Skip to content

Security1 publisher2 min readPublished

Two thirds of Microsoft 365 teams learn of governance incidents only via audits or user complaints

ShareGate surveyed nearly 1800 IT professionals across nine countries and found 77% had a Microsoft 365 governance incident last year, with full Copilot deployments doubling to 56% of organisations over the same period.

The Watch · Security desk

Illustration accompanying Two thirds of Microsoft 365 teams learn of governance incidents only via audits or user complaints

What happened

  • ShareGate's second annual State of Microsoft 365 report, built from two surveys of nearly 1800 IT professionals and leaders in nine countries, found 77% had at least one governance incident last year.
  • Among organisations that had an incident, 38% left former employees or guests with access they should have lost, 35% hit an audit or compliance gap and 26% had sensitive content reach the wrong people.
  • Full Copilot deployments roughly doubled over the past year, from 29% of organisations to 56%, and around 28% of those tenants run three or more AI tools.
  • 65% of respondents said their teams learn about incidents only after the fact, through quarterly audits or user complaints, while 35% use proactive monitoring and automated alerting.
  • 93% said they are sure their governance framework is ready for AI, and 29% said Copilot or another AI tool had already surfaced sensitive internal data it should not have reached.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • exposure About three in ten surveyed organisations had a leaver or an external guest holding access they should have lost, and that account sits in the same tenant the new AI tools read on a user's behalf.
  • constraint An audit cadence caps remediation speed regardless of what controls sit above it: a permission opened in January is found in April, and the AI tooling deployed in between inherits it.
  • contradiction Near-universal confidence in AI readiness and a near-third rate of confirmed AI disclosures come from the same respondents, so the confidence figure is not evidence that the controls hold.
  • decision Respondents put agent controls at the top of what would help and extra budget at the bottom. The choice is which monitoring tool reports in week one, not headcount.

A review every three months leaves up to about 91 days between a bad change and the report that finds it. Most of these tenants run on a 91-day detection floor [4][8].

Scale the access failure against the whole sample. 38% of the 77% who reported an incident works out to roughly 29% of every organisation surveyed, so about three in ten left a departed employee or an external guest holding access for some part of the year [1].

None of the three failure modes the report counts is an intrusion. Two of them are access that should have been revoked and content that reached the wrong readers [3][5].

Stale guest accounts are an old problem. Copilot coverage grew by a factor of 1.93 in twelve months [2], and spending moved with it: 22% of respondents said AI has taken more than a fifth of their IT budget, rising to 32% among teams with Copilot fully deployed [9].

Asked what would help most, 34% chose better controls for AI agents, 20% executive buy-in, 18% automated remediation and 3% extra budget [12]. The agent-control ask outweighs the budget ask by about eleven to one [3].

ShareGate is a Microsoft 365 governance specialist and ran both surveys itself [2][16]. Its reading is that the incidents come from poor visibility, overconfidence in current governance approaches and AI governance skills gaps [13]. Among respondents, 37% named a lack of AI governance expertise as a top concern, behind data quality and retention and behind security and access [11].

"Most of the tenant environments I look at aren't broken; they just don't know what's happening within them. Teams feel confident because nothing has surfaced yet, but that doesn't mean there's nothing wrong," said Richard Harbridge, principal industry advisor at ShareGate [14]. He also said: "The fix isn't more diligence or a bigger team. It's tooling and processes that surface and fix problems in week one instead of month three." [15]

What to watch

  • Whether ShareGate's third annual report shows the 65% audit-and-complaint share falling as Copilot coverage climbs past 56%.
  • Microsoft shipping tenant-level controls for AI agents, the single thing 34% of respondents named as their biggest help.
  • A named organisation publicly attributing an AI-surfaced data exposure to stale guest or leaver access, moving this off self-reported survey data.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories