ShareGate's State of M365 2026 puts the incident rate at 77%
The headline numbers are in ShareGate's release on PR Newswire. In the past year, 38% of organizations left former employees or guests with access they should have lost, 35% hit an audit or compliance gap, and 26% had sensitive content reach the wrong people. Altogether, 77% experienced at least one Microsoft 365 governance incident, as two-thirds now run two or more AI tools on that same content.
The categories overlap, so you can't add them up. The 77% counts organizations that reported at least one incident of any type. ShareGate also spells out what it counted. Governance incidents counted oversharing, stale access, audit gaps, and shadow IT/AI. A fifth category, users unable to find content, was reported by 41% of organizations but kept out of the headline figure, which would otherwise have been 82%. Leaving that category out makes the headline more conservative. A findability problem is a real cost, but it isn't a security exposure the way a departed contractor with live access is.
The tooling numbers are flat compared with 2025. Only 1% of respondents use purpose-built governance tooling, the same share as last year. 57% rely on Microsoft's built-in tools, 38% on manual or internal policies, and 4% have no governance at all. Detection is mostly after the fact: 65% say they find problems through quarterly audits or user complaints, and 35% use proactive monitoring and automated alerting.
The self-assessments point the other way. 63% of organizations describe their governance as "operationalized or better", and ShareGate says those answers come from the same respondent pool in which 77% reported an incident. The release doesn't publish the cross-tabulation, so we can't tell how many organizations reported an incident and rated themselves mature. Richard Harbridge, Principal Industry Advisor at ShareGate, sums up the gap as the space between "no news" and "no problems."
The release has been syndicated widely: Macau Business, The Manila Times, PR Newswire's UK and APAC feeds and others. Every copy is the same vendor text. No independent outlet has reported on or re-analysed the findings.
The State of M365 methodology turns out to be two separate surveys
The US and APAC versions of the release say the report combines two self-reported surveys, each conducted across nine countries: 943 IT professionals, ranging from managers to VPs, on Microsoft 365 migration, compliance, and governance, and 851 IT leaders on AI deployment, costs, and exposure. The UK edition's methodology note describes it differently. It says the findings come from two independent 2026 surveys: an IT operations survey conducted in May 2026 of 943 IT pros (US, CA, UK, DE, FR, JP, AU) covering migration, governance, compliance, security, and cost and an AI governance survey conducted in March 2026 of 851 IT leaders (US, UK, CA, FR, DE, NL, IE).
The UK wording is more specific, and it contradicts the "each across nine countries" line. By that account, each survey covered seven countries, and only together do they reach nine. Japan and Australia appear only in the operations survey. The Netherlands and Ireland appear only in the AI survey. So the migration and governance incident figures and the Copilot and AI-budget figures come from different people, surveyed two months apart, in partly different markets.
The AI survey also seems to have been published before. In April 2026 ShareGate released results from a survey that Centiment conducted on behalf of ShareGate in March 2026. It included 850 IT and security leaders in the United States, the United Kingdom, Canada, France, Germany, the Netherlands, and Ireland. The month and country list match the UK description of the 851-leader survey. The one-respondent difference between the two releases isn't explained. Some of that earlier data sharpens the picture. In April, twenty-nine percent of organizations said AI tools had already surfaced sensitive data they shouldn't have accessed. Yet, 93% of IT and security leaders said they were confident their Microsoft 365 governance framework could support AI responsibly.
Don't mix up the two 93% figures. In April, 93% was confidence in governance. In September, 93% is Copilot in production. Both are ShareGate numbers from what appears to be the same survey family, and neither is independent.
Copilot at 93% makes stale access easier to find
On the AI side, 93% of organizations report Microsoft 365 Copilot in production in some form, up from 82% in 2025. Full Copilot deployment roughly doubled, from 29% to 56%, and 28% of those tenants run three or more AI tools. The release doesn't say what separates "full deployment" from "in production in some form." Treat the 56% as ShareGate's own category, not a licensing tier.
The release says other AI tools are widespread alongside Copilot: ChatGPT Enterprise at 54%, Gemini at 36% and Claude for Work at 32%. 22% of organizations say AI now takes more than a fifth of their IT budget, rising to 32% among teams that have fully deployed Copilot. Asked what would help most, 34% named better controls for AI agents, ahead of executive buy-in (20%) and automated remediation (18%). Only 3% chose more budget.
ShareGate's argument is that content that was once overshared has now become a liability that an AI tool can retrieve on request. Microsoft's documentation supports the mechanism. Microsoft's guidance says Copilot surfaces organizational data the signed-in user already has permission to reach. Copilot doesn't grant new access. What changes is how easily people find what they can already open. A SharePoint site shared with "Everyone except external users" years ago, or a guest account nobody removed, sat there unnoticed before. Now a natural-language prompt can pull its contents into an answer.
That's why the 38% stale-access figure matters most for administrators. Deprovisioning failures predate AI. What Copilot adds is a fast way to query them.
Microsoft's Copilot controls cover most of the survey's incident types
Microsoft's "Copilot controls security and governance" page on Microsoft Learn (last updated September 9, 2026) lays out two tiers. Foundational controls come with SharePoint Advanced Management and Microsoft Purview under A3/E3/G3 licensing. Optimized controls sit in Microsoft Purview and Microsoft Defender for Cloud Apps under A5/E5/G5. Microsoft says what you can use depends on your licensing, so check your tenant's entitlements before planning around any single feature.
Most of the incident types in ShareGate's survey have a foundational-tier answer in that guidance:
| ShareGate incident type | Relevant Microsoft control (per Microsoft Learn) | Tier |
|---|---|---|
| Oversharing / sensitive content reaching wrong people | Data access governance reports for SharePoint sites, plus site access reviews sent to owners of overshared sites | Foundational |
| Oversharing during remediation | SharePoint Restricted Content Discovery or Restricted Access Control to limit user, Copilot and agent access to overshared sites | Foundational |
| Broad access | Removing organization-wide site access, manually or with PowerShell, and restricting sites to Microsoft 365 Groups or Entra security groups | Foundational |
| Stale or ownerless content | SharePoint site lifecycle management for inactive or ownerless sites; Purview Data Lifecycle Management to delete unneeded files | Foundational |
| Detection only after the fact | Purview Data Loss Prevention notifications when new oversharing occurs | Foundational |
| Audit and compliance gaps | Purview Audit for Copilot and AI applications; eDiscovery and legal holds covering Copilot prompts and responses | Foundational |
| AI processing sensitive files | Purview DLP for Microsoft Copilot and agents; Data Security Posture Management (DSPM) for AI risk assessments | Optimized |
| Risky user behaviour | Purview Insider Risk Management and Adaptive Protection | Optimized |
Two gaps in this mapping stand out. First, Microsoft's framework is scoped to Microsoft Copilot, Copilot Chat, Microsoft 365 prebuilt agents, and Copilot Studio agents published to Microsoft 365 channels. ChatGPT Enterprise, Gemini and Claude for Work aren't in that list. Our reading is that an organization running several AI tools needs separate governance for each third-party connector. The survey's finding that two-thirds run two or more AI tools suggests many tenants are in that position.
Second, the survey's biggest incident category is stale employee and guest access. That is fundamentally an identity lifecycle problem in Microsoft Entra ID, and the Copilot controls page approaches it mainly from the SharePoint-permissions side. The site-level controls help limit the damage. Fixing the root cause means dealing with joiner-mover-leaver processes and guest lifecycles.
The 65% who find problems only through quarterly audits or complaints could close part of that gap with tools they may already have. The DLP oversharing notifications and the data access governance reports are both in the foundational tier. The survey doesn't show how many respondents have these features licensed but switched off. So "57% use built-in Microsoft tools" could mean anything from light use to full deployment.
Compliance is now stalling Microsoft 365 migrations
The migration findings come from the larger operations survey and have gone largely unnoticed next to the AI numbers. 34% of organizations say compliance concerns made them delay or abandon a Microsoft 365 migration in the past 12 months, up from 20% in 2025. 87% say compliance moderately or significantly affects migration decisions, up from 82%.
Regret is almost universal. Only 7% would run their last migration the same way. The top changes they'd make are planning earlier (45%), buying tooling sooner (38%) and cleaning up the source environment first (36%). The last one ties back to the governance findings. If a migration copies overshared, ownerless or stale content into a new tenant as-is, the permissions problem moves with it and becomes searchable by Copilot on arrival.
Hybrid is still the norm. 68% run a mix of cloud and on-premises, while 28% are fully in the cloud, up from 22% last year. ShareGate says hybrid "means every control has to be applied twice". That's the vendor's framing, not a measured result or a literal technical rule. In practice, some controls cover both environments and some don't, depending on the product. What the survey does show is that most respondents still run two environments, so there are two places for governance to drift.
Keep in mind that ShareGate sells migration tooling, including a tenant-to-tenant Entra ID migration product it announced earlier. A finding that respondents wish they'd bought tooling sooner is one the sponsor has a clear interest in.
What this means for Microsoft 365 administrators
If your organization has Copilot in production, or is about to widen its rollout, audit access before you treat the deployment as finished. Don't wait for a complaint to reveal a problem. You don't need to accept ShareGate's 77% as an industry-wide rate to act on it. The failure modes it lists match Microsoft's own documentation, and most of the matching controls are in foundational licensing tiers many E3 tenants already have. If you've already done oversharing assessments, restricted org-wide sites and set up DLP alerting, the report mostly confirms your approach. If you rely on quarterly reviews, the survey says you're in the 65% majority, and that shouldn't reassure you.
- Treat the 77% incident rate as a self-reported finding from a vendor's survey. The governance and AI numbers come from two separate surveys run in March and May 2026 across partly different countries.
- Start by finding stale employee and guest access, the most common incident type in the survey at 38%. Copilot surfaces whatever those accounts can already reach.
- Run SharePoint data access governance reports and send site access reviews to owners of overshared sites. Use Restricted Content Discovery or Restricted Access Control to limit Copilot while you fix permissions.
- Check which Microsoft controls your licences include before planning. Microsoft splits them into foundational (A3/E3/G3) and optimized (A5/E5/G5) tiers, and features like DLP for Copilot and Insider Risk-based Adaptive Protection are in the higher tier.
- Govern ChatGPT Enterprise, Gemini, Claude for Work and similar tools separately, because Microsoft's Copilot controls framework covers only Microsoft's own Copilot and agent surfaces.
- Clean up the source environment before your next migration. 36% of respondents list it as a top regret, and content moved as-is keeps its permission problems.
The State of M365 report isn't independent research, and its most repeated numbers can't be checked against real tenant data. Its central point doesn't depend on ShareGate, though. Microsoft's documentation already establishes that Copilot works within existing permissions, and the survey shows most organizations still find permission problems after something has gone wrong. With Copilot close to universal among respondents and full deployment roughly doubling in a year, the practical effect is that permission debt teams used to put off now shows up in Copilot answers.