Three in four organizations experienced Microsoft 365 governance

In the past year, 38% of organizations left former employees or guests with access they should have lost, 35% hit an audit or compliance gap, and 26% had sensitive content reach the wrong people. Altogether, 77% experienced at least one Microsoft 365 governance incident, as two-thirds now run two or more AI tools on that same content. Meanwhile, just 1% use a purpose-built governance tool. AI Adoption moved. Controls did not. The result is compliance and security exposure that most organizations can neither measure nor prove they control.

That is the central finding of the second annual State of M365 report, released today by ShareGate, the tool helping over 100,000 IT pros keep their enterprise content under control. Drawing on two surveys of nearly 1,800 IT professionals and leaders across nine countries, the report examines how organizations managed, secured, and migrated content in Microsoft 365 in 2026.

What makes those incidents more consequential than they were a year ago is what now reads across them. Full Copilot deployment roughly doubled, from 29% to 56%, and 28% of those tenants run three or more AI tools. Content that was once overshared has now become a liability that an AI tool can retrieve on request.

The report points to three factors behind the incident rate: fragmented visibility into their own environments, overconfidence in how well governed those environments are, and an AI governance skills gap that has not closed. On the first, nothing has changed: purpose-built governance tooling still sits at 1%, the same share as in 2025, while 57% use built-in Microsoft tools, 38% rely on manual/internal policies, and 4% have no governance at all.

The research also reveals that many organizations rely on periodic reviews to catch problems that everyday collaboration in a professional Microsoft 365 environment creates. 65% of teams learn about them only after the fact through quarterly audits or user complaints, while just 35% rely on proactive monitoring and automated alerting. Surprisingly, governance self-assessment runs in the opposite direction. 63% of organizations describe their governance as operationalized or better, drawn from the same 77% group who reported an incident, with just 1% using tooling built for the job.

Read Also: Brand Engagement Network Secures $1.05 Million Private Placement at a Premium to Market