“What stands out in this data is that so few organizations can check what their AI can actually reach before switching it on, and fewer still plan to spend anything on finding out,” Toni Frankola, CEO of Syskit, said in reaction to the findings.
Syskit’s September 10 State of Microsoft 365 Governance Report
Syskit’s latest State of Microsoft 365 Governance Report, published on September 10, surveyed 327 IT and security decision-makers responsible for Microsoft 365 governance at US and UK organizations with 500 or more employees. The study found that three-quarters (76%) of those organizations have deployed or piloted an enterprise AI tool — the report cites Copilot as an example — on Microsoft 365 data. Yet only 43% of respondents said they had completed a thorough review of permissions and oversharing risk before deployment; the remainder reported only partial reviews or none at all.
AI agents and permissions: confidence without formal controls
The study surfaces a striking gap between perceived visibility and formalized controls. While 91% of respondents claimed confidence that they can see which AI agents are active and what those agents can reach, just 22% confirmed they have a formal policy defining what AI agents may access. The report also notes that one in 10 organizations (9%) allow an AI agent to inherit the full permissions of the person who deployed it.

The cyber insurance questionnaire just landed. Now what?
SOC 2, HIPAA, insurance renewals - someone has to own security strategy. Nubivance provides fractional CISO leadership without the full-time salary.
Get a security leadMicrosoft 365 permissions and configuration failures
Syskit documents multiple persistent misconfigurations in Microsoft 365 environments that widen the attack surface when AI tools are granted access. Forty-one percent of organizations leave SharePoint sites accessible to all staff without restrictions. Thirty-five percent of respondents admitted that files belonging to former employees remain available to active users, and 33% said they have files shared with “Everyone.”
Orphaned content — teams, groups and sites with no accountable owner — emerged as a leading governance worry: 47% of organizations identified orphaned teams, groups and sites as a key concern. Without assigned owners, content is less likely to be reviewed, removed or secured, yet AI tools can access that content under the same authority as any other files.
Access reporting and the experience of security incidents
The report reveals a mismatch between asserted control and demonstrable evidence. Eighty-three percent of respondents said they know exactly who can access sensitive data at any given moment, but only 4% could produce a complete access report for an external auditor within an hour; a majority (55%) said they would need a day or longer. The practical impact of these gaps is visible in incident experience: nine in 10 organizations (90%) have experienced, or suspect they have experienced, a security incident linked to misconfiguration or over-permissioned access in the past two years, and 39% have confirmed one.
What this means for technologists, procurement leaders, and end users
- Technologists and security teams: The report highlights concrete tasks — locate and assign owners for orphaned teams, produce complete access reports more quickly (only 4% can do so within an hour today), and perform thorough permissions reviews before enabling Copilot or other AI agents (only 43% did this before rollout).
- Procurement and enterprise leaders: Rapid adoption is evident — 76% have piloted or deployed AI on Microsoft 365 — but the lack of formal policies (22%) and the allowance of agents inheriting full deployer permissions (9%) point to governance gaps that decision-makers will need to weigh against business benefits.
- End users and file owners: Broadly shared content — SharePoint sites open to all staff (41%), files shared with “Everyone” (33%), and former-employee files still accessible (35%) — increases the likelihood that AI tools will surface material that has not been reviewed in years.
Toni Frankola framed the issue plainly: reviewing permissions is “unglamorous work,” but the report’s numbers make it clear that permission hygiene is now central to whether an AI rollout is safe. The Syskit survey ties rapid AI deployment directly to a governance deficit: many organizations have switched agents on before they can reliably say what those agents can reach, and only a small fraction have the formal policies or fast, auditable access reports the data would require.
The dataset Syskit published leaves a simple choice for organizations with Microsoft 365 and AI ambitions: accept the operational and security risk of incomplete permission reviews, or pause deployments to inventory, assign ownership, and codify what AI agents may access. The report does not resolve which path most organizations will take next, but its statistics make clear why the decision matters.
https://www.infosecurity-magazine.com/news/organizations-skip-permissions-ai/




