Governance is becoming the headline request
Among survey respondents, AI and Copilot governance was the client request most often ranked as the fastest-growing, at 40%. Security and compliance followed at 24%. That result does not establish a market-wide rate of demand growth: the survey does not disclose a sampling frame, geography, recruitment method, response rate, weighting, or questionnaire. It does, however, indicate where this group of MSP employees believes customer conversations are heading.
The distinction between using AI and governing it matters. A request for governance is not simply a request to switch on a feature. It implies questions about which users should receive access, what business content they can already reach, how sharing is controlled, and who is accountable when results surface information that was technically accessible but not meant to be easily found.
That concern appears throughout the responses. Data security and oversharing was the leading barrier to offering AI services, cited by 35%. When respondents were asked about concerns as AI spreads, oversharing led at 41%. Other reported concerns were adoption before governance (14%), compliance exposure (13%), incorrect permissions (11%), shadow AI (11%), and insufficient staff expertise (10%).
For customers, this shifts the practical question away from “Which AI tool should we deploy?” toward “What does a signed-in employee already have access to?” That is a more difficult question, particularly in tenants where years of ad hoc sharing, guest invitations, departmental exceptions, and hurried offboarding have accumulated.
Copilot does not bypass permissions—but existing access still matters
There is an essential technical qualification to the oversharing narrative. Microsoft states that Copilot works within the signed-in user’s existing permissions. It does not receive blanket tenant-wide visibility and cannot access data the user is not permitted to access.
That means it would be inaccurate to say Copilot itself overrides Microsoft 365 access controls. The risk described by the survey is better understood as an amplification of pre-existing conditions. If a user can already access a broadly shared document, folder, or site, AI-assisted discovery may make that material more visible or easier to locate. In that scenario, the underlying problem is the sharing or permission model, not a new bypass of that model.
Microsoft’s readiness guidance aligns with this interpretation: reduce accidental oversharing through SharePoint sharing settings, identify potentially overshared sites, and govern access before enablement. The implication for administrators is straightforward: AI readiness is inseparable from identity, sharing, and content-governance readiness.
This is also why an organisation should resist a false choice between moving quickly and doing nothing. Permission remediation need not mean indefinitely postponing AI. It means establishing a controlled rollout in which the first deployment groups, the content they can reach, and the way exceptions are handled are understood before use is widened.
The survey’s readiness numbers point to a broad confidence gap
Only 10% of respondents said that more than three-quarters of their managed client tenants were Copilot-ready. Just 3% said all their tenants were ready. Those figures sound stark, but they should not be treated as a precise industry readiness rate. The survey does not define “Copilot-ready,” so one respondent may have applied a rigorous governance standard while another may have used a narrower technical definition.
Still, the accompanying Microsoft 365 administration responses help explain why confidence could be low. Seventy-seven percent said they were not fully sure that every tenant met its security baseline. Respondents identified stale offboarding accounts as a challenge in 53% of cases, over-permissioned users or guest access in 48%, and configuration drift in 40%.
Each issue has a concrete consequence:
- Stale accounts can leave access associated with people who should no longer have it.
- Excessive user or guest permissions can make sensitive content available beyond its intended audience.
- Configuration drift can produce different security and sharing outcomes across tenants that are supposed to follow the same standard.
For an MSP, these are multiplied by the number of organisations it manages. A control that is consistently applied in one tenant may be absent or differently configured in another. The survey found that 43% of respondents managed more than 50 tenants, while 41% managed more than 1,000 licensed seats. At that scale, even a sound baseline is less useful if it is difficult to apply, verify, and maintain repeatedly.
The survey also reported that 58% applied a new tenant baseline manually or with custom scripts. Manual work and scripting are not inherently poor practices; they can be appropriate for customer-specific needs. But they can make consistency harder to demonstrate where each tenant has a different history, exceptions are poorly documented, or platform changes require repeated adjustment.
Reported exposures require caution, not dismissal
Nearly half of respondents, 47%, said they had experienced an AI- or Copilot-related data exposure or near miss during the prior 12 months. Among service delivery managers, that rose to 56%.
These figures should be read carefully. The report does not define exposure, near miss, or incident, and it does not establish whether the events involved Microsoft 365 Copilot, other Copilot products, other AI tools, or a mix. There are no incident records, severity levels, or independent verification. It therefore cannot show how often a particular product caused a particular type of data event.
But the numbers should not be dismissed merely because they are self-reported. They are a useful warning that teams responsible for client environments perceive AI-related handling of data as an operational risk today. A near miss can reveal the same weaknesses as a confirmed incident: unclear ownership, broad sharing, poor offboarding, uncertain data locations, or an absence of a clear escalation process.
The same group reported that 53% had encountered a non-AI security incident or near miss. That context matters. AI governance may be an emerging priority, but it is being added to an already demanding security workload rather than replacing traditional identity, configuration, and access-control work.
Operational friction is part of the security story
Security readiness is often discussed as a policy or permissions problem. The survey suggests that operating friction may be just as important. Onboarding and offboarding were the largest reported source of repetitive work, identified by 33% of respondents. Forty-one percent said at least one technician lost three or more hours each week switching between tenants and portals.
Such findings do not prove that portal switching causes insecure environments. Yet the relationship is plausible: work that is repetitive, fragmented, and time-constrained is harder to complete consistently. When technicians spend significant time moving among separate management surfaces, the temptation is to address the immediate request and defer the review that verifies whether old access was removed, a guest relationship still makes sense, or a baseline exception remains justified.
Only 17% described their operations as mostly proactive. Forty-two percent said they used automated client security reporting. These figures suggest a practical maturity gap: teams need not only controls, but a way to see and communicate whether controls continue to operate as intended across each tenant.
Respondents also reported that Microsoft changes had created unplanned work or broken something in 63% of cases. This is another result that needs restraint. The survey provides no product-level change records, causation analysis, severity information, or corroborating evidence, so it cannot establish that Microsoft changes were responsible for specific breakages. Nevertheless, it reflects an operating reality familiar to many administrators: a tenant standard is not a one-time project. It needs review as platforms, settings, and customer requirements evolve.
AI may ease workload, but only after the foundations are in place
The survey is not uniformly pessimistic about Copilot. More respondents said it had reduced workload than said it had increased workload, by 43% to 24%. That is an important counterweight to the readiness concerns. It indicates that MSP professionals can see operational value in AI, rather than viewing governance as a reason to avoid it.
The most sensible reading is not that AI is either a productivity breakthrough or a security liability. It can be both a useful capability and a stress test for existing controls. Organisations with clear access models, controlled sharing, dependable offboarding, and known tenant baselines may be better placed to capture the time-saving side. Organisations that cannot confidently answer who has access to what may first uncover old weaknesses when they assess AI readiness.
For Windows users inside customer organisations, the practical effect may be more deliberate access decisions. A user who is asked to justify guest access, move sensitive content into an appropriately controlled location, or accept a narrower pilot group may see friction. But that friction is preferable to learning after a rollout that a broad sharing link exposed more material than intended.
A practical readiness sequence for MSPs and customers
The evidence does not support a claim that every tenant is unready, nor that every AI deployment will lead to exposure. It does support a more disciplined order of operations.
First, define what readiness means for the organisation. Because the survey did not provide a definition, MSPs and customers should make theirs explicit: identity lifecycle controls, a documented security baseline, an approach to guest access, a process for handling overshared content, and clear ownership for governance decisions.
Second, review access before expanding access to AI-assisted discovery. Focus on stale accounts, departed staff, external guests, broad sharing practices, and permissions that have grown beyond a user’s current role. Microsoft specifically advises administrators to reduce accidental oversharing and identify potentially overshared content.
Third, make the baseline repeatable and verifiable. A manually applied baseline or custom script may be necessary in some environments, but it should be possible to check whether the intended configuration remains in place. Otherwise, differences between tenants can remain hidden until a customer request or security event exposes them.
Fourth, use reporting to turn governance into an ongoing service rather than a one-off clean-up. The survey’s low level of automated client security reporting suggests room for providers to make baseline status, remediation work, and unresolved exceptions visible to customers.
Finally, distinguish a controlled rollout from an all-or-nothing decision. A limited deployment can reveal where permissions and sharing practices need attention without assuming that every worker or every repository must be included immediately.
Demand is a signal; readiness must be demonstrated
Augmentt’s survey paints a credible picture of MSP professionals facing two pressures at once: clients want help governing AI, while providers are still wrestling with the consistency of Microsoft 365 security operations across many tenants. The data cannot prove that this pattern represents every MSP, and its undefined readiness and incident terms prevent overly precise conclusions.
Its core lesson is nevertheless durable. Copilot does not circumvent the permissions model, but it makes the quality of that model more consequential. For MSPs, the commercial opportunity may be governance services that turn uncertain, manually maintained tenant estates into environments where access, sharing, and baseline posture can be checked with confidence. For customers, the right question is not whether AI demand is real. It is whether their existing Microsoft 365 access decisions are ready to withstand more capable ways of finding information.