Ptechhub
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs
No Result
View All Result
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs
No Result
View All Result
PtechHub
No Result
View All Result

Enterprises grapple with Microsoft 365 misconfigurations

By CIO Dive by By CIO Dive
September 14, 2026
Home Enterprise IT
Share on FacebookShare on Twitter


This audio is auto-generated. Please let us know if you have feedback.

Dive Brief:

  • The call is coming from inside the house for companies grappling with Microsoft 365 security incidents, according to new research from Microsoft 365 governance platform provider Syskit. Among over 300 IT and security and decision-makers, 90% experienced or suspect they experienced a security incident tied to misconfiguration or over-permissioned access in the past two years, and 39% have confirmed one.
  • As companies adopt AI tools like Microsoft Copilot, exposure to security risk is embedded in Microsoft 365’s permission model itself, according to Syskit. More than three-quarters of respondents have deployed or piloted an enterprise AI tool on Microsoft 365 data, but less than half completed a thorough review of permissions and oversharing risk first, per the report.
  • The most common governance problem for companies is ownerless content like orphaned teams, groups and sites that are rarely reviewed or deleted, but read by AI tools just the same, according to Syskit. 

Dive Insight:

Microsoft 365 is ubiquitous among enterprises, and its troves of data are a potential quagmire for AI. Access is granted over years of shared links, guest accounts and role changes, making it easy for AI assistants to surface information and create exposure. 

“Our partners see this firsthand because they manage governance across multiple Microsoft 365 tenants,” Syskit CEO Toni Frankola said in an email. “Organizations often believe their permissions are under control, only to discover access they didn’t know existed. That’s becoming more consequential as partners are increasingly asked to turn on AI and agents for their clients.”

Fewer than one-quarter of respondents said they have a formal policy defining what AI agents may access. Yet 91% reported confidence in which agents are active and what those agents can reach.

AI is driving security risks, but IT budgets aren’t shifting to meet them. Just 3% of leaders said preparing for AI would motivate more investment in Microsoft 365 governance tooling over the next 12 months.

Frankola told Channel Dive partners should have an understanding of permissions before deploying AI tools.

“That doesn’t mean waiting for perfect governance,” he said. “There is no such thing in a living, collaborative environment. It means understanding where sensitive information is exposed and where permissions have accumulated before AI makes those problems easier to exploit. A permissions and oversharing review can also improve the information available to AI and uncover unused licenses and storage, reducing costs in the process.”



Source link

By CIO Dive

By CIO Dive

Next Post

Updated Agent Sandbox Runtime and Upgrade Guidance Released for Self-Hosted AI Agent Platforms

Recommended.

Imposter scams cost older adults 0 million in 2024, FTC finds: Some victims are ‘clearing out’ their 401(k)s

Imposter scams cost older adults $700 million in 2024, FTC finds: Some victims are ‘clearing out’ their 401(k)s

August 8, 2025
Outdated IT Controls Expose Organizations to Risk and Compliance Failures, Warns Info-Tech Research Group in New Resource

Outdated IT Controls Expose Organizations to Risk and Compliance Failures, Warns Info-Tech Research Group in New Resource

August 13, 2025

Trending.

Goldman Sachs picks China stocks poised to benefit from a new wave of AI-related hardware exports

August 16, 2026
AWS, Google, Oracle, Microsoft Top Gartner’s Cloud AI Infrastructure List For 2026

AWS, Google, Oracle, Microsoft Top Gartner’s Cloud AI Infrastructure List For 2026

July 29, 2026
Cloud Market Share Q1 2026: AWS, Microsoft, Google Battling In AI Era

Cloud Market Share Q1 2026: AWS, Microsoft, Google Battling In AI Era

May 4, 2026
Anthropic lost control of Claude in latest AI cyber blunder | Computer Weekly

Anthropic lost control of Claude in latest AI cyber blunder | Computer Weekly

July 31, 2026
Apple Expands iOS 18.7.7 Update to More Devices to Block DarkSword Exploit

Apple Expands iOS 18.7.7 Update to More Devices to Block DarkSword Exploit

April 2, 2026

PTechHub

A tech news platform delivering fresh perspectives, critical insights, and in-depth reporting — beyond the buzz. We cover innovation, policy, and digital culture with clarity, independence, and a sharp editorial edge.

Follow Us

Industries

  • AI & ML
  • Cybersecurity
  • Enterprise IT
  • Finance
  • Telco

Navigation

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Subscribe to Our Newsletter

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Copyright © 2025 | Powered By Porpholio

No Result
View All Result
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs

Copyright © 2025 | Powered By Porpholio