What happened
ShareGate's second annual State of Microsoft 365 report estimates that 77 percent of organisations worldwide had at least one Microsoft 365 governance incident in the past year. The figure comes from two surveys of nearly 1,800 IT professionals and leaders across nine countries.
Among organisations that had an incident, the failures cluster in familiar places. Thirty eight percent left former employees or guests with access they should have lost. Thirty five percent found an audit or compliance gap. Twenty six percent had sensitive content reach the wrong people.
Detection is the common thread. Sixty five percent of respondents said their teams learn about incidents only after the fact, through quarterly audits or user complaints, while 35 percent rely on proactive monitoring and automated alerting. Most organisations are auditing a point in time rather than watching the environment.
Copilot adoption is running ahead of the controls around it. Full deployments roughly doubled over the past year, from 29 percent to 56 percent of organisations, and around 28 percent of those tenants run three or more AI tools. Twenty two percent of respondents said AI now takes more than a fifth of their IT budget, rising to 32 percent among teams with full Copilot deployments. Ninety three percent said they are sure their governance framework is ready for AI, yet 29 percent have already had Copilot or another AI tool surface sensitive internal data that it should not have reached.
Asked what would help most, a third of respondents named better controls for AI agents, ahead of executive buy in at 20 percent and automated remediation at 18 percent. Extra budget came in at 3 percent. Lack of AI governance expertise ranked in the top three concerns, after data quality and retention, and security and access. Richard Harbridge, principal industry advisor at ShareGate, said most tenant environments he reviews are not broken, they simply do not know what is happening inside them.
Why this is a GRC story
Access reviews are a control with a shelf life. Leavers and guest accounts are the oldest finding in the book, and they still account for the largest share of incidents here. A control that depends on a quarterly audit has already expired by the time it runs.
Confidence is not evidence. Ninety three percent readiness against 29 percent realised data exposure is the widest gap in the report. Self assessed maturity does not survive contact with a tenant that has had three AI tools switched on it.
AI adoption moves the data boundary. An assistant surfaces what a user already had permission to reach, which means years of over permissive file sharing become an AI exposure the moment it is enabled. That is a data governance problem that AI turned into an incident.
What to watch
Watch whether AI agent controls become a standard part of identity governance or settle into a separate tool category nobody owns, and whether organisations shift spend from more people toward better monitoring now that extra budget ranked last.
The practical takeaway: pick one tenant, list the leavers and guests still holding access, and check how you would find out about an exposure today. If the honest answer is a quarterly audit, that is the gap this report is describing.
Attribution: Analysis based on Infosecurity Magazine and related public reporting. This article is original commentary, not a repost of the source material.
