Our Expertise

How We Help

We partner with teams from initial strategy through production delivery - across automation, AI, data, and cloud.
Icon

Intelligent Process Automation

Modernizing operations through automation-first redesign.
Frame

Platform Architecture & Governance

Custom automation, integrations, and application build-outs.
Icon

Enterprise AI & Copilot Systems

Applied AI for decision support, forecasting, and intelligence.
Icon

Data & Decision Intelligence

Data platforms, cloud automation, and scalable architecture.
Frame

Consulting

Strategy, assessments, roadmaps, and executive alignment.
Icon

Process Insights

Process discovery, bottleneck analysis, opportunity identification.

Every IT Director inherits a tenant that grew faster than its governance. Flows built by a contractor who left in 2023. Apps shared with a security group that has quietly ballooned to 4,000 members. A premium connector connection still authenticating as a VP who retired last spring. None of it looks urgent until an auditor, a breach, or a Microsoft true-up makes it urgent all at once.

This is why a Microsoft 365 tenant audit checklist matters more than another governance framework. Most enterprises do not have a governance problem; they have a maintenance problem. They bought the Center of Excellence toolkit, wrote the DLP policies, published the maker guidance, and then never went back to check whether any of it still reflects reality. Tenant hygiene is the ritual that closes that loop.

TL;DR

A tenant audit is not a governance rollout. It is a time-boxed annual review that finds the orphaned flows, over-permissioned apps, and stale connections your existing governance was supposed to prevent, then decides what to reassign, quarantine, or delete before renewal, audit season, or an incident forces the decision for you.

Key Takeaways

  • Treat hygiene as a ritual, not a program. Block one work week each year, produce a fixed set of artifacts, and repeat.
  • Audit the Power Platform layer, not just identity. Most M365 audit checklists stop at MFA and legacy auth and miss where the real sprawl lives.
  • Start with the three highest-risk domains: orphaned Power Automate flows, over-permissioned apps, and stale connections.
  • Use the tools you already own. Power Platform admin center, Entra ID, Purview, and PowerShell will surface 90% of the findings without a new purchase.
  • Produce an executive-ready output. A remediation queue, a license true-up estimate, and a year-over-year risk delta the CIO can actually use.

Why the Annual Tenant Hygiene Review Exists

Citizen development did what it promised. It also created a class of production assets no traditional IT audit was designed to see. Gartner and Forrester both project that low-code and citizen-developer platforms will account for the majority of new business applications built inside large enterprises this decade, and Microsoft's own tenant analytics regularly show flow and app counts growing faster than the maker population that owns them.

That growth compounds into three predictable failure modes. Orphaned assets keep running after their owner leaves. Over-permissioned apps expand their blast radius silently as groups grow. And connections outlive the humans and credentials behind them. A Power Platform governance audit that runs once a year is the cheapest control you have against all three.

The BabyBots Tenant Hygiene Ritual

The ritual is deliberately small. One week, seven domains, one output pack. We recommend running it in the quarter before your Enterprise Agreement true-up and again ahead of your SOC 2 or ISO 27001 window. Findings from BabyBots engagements consistently show that the first year of the ritual removes 20-40% of active flows and apps as orphaned, unused, or duplicative, without a single complaint from the business.

Domain 1: Orphaned Power Automate Flows

An orphaned Power Automate flow is any flow whose primary owner is a disabled or deleted Entra ID account, whose only owner is a service account nobody claims, or which has not executed successfully in 90 or more days while still being enabled. Open the Power Platform admin center, go to Resources, and use the Inventory and Analytics surfaces to filter by owner status, Last modified, and Last run. Cross-reference the owner list against Entra ID's disabled users report.

Decision rule: if the flow has run in the last 90 days and the business unit claims it, reassign to a named owner and a shared service principal. If nobody claims it, disable for 30 days. If nothing breaks, delete.

Domain 2: Over-Permissioned Apps

Start where Microsoft's own guidance starts: the Default environment, where every licensed user in the tenant is granted the Environment Maker role automatically. Then pull the list of canvas and model-driven apps shared with the tenant-wide "Everyone" group or with security groups whose membership exceeds a threshold you set (we use 250). Add every admin-consented OAuth application in Entra ID whose permissions include Mail.ReadWrite, Files.ReadWrite.All, or Sites.FullControl.All. These are the over-permissioned apps Microsoft 365 tenants accumulate quietly, and they are the most common finding in real breach post-mortems.

Decision rule: revoke tenant-wide sharing by default. Require a named business owner and a documented use case to keep any app shared with more than 250 users. Revoke admin consent for any OAuth app whose publisher, purpose, or last sign-in cannot be verified in ten minutes.

Domain 3: Stale Connections and Connection References

Connections are the audit category almost nobody runs formally, and they are where credentials go to die. In the Power Platform admin center, export the connections list per environment. Flag three categories: personal connections owned by disabled Entra ID accounts, shared connections using hardcoded credentials instead of service principals, and premium connector connections (SAP, Salesforce, Oracle, SQL, on-premises data gateway) whose owner has not signed in for 60 days.

Decision rule: rotate or delete every credential tied to a departed employee immediately. Migrate hardcoded shared connections to service principals or managed identities on a 30-day timer. Escalate premium connector orphans to the license owner because they are almost certainly driving cost you are not tracking.

Most enterprises do not have a governance problem; they have a maintenance problem, and a tenant audit is the ritual that closes the loop.

Domain 4: Unused Environments and Dataverse Databases

Environments are where sprawl becomes structural. Pull every environment in the tenant, sorted by Last activity and Database size. Any non-production environment that has had no maker activity in 60 days is a candidate for archival. Any Dataverse database over 5 GB with no active app or flow is either a shadow data store or a forgotten proof of concept. Both create backup cost and compliance surface area.

Decision rule: notify the environment admin, set a 30-day archival timer, back up Dataverse to Azure Storage, then delete. Reclaim the capacity in your license pool.

Domain 5: Expired Service Principals and App Registrations

In Entra ID, list every app registration and enterprise application whose credentials expire in the next 90 days, whose last sign-in is older than 180 days, or whose owner field is empty. This is where SOC 2 auditors find the easiest paper cuts and where attackers find the easiest footholds. Microsoft's Entra security operations guide for applications is the reference; the audit itself is a filtered CSV export.

Decision rule: rotate expiring secrets, assign a named owner and a business justification, and delete anything with no sign-in activity in 180 days after a 14-day notice.

Domain 6: DLP Policy Drift

DLP policies you wrote two years ago no longer match the connector catalog. Microsoft adds connectors monthly, and every new connector lands in the Non-Business bucket unless you place it. Export your current DLP policies, diff them against the current connector list, and confirm that every premium and third-party connector has an explicit Business, Non-Business, or Blocked classification. Pay special attention to HTTP, custom connectors, and any connector that can egress data to consumer accounts.

Decision rule: no connector remains unclassified. If a business unit needs a connector currently in Non-Business, they file a request, you evaluate, and you move it explicitly.

Domain 7: License and Premium Usage True-Up

Finish where finance cares most. Pull the Power Platform admin center's premium usage report and compare it to your entitled Per-User and Per-App license counts. Flag every user consuming premium capabilities without a premium license, every Per-App plan attached to an app that has not been used in 60 days, and every AI Builder or Copilot Studio credit line that is trending toward overage. Third-party analyses of enterprise true-ups regularly find 20-40% overspend or unplanned charges when this reconciliation is skipped.

Decision rule: rebalance licenses before renewal, not after. Every finding here has a dollar value attached, which is what makes the entire ritual fund itself.

The Audit Output Pack

The point of an annual tenant hygiene review is not the findings. It is the artifacts you can hand upward. Every ritual should produce the same four deliverables so year-over-year comparison is possible.

  • Remediation ticket queue: one ticket per finding, assigned to an owner, with a deadline and a decision rule already applied.
  • License true-up estimate: the projected cost delta if you did nothing, expressed against your next renewal.
  • Risk register update: new findings mapped to your existing security and compliance risks, with residual risk after remediation.
  • Governance maturity delta: counts of orphaned assets, over-shared apps, and stale connections compared to last year's numbers.

Frequently Asked Questions

How long should a tenant hygiene audit take?

One focused work week for a platform engineer, plus two days of IT Director review. Anything longer means you are trying to fix findings during the audit instead of after it. Separate detection from remediation and the ritual stays repeatable.

Do I need the CoE Starter Kit to run this audit?

No. Microsoft has moved the core inventory, usage, and monitoring capabilities into the Power Platform admin center itself. The CoE Starter Kit is useful if you already run it, but every domain in this checklist can be executed with the admin center, Entra ID, Purview, and PowerShell alone.

Who owns remediation for orphaned Power Automate flows?

IT owns the detection and the decision rule. The business unit that originally sponsored the flow owns the reassignment or the acceptance of deletion. If no business unit will claim ownership within 30 days, IT deletes.

What is the biggest risk of skipping this audit?

Not a breach. The most common consequence is a Microsoft license true-up that surfaces six figures of unplanned premium consumption, followed by an audit finding that names orphaned assets as a control weakness. The breach risk is real but statistically less frequent than the financial one.

How does this differ from a Microsoft 365 security audit?

A traditional M365 security audit stops at identity, mail, and endpoint. A tenant hygiene audit adds the Power Platform layer where citizen-developed apps, flows, and connections now live, which is the fastest-growing and least-audited surface in most enterprise tenants.

Sources

The Ritual Beats the Framework

Every enterprise BabyBots works with already owns more governance capability than it actively uses. The tenants that stay healthy are not the ones with the most sophisticated CoE. They are the ones whose IT Director puts a week on the calendar every year, runs the same checklist, produces the same output pack, and treats hygiene as non-negotiable operational work. Learn how BabyBots helps enterprises operationalize Power Platform governance without adding another framework.

Next year's audit will be easier than this year's, and the year after that will be almost boring. That is the point. A boring tenant is a healthy tenant, and boring is what an IT Director should be selling to the board.

Let’s make your tech stack work together

Don't see your use case here? We've likely built it. 

cta
tick
ai-innovation-01-stroke-rounded 1
ai-brain-04-stroke-standard 1
ai-computer-stroke-rounded 2
ai-security-01-stroke-standard 1
ai-cloud-stroke-sharp 1
ai-network-stroke-rounded 1