Governance Incidents Rose at 77% of Microsoft 365 Tenants
Managers must evaluate if reliance on native tools is failing to secure sensitive data as AI adoption scales.
Updated on Sept. 23, 2026 in Remote Work

Live Poll
Do you trust that most organizations prioritize your data security over their own technical speed?
Seventy-seven percent of organizations experienced a Microsoft 365 governance incident over the past year, according to ShareGate's second annual report. The data highlights a widespread disconnect between rapid AI deployment and the security controls needed to protect sensitive enterprise environments.
Why it matters
Security gaps are increasingly tied to fragmented visibility and a lack of specialized governance skills as organizations rush to integrate tools like Copilot. These incidents create significant operational risk, with 34% of companies delaying necessary migrations to avoid further compliance failures.
While 77% of organizations reported at least one governance incident, only 1% utilize purpose-built governance tools, leaving most to rely on manual policies. Meanwhile, 93% of organizations now have Copilot in production, with full deployment reaching 56% of tenants.
The players
ShareGate
A Montreal-based software provider specializing in management and migration tools for the Microsoft 365 ecosystem.
The details
Governance issues frequently manifest as unauthorized access for former employees or guests, reported by 38% of firms, and sensitive data exposure, cited by 26%. Most organizations, or 65%, remain reactive, identifying these failures only during quarterly audits or through user complaints. With 68% of firms operating complex hybrid environments, reliance on native tools without automated oversight is proving insufficient to manage the current risk profile.
Timeline
September 23, 2026: ShareGate released the second annual State of M365 report.
2025: Only 1% of organizations used purpose-built governance tools.
2026: Organizations managed, secured, and migrated content in Microsoft 365.
Market Landscape
This development follows a trend where rapid AI adoption consistently outpaces the development of necessary internal governance skills. The reliance on manual processes continues to fall short as organizations struggle to secure complex hybrid environments.
Operators should immediately audit their current offboarding procedures to prevent unauthorized access by former staff or guests. Given that most issues are only found through manual complaints, internal teams should pivot to proactive automated monitoring rather than relying on quarterly reviews.
The takeaway
The high incidence of data exposure suggests that native M365 tools may be insufficient for high-security environments. Businesses should prioritize implementing purpose-built governance software before scaling Copilot features further to mitigate compliance risk.
Further reading
For more on managing digital infrastructure and distributed teams, see the latest analysis in Remote Work.
Live Poll
Do you trust that most organizations prioritize your data security over their own technical speed?







