2026 CoreView State of Microsoft 365 Security Report

Benchmarks, trends, and surprises on admin MFA, Entra privileged access, Microsoft 365 configuration backup, Copilot risk, and tenant sprawl, from 279 enterprise IT and security leaders.
1. Maturity
2. Identities & Access
3. Copilot
4. Config Backup
5. Config Drift
6. Sprawl
7. SharePoint

Microsoft 365 security is a black box. Here's what 279 leaders found inside.

279 enterprise IT and security leaders on identity, configuration, data, and AI risk inside Microsoft 365, and where confidence outruns control.

Enterprise confidence in Microsoft 365 security has pulled away from the controls that would actually justify it. Organizations have adopted Microsoft product across the board:  Teams, SharePoint, Entra ID, and now Microsoft Copilot.

Yet, the basics for identities, tenant configuration, and data protection are not enforced consistently. That’s true even amongst organizations that call themselves mature.

Here are the seven findings from the report that map to these gaps.

  1. Microsoft 365 security maturity vs. reality. 62% rate themselves mature, but still 54% of them are missing a foundational identity or configuration control. Organizations are rating themselves more highly than what the data describes.
  2. Admin MFA and privileged access. Standard Microsoft 365 users have more protections than Admin accounts do. The accounts with the most power over your tenant have the least protection.
  3. Microsoft Copilot and data exposure. 66% of organizations delayed or cancelled a Copilot rollout due to concerns about the data it could surface via SharePoint.
  4. Microsoft 365 configuration backup. Only 17% of organizations back up their own Microsoft 365 configurations. Microsoft doesn't do it. And data backup vendors only back up a portion of tenant configurations.
  5. Configuration drift and tamper detection. 38% trust themselves to catch configuration tampering by hand. 17% aren’t monitoring for config tampering at all. Manual review does not scale when there are 10,000+ Microsoft 365 settings.
  6. Tenant sprawl and Entra app governance. Microsoft 365 sprawls in three directions at once: tenants, Entra apps, and access. 83% run multiple tenants, 14% can't count their Entra apps, and 63% skip access reviews because they take too long. Manual review can't keep up.
  7. SharePoint sharing links. 73% of organizations saw SharePoint storage grow this year, building on top of years of ungoverned sharing links. That backlog is what’s causing the AI anxiety.

Who we surveyed

  • 279 IT, security, infrastructure, and compliance leaders
  • Every organization has 1,000+ employees; roughly 40% have 5,000+ and 15% have 20,000+
  • 86% USA, 7% Canada, plus the UK, Australia, and continental Europe
  • 5 core industries: Technology/Software (28%), Healthcare (19%), Finance/Banking (14%), Manufacturing (12%), and State, Local & Education (9%)
  • Spans the full ladder: Managers, Directors, VPs, and C-level CISOs and CIOs
  • Second annual study, compared year over year against 269 Microsoft 365 leaders in 2025

Organizations think their Microsoft 365 security posture is more mature than the data shows.

62% of Microsoft 365 leaders call themselves mature. And yet, 54% of those are missing a basic control.

62% rate their Microsoft 365 security as “Established” or “Advanced.” When we looked deeper, 54% of that confident majority were missing one of three basic controls: MFA enforced on admin accounts, a privileged access management solution, and/or a defined way to detect Microsoft 365 configuration tampering.

That gap has a cost, and it tends to come due at the worst possible moment. An organization that calls itself Advanced but has not enforced admin MFA, deployed PAM, or set up tamper detection usually learns about the hole during an incident. That’s, of course, when it is most expensive to close.

The bigger risk is that the label spreads. Once leadership believes the basics are covered, no one wants to pay for the work to actually handle them. Self-rated maturity does track with self-reported detection speed. Same-day incident detection climbs from 11% at the Initial stage to 49% at Advanced. But calling yourself advanced isn’t the same thing as actually having your identity and configuration fundamentals locked down.

Percentage statistics from the 172 organisations that rated themselves as established or advanced

Admin MFA in Microsoft 365 lags standard user accounts

Privileged admin accounts are protected less consistently than regular users, and native Entra role management is the reason.

Full MFA enforcement sits at 62% for standard Microsoft 365 users but only 55% for admin accounts. Nearly one in five organizations enforces MFA more weakly on its most powerful accounts than on rank-and-file staff.

Consider for a moment what one of those accounts can actually do once it's taken. An Exchange Administrator can silently exfiltrate or manipulate executive email. An Application Administrator can grant OAuth permissions to a rogue app and establish token-based persistence that bypasses MFA and Conditional Access entirely. A Privileged Role Administrator can assign itself Global Admin privileges. Why wouldn’t you want to protect these accounts?  

The reason is tooling. When asked what blocks least privilege, leaders pointed to administrative overhead (40%) and the difficulty of building custom Entra roles (38%), far more than a lack of interest (16%).

Chart showing responses by percentage in regard to the main factors that make it challenging to reduce or remove admin privileges in M365

In reality, Microsoft's native Entra role management makes least privilege expensive to operate. So, the accounts that warrant the most protection get it last.

Adoption of Entra Privileged Identity Management (PIM) and third-party PAM is climbing fast: roughly 73% now have some form of privileged access management, up from 50% a year ago. The tooling is here. But enforcement on the accounts that matter most hasn’t caught up yet.

  • 55% full admin MFA vs 62% for standard Microsoft 365 users
  • 73% now have a PAM solution (Entra PIM or third-party), up from 50% a year ago
  • 40% name administrative overhead as the top least-privilege blocker

Microsoft Copilot rollouts stall over SharePoint exposure

Two in three organizations delayed or cancelled Microsoft 365 Copilot over confidential data it might surface.

66% have delayed or cancelled a Microsoft 365 Copilot deployment, and 73% are concerned AI is already surfacing confidential information inside their organization. This fear is specific to SharePoint.

Point Copilot at a Microsoft 365 tenant with loose SharePoint permissions, and it will surface whatever was never locked down, to whoever thinks to ask.

This example brings this risk to life:
Imagine an employee is worried about layoffs. They ask Copilot if it knows who will be laid off next quarter. Copilot searches through the Chief of HR’s files (which were never locked down) and sees the list. They share that file with their friends who are on the list.

Pie chart showing the percentage breakdown of how comfortable organisations are rolling out Copilot

None of this is new. Those files were exposed before anyone installed Copilot. What Copilot changes is how easily your ordinary employee can find them. That’s why Copilot is driving organizations to audit Microsoft 365 permissions and data, a cleanup that should’ve happened years ago.

The caution around adopting Copilot is certainly rational. In fact, it scales with seniority: the closer a leader sits to the boardroom, the more likely they are to have paused Copilot.

  • 66% delayed or cancelled a Microsoft 365 Copilot deployment
  • 73% concerned AI is surfacing confidential data internally
  • Only 27% were comfortable enough to roll Copilot out anyway

The caution around adopting Copilot is certainly rational. In fact, it scales with seniority: the closer a leader sits to the boardroom, the more likely they are to have paused Copilot.

The report shows exactly how Copilot caution scales with seniority, and the 2x gap in SharePoint concern between organizations that paused and those that proceeded.

Who backs up your Microsoft 365 configurations? Not Microsoft. Probably not your data backup vendor either.

Only 17% of organization have guaranteed back up of their Microsoft 365 configurations. The rest are trusting a safety net that isn't there.

Think of your tenant configuration as a glass and your data as the water in it. Spill the water, and you “refill” it from the backup. Break the glass, and it does not matter how much water you have. There’s nothing left to hold it. Most organizations have backed up the water. They typically assume someone else was protecting the glass.

Chart showing the percentages of those who have experienced a significant M365 security incident in the past 12 months, with and without a dedicated backup solution.

In fact, only 17% of organizations back up their Microsoft 365 configurations themselves. 37% wrongly believe Microsoft does it, but Microsoft's shared-responsibility model puts configuration backup on the customer.

Another third of those organizations assume their data-backup vendor covers it. In actuality, most of those data-backup products (you guessed it) capture data. They don’t back up the full Microsoft 365 tenant configuration (e.g., conditional access policies, security settings, and the rest of what defines how the tenant behaves).

Put those groups together and roughly 70% are trusting a configuration safety net that does not exist.

  • 17% back up their own Microsoft 365 configurations
  • 37% wrongly believe Microsoft does it, down from 49% last year
  • Native-only backup users reported roughly 2x the incident rat

Confirming who actually owns Microsoft 365 configuration recovery is a five-minute question you should probably ask your team today.

Detecting Microsoft 365 configuration drift and tampering

3% still catch configuration tampering by hand across 10,000+ Microsoft 365 settings. It doesn't scale.

In 2024, Microsoft logged 176,000 configuration-tampering instances in a single month (Digital Defense Report 2024). According to our 2026 data, 65% of organizations see attackers probing their Microsoft 365 tenant at least weekly. And yet, despite the stats from Microsoft (and Sophos), 38% still detect configuration tampering through manual review, and 17% have no defined method at all.

Microsoft 365 has more than 10,000 configuration settings across Entra, Defender, Intune, Purview, and Exchange. Manual review does not scale to that surface. Change control is the one area moving fast: 47% now maintain Dev/Test/Production tenant separation, up from 36%. Still, about 30% change production Microsoft 365 configurations directly and then rely on manual review to catch what breaks.

One team came to us in the middle of an investigation. They suspected someone had reached their CIO's OneDrive without authorization, and they were trying to confirm whether it had happened and what else had changed.

Detection tooling was not the problem. Their answers were spread across 18 admin portals in a hybrid environment, so tracing who changed what, and when, was the real bottleneck. They were reviewing by hand because the surface was too difficult to review any other way.

  • 65% ee weekly-or-more attacks on their Microsoft 365 tenant
  • 38% detect tampering manually; 17% have no defined method
  • 47% now separate Dev/Test/Prod tenants, up from 36%

It’s clear that Microsoft 365 configurations are under attack. Teams should respond by tightening change control. And yet, teams are still policing the configurations with processes that break at scale.

Bar chart showing percentages of organisations where a misconfiguration in M365 caused significant security or operational issues.

The report has the full tamper-detection and change-control breakdown with year-over-year movement.

Microsoft 365 tenant sprawl and Entra app governance

Microsoft 365 is sprawling in three directions at once: tenants, Entra apps, and access. Manual reviews can't keep up with any of them.

Microsoft 365 sprawl shows up in three places. Then they compound. Tenants first: 83% of organizations run more than one Microsoft 365 tenant, and 14% now manage more than 50. Most of that is deliberate, driven by separation of duties, mergers, and regional or regulatory lines.

Then there’s the harder kind of sprawl to see. Inside those tenants, Entra apps pile up: 22% of organizations have more than 1,000 Entra apps holding permissions. 14% can't say how many they have. Every app is a potential identity-based access path. And an app you can't count is an app you can't govern. Having a lean Global Admin count hides this completely. An organization can hold admin roles to five people and still carry hundreds of Entra apps with read-write directory access (some reachable from outside the organization).

Access is the third. The control that's supposed to contain all of this is the access review, and 63% say reviews are too time-consuming to run regularly. So the tenants multiply, the apps multiply, and the one process meant to keep them in check is the process teams skip first.

  • 83% run multiple Microsoft 365 tenants
  • 14% manage more than 50 tenants
  • 63% defer access reviews because they take too long
Bar chart showing percentages of the reasons that organisations use multiple M365 tenants

SharePoint sharing links and external access exposure

Most teams rate SharePoint sharing-link exposure "moderate." It's the exact risk stalling their Copilot rollouts.

A Microsoft 365 admin came to us after a SharePoint incident: visitor access had exposed sensitive activity data to people who should never have seen it. They were not looking for another dashboard. They wanted to understand how the exposure happened, which permissions allowed it, and how to keep the next misconfiguration from opening the same door. That question, how did this get shared, is the one most organizations can't answer quickly. It's also the exact question Copilot forces the moment you turn it on.

Bar chart showing percentages of the top reasons that organisations prioritise sprawl and lifecycle management in M365.

Ask about SharePoint sharing exposure and most organizations file it under "moderate, manageable." On confidential data leaking through anonymous sharing links, only 13% are extremely concerned, and 24% very concerned. The most common answer, 31%, is just "moderately concerned." External and guest sharing lands the same way: 41% call the exposure "moderate risk," 23% "high," and 9% "critical." Real risk, widely acknowledged, rarely treated as urgent.

The organizations most worried about anonymous links are overwhelmingly the same ones delaying Microsoft Copilot. The Copilot hesitation in Finding 3 sits directly on top of this SharePoint backlog.

What's inside:

  • Every chart and the full data set: 110+ Microsoft 365 security stats to share with stakeholders
  • The six-point profile of the organizations that closed the confidence-to-control gap
  • Year-over-year benchmarks: what moved across identity, configuration, and backup between 2025 and 2026
  • The four priorities that separate exposed Microsoft 365 tenants from resilient ones
Get the report