Every chapter, every chart, and the full methodology in one file. One email address.
Loading form…
07
The gap in Microsoft 365 is not between teams that care and teams that do not. It is between what teams believe about their environment and what they can currently prove.
That gap has shown up in the same shape in every chapter of this report.
1,794 IT leaders across two independent studies, an IT operations survey and an AI governance survey, what they believe about their environment and what they can currently show.
Each row pairs two different questions, so the distance between them is not a subtraction. In the order the chapters appear.
IT operations survey · AI governance surveyNone of those pairs is a contradiction. Each is the distance between a belief and a proof.
That isn't a criticism of the teams doing the work. Microsoft 365 behaves less like a collection of products and more like an operating environment. It changes every day as people create, share, connect, automate, migrate, and now delegate work to AI. A control that was correct at deployment can drift without one dramatic mistake ever being made.
Drew Madelung on what that means for anyone trying to hold a tenant still.
It is technically impossible to say with confidence that you will have zero overshared content in your tenant. The environment never stops moving. What we do as administrators is decrease risk, not eliminate it.”

Closing the gap is therefore not a seven-step project. It's a control loop: see what exists, decide what matters, change it safely, operate the controls continuously, and prove that the controls and investment are working. Ownership and decision rights run through every stage.
It runs as five motions rather than a policy document.
What exists, who owns it, what can AI reach, and what does it cost?
Hand-offA current baseline and a list of unknowns.
What matters most, and which requirements or risks shape the decision?
Hand-offPriorities, risk tiers, requirements, and accepted exceptions.
What should be remediated, migrated, retained, retired, or replaced?
Hand-offAn owned plan with safe execution and exit criteria.
How will the control continue after the project or policy change?
Hand-offMonitoring, lifecycle, response, and recertification.
Did the control work, did the investment create value, and what changes next?
Hand-offEvidence, measures, decisions, and the next action, which feeds the next See.
An operating model needs more than a sequence of activities. It needs names against decisions. Accountability can sit with one person without pretending that one person has all the expertise.
Most teams don't have six functions to assign this to, so this isn't an org chart. It's six questions. If you can answer each one with a name, you already have the model. A name only counts if it carries the decision and the consequence. A team, a distribution list or an admin role is not an answer.
One name, accountable for the scorecard, the priorities and the exceptions nobody has resolved. Usually an accountable service owner.
The named people doing inventory, lifecycle, monitoring, remediation and evidence, whether or not it is in their job title.
Someone who sets the control requirements, reviews the riskier changes and says whether the evidence holds up.
The business or data owner. IT can see that a site is inactive; only the owner can say whether it should be.
Finance or procurement, seeing cost attribution, realized savings and renewal decisions before the renewal rather than at it.
A standing forum that assigns the action and records who accepted the risk. A recurring meeting is fine.
1Governance is a shared intention rather than an owned outcome, and it loses every argument with a deadline.
2The work happens in the gaps between other work, and stops the week someone is busy.
3Compliance arrives at audit time as an opinion instead of a standard you were already meeting.
4Nothing is ever retired, because the only people looking are the ones who cannot answer the question.
5The first real conversation about AI spend happens after it is already committed.
6Exceptions become permanent by default, and nobody can say who agreed to them.
The minimum version is two names: one accountable owner, and a named owner for every workspace that matters. Everything else can start as an agenda item on a meeting you already hold. The structure isn't the point. Every question having an answer you could say out loud is the point.
These build the capabilities inside the loop. They're recognizable starting points, not seven gates every organization must complete in the same order.
Know what you are actually operating, on-premises and cloud.
Only 28% of organizations are fully in the cloud, only 35% automatically retire inactive workspaces, and Power Platform is the most commonly in-scope workload when a tenant moves. Most teams are governing a surface that is larger and more varied than they picture, and growing by default, because creation is automatic and retirement is manual.
In practiceA current inventory: workspaces, sites, guests, sharing links, apps and flows, and the on-premises workloads that are still there and why. Not a one-time audit but a maintained view, because a picture that is six months old is a picture of a different tenant.
You can produce a current list of the environment, its owners, and its known exceptions without launching a project to find out.
Every other control is being applied to a surface whose edges are unclear.
Evidence · Ch. 4The estate. Creation is automatic. Retirement is manual. That's the whole problem. →
Treat compliance proof as a deliverable, not a blocker.
87% let compliance shape migration decisions and 34% delay or avoid moves because of it. But when asked what would unlock them, the answers were artefacts rather than assurances: proof of regulatory fit (49%), control of encryption keys (45%), a validated pilot (37%).
In practiceWrite your hard constraints down precisely, then produce the evidence set that satisfies them: control mappings, a validated pilot with its documentation, residency and key-management decisions made up front. Constraints you have documented are scope. Constraints you carry in your head are blockers.
The compliance team can show why a decision was approved, rejected, or excepted without rebuilding the evidence first.
You join the third of organizations whose roadmap waits on questions that have no assigned owner, evidence requirement, or decision date.
Evidence · Ch. 5Compliance. Not a chapter about restriction. A chapter about evidence. →
Make migration a capability, not a one-off project.
94% migrated something in the past two years, running 2.5 migration types across them, and 35% of the most significant projects were driven by organizational change rather than technology strategy. Acquisitions and restructures do not stop, so neither does migration. The typical project runs 3 to 6 months, on a timeline usually set by someone else.
In practiceA standard, owned approach: cleanup before the move, identity handled inside the workflow rather than beside it (83% want this, 11% have it), tooling chosen for the exceptions rather than the happy path, and verification after the fact that proves what moved.
The next acquisition or restructuring would enter known stages with explicit assumptions and a defensible range for duration and risk.
You pay the setup cost every time, discover the same dependencies late, and keep meeting the 38% regret about buying tooling too late.
Evidence · Ch. 6Migration. Projects end. This doesn't — 94% moved something, 2.5 types in two years. →
Purpose-built control that keeps up after the environment changes.
77% had a governance incident in the past 12 months. 30% find out about problems reactively: when a user reports one, during an audit, after an incident, or through no consistent route at all. 57% run governance on built-in tools alone and 1% on anything purpose-built, a figure that has not moved since last year.
In practiceClose the cheap gaps first: link expiry and scheduled guest review. Then move from periodic audits to continuous monitoring with automated alerting on the signals that change fastest. The teams with proactive monitoring reported fewer incidents and more zero-incident years. Whether that is prevention or detection, both are better than finding out from the person affected.
You would learn about an oversharing incident from a system rather than from a person.
The 77% governance incident rate is the baseline, and for 30% of teams the incident is the alert.
Evidence · Ch. 3Governance. 77% had an incident. 1% use a tool built to prevent one. →
Prove what AI can reach, and what it shouldn't.
Copilot is deployed almost everywhere. Of the teams running agents, 53% have less than full visibility into what those agents can access. 48% monitor AI usage continuously. And the cleanup data showed something uncomfortable: teams that had done the work reported more incidents, because they could see them. Teams that skipped it answer "not sure" at nearly three times the sample average.
In practiceMap agents to data sources before scaling, monitor continuously rather than periodically, and name one accountable owner with the authority to enforce rather than advise. Only 48% have that owner today.
You can show which sanctioned agents exist, what each can reach and do, who owns it, and which unknowns remain.
29% report that AI has already surfaced something it should not have, and a further 8% cannot say whether it has.
Evidence · Ch. 1Confidence ≠ control. Confidence is a feeling. Incidents are facts. In 2026 they don't line up. →
Turn complexity into a line item you can explain and reduce.
AI licensing is now the biggest cost pressure in the estate at 41%, ahead of storage growth at 39%. The top obstacle to proving AI's return is cost visibility (51%), followed by governance complexity (47%). And 78% say governance activities directly shape their confidence to invest further in AI.
In practiceEstablish an AI cost baseline covering fixed license commitments and assigned-versus-active use; consumption-based agent, API, model and connector costs; third-party AI subscriptions; material supporting security, governance and operational costs; the cost centre or owner for each category; and the known gaps in attribution. Then take savings in order of confidence. Reclaim inactive licenses, add budgets and alerts for variable consumption, apply lifecycle policies to high-volume storage, and build the case for consolidation where fragmentation is materially increasing cost. Track realized savings, avoided future cost, and capacity released separately: reclaimed capacity does not always become cash available to fund another program.
`You can answer "what is AI costing us" with a figure rather than an estimate.`
Roughly eight in ten organizations now spend 6% or more of IT budget on AI, while about half lack the visibility needed to defend or redirect that investment confidently.
Evidence · Ch. 2The AI reckoning. Three quarters know what they want AI to do. Half can't see what it costs. →
Re-measure, so confidence rests on evidence rather than feel.
This is the move that makes the other six durable, and the one least likely to arrive with a natural deadline. Many of the gaps in this report persist because control status is not measured consistently. Others reflect capacity, process, skill, or tooling constraints. Measurement does not solve those by itself, but it makes the next decision harder to avoid.
In practiceCreate a small scorecard covering the estate, AI access, governance operations, compliance evidence, migration readiness, cost, and value. For each indicator, define the source, threshold or target, owner, review cadence, trend, and required response when it moves outside tolerance. Keep a decision and action log so the review produces change rather than another report.
The next review is on the calendar, the indicators have owners, and an out-of-tolerance result creates an assigned action.
Controls decay quietly and confidence remains unchanged until an incident, renewal, audit, or migration forces the question.
Evidence · Ch. 4The estate. Creation is automatic. Retirement is manual. That's the whole problem. →
The compounding runs both ways, and it shows up years later. Noorez Khamis has watched it.
The clients who did the foundational work, information architecture, security architecture, labels, DLP, years before anyone said the word AI, are in a completely different position today. That investment aged extremely well.”

Not every organization needs the same frequency. The cadence should follow risk, rate of change, and regulatory need.
Triage incidents, alerts, overdue responses, and exceptions that need escalation.
Review service health, lifecycle, cost, migration demand, and the operational scorecard.
Recertify higher-risk access, validate control evidence, review risk posture, and assess value.
Review policy, risk tolerance, capability gaps, tooling fit, and the operating model itself.
Monitor selected high-risk changes, and automate only the low-risk, reversible actions that leave clear evidence.
Run pre-deployment or pre-migration assessment, and post-change verification.
Do not treat the seven moves as seven gates. Establish a thin baseline across the full environment, then deepen the capability tied to the most immediate risk.
An unknown AI connection, unrestricted sharing path, or unsupported platform may require containment now while the wider inventory continues. Compliance requirements should be identified alongside discovery—not before it or after it—because teams need enough information about the data and workload to know which requirements apply. Cost should be visible from the start and revisited as use scales. After every major deployment, migration, or policy change, run the loop again.
For organizations that have already deployed Copilot without mapping its knowledge sources and actions, move five isn't fifth. It's an immediate risk assessment inside the See motion. For organizations whose roadmap repeatedly stalls on compliance, move two should deepen early. The model is consistent; the emphasis changes with the constraint.
The forcing function has to be yours. The SharePoint end-of-support data showed what a date does to work that would otherwise drift CH 4The estate→. Nobody will send an end-of-support notice for permission sprawl, stale workspaces, unresolved AI connections, or an ageing exception. The operating model has to create those dates.
Whether you do this with Microsoft tools, a third-party tool, or a combination, the goal has to be visibility and accountability at scale.”

Most teams already have parts of this model. Start where the evidence is weakest or the consequence of delay is highest.
If you're not sure which description fits, that uncertainty is itself useful evidence. Begin with move one, keep the first baseline thin, and let what you find determine where to go deeper.
The teams that end up in the best shape aren't the ones who bought the most or planned the longest. They're the ones who picked a date, measured honestly, and were willing to be embarrassed by what they found. The organizations that tend to make the most progress start by discovering something uncomfortable. The ones that stay stuck are the ones whose confidence never gets tested.
The M365 Governance Index scores your estate and your AI governance against the organizations in these two studies, across the dimensions this report has been circling. It takes about two minutes and returns the two or three moves that would shift you most. This is what move seven looks like the first time you do it.
The chapter that opened this report is the one worth re-reading once you have a score, because confidence is where it started, and evidence is what replaces it.