Skip to main content

Inactive SharePoint Sites Keep Their Permissions. Retire Them on a Policy, Not a Hunch.

Nick Ross4 min read

TL;DR

  • An inactive SharePoint site keeps consuming storage, keeps every permission and sharing link it ever had, and stays available to Copilot.
  • Site Lifecycle Management in SharePoint Advanced Management finds inactive sites, asks owners to certify them, and enforces read-only or archive when nobody answers.
  • Read-only is reversible, so an administrator can unlock a site later if the business needs it again.
  • Read-only does not remove content from Copilot. Restricted Content Discovery is the control that keeps a site out of Copilot, Microsoft 365 AI agents, and organization-wide search.
  • Enforcement actions cannot be edited after a policy is created, which is why the first run belongs in simulation mode.

Nobody sets out to build a graveyard. A site gets spun up for a project, the project ships, the team moves on, and the site stays exactly where it was. Do that for a few years and the Active sites list in the SharePoint admin center fills up with old project sites, dead vendor portals, test sites, and content that has not had an owner in three years.

Calling that clutter undersells it.

What an abandoned site still costs you

Three bills keep arriving after everyone stops using a site.

Storage. Old content keeps consuming SharePoint storage on the tenant you are paying for.

Security. Permissions, sharing links, and old access all survive the project that created them. Nobody revoked anything, because nobody was watching.

AI readiness. Copilot and other AI tools can surface outdated content that users can technically still reach. Stale content becomes an answer with the same confidence as current content.

Microsoft now ships tooling to work through this without a manual site-by-site review, which is what makes it a repeatable service rather than a one-off cleanup weekend.

Build the inventory before you build the policy

SharePoint Advanced Management includes Site Lifecycle Management, which identifies sites that have gone quiet over time. The shape of it is simple: Microsoft evaluates activity across the environment, sites that cross your inactivity threshold get flagged, owners are asked to confirm whether the site still matters, and sites that nobody certifies can be moved to read-only or archived.

You set the inactivity definition, whether that is 90 days, six months, or something else that fits the organization.

Start in the SharePoint admin center under Advanced Management and run an assessment.

SharePoint admin center content management assessment showing 23 sites requiring attention under Site lifecycle

The assessment surfaces inactive sites, sites missing owners, last activity dates, site storage, and site ownership. Results export to CSV when you want to work the list outside the portal.

CSV export of inactive site results showing site name, template, last activity date, owner, creation date, storage used, and inactive and ownerless flags

For MSPs, that export is a discovery artifact. Walk the inventory with the customer before any policy exists and pull out the sites that can be retired immediately. The conversation is much easier when the customer is looking at their own site names and dates.

Turn the inventory into an inactive site policy

Once the environment makes sense, go to Advanced Management > Policies > Site Lifecycle Management and create a new inactive site policy.

Site lifecycle management page in the SharePoint admin center showing inactive site, site ownership, and site attestation policy options

Scope comes first: upload a CSV of specific URLs, or select sites at scale by type and filter. OneDrive sites are excluded automatically, and you can choose whether sites under retention policies or retention holds are in scope, plus exclude specific sites outright.

Set policy scope step of the inactive site policy wizard with options to upload a CSV or select sites at scale

Configuration is where the policy gets its judgment: how long a site must be inactive, who gets notified, and what happens when nobody responds. We usually start at a three to six month window, then adjust once the first round of results comes back.

Configure policy step showing a six month inactivity window, site owner notification, and enforcement action choices

The notification is worth customizing rather than accepting. Owners receive an email asking them to certify the site, and the wording of that email decides whether they engage or ignore it.

Customize email dialog with subject, message, and policy guideline fields alongside a live preview of the certification email with a Certify site button

If the owner confirms the site is still needed, it stays active. If they confirm it is not, or they say nothing at all, the policy takes the enforcement action you configured.

Read-only or archive, and why the first run should change nothing

Two enforcement options, two different promises.

Read-only access lets users keep viewing the site but stops them modifying content. It is the right first move when you are not ready to remove anything, and it is reversible: an administrator can unlock the site later if the business needs it back. Microsoft documents the unlock path in Manage inactive sites using inactive site policies (opens in new tab).

Archive the site hands it to Microsoft 365 Archive, which reduces active storage consumption while preserving content you may still need to retain.

Enforcement selection in the policy wizard showing read-only access and archive after a mandatory read-only period, with a note that enforcement actions cannot be edited after policy creation

Read the fine print in that screen before clicking through: enforcement actions cannot be edited after the policy is created. That single line is the argument for starting in simulation mode, which generates the reports and shows you what would happen without touching site access. Move to enforcement once the results stop surprising you.

Read-only leaves the Copilot problem open

Locking a site does not remove it from AI experiences. If users can still discover the content, Copilot can still reference it, which means a site full of stale or sensitive material can be frozen and still be quoted.

SharePoint Advanced Management handles that with Restricted Content Discovery, a per-site setting that keeps content out of Copilot, Microsoft 365 AI agents, and organization-wide search results.

Site settings panel in the SharePoint admin center with Restrict content discovery set to On for a selected site

Keep the two controls in separate mental buckets. Site Lifecycle Management decides what happens to an inactive site. Restricted Content Discovery decides whether that site's content keeps showing up in AI and search. Sites carrying stale or sensitive content usually need both. For the wider permissions and oversharing picture behind Copilot deployments, we covered SharePoint Advanced Management as a Copilot readiness layer separately.

Where CloudCapsule fits

If you manage a stack of Microsoft 365 environments, the discovery half of this work does not need to happen one admin center at a time. CloudCapsule surfaces inactive SharePoint sites alongside the rest of a tenant's assessment findings, so you can spot cleanup opportunities across every customer without opening each SharePoint tenant individually.

CloudCapsule AI Readiness report showing an environment score plus site, sharing, and permission findings across 35 sites

Use those findings as discovery, then move into SharePoint Advanced Management when the customer is ready for lifecycle policies and automated enforcement.

The loop worth automating

A cleanup that runs once decays immediately. A lifecycle process that repeats holds the line:

  1. Identify inactive sites.
  2. Confirm with the business whether they are still needed.
  3. Move abandoned sites to read-only or archive them.
  4. Restrict AI discovery where the content warrants it.
  5. Let the policy run again on its own schedule.

The goal was never to delete everything old. It is to make sure every site still in Microsoft 365 has a purpose, an owner, and access that somebody chose on purpose.

Frequently asked questions

How long should a site sit idle before it counts as inactive?

You choose the threshold, commonly 90 days, six months, or another interval that matches the organization. We usually start customers at three to six months. Note what the clock measures: activity on the site, its files, and connected resources such as Microsoft Teams, Viva Engage, or Exchange, so a quiet document library attached to a busy Team is not treated as abandoned.

Does making a site read-only stop Copilot from using its content?

No. Read-only governs editing, not discovery. If users can still find the content, Copilot and other AI experiences can still reference it. Restricted Content Discovery is the separate control that prevents a site's content from appearing in Copilot, Microsoft 365 AI agents, and organization-wide search results.

Can a site come back after enforcement?

Read-only can be reversed by an administrator when the business needs the site again. Archived sites are preserved through Microsoft 365 Archive rather than deleted, so content that still has a retention obligation stays retrievable while it stops consuming active storage.

See the dead weight across every tenant you manage

CloudCapsule surfaces sharing exposure, permission sprawl, and site findings across every Microsoft 365 tenant in your book, so cleanup conversations start with a list instead of a hunch. 250+ controls, about 60 seconds per tenant.

Run a free scan
Nick Ross

Written by

Nick Ross

CEO · Microsoft MVP · Founder, T-Minus 365

Nick is not just a CEO, he's a respected thought leader and influencer in the MSP space. Tens of thousands of MSPs learn through his YouTube channel, T-Minus365. Nick has been honored as a three-time Microsoft MVP for his educational content; his expertise and influence are the backbone of our mission, ensuring that you are in the best hands when it comes to security.

Nick joined Pax8 in 2017, where he would ultimately oversee product management for PSA and Microsoft integrations. Following his tenure at Pax8, Nick has continued to demonstrate his leadership prowess as an executive at various MSPs, culminating in his most recent role at Sourcepass.

Nick holds a Bachelor's Degree in Business Management from Florida State University, as well as a Minor Degree in Entrepreneurship. In his free time, Nick is an avid hiker, reader, and fitness-junkie.

Keep reading