M365 Governance Without the Consultant Speak
Every M365 tenant eventually becomes a mess. Teams get created for every meeting. SharePoint sites multiply. Groups accumulate. Nobody cleans them up. Six months after deployment, you have 400 Teams, half of which were used once for a project that ended in February.
This isn't a technology problem. It's a governance problem that nobody wants to own because governance sounds like "I'm going to make your life harder." Good governance does the opposite.
The Teams sprawl solution
Teams creation is too easy. That's both the product's strength and its governance weakness. The fix isn't to restrict creation — that's how you drive people to shadow IT. The fix is lifecycle management.
Group expiration policy: any Microsoft 365 group (which backs every Team) that's inactive for 90 days gets deleted. Not archived. Deleted. Users get notifications at 30, 15, and 1 day before expiration. If the Team is still needed, someone clicks "renew." If it's not, it disappears.
The first time this ran, it deleted 87 groups. Nobody complained. Nobody even noticed. That's the point — cleanup should be invisible.
SharePoint without the chaos
SharePoint sites breed in the dark. Every Team creates a SharePoint site. Every Microsoft 365 Group creates one too. Without governance, you have hundreds of sites with no ownership, no classification, and no lifecycle.
I set up a simple policy: every SharePoint site must have at least two owners. Sites with fewer than two owners get flagged. Sites with no owners for 90 days get archived. Archived sites get deleted after another 90 days. This sounds aggressive. It's not. A site with no owner is a site nobody cares about.
The secondary benefit: this forces teams to acknowledge ownership. "Who owns this site?" is a question that should have a clear answer. If it doesn't, the site shouldn't exist.
External sharing without the panic
External sharing is the feature everyone wants turned off and everyone needs turned on. Marketing needs to share files with agencies. Sales needs to collaborate with customers. HR needs to send documents to candidates. Turning off external sharing is secure but useless.
The middle ground: external sharing enabled, but with controls. Share by invitation only, not by link. Guests must accept invitations within 30 days. Guest accounts without activity for 90 days get removed. Access reviews for all external users quarterly.
This isn't complex. It's four policy settings and a recurring calendar reminder. But most organisations skip the governance and either panic-restrict everything or leave everything open. Both are wrong.
The governance routine
Once a month, I spend 30 minutes on M365 governance:
- Review new groups created this month. Any that look like duplicates or test groups? Flag them.
- Check the group expiration report. Any groups about to expire that should be kept? Notify the owners.
- Run the external user access review. Any guests who shouldn't have access anymore? Remove them.
- Scan for orphaned SharePoint sites. Any with no owners? Start the archive process.
Thirty minutes a month. That's the difference between a clean tenant and a chaotic one. Governance isn't overhead. It's maintenance. Like changing the oil in your car, except your car doesn't accumulate 87 abandoned Teams sites while you're not looking.