www.infosecurity-magazine.com 11 Sept 2026, 09:30 UTC

Microsoft 365 AI Rollouts Outpace Permissions and Oversharing Reviews

CyberSIXT Evidence Panel Source marked as original reporting

A Syskit study, published as part of its State of Microsoft 365 Governance Report 2026 on 11 September 2026, finds AI deployment is accelerating even as the data foundations beneath it are not thoroughly checked. The survey, covering UK and US organisations, shows three-quarters (76%) have deployed or piloted an enterprise AI tool such as Copilot on Microsoft 365 data, yet only 43% of respondents reported having completed a thorough review of permissions and oversharing risk before deployment.

Moreover, 91% are confident they can see what AI agents are active and what those agents can reach, but only 22% have a formal policy defining what AI agents may access, and 9% allow an agent to inherit the full permissions of the person who deployed it.

Syskit’s chief executive, Toni Frankola, warns that AI agents remove friction that previously limited accidental access to sensitive files, with AI tools able to surface content based on existing permissions, including broadly shared material that has not been reviewed in years.

Separately, the report highlights persistent misconfigurations and permission failures across Microsoft 365. The risk is entrenched in the permission model, with 41% of organisations leaving SharePoint sites accessible to all staff, 35% still having former employees’ files accessible to active users, and 33% reporting files shared with “Everyone.” Almost half (47%) identify orphaned teams, groups and sites as a governance challenge, complicating review and security.

While 83% claim to know who can access sensitive data at any moment, only 4% could produce a complete access report for an external auditor within an hour, and 55% would need a day or longer. In the past two years, 90% have experienced or suspect a security incident linked to M365 misconfigurations or over-permissioned access, with 39% confirming one. The findings stem from Syskit’s survey of 327 IT and security decision-makers at UK and US organisations with 500+ employees.

View full article

Article by CyberSIXT