Microsoft 365Incident TeardownsRetrospectives

The COVID-19 Remote Work Shift (Mar 2020): Teams Sprawl, Guest Access and Shadow IT

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from March 2020, written in 2026 with the benefit of hindsight.

In March 2020, the COVID-19 pandemic sent much of the global workforce home almost overnight. Microsoft Teams usage exploded as organizations rushed to keep people working.

What happened in Microsoft 365 tenants

Speed came first. In many organizations:

  • Anyone could create a Team, and thousands were created in weeks.
  • Guest access was enabled broadly so external partners could join meetings and chats.
  • Files moved from on-premises shares into Teams and SharePoint without classification.
  • Personal devices were allowed to access corporate data without management.
  • Shadow IT grew as departments adopted other tools.

Why it mattered

These decisions were reasonable in a crisis. But temporary settings became permanent. Years later, many tenants still have hundreds of inactive Teams, ownerless sites, guest accounts nobody remembers and sensitive files shared far more broadly than intended.

The long tail

The consequences became much more visible in late 2023, when Microsoft 365 Copilot arrived. Copilot surfaces any content a user can access. Pandemic-era oversharing turned into an AI data exposure problem.

Lessons in hindsight

  • Crisis settings need an expiry date. Record emergency changes and revisit them.
  • Governance can be lightweight — naming policies, expiration policies and guest reviews don't slow people down much.
  • Ownership matters. Every Team and site needs an accountable owner.
  • Collaboration sprawl is a security problem, not just a tidiness issue.

The pandemic accelerated cloud adoption by years. Many organizations are still paying down the governance debt it created.

microsoft teams governanceCOVID remote work & Teams sprawl2020

More on this story