Every chapter, every chart, and the full methodology in one file. One email address.
Loading form…
05
How compliance shapes Microsoft 365 decisions in 2026
34% delay or avoid migrations over compliance risk, up from 20% just one year ago.
name access control policies as a top compliance challenge
of on-premises teams need proof Microsoft 365 meets their regulatory requirements before they'd move
say digital sovereignty is influencing their AI governance decisions
The share of teams who let compliance shape a migration decision barely moved, from 82% to 87%. Underneath it the share who delay or avoid outright went from 20% to 34%, and the validate-first middle gave up the difference. Confidence in the platform stayed flat across the same period, so this isn't teams losing faith in Microsoft 365. It's teams finding it harder to prove their own use of it.
Some of what gets called a compliance blocker is a requirement that will never move. Some of it is the weeks it takes to put an answer together by hand. They look the same on a roadmap and they don't respond to the same fixes. Most of this chapter is about the second group, because that's the one you can do something about.
Compliance in Microsoft 365 has meant knowing where data lives for most of the last decade. Digital sovereignty turns that into a question about what can reach into the data, which is why it now shows up in AI governance decisions rather than hosting ones. A Copilot business case increasingly has to answer where the processing happens as well as what it costs CH2The AI reckoning→.
Every stat is tagged with the study it came from: the AI governance survey (n=851) or the IT operations survey (n=943). Full methodology →
This is Chapter 5 of The State of Microsoft 365, a report on how organizations run, secure, and migrate in 2026. Learn more →
Compliance is the chapter everyone expects to be about restriction. It isn't. It's about evidence.
Teams are focused on whether they can show, on demand, that they're meeting their obligations. And on what happens to a project if they can't.
This chapter is about what that looks like in practice: the specific things IT pros name when asked what's holding up a decision right now, where data has to sit, who signs off before anything moves, and what teams still running on-premises say they'd need before they'd move.
Before a migration, someone has to establish that the destination satisfies the requirements, that the move itself won't create exposure, and that both can be evidenced afterwards. We asked IT pros how heavily that weighs on their migration decisions, and the change from last year was toward more caution.
How do compliance concerns impact your migration decisions?
A third stop or defer work outright. Another 53% validate first, which is what the 87% is made of.
IT operations surveyAgainst last year the combined figure moved modestly, from 82% to 87%. The composition underneath it shifted much harder.
How do compliance concerns impact your migration decisions?
The overall figure moved five points. The group that stops work outright moved fourteen.
IT operations survey · 2026 n=943 · 2025 n=650Four countries moving the same way points to something shared rather than local, and the composition is where it shows: the band that stops work outright took everything the validate-first middle gave up.
Compliance teams are under real pressure from the board now. It may not be perfect, but they're trying to make visible progress against risk, and that pressure is new.”

Newness is the operative part, because the platform assessment underneath it didn't move.
Asked directly, teams don't hedge.
How confident are you in Microsoft 365's ability to meet your organization's compliance needs?
96% are confident, only 3% are not. Yet 87% say compliance still shapes their migration decisions: caution without doubt.
IT operations survey‘Very confident’ M365 meets compliance needs
A verdict on Microsoft's platform rather than on their own tenant, and it barely moved.
A year ago it was 60% very confident. So across the same period that produced a 14-point rise in teams blocking migrations, the platform assessment underneath it barely moved.
Those two facts are the chapter. Near-total confidence in what the platform can do, sitting beside compliance as one of the largest brakes on actually using it. Teams aren't losing faith in Microsoft 365. They're finding it harder to prove their own use of it, and confidence in Microsoft's capability is not the same thing as confidence in your own ability to demonstrate it CH 1Confidence ≠ control→. The platform being compliant, and you being able to show that your configuration of it is compliant, are two different problems, and only one of them is Microsoft's to solve.
The moderate band is the one to notice. Requiring strict validation before migrating isn't resistance, it's a process requirement, and at 53% it's still the majority position. Validation is real and it's widespread. What varies is whether it's scheduled or discovered.
Compliance stops or defers migrations for half of IT teams in Japan and a fifth in Canada. The 34% average sits between two quite different pictures.
How do compliance concerns impact your migration decisions?
Japan 49%, Canada 20%. The widest gap between two industries is barely more than half that.
IT operations surveyWhat the spread does establish is that the national picture matters. Two teams with comparable estates and comparable tooling can be working under materially different constraints. Japan is also the market least confident in the Microsoft platform itself, at 44% very confident against 57% for the study average, and it's the one place where the two measures move together.
In some jurisdictions an unauthorised disclosure of a single document containing a passport number is enough to trigger a reportable breach. That's why organizations have started asking where their data actually sits.”

Industry varies too, but less.
How do compliance concerns impact your migration decisions?
Retail 41% down to Manufacturing 23%. Where a team operates matters more than what business it's in.
IT operations surveyThe obligations behind the word "compliance" aren't interchangeable. Some describe a state the tenant has to be in. Others describe a process the team has to go through. They don't respond to the same fixes, and they don't cost the same amount of time.
What are the biggest compliance challenges impacting your IT decisions right now? (choose up to three)
Three of the top four aren't about where data can live. They're about whether you can show what happened to it.
IT operations surveyIT pros selected 2.5 challenges on average, so these stack rather than substitute. The three the chart groups are access control, auditing and reporting, and approval processes. That's an evidence problem, and evidence problems respond to tooling rather than to intent.
Access control leading is consistent with what the same survey found elsewhere. Chapter 3 reported stale access as the most common governance incident of the year at 38%, with oversharing at 26% CH 3Governance→. The access surface producing those incidents is the same one compliance policy gets written against. The likeliest reading is that the compliance requirement and the governance backlog are the same work arriving under two different names.
Ranked by distance rather than by lowest score, so the weakness everyone shares doesn't crowd out the one that's actually yours.
The industry breakdown holds one result worth pausing on.
| Industry | n | Data residency | Access control | Regulatory delay | Auditing needs |
|---|---|---|---|---|---|
| Technology / Software | 190 | 56% | 53% | 43% | 33% |
| Healthcare & Life Sciences | 101 | 50% | 50% | 38% | 36% |
| Retail / E-commerce | 109 | 46% | 60% | 38% | 34% |
| Manufacturing | 164 | 38% | 57% | 43% | 36% |
| Financial Services / Insurance | 138 | 36% | 57% | 46% | 41% |
| Sample average | 943 | 44% | 56% | 41% | 37% |
Technology and software organizations report the highest data residency concern in the study, at 56%, twenty points above Financial Services. That's the opposite of the intuitive ranking, and the likely explanation is the sovereignty pressure covered later in this chapter: technology companies are disproportionately multinational, disproportionately European in this sample, and disproportionately the ones being asked where their customers' data physically sits.
Of the five sectors with bases above 100, Financial Services leads on the two evidentiary measures, auditing needs and regulatory delay, which is closer to what you'd expect. Across all ten sectors those two are led by Energy and by Education, both on bases too small to rank.
Regulatory approval processes are named by 41% of IT pros, and they're the clearest dividing line in the study between teams who delay migrations and teams who don't.
What are the biggest compliance challenges impacting your IT decisions right now? (choose up to three)
Access control is the most-named challenge in the study, and it barely tells these two groups apart: 53% against 57%.
IT operations surveyApproval processes split the two groups by nine points, the widest gap in the list. Certifications come next at seven. The M&A row is the same size and points the other way, which is the one worth stopping on.
Labelling is identical at 25% either way. Access control barely moves, and what movement there is runs backwards: 53% of the teams that stall name it, against 57% of the teams that don't. The most-named compliance challenge in the study is not what separates them. The queue is.
Teams whose compliance challenge is managing multiple tenants during a merger are less likely to delay, at 9% against 17%. The survey doesn't test why, but it could be that deal-driven migrations arrive with a contractual deadline, and a deadline someone else set doesn't leave room to wait.
The approval cost doesn't show up where you'd look for it. Teams naming approval processes don't report longer projects. If anything they report slightly shorter ones: 19% finished inside three months against 13% of everyone else, and the share running past a year is identical at about 10%. That looks backwards until you notice who the question reaches. It only asks teams who ran a project. A migration still sitting in an approval queue has no timeline to report, so the teams that got through the queue are the only ones the question can see.
Two numbers, from opposite ends of the same problem.
Teams that took an audit finding last year name reporting 43% of the time, against 33% of teams that didn't.
IT operations surveyThose two numbers describe the same problem from opposite ends. A meaningful share of teams are being asked to produce audit-grade evidence about permissions, retention, and access history, using tooling that was designed to administer a tenant rather than to report on it CH 3Governance→.
The usual result is a manual export, a spreadsheet, and a week nobody planned for. When an auditor asks who had access to this site in March, the honest answer for most environments is that it would take some work to find out.
Having been caught moves the number. Chapter 3 reported that 35% of organizations had an audit or compliance gap in the past 12 months. Among those teams, 43% name auditing and reporting tools as a compliance challenge, against 33% of teams with no finding. The teams who have been through a finding are the likeliest to name the reporting gap.
Given a single choice about what would most improve their governance and security, 25% of teams who delay or avoid migrations choose executive buy-in to prioritize governance, against 17% of everyone else. Only 1% of them ask for more budget, so this isn't a money problem. It's about getting leadership to prioritize governance work at all, even though it isn't glamorous and doesn't have a concrete deadline like other projects. Chapter 4 found the mirror image on migrations: prioritization came last among the reasons a legacy migration hadn't finished CH 4The estate→. Governance work stalls for want of a mandate. Migration work has the mandate and stalls anyway.
Sensitivity labelling and data classification (25%) looks like a middling concern until you read it alongside chapter 1 CH 1Confidence ≠ control→. Labels are one of the primary levers for controlling what AI can surface, because they're how the platform knows which content deserves the strictest defaults. A quarter of teams naming labelling as a compliance challenge is, in practice, a quarter of teams telling you their AI exposure controls rest on an incomplete foundation.
Managing compliance across multiple tenants during M&A is the smallest entry on the list at 14% across the sample, and one of the hardest problems on it. Chapter 6 finds that 23% of organizations say their most significant migration was an M&A move CH 6Migration→. During those integrations, two tenants run in parallel with different policies, different labels, and different retention rules, while the compliance obligation applies to both as one organization. The teams who named it are not overreacting.
Not every organization keeps its data where Microsoft 365 can reach it. File shares, on-premises SharePoint and local servers still hold a meaningful share of the corporate record, and the teams running them carry the same obligations as everyone else.
Chapter 4 covers how large that footprint is and how much of it is deliberate CH 4The estate→. The question here is narrower: for teams still holding data on-premises, what would have to be true before they'd be confident moving it. Their answers are the most direct statement in the study of what compliance assurance actually has to look like.
If your organization stores data on-prem, what would need to be true for you to feel confident moving it to the cloud? (choose up to two)
The two ways of having somebody else vouch for it come last, at 12% and 8%. Nobody's waiting to be told it's fine.
IT operations survey · the 675 who still store some data on-premises⚠ SMALL SAMPLE (n=) — READ AS DIRECTIONAL
Every leading answer is an artefact. Proof. Key control. A validated pilot. Residency guarantees. Nobody is asking to be reassured, and the two options that amount to someone else vouching for it, an auditor endorsement and a third-party assessment, come last by a wide margin.
Two of those conditions are less about where data sits than about who can read it. 45% want to hold their own encryption keys. Residency guarantees sit fourth overall at 34%, but that average hides two different worlds: Japan at 49%, Australia at 42%, Germany at 41% and France at 39%, against the US and Canada at 28% and the UK at 23%. The markets that want a residency guarantee are the ones about to ask the same question of their AI, which is where this chapter goes next. Japan's cut stands on 71 respondents and France's on 59, so read both as directional.
The alternative to delaying your migration is moving without the artefacts. And finding out afterwards that you missed something.
I would far rather carry the delay than finish a migration and discover I lost the crown jewels. I have seen that happen.”

Every condition on this list is a way of making sure that doesn't happen. Which is unusually good news, because artefacts can be produced on a schedule. A validated pilot migration is a project with a start date. A control-mapping document against your specific regulatory obligations is a deliverable. Customer-managed keys are an architectural, licensing, and operating decision. None of this requires the regulator to change position or the platform to add a feature.
A validated pilot with the compliance team in the room from day one does more to unblock a roadmap than another year of vendor assurances, because at the end of it you own an artefact instead of an opinion. And you can reuse that artefact on the next twelve workloads.”

As we mentioned in chapter 4, we were surprised to find that 72% of organizations still have data on-premises CH 4The estate→. We thought compliance might be the explanation. The data doesn't support that, and the way it fails is more interesting than the assumption.
How do compliance concerns impact your migration decisions?
43% of the teams that already finished still delay or avoid a move over compliance. That's the highest of any group.
IT operations surveySo compliance isn't the main reason organizations are keeping data on-premises. Chapter 4 asked the 180 organizations still carrying SharePoint 2016 or 2019 why they hadn't finished, and compliance came fourth at 13%, behind migration complexity at 37% and a lack of internal resources at 26% CH 4The estate→.
Read the other way round, the same crosstab is starker still.
| Compliance impact on migration | n | Fully in the cloud |
|---|---|---|
| Significantly delays or prevents moves | 320 | 36% |
| Moderately — we validate before moving | 503 | 24% |
| Slightly — a consideration, not a barrier | 91 | 24% |
| Not at all | 29 | 38% |
| Sample average | 943 | 28% |
Gating and cloud completeness move together at the top of that table. The 29 teams who say compliance doesn't affect them at all are too few to read, which is why that row is marked.
The likeliest explanation is volume. Fully-migrated organizations are the most migration-active group in the study, reporting 2.6 migration types completed, underway or planned in the past 24 months against a sample average of 2.4, and only 2% report none at all. Among organizations with all their data on-premises, a third ran no migrations in the period. More migration work means more occasions for compliance to stop one.
Volume doesn't account for all of it. Teams with a small on-premises remainder report almost as much activity, at 2.5 types, and gate 11 points lower. But it reframes what the top row means.
Reaching the cloud doesn't end the migration programme. Chapter 6 makes the case that migration is a standing capability rather than a project CH 6Migration→, and the compliance validation travels with it. Compliance doesn't stop movement. It adds a stage to it, and that stage is producing the evidence, for an auditor, a regulator, or a board.
Residency asks where data is stored. Sovereignty asks the broader question: whose jurisdiction does it sit under, and who ultimately controls the systems it passes through? What's changed this year is how far sovereignty reaches, because it's now shaping decisions about AI, not just storage.
To what degree is digital sovereignty influencing your AI governance decisions?
For a third it's a major influence, not just a consideration. Only 4% say it has none.
AI governance surveySovereignty requirements are written by national governments and regional blocs. If the pressure followed the policy, it would concentrate where the policy is written. It doesn't.
On the pressure, every market lands between 72% and 84%. On whether Microsoft has it covered, they run from 25% to 59%.
AI governance surveyIn highly regulated organizations I see people digging in hard on where their data sits. The political climate is part of it. But it varies enormously from one company to the next, far more than you would expect.”

So the useful question isn't which jurisdiction you're in. It's how hard your own compliance function is pushing.
You get a percentile instead of an impression, and your gaps ranked by how far behind the field they actually are.
Asked how much they prioritize EU-based or French-developed platforms over US platforms such as Microsoft 365, a majority of IT leaders said they lean European.
How much do you prioritize EU-based or French-developed platforms over US platforms such as Microsoft 365?
A majority lean toward EU-based platforms.
AI governance surveyTo what extent has your organization been affected by French government directives encouraging EU-based technology platforms?
46% are moderately or significantly affected; 27% not at all. The regional cut is the story here, not the total.
AI governance survey · the whole sample, across seven countries59% lean toward EU-based or French-developed platforms, 31% toward US platforms, and 10% are neutral. Read that as a stated preference rather than a procurement plan: chapter 1 found Copilot deployed or being deployed in 93% of these organizations CH 1Confidence ≠ control→. Preference and installed base are pointing in different directions.
Unlike the sovereignty requirement, the platform preference does follow the map. European countries prefer EU-based platforms most, followed by the UK, the US, and Canada, with a 42-point spread between France at 82% and Canada at 40%. Ireland and the Netherlands sit inside that European cluster on 54 and 56 respondents, so treat both as directional.
Half of US-based IT leaders leaning toward EU platforms is the part worth pausing on, and the policy question underneath it points the same way. 46% report being significantly or moderately affected by French government directives encouraging EU-based technology platforms, and that includes plenty of respondents nowhere near France. Only 27% report no effect.
Part of that is the sample: this study is weighted toward European markets and technology-sector organizations, so read these figures as that audience rather than as a global average. But the question also asks about the organization rather than the individual, and the likeliest reading is that multinationals with European subsidiaries or European customers are answering for the whole entity. The rest of their answers support it. US respondents reporting significant impact favour EU platforms at 83%, against 44% of other US respondents, and 95% say sovereignty is influencing their AI governance, against 81%. Whatever they're describing, they describe it consistently. That group is 41 respondents, so it's directional, but it's internally coherent.
Ask whether Microsoft has it covered, and the doubt disappears again.
How confident are you that Microsoft 365 will continue to meet your data sovereignty and regulatory requirements over the next two years?
90% are confident and only 8% have any doubt, while four in five say sovereignty is reshaping their AI decisions.
AI governance surveyEighty percent say sovereignty is shaping their AI decisions. Fifty-nine percent lean European. Ninety percent still trust Microsoft 365 to meet their sovereignty needs. Those three numbers are not contradictory, but they describe an unstable position: teams are hedging toward EU platforms while expecting the incumbent to remain adequate. Something eventually resolves that tension, and it will probably be resolved by procurement rather than by IT.
The country split is the figure above. 34 points separate the UK at 59% very confident from the Netherlands at 25%, and the Netherlands anchors that low end on 56 respondents, so the width of the spread is directional even though its shape isn't.
Doubt is the sharper measure, because it doesn't depend on anyone reaching for a top box. 17% of French respondents say they're uncertain or not confident, along with 16% in the Netherlands and 11% in both Germany and Ireland. In the UK and the US it's 4% each. Canada belongs to neither group: just 5% express doubt, but only 35% are very confident, with a clear majority sitting in the middle.
It would be tidy if platform preference and platform doubt were the same thing, if leaning European meant expecting Microsoft to fall short. The data doesn't support it.
Doubt sits near 8% whichever way a team leans. No two groups here are more than three points apart.
AI governance surveyRespondents who prioritize EU platforms most strongly are no less likely to doubt Microsoft 365 than anyone else. Preference and doubt are running on separate tracks.
A sovereignty requirement used to shape an infrastructure decision. On this evidence it now shapes an AI one, which means a Copilot business case has to answer where the processing happens as well as what it costs CH 2The AI reckoning→. The teams that already know where their AI processing happens will spend the next two years answering the question rather than researching it.
Not a list of the top three in this report. Access control, residency and approval timelines are the three most-named constraints in the data, and this chapter's own industry table shows they're the top three for almost nobody in particular: Technology leads on residency and sits below sample on access control, Financial Services leads on approval delay and sits eight points below on residency, Retail leads on access control and sits below on approval. The delay-vs-everyone cut goes further: the most-named challenge in the study is the one that least distinguishes teams that stall from teams that don't.
So build the register instead. For each requirement record the obligation and its source, the applicable data and workload, the control objective, the required evidence, the decision owner, the current status or exception, and a review date. Chapter 4's estate inventory is where these surface CH 4The estate→; this is where they get specified.
Then identify the three unresolved requirements most likely to delay work in flight. Precision matters, because vague constraints block more than specific ones. "We can't put regulated data in the cloud" stops a project. "Category 3 data requires customer-managed keys and EU residency, with a six-week approval cycle" is a scope item, and it's the version you can hand to a vendor.
37% of on-prem holdouts say a successful pilot with compliance validation is what they need, and 49% want proof of regulatory fit. A pilot produces both at once.
Choose a workload that's genuinely representative rather than conveniently easy, involve the compliance team in defining the validation criteria before you start, and document the controls, the testing, and the outcome as you go. The artefact is as much the point as the migration. Done once properly, it becomes the template that unblocks everything behind it.
The pilot is also the thing to take upstairs. Executive buy-in to prioritize governance is the ask that rises most among teams who delay or avoid migrations: 25% pick it against 17% of everyone else, which moves it past automated remediation into second place behind AI agent controls. Budget comes last in both groups, at 1% among the teams that stall. A completed validation with a compliance sign-off attached is a considerably better ask than a request for money nobody is asking for.
45% of on-premises holdouts say control of their own encryption keys is a precondition. That's a contractual and architectural decision best made at the start of a program rather than discovered in the middle of one.
Alongside it, build the evidence set as a maintained asset rather than a per-project scramble: control mappings to your specific obligations, audit and reporting coverage, residency documentation, and the pilot validation record. Across the whole sample, 41% say regulatory approval processes are delaying deployments and 37% say they lack adequate auditing and reporting tools.
The requirement is fixed. The approval cycle usually isn't, and it runs long because the evidence gets rebuilt rather than maintained. A standing evidence pack, produced by tooling rather than by hand, is what turns each approval from a research exercise into a review.
And expect sovereignty to keep escalating from an infrastructure question into an AI question. The teams that already know where their AI processing happens will spend the next two years answering the question rather than researching it.
Protect gives you a tenant-wide view of what users and Copilot agents can access, ranked by severity, then lets you close what shouldn't be open and keep it closed with automated policies.
Know what your AI can reach →