How Many Orphaned Users Do You Have in SharePoint? A Simple Estimation Method

This article answers two simple questions:
– how many SharePoint orphaned users do you have in your Microsoft 365 tenant?
– what is the likelihood of having User id Mismatch issue?

Unfortunately, Microsoft 365 does not provide a built-in report that can quickly answer this question across an entire tenant. As a result, administrators often need to estimate the scale of the problem before investing time in tenant-wide scanning and cleanup efforts.

This article provides a simple estimation method based on observations from several real-world Microsoft 365 tenants. The goal is not to produce an exact number, but rather to determine whether your organization is likely dealing with dozens, thousands, or millions of orphaned users.


What Is an Orphaned User?

In SharePoint, an orphaned user is a user record that still exists in a site’s User Information List even though the corresponding account no longer exists in Microsoft Entra ID. Orphaned users are not necessarily a problem by themselves. However, they can contribute to User ID Mismatch issues when a user account is recreated with a previously used User Principal Name (UPN) and SharePoint fails to provide access.

Please take a look at the more detailed “Orphaned Users in SharePoint and Their Connection to User ID Mismatch“


A Simple Orphaned User Count Estimation Formula

Based on observations from several production tenants, a simple estimation model is to assume that the number of orphan users grows roughly in proportion to tenant age and, a 10-year-old tenant is expected to have approximately the same number of orphan users as enabled Entra ID accounts

Estimated Orphan Users = Enabled Entra ID Users × Tenant Age ÷ 10

The actual number of orphaned identities depends on many factors (see below).


Estimating User ID Mismatch Risk

Orphaned users do not directly cause User ID Mismatch issues by themselves. However, User ID Mismatch typically occurs when an orphaned user exists in SharePoint and the same UPN is reused for a new account.

In general, the likelihood of User ID Mismatch issues increases as the number of orphaned users grows. Based on observations from several production tenants, a rough estimate is approximately one User ID Mismatch ticket per month for every 100 enabled user accounts in a 10-year-old tenant. Actual numbers may vary depending on employee turnover, SharePoint adoption, and UPN reuse practices.

Estimated User ID Mismatch Tickets per Month = Enabled Entra ID Users × Tenant Age ÷ 1000

E.g. for a 5 year old tenant with 10,000 users you can have as much as 50 issues related to the User Id Mismatch scenario every month. The actual number of User Id Mismatch related issues depends on many factors.

Note. It is important to understand, that typically a regular user do not have access to one site only. For an organization that uses Microsoft 365 SharePoint an average user can have access to dozens and hundreds sites. And a User Information List (UIL) – where SharePoint caches all user’s data and where the orphan users exist – exists at every site, so the number of orphan user records, and consequently potentially user id mismatch issues is much higher than just a number of orphan users.

I assume (again, based on real-world experience) the average number of sites every user access is ~100.
So this estimation assumes that we fix the User Id Mismatch issue for the affected site upon the ticket from user. So if a reactive clean-up of all affected sites for a specific user is implemented – it’d decrease the number of issues (see Preventing SharePoint User ID Mismatch).


What Contributes to Orphaned User Counts and User ID Mismatch Risk

The following factors generally increase the number of orphaned users in a tenant and consequently the risk of User ID Mismatch issues:

  • Higher employee and contractors turnover
  • Practice of re-creating accounts for contractors converted to employee
  • Practice of removing employees accounts in cases like long-term leave

The following factors generally decrease the risk of User ID Mismatch issue and the number of orphaned users in a tenant:

  • Practice of assigning unique UPNs
  • Lower adoption (footprint) of the Microsoft 365 collaboration services (e.g. SharePoint, Teams, Viva Engage, Search, Copilot)

Final Thoughts

The formulas presented in this article is intentionally simple and should be treated as a rough planning estimate, not a precise calculation.

Its purpose is to help administrators quickly assess the possible scale of orphaned users in their environment and determine whether a deeper investigation is justified. If the estimate suggests – it may be worth investing in tenant-wide analysis, cleanup, and User ID Mismatch prevention strategies.

To get exact number of orphan users – you can

  • develop a PowerShell script (example) that scans tenant
    you do not need to scan entire tenant – it might take forever…
    instead you can scan e.g. 2-3% of tenant sites and use Chao2 or Chapman estimator (TBP)
  • use 3-rd party tools (e.g. SysKit Point, Sharegate)

===========

References

Leave a Reply

Your email address will not be published. Required fields are marked *