www.infosecurity-magazine.com 24 Sept 2026, 09:30 UTC

Microsoft 365 Governance Incidents Hit 77% as AI Risks Grow

Microsoft 365 Governance Incidents Hit 77% as AI Risks Grow
CyberSIXT Evidence Panel Source marked as original reporting

AN estimated 77% of organisations worldwide experienced at least one Microsoft 365 governance incident in the past year, according to ShareGate’s second annual *State of Microsoft 365* report. The findings are based on two surveys of nearly 1,800 IT professionals and leaders across nine countries. Among organisations reporting an incident, 38% said former employees or guests retained access they should have lost, 35% encountered an audit or compliance gap, and 26% had sensitive content shared with the wrong people.

The report links the problems to poor visibility, confidence in existing governance processes and shortages of AI governance expertise. Microsoft Copilot deployments roughly doubled over the past year, from 29% to 56% of organisations, while 28% of tenants use three or more AI tools. However, 65% of respondents said they discover incidents only after the fact through quarterly audits or user complaints; just 35% use proactive monitoring and automated alerts.

Although 93% believed their governance framework was ready for AI, 29% said Copilot or another AI tool had already exposed sensitive internal data it should not have accessed. Better controls for AI agents were the most requested improvement, cited by 34% of respondents, followed by executive backing at 20% and automated remediation at 18%. ShareGate executive Richard Harbridge said organisations need tools and processes that identify and correct problems earlier.

View full article

Article by CyberSIXT