Over 75% of Organizations Experience Microsoft 365 Governance Issues
ShareGate says 77% of organizations had a Microsoft 365 governance incident last year, often involving Copilot data exposure.
ShareGate’s second State of Microsoft 365 report, based on two surveys of nearly 1,800 IT professionals in nine countries, found that 77% of organizations had at least one Microsoft 365 governance incident in the past year. Among those affected, 38% left former employees or guests with access, 35% hit an audit or compliance gap, and 26% let sensitive content reach the wrong people. Full Copilot deployments rose from 29% to 56%, and 29% said AI tools had already surfaced sensitive internal data, despite 93% claiming their governance was ready for AI. About 65% said teams learn of incidents only after quarterly audits or user complaints.
- 77% of surveyed organizations reported a Microsoft 365 governance incident in the past year.
- 38% left former employees or guests with access; 26% exposed sensitive content.
- Full Copilot deployments rose from 29% to 56% of organizations.
- 29% said AI surfaced sensitive data even though 93% claimed they were ready.
- 65% learn of incidents only after audits or complaints, not live monitoring.
Full article461 words · extracted from infosecurity-magazine.com · click to collapse
An estimated 77% of global organizations experienced at least one Microsoft 365 governance incident over the past year, with overconfidence in AI controls creating new risks, according to ShareGate.
The governance specialist ran two surveys of nearly 1800 IT professionals and leaders across nine countries to produce its second annual State of Microsoft 365 report.
Of those that suffered an incident, 38% admitted to leaving former employees or guests with access they should have lost, 35% encountered an audit or compliance gap and 26% had sensitive content reach the wrong people.
ShareGate claimed these issues stemmed primarily from poor visibility, overconfidence in current governance approaches and AI governance skills gaps.
Read more on governance: Microsoft Copilot Deployments Delayed Over Security Concerns
The news comes as full Microsoft Copilot deployments roughly doubled over the past year, from 29% to 56% of organizations, according to the report. Around 28% of those tenants run three or more AI tools.
Part of the problem is that most organizations still rely on point-in-time audits to find out what’s going on in their environment, ShareGate argued.
Two thirds (65%) of respondents said teams learn about incidents only after the fact through quarterly audits or user complaints, while only a third (35%) rely on proactive monitoring and automated alerting.
AI a Major Driver of Risk
Rapid adoption of AI has exacerbated these risks, the report argued. Some 22% of responding organizations claimed AI has taken more than a fifth of their IT budget, rising to 32% among teams that have fully deployed Copilot.
Over-confidence is rife: 93% said they are sure their governance framework is ready for AI, but 29% have already had it surface sensitive internal data that Copilot or another AI tools should not have had access to.
These issues may stem from skills shortages. Lack of AI governance expertise (37%) ranked in the top three respondent concerns after data quality/retention and security/access.
Better controls for AI agents is the number one thing IT professionals say would help most with their governance challenges. It was cited by a third (34%) of respondents, ahead of executive buy-in (20%) and automated remediation (18%), with extra budget on just 3%.
"Most of the tenant environments I look at aren't broken; they just don't know what's happening within them. Teams feel confident because nothing has surfaced yet, but that doesn't mean there's nothing wrong,” said Richard Harbridge, principal industry advisor at ShareGate.
“That gap between 'no news' and 'no problems' is exactly where the governance incidents live, and when you layer in multiple AI tools, the visibility problem compounds fast. The fix isn't more diligence or a bigger team. It's tooling and processes that surface and fix problems in week one instead of month three.”
Image credit: gguy / Shutterstock.com