OneDrive after they leave: the 30-day rule nobody actually enforces
OneDriveTSO.logisam.com
OneDriveGovernanceLeavers

OneDrive after they leave: the 30-day rule nobody actually enforces

Microsoft retains a leaver's OneDrive for 30 days by default, then deletes it. Almost every tenant we scan has OneDrives from employees who left years ago — still occupying quota, still holding drafts Copilot can quote. Here is the process that actually works.

LogiSam EngineeringThe team behind TSO08 Sept 20266 min read

Microsoft's documented behaviour when a user account is deleted: OneDrive is retained for 30 days by default, then removed. In practice, almost every tenant we scan has OneDrives belonging to people who left 3, 5, 8 years ago — still consuming quota, still visible to former managers, and still being surfaced by Copilot when it answers a policy question.

Why the 30-day rule breaks

Three failure modes explain most of it:

  1. Litigation hold — an eDiscovery hold on the mailbox typically also freezes the OneDrive. The hold gets forgotten; the OneDrive persists indefinitely. Every hold you set needs a review date on the calendar.
  2. Account disabled but not deleted — HR disables the Entra account but never runs a "delete" (or hands the ticket to IT). OneDrive retention only kicks in on delete, so a disabled-but-not-deleted account sits there forever.
  3. Retention policy override — a global retention policy set at Purview level for "OneDrive content" overrides the 30-day cleanup. Retention wins over deletion until the policy expires or the label is removed.

The Copilot amplifier

When Copilot for Microsoft 365 generates an answer, it retrieves from everything the current user can access — which, if the current user was the leaver's manager, still includes the leaver's OneDrive. That "draft pricing 2019" the leaver was working on is now cited alongside the live 2026 site. This is the single biggest source of Copilot embarrassment we see in the field, and it is entirely governance, not model behaviour.

The pragmatic process

A three-step process that actually works, in order:

  1. Audit — surface every OneDrive whose owner account is disabled or deleted. TSO shows these with a red flag; PowerShell / Graph works too if you prefer to build it.
  2. Rehome anything worth keeping — for each OneDrive over a size threshold (say 1 GB), export a manifest and either (a) transfer specific folders into a shared library the team keeps, or (b) leave a placeholder note in a "leavers archive" SharePoint site with a link.
  3. Delete — after the review window (14-30 days is usual), delete the OneDrive. If there is a legal hold, transfer that hold to the archive site and clear it on the OneDrive.

The retention paradox

The OneDrives we see hoarded the longest are almost always the ones covered by a "just in case" retention policy from a previous compliance sweep. The policy was set five years ago, nobody remembers the reason, and the storage is quietly billed every month since. Every retention policy your tenant enforces should have a documented reason, a review date, and an owner. If it doesn't have those three things, it is a leak.

How TSO helps

On the OneDrive tab of any scan, disabled and deleted user accounts are shaded pale red and marked with a badge. The Excel export carries the flag through so the admin acting on the report can filter to just leavers with one click. The No-Owner tab surfaces the SharePoint equivalent — sites whose creator is gone and whose owner never got reassigned.