The M365 storage bill is coming. Here's what to do about it.

Eric Polet, Director of US Operations, Arcitecta
News

For most of the last decade the IT department at a university didn’t have to think twice about where to put a file. Lecture recordings, research datasets, department shares, half-finished projects from a grad student who left in 2019 — it all went into OneDrive, SharePoint, or Teams, because it was already there and effectively bottomless. Nobody budgeted for it. Nobody governed it. It was just storage.

That's over now. Microsoft is moving M365 Education off unlimited storage and onto a capped, pooled model. The change lands at every license renewal starting in August 2026 and goes into effect for all universities December 2026. Institutions that have built up years of "free" data are about to find out what it really costs.

If your university is sitting on hundreds of terabytes, or a few petabytes, this isn't a line item you can shrug off. It's a real decision, and it needs to be made soon.

What's actually happening?

Under the new model, each tenant gets 100TB free, plus a per-user allowance of 50–100GB depending on whether you're on an A3 or A5 license. Go over that and Microsoft charges roughly $360,000 per petabyte, per year, for the overage. That's not a rounding error for anyone managing serious volume, it carries some momentous weight.

Some institutions have already done the math and concluded that the only way to get under the cap affordably is to just start deleting — in a few cases, as much as 95% of what's sitting in M365. This should make anyone in research administration or records management a little nervous, because that data isn't junk. The two big categories eating up space are teaching and learning materials (lecture capture, media libraries, years of course content) and research data — which was never supposed to live long-term in a collaboration tool in the first place. A lot of the data has no retention policy attached to it at all. Some of it contains Personally Identifiable Information (PII), and some of it is intellectual property that exists nowhere else. Deleting first and figuring out what you lost later isn't really a plan.

Then there's the timing problem, which makes everything worse. Microsoft has also capped how fast data can move in or out of a tenant — 400GB an hour, or about 9.6TB a day. Do the math on a petabyte and you're looking at roughly 105 days to get it out, and that's if you already know exactly what needs to move. An institution carrying three or four petabytes of overage is realistically looking at the better part of a year to relocate it, and that clock doesn't start until someone begins.

On top of all that: Microsoft is going to start deleting accounts that have gone inactive for 12 months. Whatever's sitting in a dormant staff or alumni account — nobody's checking it, nobody's backing it up, and eventually it's just gone.

Put all three of those together and you have a genuinely uncomfortable position: a shrinking window, a hard deadline, and not many good options. The options that do exist are worth laying out plainly, because one of them is clearly better than the other three.

The four paths, and why three of them don't really work

1. Do nothing - Just eat the overage charges. If you're under the cap, or barely over it, this might be fine for now — it's not really a decision so much as a lack of one. Once you're meaningfully over the line, somewhere past 500TB or so, the ongoing bill stops being tolerable, and you're still at Microsoft's mercy for whatever they decide to change next.

2. Delete it - Fast, free, and immediately effective. Also permanent. If you haven't actually looked at what you're deleting, you're gambling with data that might be the only copy of something important — a dataset, a piece of IP, a record you're legally obligated to keep. This is the option that solves the cost problem by creating a much bigger one.

3. Back it up, then delete it - This is the safer-sounding version of option two, and it's usually what IT proposes first, because it's defensible. Copy everything to Veeam or AvePoint or Rubrik, delete the original, cap solved. Except now the data is sitting in a backup archive that nobody can actually use. Faculty can't open it. Students can't find it. It's "saved" in the sense that it exists somewhere, but it's functionally gone from anyone's day-to-day work. And because backup tools move data through the same tenant, they're bound by the same 400GB/hour limit as everything else — so even this option is slower than it used to be.

4. Bring it under management - This is the one that treats M365 data like every other kind of institutional data instead of treating it as a special case that got out of hand. Rather than scrambling to hit a deadline, you use the deadline as the reason to finally get a real handle on what's in there — what needs to stay, what needs to move, what can go — and you build a system for keeping it that way going forward.

Why that fourth option is the one to pick

Look at what the other three actually cost you. Doing nothing costs you money, indefinitely, with no plan behind it. Deleting is risky and costs you data you might not be able to replace. Backup-and-delete solves the money problem but kills access for everyone who actually uses that data day to day. None of them fix the issue, which is that M365 data was never properly managed to begin with.

Bringing your data under management is the only option that deals with the cost, the risk, and the access problem all at once — which is exactly the gap Mediaflux® Connect 365 is built to close.

Instead of treating this as a one-time extraction job — get the data out, call it done — Mediaflux Connect 365 brings real, active data management to OneDrive, SharePoint, and Teams. It does four things, and they matter roughly in this order:

  • It analyzes what's in there first, so you're working from a real inventory instead of a guess about what needs to stay, move, or go.

  • It migrates the data intelligently — using analytics to cut down what needs to move, then sending it to on-prem, cloud, or hybrid storage in a way that makes the most of that slow 400GB/hour allowance instead of just throwing everything at it and hoping.

  • It keeps the data usable. This is the part backup-and-delete misses entirely. Through Mediaflux® DAMS, people keep real ongoing access to their files — not a static archive they'd have to file a ticket to retrieve.

  • It governs the data going forward, bringing M365 content into the same visibility and control the institution already applies to everything else. Which, honestly, is where this should have been all along.

One more thing worth mentioning: Mediaflux Connect 365 doesn't lock you into a single destination. On-prem, cloud, a mix of both — pick what makes sense for cost, performance, or data sovereignty, and change your mind later without disrupting anyone. A research dataset with sovereignty requirements and an old course archive don't belong in the same place, and a rigid one-size-fits-all answer never really fits.

There isn't a lot of runway left.

Overage pricing hits at every renewal, starting from this December. A large migration can eat the better part of a year once you factor in the movement cap. If your institution is holding hundreds of terabytes or more, waiting until renewal to start figuring this out isn't really an option — by then the 400GB/hour ceiling is already working against you.

In a strange way, Microsoft forcing this change is doing universities a favor, even if it doesn't feel like it. It's making people confront data they've been able to ignore for years. Without management, you either bleed money forever, risk losing something you can't get back, or quietly cut off the people who need the data to do their jobs. Understanding and managing the data is the only path that fixes all three problems at once. Mediaflux Connect 365 can turn a compliance headache into the moment your institution finally gets its data under control.

For more information about Mediaflux Connect 365 contact talk@arcitecta.com.