Inactive SharePoint Sites Keep Their Permissions. Retire Them on a Policy, Not a Hunch.
TL;DR
- An inactive SharePoint site keeps consuming storage, keeps every permission and sharing link it ever had, and stays available to Copilot.
- Site Lifecycle Management in SharePoint Advanced Management finds inactive sites, asks owners to certify them, and enforces read-only or archive when nobody answers.
- Read-only is reversible, so an administrator can unlock a site later if the business needs it again.
- Read-only does not remove content from Copilot. Restricted Content Discovery is the control that keeps a site out of Copilot, Microsoft 365 AI agents, and organization-wide search.
- Enforcement actions cannot be edited after a policy is created, which is why the first run belongs in simulation mode.
Nobody sets out to build a graveyard. A site gets spun up for a project, the project ships, the team moves on, and the site stays exactly where it was. Do that for a few years and the Active sites list in the SharePoint admin center fills up with old project sites, dead vendor portals, test sites, and content that has not had an owner in three years.
Calling that clutter undersells it.
What an abandoned site still costs you
Three bills keep arriving after everyone stops using a site.
Storage. Old content keeps consuming SharePoint storage on the tenant you are paying for.
Security. Permissions, sharing links, and old access all survive the project that created them. Nobody revoked anything, because nobody was watching.
AI readiness. Copilot and other AI tools can surface outdated content that users can technically still reach. Stale content becomes an answer with the same confidence as current content.
Microsoft now ships tooling to work through this without a manual site-by-site review, which is what makes it a repeatable service rather than a one-off cleanup weekend.
Build the inventory before you build the policy
SharePoint Advanced Management includes Site Lifecycle Management, which identifies sites that have gone quiet over time. The shape of it is simple: Microsoft evaluates activity across the environment, sites that cross your inactivity threshold get flagged, owners are asked to confirm whether the site still matters, and sites that nobody certifies can be moved to read-only or archived.
You set the inactivity definition, whether that is 90 days, six months, or something else that fits the organization.
Start in the SharePoint admin center under Advanced Management and run an assessment.

The assessment surfaces inactive sites, sites missing owners, last activity dates, site storage, and site ownership. Results export to CSV when you want to work the list outside the portal.

For MSPs, that export is a discovery artifact. Walk the inventory with the customer before any policy exists and pull out the sites that can be retired immediately. The conversation is much easier when the customer is looking at their own site names and dates.
Turn the inventory into an inactive site policy
Once the environment makes sense, go to Advanced Management > Policies > Site Lifecycle Management and create a new inactive site policy.

Scope comes first: upload a CSV of specific URLs, or select sites at scale by type and filter. OneDrive sites are excluded automatically, and you can choose whether sites under retention policies or retention holds are in scope, plus exclude specific sites outright.

Configuration is where the policy gets its judgment: how long a site must be inactive, who gets notified, and what happens when nobody responds. We usually start at a three to six month window, then adjust once the first round of results comes back.

The notification is worth customizing rather than accepting. Owners receive an email asking them to certify the site, and the wording of that email decides whether they engage or ignore it.

If the owner confirms the site is still needed, it stays active. If they confirm it is not, or they say nothing at all, the policy takes the enforcement action you configured.
Read-only or archive, and why the first run should change nothing
Two enforcement options, two different promises.
Read-only access lets users keep viewing the site but stops them modifying content. It is the right first move when you are not ready to remove anything, and it is reversible: an administrator can unlock the site later if the business needs it back. Microsoft documents the unlock path in Manage inactive sites using inactive site policies (opens in new tab).
Archive the site hands it to Microsoft 365 Archive, which reduces active storage consumption while preserving content you may still need to retain.

Read the fine print in that screen before clicking through: enforcement actions cannot be edited after the policy is created. That single line is the argument for starting in simulation mode, which generates the reports and shows you what would happen without touching site access. Move to enforcement once the results stop surprising you.
Read-only leaves the Copilot problem open
Locking a site does not remove it from AI experiences. If users can still discover the content, Copilot can still reference it, which means a site full of stale or sensitive material can be frozen and still be quoted.
SharePoint Advanced Management handles that with Restricted Content Discovery, a per-site setting that keeps content out of Copilot, Microsoft 365 AI agents, and organization-wide search results.

Keep the two controls in separate mental buckets. Site Lifecycle Management decides what happens to an inactive site. Restricted Content Discovery decides whether that site's content keeps showing up in AI and search. Sites carrying stale or sensitive content usually need both. For the wider permissions and oversharing picture behind Copilot deployments, we covered SharePoint Advanced Management as a Copilot readiness layer separately.
Where CloudCapsule fits
If you manage a stack of Microsoft 365 environments, the discovery half of this work does not need to happen one admin center at a time. CloudCapsule surfaces inactive SharePoint sites alongside the rest of a tenant's assessment findings, so you can spot cleanup opportunities across every customer without opening each SharePoint tenant individually.

Use those findings as discovery, then move into SharePoint Advanced Management when the customer is ready for lifecycle policies and automated enforcement.
The loop worth automating
A cleanup that runs once decays immediately. A lifecycle process that repeats holds the line:
- Identify inactive sites.
- Confirm with the business whether they are still needed.
- Move abandoned sites to read-only or archive them.
- Restrict AI discovery where the content warrants it.
- Let the policy run again on its own schedule.
The goal was never to delete everything old. It is to make sure every site still in Microsoft 365 has a purpose, an owner, and access that somebody chose on purpose.
Frequently asked questions
How long should a site sit idle before it counts as inactive?
You choose the threshold, commonly 90 days, six months, or another interval that matches the organization. We usually start customers at three to six months. Note what the clock measures: activity on the site, its files, and connected resources such as Microsoft Teams, Viva Engage, or Exchange, so a quiet document library attached to a busy Team is not treated as abandoned.
Does making a site read-only stop Copilot from using its content?
No. Read-only governs editing, not discovery. If users can still find the content, Copilot and other AI experiences can still reference it. Restricted Content Discovery is the separate control that prevents a site's content from appearing in Copilot, Microsoft 365 AI agents, and organization-wide search results.
Can a site come back after enforcement?
Read-only can be reversed by an administrator when the business needs the site again. Archived sites are preserved through Microsoft 365 Archive rather than deleted, so content that still has a retention obligation stays retrievable while it stops consuming active storage.
See the dead weight across every tenant you manage
CloudCapsule surfaces sharing exposure, permission sprawl, and site findings across every Microsoft 365 tenant in your book, so cleanup conversations start with a list instead of a hunch. 250+ controls, about 60 seconds per tenant.
Run a free scan
Written by
Nick Ross
CEO · Microsoft MVP · Founder, T-Minus 365
Nick is not just a CEO, he's a respected thought leader and influencer in the MSP space. Tens of thousands of MSPs learn through his YouTube channel, T-Minus365. Nick has been honored as a three-time Microsoft MVP for his educational content; his expertise and influence are the backbone of our mission, ensuring that you are in the best hands when it comes to security.
Nick joined Pax8 in 2017, where he would ultimately oversee product management for PSA and Microsoft integrations. Following his tenure at Pax8, Nick has continued to demonstrate his leadership prowess as an executive at various MSPs, culminating in his most recent role at Sourcepass.
Nick holds a Bachelor's Degree in Business Management from Florida State University, as well as a Minor Degree in Entrepreneurship. In his free time, Nick is an avid hiker, reader, and fitness-junkie.


