Unchecked Microsoft 365 Accounts could Become the Next Business Security Crisis, says Espria
Ensuring licenses are regularly reviewed, right sized and aligned with actual usage will keep costs under control even as prices rise.
The UK’s new Cyber Security & Resilience Bill is set to bring businesses, not just MSPs, under stricter regulatory control, including tighter rules around resilience planning, faster reporting of cyber incidents, and stricter expectations for maintaining secure systems.
The Cyber Security & Resilience Bill increases pressure on organisations to tighten identity governance and reduce avoidable attack surfaces. This directly impacts Microsoft 365 environments, where dormant or “zombie” accounts become a material compliance and security risk. Microsoft’s renewal process enables zombie accounts because auto‑renewal keeps every licence active by default, even those tied to ex‑employees. The M365 Admin Centre gives limited visibility, making dormant identities hard to spot but this has lead to bloat, inefficiencies and in turn, increased risk.
“As businesses enter licence renewal season, dormant Microsoft 365 accounts become not just a budget leak but also a compliance risk. With employee turnover typically highest in January and finance teams tightening budgets for the year ahead, unused accounts often slip through unnoticed,” said Stephen Cook at Espria.
At the same time, Microsoft is significantly increasing the embedded security value within its licenses. From 2026, Microsoft 365 E5 will automatically include Security Copilot, adding AI-powered support across Microsoft’s security tools. While this gives organisations more security out of the box, it also means poorly managed or unused licences now carry greater risk as well as unnecessary cost.
“With commercial pricing changes taking effect from July 2026, Microsoft is signalling increased value. These changes mean organisations often have far stronger security tooling than they realise, but unused licences completely undermine that value, carrying greater security risk. The result is an exposed attack surface which must be addressed before it snowballs into something bigger.”
IT teams may buy licenses in bulk for volume discounts, but there can be a disconnect between purchasing decisions and actual license usage.
“To simplify procurement, IT leaders might buy large quantities of licenses, but these often get distributed without a true understanding of who needs what. Multiple, unused subscriptions create disconnected systems, fragmented information and excessive time spent on admin that employees could be spending on growth or service.
“Simply understanding what’s already in your M365 toolbox is a gamechanger. Businesses should be able to track real-time insights into licenses so they can be purchased based on needs rather than outdated estimates.
Cook also believes governance plays an important role in preventing licences from incurring unnecessary costs or introducing avoidable risks.
“Employees leave and accounts become obsolete, but their licenses remain active, consuming resources, including storage space and costs, as well as futile resource allocation due to unnecessary maintenance of these accounts.
“It can also become a common entry point for attackers as credential stuffing and phishing attacks often target these neglected identities. Not to mention that these accounts may violate regulatory compliance requirements, especially as industries become stricter with data protection regulations.
“Businesses must enforce periodic reviews to identify and reclaim unused or unnecessary licenses. By automating the deactivation process, organisations only pay for active users, reducing the cost of unused licenses. This may include setting expiration dates to automatically revoke access for inactive accounts after a specified period and access review tools that allows administrators to review access permissions.”
Cook added that simple benchmarking can be an effective way for organisations to regain control of licensing decisions.
“Espria has introduced a tool that helps businesses compare their Microsoft 365 licensing costs with typical industry patterns, highlighting potential mismatches between spend, usage and security coverage. This kind of insight is becoming increasingly valuable as Microsoft adds more security features and adjusts pricing ahead of 2026.”
Cook concluded, “right-sizing licences, removing unused accounts and aligning tools to job roles reduces both spend and attack surface. With pricing changes landing in July 2026, organisations that understand which advanced features are actually enabled will be best placed to control costs and strengthen cyber resilience. The proper insight into user profiling and regular audits, unnecessary costs can allow businesses optimise every penny spent.”
You may be interested in
The Hidden Costs of Printing: How Managed Print Services Reduce Business Waste
Introduction For many organisations, printing is viewed as a routine operational expense. Printers are purchased, toner is replaced when needed, and documents continue to flow through the business without much scrutiny. However, the true cost of printing extends far beyond paper and ink. Unmanaged print environments often create hidden expenses through inefficient device usage, excessive energy consumption, IT support demands, security risks, and employee downtime. These costs can accumulate significantly over time, impacting productivity and profitability. This is particularly relevant as businesses seek to optimise operations, reduce waste, and improve sustainability while controlling expenditure. Whether…
Can Your Business Actually Recover? The Operational Resilience Question Most SMEs Cannot Answer
Operational resilience is not a technology problem. It is a business problem. And until boards and leadership teams own it, no amount of IT investment will be enough. The Gap Between Confidence and Reality Most organisations believe they are more resilient than they are. The backups are running. The antivirus is licensed. The IT team knows what they are doing. That confidence, in our experience, rarely survives first contact with an actual incident. The question is not whether your systems are protected. The question is whether your business can keep delivering its most important services…
Why the Sophos–Microsoft Partnership Matters – Especially for Education, Financial Services and Legal Organisations
For most organisations today, Microsoft is the foundation of how you operate and on top of this there is also a requirement for regulatory compliance and operational resilience. Whether it’s Microsoft 365 for collaboration, Teams for communication, or Azure for infrastructure, these platforms sit at the heart of day-to-day business. But for sectors like Education, Financial Services, and Legal, that reliance comes with heightened risk, and responsibility. These organisations are not only prime targets for cyber attackers, they are also subject to strict regulatory, data protection and governance obligations. That’s why the partnership between Sophos…
Why Cyber Resilience Can’t Be Audited Once a Year: Lessons from the UK Cyber Action Plan
Moving from box‑ticking compliance to real‑world cyber readiness Written by Richard Puckey Cyber security has a confidence problem For years, many organisations have taken comfort in annual cyber audits, certifications and compliance checklists. Pass the audit, tick the box and move on. On paper, everything looks secure. The problem? Cyber threats don’t operate on an annual cycle. The UK’s Cyber Action Plan is a clear signal that this approach is no longer enough. It challenges businesses to rethink cyber security not as a periodic compliance exercise, but as a living, breathing capability and culture that must stand up…
How Housing Associations Can Transform Tenant Experience with Modern OmniChannel CX
Written by Russell Hallam, CX Consultant at Espria In today’s housing landscape, tenants expect fast, seamless and personal interactions, no matter which channel they use. Phone, digital, web chat, video, email, messaging: it all needs to feel connected, consistent and effortless. But for many teams, the reality is different. Disconnected systems slow down responses, important information is buried across platforms and frontline staff shoulder the burden of manual processes. At Espria, we’ve helped housing associations modernise their customer experience with cloud-enabled omnichannel solutions designed for efficiency, visibility and compliance. Here’s what that looks like in action. 1. RealTime CRM Integration: Context at the Exact Moment You Need It When a tenant calls,…
Elevating Human Risk Management: A Boardroom Must for Cyber Resilience in 2026
Written by Richard Puckey As organisations move through 2026, cybersecurity has firmly established itself as a core business risk. Regulatory scrutiny is increasing, threat actors are more capable than ever and the operational and reputational impact of cyber incidents continues to escalate. In response, businesses have invested heavily in security technology such as advanced detection platforms, zero trust architectures, AI-driven analytics and automated response capabilities. These controls are considered essential and non-negotiable. However, are they sufficient? The reality facing security leaders today is clear, the majority of material cyber incidents still involve a human decision…





