Skip to main content
Cybersecurity

Microsoft 365 Governance Gaps Expose Organizations to Risk

A well-lit corporate office interior with people working at computer workstations.

"Most of the tenant environments I look at aren't broken; they just don't know what's happening within them. Teams feel confident because nothing has surfaced yet, but that doesn't mean there's nothing wrong,” said Richard Harbridge, principal industry advisor at ShareGate.

ShareGate's survey: scope and headline findings

ShareGate's second annual State of Microsoft 365 report, based on two surveys of nearly 1,800 IT professionals and leaders across nine countries, found governance problems are widespread. An estimated 77% of global organizations experienced at least one Microsoft 365 governance incident over the past year, the report said.

Among respondents who reported an incident, the survey quantified the types of failures: 38% admitted former employees or guests retained access they should have lost; 35% encountered an audit or compliance gap; and 26% had sensitive content reach the wrong people. ShareGate attributed these incidents primarily to poor visibility, overconfidence in current governance approaches, and gaps in AI governance skills.

Microsoft Copilot and rapid AI adoption

The report tied governance pressures to accelerating AI use inside Microsoft 365 tenants. Full Microsoft Copilot deployments roughly doubled year over year, rising from 29% to 56% of organizations, ShareGate said. Around 28% of those tenants run three or more AI tools.

Budgetary shifts accompanied the adoption: 22% of responding organizations reported AI had consumed more than a fifth of their IT budget, a share that rises to 32% among teams that have fully deployed Copilot. Yet that fiscal commitment sat beside a striking confidence gap: 93% of respondents said they were sure their governance framework was ready for AI, while 29% had already experienced AI surfacing sensitive internal data that Copilot or another AI tool should not have had access to.

Visibility, monitoring, and the persistence of point-in-time audits

ShareGate argued much of the problem is organizational visibility. The report found that two thirds (65%) of respondents learn about incidents only after the fact through quarterly audits or user complaints. Only a third (35%) rely on proactive monitoring and automated alerting, according to the survey.

ShareGate framed that timing gap as decisive. Where teams rely on point-in-time audits, the report said, “the gap between 'no news' and 'no problems' is exactly where the governance incidents live,” and adding multiple AI tools compounds the visibility problem.

Skills, priorities, and the controls respondents want

The surveys also measured priorities and perceived capability shortfalls. Lack of AI governance expertise (37%) ranked among the top three concerns reported, trailing only data quality/retention and security/access, ShareGate said. When asked what would help most with governance challenges, respondents put better controls for AI agents first (34%), followed by executive buy-in (20%) and automated remediation (18%). Extra budget was cited by just 3%.

What this means for IT teams, executives, and auditors

  • IT teams and security professionals: The report indicates many teams are detecting incidents through periodic audits or user complaints rather than continuous monitoring; the surveys show 65% learn about incidents after the fact and only 35% use proactive monitoring and automated alerting.
  • Executives and procurement leaders: Rapid Copilot adoption—full deployments rising from 29% to 56%—and the fact that 22% of organizations devote more than a fifth of IT budgets to AI suggests procurement and budget decisions are shifting even as respondents place low priority on extra budget for governance (3%).
  • Auditors and compliance teams: Thirty-five percent of respondents reported encountering an audit or compliance gap, and ShareGate identified point-in-time auditing practices as a root cause of late discovery; that pattern signals a need to reassess controls that rely on quarterly or ad hoc reviews.

ShareGate summarizes the policy implication in practical terms through Richard Harbridge's counsel: the fix is not simply a bigger team or greater diligence but "tooling and processes that surface and fix problems in week one instead of month three.” The survey data underpinning the report tie that prescription to concrete gaps—visibility shortfalls, AI governance skills deficits, and mismatches between where organizations are investing (AI deployments and budget shares) and where they say they need help (AI agent controls and automated remediation).

The report leaves a clear, testable challenge for organizations with Microsoft 365 estates: reconcile fast-moving AI adoption—Copilot deployments rising to 56% and multi-tool tenants in the field—with monitoring, access control, and AI governance practices that currently flag incidents only after they occur. Whether teams act on tooling and process changes at scale will determine if the next annual report reflects improvement or simply a higher rate of discovery.

Original story