https://www.sikich.com

The end of ‘set it and forget it’: Understanding Microsoft’s changes to unlicensed OneDrive accounts

INSIGHT 9 min read

For many years, Microsoft 365 administrators followed a common offboarding process when employees left an organization. The mailbox would be converted to a shared mailbox, the Microsoft 365 license would be removed, sign-in would usually be blocked, and the employee’s OneDrive data would simply remain where it was.

That approach was convenient, and in many environments it appeared to work. The business still had access to the mailbox, the license count went down, and the OneDrive content was not immediately removed. Over time, this led to a common assumption: if the user account was not deleted and the mailbox was converted to shared, the user’s OneDrive data would remain indefinitely.

That assumption is no longer safe. Microsoft has introduced and updated enforcement behavior for unlicensed OneDrive accounts, first around January 2025 and then again with a more significant retention enforcement update beginning July 2026. These changes require administrators to handle OneDrive data as its own offboarding decision rather than treating it as a side effect of mailbox conversion.

Quick summary

TimelineWhat changedAdmin impact
January 2025Enforcement began for unlicensed OneDrive accounts. Accounts move to read-only at Day 60 and archive at Day 93.Removing a license starts a OneDrive lifecycle even if the mailbox was converted to shared.
July 2026Unpaid unlicensed OneDrives are subject to a cumulative 365-day nonpayment clock.Archived content can become subject to deletion risk if billing, licensing, or migration is not addressed.
Going forwardRetention planning must include licensing or billing decisions.Offboarding checklists should explicitly document what happens to OneDrive content.

The historical approach

For years, many Microsoft 365 administrators followed a very familiar offboarding pattern. When an employee left the organization, the administrator converted the mailbox to a shared mailbox, removed the Microsoft 365 license, blocked sign-in, and moved on to the next task. In many environments, the OneDrive content remained in the background and was not treated as an urgent cleanup item.

That approach made sense based on how many tenants behaved historically. The mailbox conversion addressed the immediate business need: preserve access to email without continuing to pay for a user license. The user’s OneDrive data often continued to exist because the Entra ID account remained present, retention settings may have been in place, and there was no immediate operational pressure forcing a decision about the files.

The risk with that process is that it created a false sense of permanence. Administrators could easily start to believe that converting a mailbox to a shared mailbox also protected the user’s OneDrive data indefinitely. In reality, the mailbox and OneDrive are separate workloads with separate lifecycle rules. The shared mailbox conversion preserves the mailbox experience; it does not automatically guarantee long-term preservation of the user’s OneDrive content.

January 2025: Read-only and archive enforcement

The first major shift came through Microsoft’s communication around unlicensed OneDrive accounts, including Message Center post MC836942. That update established that enforcement for unlicensed OneDrive accounts began on January 27, 2025. It also documented that accounts left unlicensed would move through an enforcement lifecycle instead of remaining fully accessible forever.

Under this model, unlicensed OneDrive accounts are placed into read-only mode after 60 unlicensed days and are archived after 93 unlicensed days. Once an account is archived, the content remains visible through administrative tooling, but normal user access is restricted unless an administrator takes a supported action, such as assigning a valid license, enabling applicable billing, reactivating archived content, moving the data, or deleting the account.

This was an important change for offboarding procedures. It meant that removing the license from a former employee’s account was no longer a low-impact administrative cleanup action. It started a OneDrive-specific lifecycle. Even if the mailbox was converted to a shared mailbox and still existed, the OneDrive content could become read-only and then archived based on its own licensing state.

At this stage, many organizations viewed the change mainly as an access issue. The data was not necessarily gone, but it was no longer convenient to access. If a department later needed files from a former employee’s OneDrive, the administrator might need to relicense the account or use Microsoft 365 Archive billing to reactivate or manage that content. That alone was enough reason to revisit offboarding documentation.

July 2026: The additional deletion-risk layer

The July 2026 update is the bigger retention governance concern. Message Center post MC1381110 introduced additional retention enforcement for unlicensed OneDrive accounts that remain unpaid for an extended period. The key point is not that Microsoft immediately deleted archived OneDrive accounts on July 1, 2026. The more accurate statement is that Microsoft introduced a cumulative unpaid-day clock that can eventually make the data subject to deletion.

The current lifecycle can be summarized this way: an unlicensed account becomes read-only after 60 days, it is archived after 93 days, and after 365 cumulative unpaid days it becomes subject to deletion risk. For accounts already unlicensed and unpaid on July 1, 2026, the deletion-risk clock begins on that date, which means the earliest deletion-risk date would be July 1, 2027. For accounts that become unlicensed after July 1, 2026, the clock begins when the account becomes unlicensed or otherwise unpaid.

This distinction matters. July 2026 is not best described as an instant deletion event. It is better understood as the point where unpaid archived OneDrive content stopped being something organizations could assume would remain in archive indefinitely. From that point forward, administrators need to make an affirmative decision: pay for preservation, relicense the user, migrate the content, or allow deletion based on business and retention requirements.

Why this matters for shared mailbox conversions

The most common misconception is that a shared mailbox conversion protects everything connected to the former employee. It does not. Converting the mailbox to a shared mailbox addresses Exchange Online mailbox licensing and access. It does not convert the user’s OneDrive into a shared storage location, and it does not exempt the OneDrive from unlicensed account enforcement.

This is especially important for organizations that have long used shared mailbox conversion as the default offboarding answer. The mailbox may be retained without a user license if it meets shared mailbox requirements, but the user’s OneDrive is still tied to the licensing and lifecycle rules for OneDrive. If that OneDrive remains unlicensed and unpaid, it can move into read-only mode, then archive, and eventually become subject to deletion risk under the July 2026 model.

The practical takeaway is simple: offboarding procedures need a separate OneDrive decision. The decision should not be implied. It should be documented as a required step, just like mailbox handling, device return, MFA cleanup, group membership removal, and access termination.

Retention policies, holds, and eDiscovery

Another area that needs careful attention is retention. Administrators often assume that if a OneDrive is subject to a retention policy, litigation hold, or eDiscovery hold, the data is protected no matter what. Microsoft’s current guidance requires a more careful reading.

Archived OneDrive accounts can honor retention policies, retention settings, litigation holds, and eDiscovery requirements when the appropriate billing is enabled. However, Microsoft also indicates that if billing is not enabled and the account remains unpaid, the account may become subject to deletion after the cumulative unpaid period, even when retention policies or holds exist.

That does not mean retention is irrelevant. It means retention planning and storage billing are now connected for unlicensed OneDrive data. If an organization has a legal, regulatory, or operational requirement to preserve former employee OneDrive data, it should not rely on an unpaid archived state as the long-term preservation strategy. The organization should either maintain appropriate licensing, enable the required billing, or move the content into an actively managed repository such as SharePoint.

The best response is to update the offboarding process so OneDrive handling is explicit. Administrators should inventory unlicensed OneDrive accounts, identify anything already archived, review whether the content has retention or business value, and decide whether it should be licensed, archived with billing, migrated, or deleted.

For active offboarding, the process should include a OneDrive review before the license is removed or shortly after removal. Business-critical files should be moved to a SharePoint site or another approved repository. Personal or stale data should be handled according to the organization’s retention policy. If the organization needs long-term preservation of the former employee’s complete OneDrive, then licensing or Microsoft 365 Archive billing should be planned intentionally rather than discovered during an emergency restore request.

This is also a good time to review user deletion processes. Deleting the Entra ID user starts a different OneDrive cleanup process than simply removing the license while leaving the user active. Administrators should understand which scenario applies because the lifecycle and available recovery paths are not always the same.

Final thoughts

The old assumption was convenient: convert the mailbox to shared, remove the license, and expect OneDrive data to remain indefinitely. That assumption is no longer safe.

The January 2025 enforcement introduced read-only and archive behavior for unlicensed OneDrive accounts. The July 2026 change added a more serious long-term retention concern by introducing deletion risk for accounts that remain unpaid for 365 cumulative days. Together, these changes mean organizations must actively manage unlicensed OneDrive data instead of letting it sit unmanaged for years.

For administrators, the message is not complicated, but it does require discipline. Every offboarding workflow should include a documented OneDrive decision: keep it licensed, pay to archive it, migrate the content, or intentionally let it age out. What should no longer happen is removing the license and assuming the data will be there forever.

The days of set-it-and-forget-it OneDrive retention are over. Administrators who update their processes now will avoid confusion later, especially when a department, auditor, or legal team asks for data that everyone assumed was still safely preserved.

The following source links are useful for validating the current Microsoft guidance and Message Center history behind the timeline discussed above:

Author

Craig Schellenberg is a Senior Network Consultant at Sikich that works with businesses to improve their IT. Being detail oriented assists in his ability to design and deploy new solutions as well as troubleshoot complex issues. His primary areas of focus are virtualization and storage on premise (whether through VMware vSphere or Microsoft Hyper-V), Microsoft Cloud services such as Azure and Office 365, Microsoft SQL design and administration, backup/DR/Business Continuance, and network route/switch/firewalls.

Craig holds many certifications including his MCSE (Microsoft Certified Solutions Expert) in Productivity, Messaging, and Cloud Platform and Infrastructure. Craig also holds multiple certifications of his VCP (VMware Certified Professional) including version 3, 4 (Data Center Virtualization), 5 (Data Center Virtualization), 5 (Desktop), Cloud, and 6 (Data Center Virtualization).