Most Organisations Are Losing Track of Who Can Access Their Microsoft 365 Data
A survey of nearly 1,800 IT professionals across nine countries has found that 77% of organisations experienced at least one Microsoft 365 governance incident in the past year. Common problems included former employees or guests keeping access they should have lost (38%), audit or compliance gaps (35%), and sensitive content reaching the wrong people (26%). The report, from governance specialist ShareGate, points to poor visibility, overconfidence in existing controls, and a lack of AI governance skills as the main causes.
The issue is being amplified by the rapid rollout of AI tools such as Microsoft Copilot, which has roughly doubled in full deployment over the past year, from 29% to 56% of organisations. Nearly a third of Copilot users run three or more AI tools at once. Despite this, 93% of respondents said they believe their governance framework is ready for AI, yet 29% admitted Copilot or another AI tool had already exposed sensitive internal data it should not have accessed.
Much of the problem comes down to how organisations monitor their systems. Two-thirds of respondents said they only learn about incidents after the fact, through quarterly audits or user complaints, rather than through proactive, real-time monitoring. IT professionals said better controls for AI agents would help most, ahead of executive buy-in or automated remediation.