A new Syskit study reveals that a significant majority of organizations deploy AI agents in Microsoft 365 environments without thorough permissions reviews, exposing them to security risks. Only 43% of organizations completed a comprehensive permission review before deployment.
Microsoft 365 Permissions Leave Organizations Exposed
The Syskit study highlights widespread misconfigurations and permission failures within Microsoft 365. It found that 41% of organizations have SharePoint sites accessible to all staff without restrictions, 35% maintain former employees' file access, and 33% share files with "Everyone." A major governance challenge is orphaned content lacking an owner (47%), which AI tools can access with full authority. Despite 83% of organizations claiming precise knowledge of data access, only 4% could provide a complete access report for an external auditor within an hour, with most requiring a day or more. Overall, 90% of organizations have either experienced or suspected a security incident related to misconfiguration or excessive permissions in the last two years, with 39% confirming such incidents.