MSPs report Microsoft 365 readiness gaps as AI governance demand grows

Only 10% of MSPs say most client tenants are ready for Copilot, even though AI governance is now the fastest-growing client request for 40% of respondents. The Augmentt study of 193 MSPs also found 47% experienced an AI-related data exposure or near miss in the past year.

Categorized in: AI News Management
Published on: Aug 31, 2026
MSPs report Microsoft 365 readiness gaps as AI governance demand grows

Managed service providers are fielding rising demand for AI governance from Microsoft 365 clients, but most admit their client tenants are not ready for Copilot, according to research from software vendor Augmentt. The study of 193 MSP professionals found that AI and Copilot governance was the fastest-growing client request for 40% of respondents, ahead of security and compliance at 24%. Yet only 10% said more than three-quarters of the client tenants they manage are ready for Copilot, and just 3% said every client tenant under their management is ready.

The gap between demand and readiness carries real risk. Nearly half of respondents, 47%, said they had experienced an AI- or Copilot-related data exposure or near miss in a client tenant during the previous 12 months. Among service delivery managers, that figure rose to 56%.

Data oversharing is the top concern

Data handling is the central worry as MSPs take on a wider role overseeing AI inside Microsoft 365 estates. Data security and oversharing risk was cited by 35% of respondents as the biggest barrier to offering AI or Copilot as a managed service, while 41% named data oversharing as their main concern as AI use expands.

Other concerns included clients adopting AI before governance is in place, cited by 14%, compliance exposure at 13%, incorrect permissions at 11%, shadow AI at 11%, and staff lacking sufficient AI expertise at 10%.

Security baselines are not standardised

The study suggests many MSPs are supporting AI deployments on top of Microsoft 365 environments that are not fully standardised. More than three-quarters of respondents, 77%, said they were not fully confident that every client tenant currently met their own security baseline.

Several common weaknesses stood out. Stale accounts remaining active after offboarding were reported by 53% of MSPs, while 48% pointed to over-permissioned users or guest access. Another 40% cited configuration drift over time.

Those issues matter because Copilot works across the permissions and data structures already present in Microsoft 365. Existing gaps in identity management, access controls, and tenant configuration can become more visible when AI tools are introduced into day-to-day workflows. For professionals looking to close those gaps, Microsoft AI Courses cover the practical side of deploying and governing Copilot within existing tenant structures.

Manual administration adds pressure

Much of the underlying administration remains manual. Overall, 58% of MSPs said they establish a new client tenant's security baseline manually or through custom scripts rather than applying it automatically.

Scale appears to be adding pressure. More than 2 in 5 respondents, 43%, manage more than 50 client tenants, while 41% manage more than 1,000 licensed seats. Microsoft 365 administration also involves large teams: 35% said four to six staff members work inside client environments on a typical day, 19% said seven to 10 do so, and 30% said more than 10 team members are involved.

Onboarding and offboarding was identified as the largest source of repetitive daily Microsoft 365 work by 33% of respondents. MFA and security configuration followed at 23%, while licence management was cited by 17%.

Switching between tenants and portals is also eating up time. The study found that 41% of MSPs said a single technician loses three or more hours each week moving between separate client tenants and portals. Among providers managing 251 or more tenants, 56% reported losing at least three technician hours per week to that task.

Reactive operations dominate

Consistency and standardisation ranked as the top Microsoft 365 priority for 52% of respondents, ahead of margin, scale, or upsell opportunities. Even so, only 17% described their Microsoft 365 work as mostly proactive. The remaining 83% said their workload was mostly reactive or a mix of reactive and proactive work. Among MSPs managing 251 or more tenants, only 8% said their Microsoft 365 operations were mostly proactive.

Microsoft's pace of platform change is adding to that burden. Nearly two-thirds of respondents, 63%, said a Microsoft change had created unplanned work or broken something within a client environment during the previous 12 months. More than half, 53%, also said they had experienced a security incident or near miss unrelated to AI during the same period.

Reporting and pricing practices vary widely. Only 42% said they show clients security results through automated reporting, while 28% assemble reports manually, 16% communicate results verbally, and 10% rely on screenshots. Four percent said they do not report security results to clients at all. Some 36% price Microsoft 365 security and management work on a project-based or as-needed basis, 32% treat it as a separate line item on client invoices, and 30% bundle it into their standard managed services fee.

Despite the security and operational issues, respondents did not appear broadly negative about Copilot itself. More MSPs said Copilot reduces their workload than increases it, with 43% reporting a reduction versus 24% who said it adds to their workload. The larger challenge for MSPs appears to be not willingness to support AI, but bringing Microsoft 365 environments to a consistent standard across multiple clients.

Why this matters for management

For managers overseeing MSP operations, the takeaway is that client demand for AI governance is already outpacing the operational foundations underneath it. The 77% of MSPs who lack full confidence in their client security baselines are carrying exposure that becomes more visible with every Copilot deployment. Managers should treat tenant standardisation, automated onboarding and offboarding, and proactive security reporting as prerequisites for AI service delivery, not optional upgrades. The teams that close that readiness gap first will be the ones able to price AI governance as a managed service rather than reacting to incidents after the fact. For leadership teams weighing where to invest, AI for Management offers guidance on structuring governance and oversight responsibilities as AI workloads expand.


Get Daily AI News

Your membership also unlocks:

700+ AI Courses
700+ Certifications
Personalized AI Learning Plan
6500+ AI Tools (no Ads)
Daily AI News by job industry (no Ads)