Avoid sandbox administration mode: 11 cleanups that work without buying capacity
From 9 November 2026, Microsoft validates Dataverse storage capacity. If a tenant remains over 100% for 30 days after its first overage, only administrators can open its sandboxes. Microsoft calls this state administration mode; in the German interface, it is called “Verwaltungsmodus” (all stages and deadlines). What counts is the consumption of the whole tenant, not of the individual sandbox: a cleanup in production protects your sandboxes just as well.
All eleven measures work without buying capacity; you can start with Group A today. The effect shows up in the capacity report after up to 72 hours; Microsoft evaluates storage about every 24 hours. So don’t leave cleanups to the last days before a deadline. We only list measures that Microsoft documents or that NXTGN Capacity Control carries out, each with its risk and effort.
Three ground rules
- Target the right storage type. A database deficit only goes down through cleanup in the database or by buying capacity. File and log, by contrast, borrow unused capacity: log from database, file from log and database. So if you delete attachments, you also free borrowed database capacity for the log.
- Mind the recycle bin. If “Keep deleted Dataverse records” is turned on, deleted records keep counting toward capacity for up to 90 days. For system data, the “Permanent deletion” option of a bulk deletion job, or
CanRecoverDeletedRecords = falsein the Web API, is therefore worthwhile. - Test first, then delete. Microsoft recommends developing deletion jobs in a sandbox and previewing the matching records first. What a bulk deletion job has deleted stays deleted, even if the job fails or ends early.
The measures at a glance
| # | Measure | Storage type | Risk | Effort | With NXTGN Capacity Control |
|---|---|---|---|---|---|
| 1 | Lower the plug-in trace level | log | low | minutes | show and change |
| 2 | Delete completed system jobs | database, partly file | low | minutes | check the deletion service, template |
| 3 | Import history, duplicate detection jobs, trace records | database | low | minutes | templates for import history and trace records |
| 4 | Cancel stuck workflow jobs | database | medium | hours | per process, after approval |
| 5 | Archive the audit log, then delete it | log | high without an archive, low with a verified archive | hours to days | archive with evidence |
| 6 | Delete Copilot interactions | database | medium | minutes | template, only on explicit request |
| 7 | Delete unused sandboxes | all | high if still needed | minutes plus coordination | shows consumption per environment |
| 8 | Shrink a sandbox after a full copy | all | medium to high | hours | not included |
| 9 | Empty the recycle bin | all | high | minutes | not included |
| 10 | Delete attachments | file | high | hours | shows count and size |
| 11 | Slim down Dataverse search | database | medium | hours | not included |
Group A: low risk, no business decision needed
1. Lower the plug-in trace level
If “Enable logging to plug-in trace log” is set to “All”, every plug-in execution writes a record to PlugInTraceLogBase. A daily job deletes records older than 24 hours, so one day’s volume always sits in log storage. Microsoft recommends “Off” for production environments.
- Where: Settings › Administration › System Settings › Customization tab, or through the Web API in
organization.plugintracelogsetting(0 = Off, 1 = Exception, 2 = All). - Risk: low. For troubleshooting, switch to “Exception” temporarily.
- Effort: minutes. No new records are written, and Dataverse removes the existing ones after 24 hours.
2. Delete completed system jobs
Every workflow, plug-in and background operation leaves a system job in AsyncOperationBase, and workflows also leave records in WorkflowLogBase. The Dataverse deletion service removes completed system jobs after fixed periods; by default, succeeded jobs after 30 days, failed and canceled jobs after 60 days.
- Where: Power Platform admin center › Manage › Environments › environment › Settings › Audit and logs › “Set retention policy for system job deletions” (preview). Alternatively, a bulk deletion job on system jobs with the status “Completed”. For asynchronous workflows, the workflow option “Automatically delete completed workflow jobs” helps.
- Risk: low. You lose the history of which job ran when; the results of the workflows remain.
- Effort: minutes. For large volumes, Dataverse gives priority to new, nonrecurring deletion jobs on system jobs (up to five such jobs).
3. Import history, duplicate detection jobs and trace records
Microsoft documents all three as data you can clean up: completed data imports, instances of duplicate detection jobs (each instance stores a copy of the duplicates found) and server-side synchronization trace records in TraceLogBase, which appear on the “Alerts” tab of mailboxes and email server profiles.
- Where: Settings › Data management › Bulk deletion (System Job Type “Import”, Status Reason “Succeeded”, older than one month), or Settings › Data management › Duplicate detection jobs.
- Risk: low. Once you delete an import job, you can no longer roll back that import.
- Effort: minutes.
With NXTGN Capacity Control (Group A): The app shows the trace level and changes it, checks the state and periods of the deletion service, and flags your own deletion jobs that duplicate the deletion service. For completed system jobs (only while the deletion service is turned off), import history (default: older than 90 days) and trace records (default: older than 30 days), it provides templates with preview, approval, a canary run on the oldest segment, and a run log.
Group B: effective, but with review
4. Cancel stuck workflow jobs
Waiting workflow jobs remain until someone cancels them; the deletion service only covers completed jobs. Microsoft recommends evaluating each case, because some workflows wait on purpose. In our own development environment, 25,721 waiting jobs were stuck on a workflow that had been deleted long ago.
- Risk: medium. A canceled job of an active workflow no longer runs its remaining steps.
- Effort: one business review per workflow.
- With NXTGN Capacity Control: The app groups the jobs by process, showing the state of the workflow (active, deactivated, deleted), and after your approval cancels them in batches, group by group.
5. Archive the audit log, then delete it
In the admin center, you delete audit logs by table, by access logs or up to a date (Manage › Environments › environment › Auditing › “Delete audit logs”). As a guideline for the deletion, Microsoft cites about 100 million records per day.
- Risk: high without an archive, because deleted audit logs can’t be restored; low with a verified archive.
- Effort: Starting the deletion takes minutes, and the job runs in the background. An archive needs setup and export time.
- With NXTGN Capacity Control: Export per table and month to your Azure Blob Storage, evidence for every audit ID, removal according to your rule. In detail: reducing the audit log safely.
6. Delete Copilot interactions
The msdyn_copilotinteraction table stores interactions with Copilot features. Microsoft describes cleaning it up with bulk deletion or long-term retention.
- Risk: medium. The records may be needed for analysis and compliance. Clarify this beforehand with the business owners and your data protection officer.
- Effort: minutes.
- With NXTGN Capacity Control: Template with a minimum age (default 90 days), only on explicit request.
Group C: large effect, only with a decision
7. Delete unused sandboxes
A deleted environment frees its entire consumption; Microsoft explicitly lists this as a measure. You can recover a deleted sandbox only for 7 days and, depending on the environment type, only with free capacity; in stage 1, recovery is blocked.
- Risk: high if the sandbox is still needed.
- Effort: minutes, plus coordination with the teams that use it.
8. Shrink a sandbox after a full copy
A copy with the “Everything” option takes over all production data. For sandboxes, the BulkDelete Web API action offers a fast delete mode (RunJobForSandbox) that Microsoft describes for large data volumes after a production copy; it bypasses plug-ins and workflows and deletes permanently. For development and proofs of concept, Microsoft points to the “Customizations and schemas only” copy, which, among other things, leaves out audit, activities and attachments. Note that copying is blocked in stage 1.
- Risk: medium to high, because the delete mode is permanent and runs no business logic.
- Effort: hours for the query, a test run and the Web API call.
9. Empty the recycle bin
“Delete all records” under Settings › Data management › Deleted Records permanently removes all retained deleted records of the environment.
- Risk: high. Afterwards, nothing can be restored, and the action affects all tables.
- Effort: minutes.
10. Delete attachments
Microsoft describes deleting email and note attachments with Advanced Find or bulk deletion, for example all attachments over 1 MB.
- Risk: high. The attachments are then missing in Dynamics 365; copies saved in Outlook remain.
- Effort: hours for criteria and coordination.
- With NXTGN Capacity Control: The app shows count and size; it doesn’t offer an archive for attachments yet.
11. Slim down Dataverse search
The Dataverse search index appears as the DataverseSearch table and is counted like database capacity. Microsoft describes removing tables and columns you don’t need from search.
- Risk: medium. Search and Copilot features find less. Microsoft explicitly advises against turning search off completely.
- Effort: hours for agreeing which columns stay searchable.
Measures without effect
- Reallocating capacity between environments: according to Microsoft, this changes neither the tenant’s entitlement nor a deficit.
- Taking a sandbox out of administration mode: restores access temporarily, but doesn’t pause the deadline.
- Deleting data in trial, developer or Teams environments: these environments don’t count toward the tenant’s consumption.
When cleanup is not enough
- Pay-as-you-go for individual sandboxes: takes the linked sandbox out of the stages. Without allocated capacity, only 1 GB of database and 1 GB of file storage per environment are free; log storage costs from the first GB (list price according to Microsoft Learn: $12 per GB per month).
- Capacity extension: 25% of consumption for at most 45 days, from 80% consumption, at most three times in 365 days. Afterwards, the blocks apply again.
- Buying capacity in the storage type that is actually missing.
Recommended order
Start with Group A: it takes minutes and needs no business decision. In parallel, clarify which sandboxes are still needed and how long you must be able to provide audit evidence. Carry out Group C only with the approval of the people responsible.
Sources
- Microsoft Learn: Dataverse capacity-based storage details (opens in a new tab): stages, borrowing, exiting administration mode, FAQ
- Microsoft Learn: Free up storage space (opens in a new tab): methods for database, file and log, delay of up to 72 hours
- Microsoft Learn: Delete completed system jobs and process log (opens in a new tab): deletion service, default periods, priority jobs, plug-in trace logs
- Microsoft Learn: Tracing and logging (opens in a new tab): deletion after 24 hours, trace levels
- Microsoft Learn: Delete data in bulk (opens in a new tab):
CanRecoverDeletedRecords,RunJobForSandbox, no rollback - Microsoft Learn: Restore deleted Microsoft Dataverse table records (opens in a new tab): deleted records count toward capacity
- Microsoft Learn: Manage data with governance policies in Dataverse (opens in a new tab): recommendations, “Permanent deletion”
- Microsoft Learn: Copy an environment (opens in a new tab): copy types and tables left out
- Microsoft Learn: Recover environment (opens in a new tab): 7 days, capacity required
- Microsoft Learn: Overview of the msdyn_copilotinteraction table (opens in a new tab)
- Microsoft Learn: Manage Dataverse auditing (opens in a new tab): deleting audit logs, guideline of 100 million records per day
- Microsoft Learn: Pay-as-you-go meters (opens in a new tab)
- Microsoft Learn: Administration mode (opens in a new tab)