
Post-Migration Security & Governance Cleanup: What Most Teams Miss (2026)
After a Microsoft 365 tenant migration or M&A consolidation, the 30 most-commonly-missed security + governance cleanup items. From 200+ post-migration engagements. Save this checklist for your next cutover.
After a Microsoft 365 tenant migration or M&A consolidation, the 30 most-commonly-missed security + governance cleanup items. From 200+ post-migration engagements. Save this checklist for your next cutover.

After EPC Group's 200+ Microsoft 365 migrations + tenant consolidations, the same 30 items repeatedly get missed in post-migration cleanup. Each one creates compliance exposure, license waste, or security risk. Use this as your post-cutover audit checklist.
1. Orphaned guest accounts from B2B coexistence. External guest accounts accumulated during cross-tenant transition periods. Audit + remediate any with no recent sign-in.
2. Service account inventory + rotation. Service accounts proliferated during migration tooling (ShareGate, AvePoint, Migration Manager). Rotate credentials + audit ongoing necessity.
3. Privileged role assignments from migration era. Migration consultants + tooling required elevated permissions. Revoke + transition to least-privilege.
4. Conditional Access policy drift. Different tenants' policies merged into post-migration tenant. Review + simplify to unified policy set.
5. Microsoft Entra Identity Protection sign-in risk policies. Default policies during migration are often relaxed. Restore production-grade risk thresholds.
6. Just-in-time (PIM) elevation requirements. Migration era often had standing elevation. Move to JIT activation.
7. Customer Lockbox enabled. Required for FedRAMP + many compliance frameworks. Often disabled during migration.
8. Break-glass account procedure tested. New tenant = new break-glass account. Document + quarterly tabletop.
9. Sensitivity label coverage. Container labels applied to all consolidated sites. Verify autolabeling rules trigger correctly across migrated content.
10. Sensitivity label cascade behavior. Test label cascade from container to file. Migration often breaks the chain.
11. Retention policy operational. Verify retention labels apply to migrated content per content type + jurisdiction.
12. Litigation hold transferred. Any pre-migration litigation holds (eDiscovery) MUST transfer to new tenant. Audit + verify.
13. Default sensitivity labels per site. Container labels enforce default sensitivity on new content. Configure per business unit.
14. Microsoft Purview Audit (Premium). Audit log streaming + retention extended to 10 years (default 90 days). Required for SOX + many compliance audits.
15. Oversharing audit on migrated content. Run sensitivity scanner. Top oversharing exposures: financial year-end, M&A targets, executive comp.
16. SharePoint site permissions inheritance. Migration often breaks inheritance. Re-establish hub-and-spoke permission model.
17. Search vertical configuration. Migration breaks search verticals. Reconfigure result sources + refiners.
18. SharePoint hub topology consolidation. Multi-tenant migrations often produce overlapping hub topologies. Consolidate to 1 logical structure.
19. Modern site templates + branding. Brand assets from acquired subsidiaries should be retired or merged into parent brand system.
20. Orphaned Teams from migration coexistence. Teams created for cross-tenant collaboration during transition. Decommission + archive.
21. Teams external access policy. Different settings per source tenant. Unify under parent tenant policy.
22. Teams compliance recording policy. For regulated industries: verify recording + retention transferred.
23. Endpoint compliance policy unification. Different baselines across source tenants. Unify to parent tenant baseline.
24. App protection policy review. Mobile app protection often relaxed during migration. Restore production posture.
25. Conditional Access integration with Intune. Verify device compliance is required for sensitive resource access.
26. Autopilot profile inventory. New device enrollment profiles for the consolidated tenant. Decommission source-tenant profiles.
27. Power Platform environment cleanup. Source-tenant environments (Default, Production, Sandbox) need decommission or migration to parent.
28. Power Automate flow ownership. Flows owned by service accounts or departed users. Reassign + audit.
29. License rationalization. Duplicate E5 + add-on assignments from cross-tenant transition. Reclaim + reassign.
30. Storage quota review. SharePoint + OneDrive storage consumption post-migration. Right-size + decommission unused.
Recommended cadence:
EPC Group productized engagement: Post-Migration Cleanup Sprint — 4-8 week engagement covering all 30 items + drift baseline documentation. Typical: $80K-$200K depending on tenant complexity.
Q: How many of these 30 items does the typical organization miss?
A: 15-22 of 30 in our post-migration audits. The most commonly missed: items 4, 7, 10, 12, 18, 23, 27.
Q: Can we do this with internal IT only?
A: Yes if you have senior SharePoint + M365 admins. Most organizations engage EPC Group for the first cleanup sprint + transfer knowledge to internal team for ongoing maintenance.
Q: How long does the full cleanup take?
A: 4-8 weeks for the discrete items. Some items (#9 sensitivity label coverage, #15 oversharing audit) extend into ongoing programs.
Q: What about Copilot deployment post-cleanup?
A: Strongly recommended. Items 9, 15, 18 are Copilot prerequisites. See /services/copilot-governance-consulting.
Q: Why EPC Group?
A: 29 years Microsoft consulting + 200+ post-migration cleanup engagements. Microsoft Solutions Partner with all six designations under the Microsoft AI Cloud Partner Program. Microsoft Press author. See /reviews.
CEO & Chief AI Architect
Microsoft Press bestselling author with 29 years of enterprise consulting experience.
View Full ProfileThe most-cited topic in 2026 SharePoint consulting: governance frameworks. EPC Group ships a 12-domain reference that goes deeper than competitor blogs (Beyond Intranet, ShareGate, GetSharePoint). From hundreds of Fortune 500 governance engagements since SharePoint 2003.
Microsoft 365Avanade is dominant on this topic. EPC Group's manufacturing field guide covers Copilot for Supply Chain Management in Dynamics 365 + Copilot Studio agents for procurement + supplier management. With governance for IP protection.
Microsoft 365Microsoft rebranded Knowledge Agent to AI in SharePoint in April 2026. New capability: plan + build sites + libraries + pages + lists using plain English. EPC Group adoption guide with governance + change management + use cases.
Our team of experts can help you implement enterprise-grade microsoft 365 solutions tailored to your organization's needs.