Dive Brief:
- The call is coming from inside the house for companies grappling with Microsoft 365 security incidents, according to new research from Microsoft 365 governance platform provider Syskit. Among over 300 IT and security and decision-makers, 90% experienced or suspect they experienced a security incident tied to misconfiguration or over-permissioned access in the past two years, and 39% have confirmed one.
- As companies adopt AI tools like Microsoft Copilot, exposure to security risk is embedded in Microsoft 365’s permission model itself, according to Syskit. More than three-quarters of respondents have deployed or piloted an enterprise AI tool on Microsoft 365 data, but less than half completed a thorough review of permissions and oversharing risk first, per the report.
- “Our partners see this firsthand because they manage governance across multiple Microsoft 365 tenants,” Syskit CEO Toni Frankola said in an email. “Organizations often believe their permissions are under control, only to discover access they didn't know existed. That's becoming more consequential as partners are increasingly asked to turn on AI and agents for their clients.”
Dive Insight:
Microsoft 365 is ubiquitous among enterprises, and its troves of data are a potential quagmire for AI. Access is granted over years of shared links, guest accounts and role changes, making it easy for AI assistants to surface information and create exposure.
The most common governance problem for companies is ownerless content like orphaned teams, groups and sites that are rarely reviewed or deleted, but read by AI tools just the same, according to Syskit.
Fewer than one-quarter of respondents said they have a formal policy defining what AI agents may access. Yet 91% reported confidence in which agents are active and what those agents can reach.
AI is driving security risks, but IT budgets aren’t shifting to meet them. Just 3% of leaders said preparing for AI would motivate more investment in Microsoft 365 governance tooling over the next 12 months.
Frankola told Channel Dive partners should have an understanding of permissions before deploying AI tools.
“That doesn't mean waiting for perfect governance,” he said. “There is no such thing in a living, collaborative environment. It means understanding where sensitive information is exposed and where permissions have accumulated before AI makes those problems easier to exploit. A permissions and oversharing review can also improve the information available to AI and uncover unused licenses and storage, reducing costs in the process.”