First page of Microsoft's 100,000-partner directory, sorted by responsiveness Microsoft Solutions Partner — Security, Modern Work, Infrastructure, App Innovation Microsoft partner since 2006 1,100+ organizations under management
Home/Services/Microsoft 365 External Sharing and Guest Access Cleanup
Security and ProtectionImplementation

Microsoft 365 External Sharing and Guest Access Cleanup

Every Microsoft 365 tenant that has collaborated with the outside world for a few years is holding access it never consciously granted: guest accounts from projects that finished years ago, 'Anyone' links pasted into emails in 2022, sites shared with everyone in the organization by someone who has since left, and external members of teams nobody reviews. Microsoft applies no expiry to any of it unless you switch expiry on. This is a fixed-price, two-week cleanup for one tenant. IT Partner inventories every guest in Microsoft Entra ID — invitation source, sponsor, last sign-in, and every group, team and site the guest can reach — plus every anonymous and organization-wide sharing link across the SharePoint sites and OneDrive accounts in scope, every externally shared team and shared channel, and every site whose sharing settings sit outside the baseline we agree with you. We then remove what the owners confirm is finished, tighten the tenant and site defaults that let it accumulate — default link type, link expiry, guest expiry, domain allow and block lists, who may invite — and leave recurring owner-driven reviews running, with a dated before-and-after evidence pack. $2,950 fixed, covering one tenant with up to 500 guest accounts and 100 sites in the cleanup scope; larger estates are quoted per tenant in writing before anything starts. Microsoft licensing, and any metered Microsoft Entra ID Governance charge for governed guests, are yours.

Timeline 2 weeksService owner Roman SotnikMicrosoft 365Microsoft Entra IDSharePoint Online

What this engagement is

External access in Microsoft 365 accumulates because nothing in the platform makes it stop. A guest invited for a two-month project keeps the invitation forever; an 'Anyone' link created to get a file to a client keeps working long after the deal closes; a site shared with 'everyone except external users' quietly becomes tenant-wide reading; a partner's staff turn over and their accounts stay. None of it expires by default — guest lifetime, sharing-link lifetime and site-level review are all opt-in settings that most tenants have never turned on. The bill usually arrives as a question rather than a breach: an auditor asking who outside the company can read the finance site, a cyber-insurance questionnaire asking how external access is reviewed, a departed partner nobody thought to remove, or a Microsoft 365 Copilot rollout that makes every over-broad permission suddenly easy to exercise. This engagement answers that question with evidence and then fixes what the evidence shows, in two weeks, for one tenant. We inventory four surfaces, not one. Guests in Microsoft Entra ID: every guest account with its invitation source, sponsor where one was recorded, last sign-in, creation date, and the groups, teams and sites it can reach. Sharing links in SharePoint and OneDrive: anonymous 'Anyone' links, organization-wide links, and links that reach people outside the company, per site and per library across the sites in scope, including the OneDrive accounts of people who have left. Teams and channels: teams with external members, shared channels running on Microsoft Entra B2B direct connect, and the cross-tenant access settings that permit them. Site and tenant settings: the external-sharing level of every in-scope site compared with the baseline you agree, plus externally shared sites with no surviving owner. Everything then lands in one decision workbook — one row per finding, with the owner who has to decide and our recommendation — and removal runs in waves against that workbook, never against a script's opinion. The part most cleanups get wrong is what happens after. Deleting a thousand stale guests and leaving the tenant configured exactly as it was buys you about six months. So the second week is spent on the settings that stop re-accumulation: default sharing link type and permission, expiry on anonymous and guest links, guest access expiry for sites, domain allow or block lists at the Microsoft Entra and SharePoint levels, who is allowed to invite guests at all, per-site sharing levels that match what the site actually holds, and recurring reviews that ask site and team owners — not IT — whether external access is still needed. Where your licensing supports it, those reviews are automated: SharePoint Advanced Management site access reviews delegated to site owners, and Microsoft Entra access reviews scoped to guests. Where it does not, you get the same cadence as a runbook your admins run, and we say so before the project starts rather than at the handover. One structural honesty note, because it changes what a guest cleanup can promise. Guest accounts are only one of the doors. External participants in Teams shared channels connect through Microsoft Entra B2B direct connect and never get a guest object in your directory at all — they stay in their home tenant, and they are governed by your cross-tenant access settings, not by your guest list. Deleting guests does nothing to them. This engagement covers both, and the inventory says plainly which external person reaches you through which mechanism. Boundaries are drawn where the neighbouring services begin. Teams lifecycle governance — naming, creation, expiration, ownerless-team attestation — is Microsoft Teams Governance and Sprawl Cleanup; here we touch Teams only where external access lives. What your own employees can over-reach internally, and what Copilot can therefore surface, is Microsoft 365 Copilot Oversharing Assessment and Remediation. The monthly cycle after this cleanup is Managed Entra ID Identity Hygiene and Access Reviews. And the wider identity-governance programme — access packages, entitlement management, lifecycle workflows for external users — is Microsoft Entra ID Governance Implementation.

Success criteria

01A dated inventory of external access exists for the tenant in one place: every guest account with last sign-in, invitation source, sponsor where recorded and the groups, teams and sites it can reach; every anonymous and organization-wide sharing link found in the in-scope sites and OneDrive accounts; every team and shared channel with external participants; and every in-scope site's sharing level against the agreed baseline.
02Every finding has a named owner and a recorded decision — keep, replace with a narrower link, remove access, or delete the account — in the decision workbook you sign off. Nothing was removed on our judgement alone.
03Guest accounts approved for removal are gone from the tenant, or disabled first and removed on the agreed delay, with the audit evidence of each action and a restore path inside Microsoft's documented 30-day window for deleted users.
04Anonymous and organization-wide sharing links approved for removal no longer exist; live collaborations that depended on them were re-shared as specific-people links before the old link was revoked.
05Tenant and site sharing defaults match the approved baseline — default link type and permission, link and guest expiry, domain allow or block lists, guest invitation permissions, and the per-site sharing level of every in-scope site.
06External access to teams and shared channels matches the approved model, with cross-tenant access settings configured for the organizations you actually work with rather than left at 'everyone'.
07Recurring reviews are live and have completed one cycle in front of us: SharePoint site access reviews and Microsoft Entra guest access reviews where your licensing supports them, or the manual review runbook executed once with your admins where it does not.
08You hold a before-and-after report that states, on a dated basis, what external access existed at kickoff, what was removed, what was deliberately kept and why — the document that answers the auditor's or the insurer's question.

What you receive

Guest inventory (Microsoft Entra ID): every guest account with creation date, invitation source, sponsor where recorded, last sign-in, account state, and the groups, teams and sites the account can reach — exported and explained, not just dumped.
External sharing report (SharePoint and OneDrive): anonymous 'Anyone' links, organization-wide links and externally shared items across the in-scope sites and OneDrive accounts, ranked by reach and by the sensitivity of what they expose.
Teams and shared-channel report: teams with external members, shared channels running on Microsoft Entra B2B direct connect, and the cross-tenant access configuration that allows each one — with the distinction between guests and direct-connect participants made explicit.
Site settings comparison: every in-scope site's external-sharing level, permitted domains and link defaults against the tenant baseline, plus externally shared sites with no surviving owner.
Decision workbook: one row per finding, the owner who must decide, our recommendation, the decision recorded, and the date it was executed — the evidence trail the whole cleanup runs on.
Removal waves executed with owner sign-off: guest access removed or accounts disabled and deleted per your policy, stale sharing links revoked, over-broad site permissions narrowed, external team and channel membership corrected.
Tenant and site sharing baseline implemented: default link type and permission, anonymous-link and guest-access expiry, Microsoft Entra external collaboration settings including who may invite and which domains are allowed or blocked, SharePoint domain restrictions, and per-site sharing levels.
Recurring review setup: SharePoint site access reviews delegated to site owners and Microsoft Entra access reviews scoped to guests where your licensing supports them, configured with the reviewers, cadence, escalation and auto-apply behaviour you approve.
External access runbook: the quarterly (or monthly) cycle written down — which reports to pull, which thresholds to apply, who chases owners, what to do with non-responses, and how to onboard a new external partner cleanly.
Before-and-after report: the same measurements re-run at the end of the engagement, dated, with what was removed, what was kept and the named reason for each exception — plus the backlog of anything the fixed scope did not cover.

How the work unfolds

Days 1–2 — Access, discovery and the first evidence pull

We take the time-bound delegated access you approve, confirm what your licensing makes visible, and run the discovery: guest accounts and their reach from Microsoft Entra ID and Microsoft Graph, sharing-link and permission reports from the SharePoint admin center (data access governance reports where SharePoint Advanced Management is entitled, PowerShell and Graph inventory where it is not), Teams external membership and shared channels, cross-tenant access settings, and per-site sharing configuration. Read-only: nothing changes this week without a decision behind it.

Day 3 — Baseline and decisions workshop

A two-hour working session with whoever owns security and collaboration. We agree the target external-sharing baseline (who may invite, default link type, expiry periods, allowed or blocked domains, which site tiers may share externally at all), the removal posture (remove access, disable then delete, or delete outright, and the response window before the default applies), and the review model you will live with afterwards. Every setting we change traces back to a decision made in this session.

Days 4–5 — Owner attestation

The decision workbook goes to site and team owners through your communications channel: here is who from outside can reach your site, here is what they last did, tell us what to keep. We chase, consolidate the answers, and escalate the sites whose owners do not respond or no longer exist to your named decision-maker — they are never silently deleted and never silently kept.

Days 6–7 — Removal waves

Execution against the attested workbook, in waves and in a deliberate order: replace live collaborations that depend on anonymous links with specific-people links first, then revoke the stale links, then remove guest access from groups, teams and sites, then disable or delete the guest accounts per the agreed policy. Each wave is logged, checked against Microsoft's audit records, and paused if anything looks wrong.

Days 8–9 — Settings baseline and recurring reviews

The tenant and site settings that let it all accumulate are brought to the approved baseline — Microsoft Entra external collaboration settings, cross-tenant access, SharePoint and OneDrive sharing defaults, link and guest expiry, domain lists, per-site sharing levels. Then the reviews are configured and started: site access reviews delegated to site owners, and guest access reviews in Microsoft Entra ID, with the scope, cadence and non-response behaviour agreed at the workshop.

Day 10 — Evidence, runbook and handover

Discovery is re-run for the before-and-after report, the runbook is walked through with your admins, the first review cycle is inspected together, and the residual backlog — anything outside the fixed scope — is written down and costed so nothing quietly disappears at the end of the engagement.

Prerequisites

One Microsoft 365 tenant, and delegated administrative access we request as time-bound, least-privilege roles that you approve — typically SharePoint Administrator, Teams Administrator, and a directory role that can read sign-in activity and manage guest accounts. We never ask for standing Global Administrator.
Microsoft Entra ID P1 or higher for last-sign-in data: the sign-in activity properties Microsoft Graph exposes for reporting require Microsoft Entra ID P1 or P2 (P1 is included in Microsoft 365 Business Premium, E3 and E5). Without it we can still inventory guests and their access, but 'when did this guest last sign in' becomes an estimate from audit logs rather than a reported fact.
For the SharePoint data access governance reports and site access reviews: SharePoint Advanced Management entitlement. Most of its features become available to SharePoint administrators once at least one Microsoft 365 Copilot licence is assigned in the tenant; otherwise it is a paid add-on. We verify your exact entitlement in your tenant during the first two days and fall back to PowerShell and Microsoft Graph inventory where it is absent — the cleanup still happens, the reporting is simply more manual.
For automated recurring guest access reviews: Microsoft Entra ID P2, Microsoft Entra ID Governance or Microsoft Entra Suite, depending on the review type you choose. Reviews scoped to inactive guests, machine-learning reviewer recommendations and lifecycle workflows for guests are Microsoft Entra ID Governance features and require an Azure subscription linked to the tenant for billing.
A named decision-maker with the authority to set the external-sharing baseline and to arbitrate sites whose owners do not respond.
A communications channel to site and team owners, and agreement on who sends the attestation messages — the removal waves move at the speed of owner answers, and messages from IT get answered faster than messages from a consultant.
Agreement, before the first removal, on the default action for non-responses and on whether guest accounts are removed from resources, disabled, or deleted — with the delay between disable and delete written into the workbook.

Who does what

IT Partner

  • Run the discovery across all four surfaces and present it as evidence a non-specialist can act on, not as raw exports.
  • Put every policy choice in front of you with its trade-off before implementing it, and record the decision.
  • Drive the attestation: prepare the owner communications, chase, consolidate, and escalate what nobody answers.
  • Execute removals in the agreed order and posture, with logging, verification against Microsoft's audit records, and a documented restore path for each type of action.
  • Implement the tenant and site sharing baseline and the recurring reviews, and prove they work by watching one cycle complete.
  • Deliver the before-and-after report and the runbook, and hand over the residual backlog costed and in writing.

Your team

  • Approve the delegated access request and confirm the licensing position we verify at kickoff.
  • Make the baseline decisions at the workshop — this is your external-collaboration policy, not a template we impose.
  • Send the owner communications through your channel, on the agreed schedule.
  • Arbitrate escalations: sites and teams where no owner responds need a business decision, not an IT default applied quietly.
  • Approve each removal wave before it runs, and the deletion queue explicitly.
  • Own the review cycle after handover — or move it to the managed service if you would rather we ran it.

What's not included

Teams lifecycle governance beyond external access — naming policy, creation control, expiration with activity-based renewal, ownerless-team attestation and the sprawl cleanup itself — is Microsoft Teams Governance and Sprawl Cleanup. Here we change guest and external-channel settings only.
Internal oversharing and what Microsoft 365 Copilot can surface to your own employees — 'everyone except external users' grants, broken inheritance, unlabeled sensitive content — is Microsoft 365 Copilot Oversharing Assessment and Remediation and, at programme scale, Microsoft Purview Data Governance for Microsoft 365 Copilot.
Data loss prevention policy design and enforcement is Configure and Enable DLP Policies; sensitivity-label taxonomy and rollout is Azure Information Protection Implementation. This service acts on who can reach content, not on classifying or blocking the content itself.
The ongoing cycle after this cleanup — monthly guest and access hygiene, recurring reviews run for you, drift reporting — is Managed Entra ID Identity Hygiene and Access Reviews. This engagement leaves you the runbook and the configured reviews; running them every month is a separate, recurring scope.
The wider identity-governance programme — access packages, entitlement management, approval workflows, lifecycle workflows for external users — is Microsoft Entra ID Governance Implementation. We configure guest access reviews; we do not build the entitlement-management catalogue here.
Customer- and partner-facing identity for your own applications — sign-up and sign-in flows, external tenants, CIAM — is Microsoft Entra External ID Implementation. Business-to-business collaboration inside Microsoft 365 is what this service covers.
SharePoint information architecture, hub topology and permission model redesign is the SharePoint Governance and Information Architecture Review. Where the cleanup shows a site whose structure is the real problem, we say so and cost it separately.
A full security-baseline assessment against a published framework — for that, the Microsoft 365 Advanced Security Audit Using the SCuBA Framework.
Content migration out of sites being retired, tenant-to-tenant moves, eDiscovery or legal-hold decisions about what must be preserved before anything is removed, and forensic investigation of a suspected external breach — each is separate work, and we will not start a removal wave over an unresolved hold.
Microsoft licence costs, including SharePoint Advanced Management where your tenant lacks a Copilot licence, Microsoft Entra ID P1 or P2, and Microsoft Entra ID Governance — and any metered Microsoft Entra ID Governance charge for governed guests, which Microsoft bills to your Azure subscription per monthly active guest. Those are yours; we tell you what a decision will cost before you make it.

Limitations & technical notes

!This is a point-in-time cleanup. New guests and new sharing links appear the day after we finish — which is exactly why the settings baseline and the recurring reviews are half the engagement, and why the runbook matters more than the removal count.
!Guest accounts are not the whole external surface. External participants in Teams shared channels use Microsoft Entra B2B direct connect and have no guest object in your directory; they are controlled by cross-tenant access settings. Any tool or consultant who measures external access purely by counting guest accounts is under-reporting it, and we will show you the difference in your own tenant.
!Microsoft's sharing-link and guest-expiry controls have documented carve-outs. The SharePoint guest expiration policy applies to guests who hold direct site permissions or arrived through a sharing link — it does not cover guests who reach content through Microsoft 365 group or team membership, and Microsoft's guidance indicates it is not retroactive to access granted before it was enabled. We verify the behaviour in your tenant rather than assuming it, and cover the gap with access reviews.
!The Sponsors field that records who is responsible for a guest is only as good as how the guest was created: Microsoft documents that guests invited through SharePoint sharing do not get a sponsor recorded. Where it is empty we reconstruct accountability from invitation audit records and site membership, and set sponsors going forward — but for the oldest accounts the honest answer is sometimes 'nobody living remembers, ask the site owner'.
!Last-sign-in reporting depends on licensing. Microsoft requires Microsoft Entra ID P1 or P2 for the sign-in activity properties Microsoft Graph exposes; without it, 'inactive' is inferred from audit logs and creation dates and is weaker evidence. We say which of the two your report is based on.
!Depth of reporting follows SharePoint Advanced Management entitlement. Data access governance reports and delegated site access reviews need it; Microsoft makes most SharePoint Advanced Management features available to SharePoint administrators when at least one Microsoft 365 Copilot licence is assigned in the tenant, and not every feature is included that way. Where it is absent we inventory through PowerShell and Microsoft Graph — slower to produce, same decisions at the end.
!Automated guest reviews can carry a Microsoft charge that is yours, not ours. Standard Microsoft Entra access reviews of groups and applications are a Microsoft Entra ID P2 capability; reviews scoped to inactive guests, machine-learning reviewer recommendations, catalogue reviews and lifecycle workflows for guests are Microsoft Entra ID Governance features, billed per monthly active governed guest against an Azure subscription linked to your tenant. We design the review model around the licence position you choose, and we tell you which option starts a meter before you choose it.
!Removal moves at the speed of owner decisions, and revoking access is visible to the people who lose it. An 'Anyone' link stops working the moment it is revoked, which is why live collaborations are re-shared before old links are cut. Deleted guest accounts are restorable inside Microsoft's documented 30-day window; after that, re-invitation is a new account with new permissions.
!The fixed fee covers one tenant with up to 500 guest accounts and 100 sites in the cleanup scope. The guest inventory and the tenant-level settings review still run across the whole tenant, so the identity picture is always complete; what the cap bounds is the site-by-site sharing scan, the attestation and the removal waves. If the estate is materially larger, we say so at the scoping call and quote the extra waves per tenant before starting, not in week two.
!Microsoft renames and re-licenses controls in this area regularly. Every product statement on this page carries the position at the time of writing and is re-checked at each review of this service; where Microsoft's current documentation disagrees with us, Microsoft is right and we implement what your tenant actually offers.

Frequently asked questions

Will removing guests and links break work that is still going on?

That is the risk the whole method is built around, so the order of operations is deliberate. Nothing is removed until the site or team owner has looked at the row and answered. Live collaborations that depend on an anonymous link are re-shared as specific-people links before the old link is revoked, so the partner keeps working through a link that is now attributable. Guest accounts can be removed from resources, disabled for an agreed period, or deleted — your choice, recorded before the first wave. And a deleted guest account is restorable inside Microsoft's documented 30-day window, so a mistake in week two is recoverable in week six.

What actually counts as 'external access' in Microsoft 365?

Four different mechanisms, which is why counting guest accounts alone under-reports the problem. Guest accounts in Microsoft Entra ID (B2B collaboration) are the visible ones. Anonymous 'Anyone' links in SharePoint and OneDrive grant access with no account at all — whoever holds the URL. Organization-wide links are internal but frequently behave like external exposure once a link leaves the building. And Teams shared channels use Microsoft Entra B2B direct connect, where the external person keeps working in their own tenant and never appears in your guest list. This engagement inventories all four and tells you which people reach you through which door.

Do we need SharePoint Advanced Management for this?

No, but it changes how the reporting is produced. SharePoint Advanced Management supplies the data access governance reports and the site access reviews that let you delegate a finding straight to a site owner. Microsoft makes most of its features available to SharePoint administrators once at least one Microsoft 365 Copilot licence is assigned in the tenant; otherwise it is a paid add-on, and not every feature is covered by the Copilot route. We check your exact entitlement in the first two days. Without it, we produce the same inventory through PowerShell and Microsoft Graph and run the attestation through your own communications — more manual to build, identical decisions at the end.

Do we need Microsoft Entra ID P2 or ID Governance for the recurring reviews?

It depends on the review you want. Access reviews of groups and applications, including reviews scoped to guest users, are a Microsoft Entra ID P2 capability. The features that make guest review genuinely low-effort — reviews scoped to inactive guests using a tenant-level inactivity threshold, machine-learning reviewer recommendations, catalogue reviews and lifecycle workflows for guests — are Microsoft Entra ID Governance features. Those are billed by Microsoft per monthly active governed guest and require an Azure subscription linked to your tenant; that charge is yours and we will not pretend otherwise. If you hold neither, the review cadence ships as a runbook and we execute one cycle with your admins.

How do you work out who invited a guest nobody remembers?

In order of reliability: the Sponsors field on the guest object, where it was populated at invitation; the invitation and audit records showing which account created the guest and when; and the resources the guest can reach, which tells you which site owner has to decide. Microsoft documents a gap here — guests created by SharePoint sharing do not get a sponsor recorded — so for the oldest accounts the honest answer is often that accountability has to be re-established rather than looked up. Setting sponsors correctly going forward is part of the baseline we implement.

Will you delete guest accounts, or just remove their access?

Whichever you decide, and the decision is made at the workshop before anything is executed. Removing a guest from a group, team or site ends the access but keeps the account, which is right when the relationship is dormant rather than over. Disabling the account blocks sign-in while keeping everything reversible — the pattern Microsoft's own guidance uses for stale guests is to block sign-in first and delete after a defined period. Deleting removes the account entirely, with the 30-day restore window as the safety net. Most clients land on: remove access at the resource for anything ambiguous, disable-then-delete for guests inactive beyond the threshold they set.

What happens to Teams shared channels and the partners in them?

They are inventoried and governed separately from guests, because they are a different mechanism. Shared-channel participants connect through Microsoft Entra B2B direct connect and stay in their home tenant, so removing guest accounts does nothing to them — what governs them is your cross-tenant access settings, which decide which external organizations may connect inbound and outbound at all. We show you which organizations are currently trusted, which shared channels exist, and who is in them, and we implement the model you approve: usually a named list of partner tenants instead of an open default.

What will our own users notice after the cleanup?

Three things, and we would rather you heard them here than from the service desk. Sharing gets a different default — usually a specific-people link with an expiry, instead of an anonymous link that lives forever. Sharing outside allowed domains, or inviting guests at all, may now be restricted to a defined group of people or require a request. And owners start receiving review prompts on a schedule. The mitigation is the communication plan and the response windows; the alternative is a tenant where nobody can answer the auditor's question.

Do 'Anyone' links stop working immediately when you revoke them?

Yes — that is the point of them, and the reason we never revoke in bulk without evidence. The inventory shows which links exist, where they point, and where we can see recent activity against them. Anything that looks live goes back to the owner first and is replaced with a specific-people link before the anonymous one is cut. Anything with no activity and no owner claim is revoked in the wave, and the workbook records who approved it — if a request comes back later, the row explains exactly what happened and who decided.

How is this different from your Copilot oversharing service?

Direction of exposure. This service is about people outside your organization: guests, anonymous links, external channels, partner tenants. The Copilot oversharing service is about your own employees and what Copilot makes easy for them to find — 'everyone except external users' grants, broken inheritance, unlabeled sensitive content in sites that were never meant to be tenant-wide. They overlap in the reports and share some remediation, but they answer different questions. If a Copilot rollout is the trigger, most tenants need both; we will tell you which one to do first based on what your discovery actually shows.

How is this different from your managed identity hygiene subscription?

This is the one-time cleanup that makes a monthly cycle affordable; Managed Entra ID Identity Hygiene and Access Reviews is that monthly cycle. Running a recurring service against years of untriaged backlog means paying a monthly fee to look at the same thousand-row report every month. Clear the backlog once, set the baseline that stops re-accumulation, then either run the runbook yourselves or hand the cycle to the managed service. Both work; doing them in the other order does not.

What if we have far more than 500 guests or 100 sites?

The guest inventory and the tenant-level settings review always run across the whole tenant — a partial guest list is not evidence, and you get the complete identity picture regardless of size. What the fixed fee bounds is the deep work: the site-by-site sharing scan, the owner attestation and the removal waves, for up to 500 guest accounts and 100 sites. Larger estates are prioritized by risk — anonymous links first, then guests with no sign-in and broad reach, then everything else — and the remainder is quoted per tenant, in writing, before that work starts. We would rather tell you at the scoping call that this is a two-phase job than discover it on day eight.

Can you do this without disrupting an active audit or legal hold?

Yes, and it has to be planned for. Removing access is not the same as deleting content, but retention, holds and eDiscovery obligations can still make a removal the wrong move at the wrong moment. We ask at kickoff whether any hold, investigation or audit is live, and anything covered is flagged in the workbook and left alone until your compliance owner releases it. We will not run a removal wave over an unresolved hold to hit a milestone date.

What do we get at the end, and what does it cost?

$2,950 fixed for one tenant, two weeks, covering up to 500 guest accounts and 100 sites in the cleanup scope. You get the four inventories, the signed decision workbook, the executed removal waves with their evidence, the implemented sharing baseline, the recurring reviews configured and one cycle observed, the runbook, and the dated before-and-after report that answers the auditor's or the insurer's question. The quote is in writing before work begins and you pay after you approve delivery. Microsoft licence costs and any metered Microsoft Entra ID Governance guest charges are billed by Microsoft to you, not by us.

Didn’t find your question?

Ask it here. A real engineer answers by email within one business day — and if it’s a good one, it becomes part of this page so the next person finds it.

Answered by a person, one time, to your inbox. Nothing you type here is published without a human reviewing and anonymizing it first.

Often combined with

$2,950 per project
2 weeks
Scope my guest cleanup