Microsoft 365 lifecycle management
Half of your tenant is abandoned. We show you which half.
In a typical Microsoft 365 tenant, more than half of all files sit in sites nobody has opened in a year, hundreds of licensed accounts have not signed in for months, and dozens of paid apps have no users left. 1Security lists every one of them, ranks them by cost and exposure, and cleans up behind a review window - so lifecycle management stops depending on someone remembering.
The problem
Everything in Microsoft 365 gets created. Almost nothing gets deleted.
A project ends and its Teams site stays. A contractor leaves and their guest account stays. Someone trials an app for a week and its consent stays for years. Microsoft 365 has an owner for every "create" and nobody for "delete", so the tenant only ever grows. Most tenants hold several times more sites than IT believes they have.
The numbers we see on the first day of a new connection are remarkably consistent: more than half of all files sitting in sites with no activity for a year, 10-30% of paid licenses on accounts that have not signed in for months, dozens of consented apps with zero users, and terabytes on SharePoint sites nobody remembers creating.
Clutter alone would be fine. The problem is that abandoned things keep their permissions. The site nobody has opened since 2024 still has external users. The dormant account still reaches thousands of files. The dead group still unlocks a mailbox. Nobody would defend that access - and nobody is looking at it either.
In practice
From "we should clean up someday" to a list you can act on today.
How a lifecycle pass runs in 1Security - no scripts, no CSV exports, no guessing.
- 01
See what is abandoned, per resource type
Open Sites and filter to no activity in a year. Open Users and filter to no sign-in for 90 days with a license attached. Open Apps and filter to zero active users. Open Groups and filter to no owner or no members. Every list is live and every filter is one click - the same orphaned indicators exist for sites, groups, users, guests, apps, AI agents, devices and licenses.
- 02
Sort by what it still costs - or still exposes
Storage in TB, paid seats per month, external users, sensitive files in reach: each is a column. Sort by any of them and the top of the list is where cleanup pays first - the 4 TB archive site with anyone links, the 200 dormant accounts still on E3, the 40 paid apps nobody has opened this year.
- 03
Clean up behind a review window
Enable a suggested automation - archive dormant sites, remove idle guests, reclaim unused licenses - and 1Security stages a proposal for every matching resource. 72 hours to review by default, owners can be asked to confirm, and rejecting a proposal snoozes it. Nothing disappears silently.
- 04
Show the result in numbers
Storage reclaimed, licenses returned to the pool, external access removed, sites archived - every executed action is logged in one place. Your quarterly review opens with "we reclaimed 11 TB and 180 licenses", not with a promise to look into it.
What makes it work
Three parts of the platform, one cleanup pass.
Lifecycle management in 1Security is not a separate module. It runs on the same live inventory, user lifecycle and site governance you can read about in depth.
Inventory
Every site, OneDrive, group, user, guest, app, AI agent, device and license in one live inventory - with abandoned and orphaned filters on each list.
Explore the feature →User lifecycle
Joiners, movers, leavers and the dormant accounts in between - access, sharing links and licenses handled as one flow.
Explore the feature →SharePoint governance
Sites ranked by size, silence and exposure, with staged site-level automations for sharing, ownership and archival.
Explore the feature →
FAQ
Common questions.
Will it delete something someone still needs?
Not without a human seeing it first. Every proposal waits in a review window - 72 hours by default, configurable all the way to manual approval only - and can be routed to the site or group owner to confirm. Rejecting a proposal snoozes it. Every executed action is logged with who approved it and when.
How much do tenants typically find?
Enough to matter on day one. It is common to see more than half of all files in sites with no activity for a year, 10-30% of paid licenses on dormant accounts, dozens of consented apps with no users, and single sites holding terabytes nobody has opened. Your own numbers appear the same day you connect.
Do we need to grant write permissions to start?
No. The base connection is read-only, and every suggested cleanup shows its live match count before you grant anything. Write actions are a separate module you approve only when you decide to let 1Security act - and even then every action passes through the review window.
Does this need E5 or an extra Microsoft license?
No. It runs on standard Microsoft 365 licensing, with no agent to install and no E5 requirement.
See what your tenant is still paying for.
Connect read-only and get your abandoned sites, dormant accounts and unused licenses listed the same day. Then decide what to clean up, with a review window in front of every action.
Or keep paying for what nobody uses.