EPC Group - Enterprise Microsoft AI, SharePoint, Power BI, and Azure Consulting
G2 High Performer Summer 2025, Momentum Leader Spring 2025, Leader Winter 2025, Leader Spring 2026
BlogContact
Ready to transform your Microsoft environment?Get started today
(888) 381-9725Get Free Consultation
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌

EPC Group

Enterprise Microsoft consulting with 29 years serving Fortune 500 companies.

(888) 381-9725
contact@epcgroup.net
4900 Woodway Drive, Suite 830
Houston, TX 77056

Follow Us

Solutions

  • M&A Practices

    • M&A Tenant Migration
    • Carve-Out Migration
    • Private Equity Practice
    • Engagement Operating Model
  • All Services
  • Microsoft 365 Consulting
  • AI Governance
  • Azure AI Consulting
  • Cloud Migration
  • Microsoft Copilot
  • Data Governance
  • Microsoft Fabric
  • Dynamics 365
  • Power BI Consulting
  • SharePoint Consulting
  • Microsoft Teams
  • vCIO / vCAIO Services
  • Large-Scale Migrations
  • SharePoint Development

Industries

  • All Industries
  • Healthcare IT
  • Financial Services
  • Government
  • Education
  • Teams vs Slack

Power BI

  • Case Studies
  • 24/7 Emergency Support
  • Dashboard Guide
  • Gateway Setup
  • Premium Features
  • Lookup Functions
  • Power Pivot vs BI
  • Treemaps Guide
  • Dataverse
  • Power BI Consulting

Company

  • About Us
  • Our History
  • Microsoft Gold Partner
  • Case Studies
  • Testimonials
  • Fixed-Fee Accelerators
  • Blog
  • Resources
  • All Guides & Articles
  • Video Library
  • Client Reviews
  • Engagement Operating Model
  • FAQ
  • Contact
  • Schedule a consultation

Microsoft Teams

  • Teams Questions
  • Teams Healthcare
  • Task Management
  • PSTN Calling
  • Enable Dial Pad

Azure & SharePoint

  • Azure Databricks
  • Azure DevOps
  • Azure Synapse
  • SharePoint MySites
  • SharePoint ECM
  • SharePoint vs M-Files

Comparisons

  • M365 vs Google
  • Databricks vs Dataproc
  • Dynamics vs SAP
  • Intune vs SCCM
  • Power BI vs MicroStrategy

Legal

  • Sitemap
  • Privacy Policy
  • Terms
  • Cookies

About EPC Group

EPC Group is a Microsoft consulting firm founded in 1997 (originally Enterprise Project Consulting, renamed EPC Group in 2005). 29 years of enterprise Microsoft consulting experience. EPC Group historically held the distinction of being the oldest continuous Microsoft Gold Partner in North America from 2016 until the program's retirement. Because Microsoft officially deprecated the Gold/Silver tiering framework, EPC Group transitioned to the modern Microsoft Solutions Partner ecosystem and currently holds the core Microsoft Solutions Partner designations.

Headquartered at 4900 Woodway Drive, Suite 830, Houston, TX 77056. Public clients include NASA, FBI, Federal Reserve, Pentagon, United Airlines, PepsiCo, Nike, and Northrop Grumman. 6,500+ SharePoint implementations, 1,500+ Power BI deployments, 500+ Microsoft Fabric implementations, 70+ Fortune 500 organizations served, 11,000+ enterprise engagements, 200+ Microsoft Power BI and Microsoft 365 consultants on staff.

About Errin O'Connor

Errin O'Connor is the Founder, CEO, and Chief AI Architect of EPC Group. Microsoft MVP multiple years, first awarded 2003. 4× Microsoft Press bestselling author of Windows SharePoint Services 3.0 Inside Out (MS Press 2007), Microsoft SharePoint Foundation 2010 Inside Out (MS Press 2011), SharePoint 2013 Field Guide (Sams/Pearson 2014), and Microsoft Power BI Dashboards Step by Step (MS Press 2018).

Original SharePoint Beta Team member (Project Tahoe). Original Power BI Beta Team member (Project Crescent). FedRAMP framework contributor. Worked with U.S. CIO Vivek Kundra on the Obama administration's 25-Point Plan to reform federal IT, and with NASA CIO Chris Kemp as Lead Architect on the NASA Nebula Cloud project. Speaker at Microsoft Ignite, SharePoint Conference, KMWorld, and DATAVERSITY.

© 2026 EPC Group. All rights reserved. Microsoft, SharePoint, Power BI, Azure, Microsoft 365, Microsoft Copilot, Microsoft Fabric, and Microsoft Dynamics 365 are trademarks of the Microsoft group of companies.

‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
Post-Migration Security & Governance Cleanup: What Most Teams Miss (2026) - EPC Group enterprise consulting

Post-Migration Security & Governance Cleanup: What Most Teams Miss (2026)

After a Microsoft 365 tenant migration or M&A consolidation, the 30 most-commonly-missed security + governance cleanup items. From 200+ post-migration engagements. Save this checklist for your next cutover.

HomeBlogMicrosoft 365
Back to BlogMicrosoft 365

Post-Migration Security & Governance Cleanup: What Most Teams Miss (2026)

After a Microsoft 365 tenant migration or M&A consolidation, the 30 most-commonly-missed security + governance cleanup items. From 200+ post-migration engagements. Save this checklist for your next cutover.

EO
Errin O'Connor
CEO & Chief AI Architect
•
May 20, 2026
•
11 min read
Post-MigrationSecurity CleanupGovernanceMicrosoft 365M&A MigrationChecklistPurviewIntune
Post-Migration Security & Governance Cleanup: What Most Teams Miss (2026)
11 min readPublished May 20, 2026

Key Takeaways

  • After a Microsoft 365 tenant migration or M&A consolidation, the 30 most-commonly-missed security + governance cleanup items. From 200+ post-migration engagements. Save this checklist for your next cutover.

Post-Migration Security & Governance Cleanup: The 30-Item Checklist

After EPC Group's 200+ Microsoft 365 migrations + tenant consolidations, the same 30 items repeatedly get missed in post-migration cleanup. Each one creates compliance exposure, license waste, or security risk. Use this as your post-cutover audit checklist.

Identity + Access (8 items)

1. Orphaned guest accounts from B2B coexistence. External guest accounts accumulated during cross-tenant transition periods. Audit + remediate any with no recent sign-in.

2. Service account inventory + rotation. Service accounts proliferated during migration tooling (ShareGate, AvePoint, Migration Manager). Rotate credentials + audit ongoing necessity.

3. Privileged role assignments from migration era. Migration consultants + tooling required elevated permissions. Revoke + transition to least-privilege.

4. Conditional Access policy drift. Different tenants' policies merged into post-migration tenant. Review + simplify to unified policy set.

5. Microsoft Entra Identity Protection sign-in risk policies. Default policies during migration are often relaxed. Restore production-grade risk thresholds.

6. Just-in-time (PIM) elevation requirements. Migration era often had standing elevation. Move to JIT activation.

7. Customer Lockbox enabled. Required for FedRAMP + many compliance frameworks. Often disabled during migration.

8. Break-glass account procedure tested. New tenant = new break-glass account. Document + quarterly tabletop.

Data Classification + Retention (6 items)

9. Sensitivity label coverage. Container labels applied to all consolidated sites. Verify autolabeling rules trigger correctly across migrated content.

10. Sensitivity label cascade behavior. Test label cascade from container to file. Migration often breaks the chain.

11. Retention policy operational. Verify retention labels apply to migrated content per content type + jurisdiction.

12. Litigation hold transferred. Any pre-migration litigation holds (eDiscovery) MUST transfer to new tenant. Audit + verify.

13. Default sensitivity labels per site. Container labels enforce default sensitivity on new content. Configure per business unit.

14. Microsoft Purview Audit (Premium). Audit log streaming + retention extended to 10 years (default 90 days). Required for SOX + many compliance audits.

SharePoint Hygiene (5 items)

15. Oversharing audit on migrated content. Run sensitivity scanner. Top oversharing exposures: financial year-end, M&A targets, executive comp.

16. SharePoint site permissions inheritance. Migration often breaks inheritance. Re-establish hub-and-spoke permission model.

17. Search vertical configuration. Migration breaks search verticals. Reconfigure result sources + refiners.

18. SharePoint hub topology consolidation. Multi-tenant migrations often produce overlapping hub topologies. Consolidate to 1 logical structure.

19. Modern site templates + branding. Brand assets from acquired subsidiaries should be retired or merged into parent brand system.

Microsoft Teams Cleanup (3 items)

20. Orphaned Teams from migration coexistence. Teams created for cross-tenant collaboration during transition. Decommission + archive.

21. Teams external access policy. Different settings per source tenant. Unify under parent tenant policy.

22. Teams compliance recording policy. For regulated industries: verify recording + retention transferred.

Microsoft Intune + Endpoint Management (4 items)

23. Endpoint compliance policy unification. Different baselines across source tenants. Unify to parent tenant baseline.

24. App protection policy review. Mobile app protection often relaxed during migration. Restore production posture.

25. Conditional Access integration with Intune. Verify device compliance is required for sensitive resource access.

26. Autopilot profile inventory. New device enrollment profiles for the consolidated tenant. Decommission source-tenant profiles.

Power Platform Hygiene (2 items)

27. Power Platform environment cleanup. Source-tenant environments (Default, Production, Sandbox) need decommission or migration to parent.

28. Power Automate flow ownership. Flows owned by service accounts or departed users. Reassign + audit.

License + Cost Optimization (2 items)

29. License rationalization. Duplicate E5 + add-on assignments from cross-tenant transition. Reclaim + reassign.

30. Storage quota review. SharePoint + OneDrive storage consumption post-migration. Right-size + decommission unused.

How to Operationalize This

Recommended cadence:

  • Day 30 post-cutover: items 15, 16, 17 (SharePoint hygiene)
  • Day 60 post-cutover: items 1-8 (identity + access) + 23-26 (Intune)
  • Day 90 post-cutover: items 9-14 (data classification + retention) + 27-30 (Power Platform + licensing)
  • Quarterly: full re-audit + drift remediation

EPC Group productized engagement: Post-Migration Cleanup Sprint — 4-8 week engagement covering all 30 items + drift baseline documentation. Typical: $80K-$200K depending on tenant complexity.

Frequently Asked Questions

Q: How many of these 30 items does the typical organization miss?
A: 15-22 of 30 in our post-migration audits. The most commonly missed: items 4, 7, 10, 12, 18, 23, 27.

Q: Can we do this with internal IT only?
A: Yes if you have senior SharePoint + M365 admins. Most organizations engage EPC Group for the first cleanup sprint + transfer knowledge to internal team for ongoing maintenance.

Q: How long does the full cleanup take?
A: 4-8 weeks for the discrete items. Some items (#9 sensitivity label coverage, #15 oversharing audit) extend into ongoing programs.

Q: What about Copilot deployment post-cleanup?
A: Strongly recommended. Items 9, 15, 18 are Copilot prerequisites. See /services/copilot-governance-consulting.

Q: Why EPC Group?
A: 29 years Microsoft consulting + 200+ post-migration cleanup engagements. Microsoft Solutions Partner with all six designations under the Microsoft AI Cloud Partner Program. Microsoft Press author. See /reviews.

Next Steps

  • Schedule discovery: /contact
  • Productized assessment: /services/sharepoint-oversharing-permissions-audit
  • Ongoing governance: /services/sharepoint-governance-consulting
  • M&A specific: /services/m-and-a-tenant-migration-assessment
  • Call (888) 381-9725
Share this article:
EO

Errin O'Connor

CEO & Chief AI Architect

Microsoft Press bestselling author with 29 years of enterprise consulting experience.

View Full Profile

Related Articles

Microsoft 365

SharePoint Governance Framework: The 12-Domain Enterprise Reference (2026)

The most-cited topic in 2026 SharePoint consulting: governance frameworks. EPC Group ships a 12-domain reference that goes deeper than competitor blogs (Beyond Intranet, ShareGate, GetSharePoint). From hundreds of Fortune 500 governance engagements since SharePoint 2003.

Microsoft 365

Microsoft Copilot for Supply Chain: Field Guide for Manufacturing (2026)

Avanade is dominant on this topic. EPC Group's manufacturing field guide covers Copilot for Supply Chain Management in Dynamics 365 + Copilot Studio agents for procurement + supplier management. With governance for IP protection.

Microsoft 365

AI in SharePoint (formerly Knowledge Agent): Adoption Guide for Enterprise (2026)

Microsoft rebranded Knowledge Agent to AI in SharePoint in April 2026. New capability: plan + build sites + libraries + pages + lists using plain English. EPC Group adoption guide with governance + change management + use cases.

Need Help with Microsoft 365?

Our team of experts can help you implement enterprise-grade microsoft 365 solutions tailored to your organization's needs.

Microsoft 365 Consulting ServicesSchedule a Consultation