permissions, still holds documents, and still shows up in search for whoever has access. Sites created for a short-lived project with an external partner often retain guest access long after the project ended. Every one of these is an access path nobody is reviewing.

Staff waste real time. When people cannot find the current version of a document, they either recreate it or they ask someone. Both are expensive. In a fifty-person business, ten minutes a day per person lost to hunting for files is over a thousand hours a year.

Decisions get made on stale documents. This is the cost that hurts most and gets measured least. Somebody quotes from an old price list, commits to an old SLA, or works from a superseded policy.

Compliance and discovery get harder. If you are ever asked to produce all records relating to a client, a matter, or a period, sprawl turns a defined task into an open-ended one. The same applies to a Privacy Act request or a cyber insurance questionnaire that asks where your sensitive data lives.

Work out what you have

You cannot govern what you have not measured. Start with a read-only audit. This is entirely non-disruptive and can be done from the admin centre and reporting tools you already have.

For every Team and SharePoint site, capture the following:

  • The named owner. Not the creator. An actual current staff member who accepts responsibility for it.
  • The last meaningful activity date. Not the last time a sync client touched a file, but the last time a human added, edited, or read something.
  • The membership count, and specifically the guest count. External members are where the risk concentrates.
  • The sensitivity of the content. Does it hold client data, financial records, contracts, personal information?
  • The stated purpose. One sentence. If nobody can supply one, that is the finding.

Most tenants we audit come back with a similar shape. Somewhere between fifteen and thirty per cent of sites are genuinely active and well owned. Another quarter are active but poorly organised. The remainder, often close to half, are dormant, orphaned, or duplicates.

That distribution is the good news, because it means the majority of the problem is deletable rather than fixable.

Retire before you reorganise

Work through the dormant and orphaned material first. It is the largest category, it carries most of the security exposure, and it requires no design decisions.

Set a dormancy threshold and stick to it. Twelve months with no meaningful activity is a reasonable default for most businesses. Some regulated content needs longer; decide that once, as a rule, rather than site by site.

Never delete straight away. The pattern that works is: notify, wait, archive, then delete. Notify the last known owner and members that a site is scheduled for archive, with a clear date and an easy way to object. Wait a genuine period, four weeks is sensible. Archive to a read-only state rather than deleting. Only after a further period, typically twelve months, does deletion follow.

Handle orphaned sites explicitly. For anything with no living owner, the site needs to be assigned to a department head who either claims it or agrees it can be archived. This is a five-minute conversation per site and it is the single highest-value part of the exercise.

Revoke stale guest access immediately, separately from the archive process. This does not need to wait for the notify-and-wait cycle. Any external guest who has not signed in for six months should be removed now. If they need access again, re-granting takes a moment.

By the time this pass is done, most businesses have removed a third to a half of their sites and closed the majority of their unmanaged external access. No migration has occurred, no active user has been disrupted, and the remaining problem is now small enough to reason about.

Then put governance in place

This is the part that prevents a repeat. It is also the part that gets skipped, which is why the cleanup keeps needing to be redone.

Decide who can create Teams. The default in Microsoft 365 is that anyone can. For most businesses under a hundred staff, restricting creation to a small group, or routing it through a lightweight request, removes the primary source of sprawl at almost no cost to productivity. The objection is always that it will slow people down. In practice, a request that is approved the same day is not a meaningful barrier, and the discipline of naming an owner and a purpose at creation time is worth more than the friction costs.

Require an owner and a purpose at creation. Two mandatory fields. Every site has a named human responsible for it and a one-line description of what it is for. This alone makes every future audit dramatically cheaper.

Set expiry policies. Microsoft 365 supports group expiration: a site with no activity prompts its owner to confirm it is still needed, and archives if nobody responds. Configure it once and the dormancy problem largely manages itself from then on.

Adopt a naming convention. It does not need to be elaborate. A prefix that distinguishes client work from internal from projects, plus a consistent format, makes search work and makes duplicates visible before they are created.

Review guest access on a schedule. Quarterly, an owner confirms each external member still needs access. This takes minutes per site and it is the control that cyber insurers increasingly ask about directly.

Set sensitivity labels for the content that matters. You do not need to label everything. Identify the categories that genuinely carry risk, client data, financial records, personal information, and label those. Labels then drive retention and sharing restrictions automatically.

What this looks like in practice

For a fifty-person business with a three-year-old tenant, the realistic shape is:

The audit takes two to three days, most of it automated reporting followed by a review conversation. The retirement pass runs over about six weeks, dominated by the notify-and-wait period rather than by effort. The governance configuration is one day of work. The ongoing cost is a quarterly review that takes an hour.

The result is not a perfectly organised tenant. It is a tenant where every site has an owner, dormant material ages out on its own, external access is reviewed, and the sensitive content is labelled. That is a materially better security and compliance position than a beautiful structure that nobody maintains.

A note on what not to do

Two common approaches make things worse.

Do not build the perfect information architecture first. Designing a comprehensive taxonomy before cleaning up is how these projects stall. The taxonomy takes months to agree, and by the time it is agreed the sprawl has grown. Clean up first, structure the survivors second.

Do not migrate to a new platform to escape the mess. The mess is a governance problem, not a platform problem. It will follow you. Businesses that move to a new collaboration platform without fixing governance reliably recreate the same sprawl in the new system, and now they have two.

Where to start this week

The audit is the only step that has to come first, and it is read-only, so it carries no risk. Everything else follows from what it shows.

If you would like an outside view of what your tenant actually looks like, our free IT health check includes a Teams and SharePoint sprawl audit. We report site count, ownership gaps, dormancy, and external access exposure, with a prioritised cleanup plan. Read-only, no changes made, no obligation.

Learn more about our Microsoft 365 services

Need help with microsoft 365?

Our free IT health check will show you exactly where your business stands and what to prioritise. No obligation.

Book your free health check

Get IT insights in your inbox

Practical tips for Australian businesses. No spam. Unsubscribe anytime.