Device cleanup in Intune: a stale record is not a retired device
13 August 2026
The cleanest Intune portal is not necessarily the healthiest device estate. A record can be stale because a device was replaced, rebuilt, offline for legitimate reasons, or managed through a different channel. It can also be the only remaining evidence that a device still has a BitLocker recovery key or an Entra identity.
Entra application hygiene: investigate the workload identity, not the display name
13 August 2026
An Entra application called test, old, or do-not-use is not evidence that it is safe to remove. The same is true in reverse: a reassuring display name does not make an application safe. Start with what the workload identity can do, how it authenticates, and who can explain its purpose.
Governing BYOAI on managed devices: from visibility to a defensible block
13 August 2026
BYOAI is usually framed as shadow IT with a better user experience. Someone has a question, a deadline, or a document that needs improving. A public AI tool is one browser tab away. The risk is real, but the human need is real too.
Guest access hygiene: review the relationship, not only the account
13 August 2026
A guest account is the technical trace of a business relationship. Removing old guests can be useful, but a date field alone cannot tell you whether a supplier engagement, project, legal matter, or shared workspace is still active.
Start with the resource
The useful question is not “when did this guest last sign in?” It is “what does this person still have access to, who sponsored it, and when should that access end?” A guest can be inactive and still be the only external owner of a shared artefact. A recently active guest can still have access that is no longer justified.
Orphaned OneDrives: prove ownership, retention, and recovery before changing scope
13 August 2026
An unlicensed or inactive OneDrive is not automatically disposable. It can contain project evidence, personal working files required for a case, or content subject to retention. “Orphaned” should be a conclusion from evidence, not a label created by a storage report.
SharePoint archiving: select the access model before selecting the storage tier
13 August 2026
Archiving a SharePoint site is a change to access, ownership, recovery, and compliance. Storage cost matters, but it is the last question I ask, not the first.
Begin with a decision record
For each site, document the business purpose, accountable owner, last meaningful activity, external sharing, sensitivity and retention state, eDiscovery considerations, expected retrieval time, and future disposition date. “No recent edits” is a useful signal. It is not an archival decision by itself.
When SharePoint storage grows, investigate retention before deleting files
13 August 2026
Large files are visible. Retention side effects often are not. That is why a storage incident can become a compliance incident when somebody responds by changing a policy before understanding what is preserving the content.
Deletion and storage reclamation are different events
When SharePoint or OneDrive content is retained, Microsoft can preserve the original version in the Preservation Hold library after a user edits or deletes it. The user may see a file disappear while the tenant still retains a copy. Microsoft explains the workload-specific behaviour in retention for SharePoint and OneDrive.