Forty-two casual staff contracts expired at the end of Term 2. Six weeks into the July break, 39 of those accounts still appeared as active members across 74 school sites in SharePoint Online.
Ben is the IT coordinator for a regional school authority running 14 schools on a single Microsoft 365 tenant. Each term brings a fresh intake of casual teachers, administration staff, and contract support workers, all of whom receive SharePoint site access as part of onboarding. Each holidays period should, in theory, see those accounts cleaned up. In practice, term-end is frantic and the cleanup never quite happens. By mid-July Ben is staring at a tenant that reflects where people worked in 2023 nearly as much as where they work now.
The storage picture is no better. A full school year of co-authored lesson plans, curriculum documents, and administration spreadsheets means version history has accumulated across every library. The recycle bin, tenant-wide, holds months of deleted content that nobody has reviewed. And with Term 1 starting in four weeks, Ben needs the tenant tidy, compliant, and under the storage quota Microsoft flagged in a licence renewal notice.
The scope of the problem
Permission sprawl across 14 schools
Each school has its own site collection, with dozens of document libraries for curriculum teams, administration, HR, and facilities. Casual staff typically receive site member access for the duration of their engagement. The problem is that access removal depends on HR notifying IT, and that handoff breaks down reliably at busy times of year. Ben's permission audit reveals over 200 accounts with unexpired SharePoint access who have not logged into Microsoft 365 in more than 90 days. Some are former staff. Others are contractors whose project ended in March.
Shared links add a second layer of risk. Several curriculum libraries contain files shared with external consultants via "Anyone with the link" sharing links that were created during a content review and never revoked. Ben cannot see all of these from the SharePoint admin center without clicking into each library individually.
A year of version history and full recycle bins
The authority's document libraries default to 500 major versions per file. A year of co-authoring across active curriculum libraries has produced files with hundreds of versions each. The storage report shows three schools approaching their site storage allocation, though the actual working content in those sites is modest. Most of the quota is version history.
The recycle bin problem is compounding the storage issue. Term 4 saw several large curriculum restructures that involved deleting and reorganising content. That deleted content sits in the first-stage and second-stage recycle bins, still counting against quota. Nobody is going to need it back; it just needs to go.
Step 1: Auditing who still has access
Ben starts with a full permissions audit. Using Report Master, he exports a permissions matrix for all 14 school sites to Excel. The export shows, for each site and library, which accounts hold which permission levels. He filters the export to show accounts that have not been active in 90-plus days and cross-references against the HR leavers list for the last two terms.
The Shared Links and Permissions tool handles the second part of the audit. Ben connects it to each site collection in turn and runs a shared-link report. In under an hour he has a full list of active sharing links across all libraries, including their creation date, creator, and link type. He identifies 31 "Anyone with the link" sharing links that can be safely revoked: the consultants' projects are complete and no further access is needed.
With both audit lists in hand, Ben uses the Shared Links and Permissions tool to revoke the identified sharing links in bulk, and removes the stale account memberships directly in SharePoint based on the Report Master export. What would have taken days of per-site clicking takes an afternoon. For a step-by-step walkthrough of the permissions export process, see how to export SharePoint permissions to Excel.
Step 2: Reclaiming storage before the new year
Storage cleanup comes next. Ben opens Space Master's Version Trimmer and connects it to the authority's SharePoint tenant. He sets a keep policy: retain the last 20 major versions per file, delete everything older than 90 days beyond those 20. He scopes the trim to all 14 school site collections and runs the audit to preview the impact before committing.
The preview shows that applying this policy will reclaim approximately 340 GB of version storage across the tenant. Three schools that were approaching their storage limits will come back comfortably inside their allocations. Ben runs the trim.
The empty folder pass comes next. Several libraries contain folder hierarchies that were created for projects now complete: empty folders left behind after files were moved or deleted. The Empty Folder Remover in Space Master identifies and removes these without touching any remaining content. It also removes a layer of visual noise from the libraries, making them easier for staff to navigate when term begins.
The Bulk Delete tool handles the last storage job: a set of backup files that curriculum staff had uploaded as ZIP archives before a system migration in early 2025, then never removed. These are confirmed safe to delete. Ben removes them in a single batch.
See how Space Master's version trimmer and storage tools work together for a full tenant cleanup.
Try ShareMaster free for 14 daysStep 3: Clearing the recycle bin
The final task is the recycle bin. Ben opens Recycle Master and runs a tenant-wide recycle bin report. The report shows the total volume of items in the first and second-stage bins across all 14 school sites, broken down by site, deletion date, and deleted-by account. Content deleted more than 60 days ago and not flagged by any staff or HR record as needing recovery is safe to clear.
Ben uses Recycle Master's bulk clear function to remove all items older than 60 days across the tenant in a single operation, working school site by school site. The same pass also clears the second-stage bin - items that users had already moved out of their own first-stage bins. Clearing all 14 school sites takes minutes rather than the hour of manual per-site clicking it would otherwise require.
For a guide to running a tenant-wide recycle bin clear, see how to clear the SharePoint recycle bin tenant-wide.
The result: a clean tenant for Term 1
After two days of structured cleanup work (one for permissions, one for storage and recycle bin), the authority's SharePoint tenant is in the best shape it has been in years.
- Over 200 stale accounts removed from site membership across 14 schools
- 31 "Anyone with the link" sharing links revoked across curriculum and administration libraries
- Approximately 340 GB of version history reclaimed, bringing three sites back inside their storage allocations
- Empty folders cleared from active libraries across 8 school sites
- Tenant-wide recycle bin cleared of content older than 60 days
Beyond the numbers, the cleanup closed a compliance gap two years in the making. The audit found former staff accounts that should have been removed long before, and sharing links that had outlived their purpose - both addressed in the same pass. Ben now has a documented baseline: a spreadsheet of current permissions, a record of what was removed, and a process he can repeat at the end of every term rather than letting it accumulate into a year-end crisis.
For school districts and education authorities running Microsoft 365, SharePoint is often the single largest repository of sensitive content in the organisation: student data, staff HR documents, curriculum materials, and financial records all share the same tenant. Keeping that tenant clean is not optional. It is the minimum standard for responsible data governance.