ShareGate Released Second Annual State of M365 Report

The study reveals that 77% of organizations faced at least one Microsoft 365 governance incident over the past year.

Updated on Sept. 23, 2026 in Remote Work

Isometric editorial illustration of a modular steel grid structure with a central gap, representing corporate governance and security vulnerabilities.
A new report from ShareGate indicates that 77% of organizations experienced at least one Microsoft 365 governance incident over the past year. AI Illustration. Upload story photo >

Live Poll

Do you trust that most organizations prioritize your data security over their own technical speed?

ShareGate has published its second annual State of M365 report, highlighting widespread security and compliance vulnerabilities within digital workspaces. The findings suggest that rapid AI adoption is currently outpacing the development of necessary governance skills.

Why it matters

Governance incidents often stem from fragmented visibility and a persistent AI skills gap, which leave many organizations vulnerable to unauthorized access and audit failures. As companies rush to integrate new tools, the lack of dedicated governance frameworks has created significant operational risks.

While 93% of organizations now have Copilot in production, only 1% employ purpose-built governance tools to manage their environments. Meanwhile, 38% of entities reported leaving unauthorized users with access to their systems.

The players

ShareGate

A Montreal-based technology firm that provides management and migration tools for IT professionals.

The details

Organizations are largely identifying security incidents through reactive quarterly audits or user complaints rather than proactive monitoring. This issue is compounded by the fact that 68% of companies manage complex hybrid environments, with 34% of firms even delaying migrations due to compliance fears.

Timeline

  1. September 23, 2026: ShareGate released the second annual State of M365 report.

  2. 2025: Only one percent of organizations used purpose-built governance tools.

Market Landscape

The report highlights a critical misalignment between rapid AI feature deployment and the maturity of corporate governance frameworks. As tech rivals prioritize speed-to-market for AI assistants, the widening gap in security oversight suggests an urgent shift toward specialized management software.

IT professionals and business leaders should anticipate increased scrutiny during quarterly audits as companies tighten security to prevent unauthorized access. Shoppers and subscribers of software services may eventually face higher costs if firms begin mandating purpose-built governance tools to mitigate compliance risks.

The takeaway

Organizations should prioritize proactive governance tools to keep pace with rapid AI implementation and avoid future compliance failures. Relying on manual oversight or reactive audits is increasingly insufficient in modern hybrid cloud environments.

Further reading

For additional context on organizational structure and digital management, visit Remote Work.

Live Poll

Do you trust that most organizations prioritize your data security over their own technical speed?