$ techbeacon▋
Threats

Study Finds Less Than Half of Companies Vet Permissions Before Adding AI to Microsoft 365

Study Finds Less Than Half of Companies Vet Permissions Before Adding AI to Microsoft 365

A recent study conducted by security‑automation firm Syskit reveals that just 43 percent of organizations that have introduced AI agents into their Microsoft 365 environments performed a formal permission review beforehand. The findings, first highlighted by Infosecurity Magazine, underscore a growing gap between rapid AI adoption and established governance practices.

The research surveyed a cross‑section of enterprises that have integrated AI‑driven assistants, chatbots, or workflow automations into the popular Office suite. While the allure of productivity gains and streamlined processes is evident, the study shows that a majority of firms are deploying these tools without first confirming that the agents have appropriate access rights to data and services.

Permission reviews are a cornerstone of IT risk management, especially in cloud‑based platforms where granular access controls can prevent inadvertent data exposure or privilege escalation. Skipping this step can leave sensitive documents, emails, and collaborative files vulnerable to misuse, either through misconfiguration or malicious exploitation of the AI agents themselves.

Industry analysts note that the issue is partly cultural: many organizations treat AI agents as extensions of existing user accounts rather than distinct services requiring separate security assessments. Additionally, the speed at which AI capabilities are being rolled out often outpaces internal policy updates, leaving security teams scrambling to catch up.

Microsoft has long advocated for a “zero‑trust” approach within its cloud ecosystem, encouraging customers to adopt least‑privilege principles and to regularly audit application permissions. The Syskit data suggests that, despite these recommendations, operational realities are falling short of best‑practice guidelines.

Experts say the findings should prompt CIOs and security officers to embed permission reviews into the deployment pipeline for AI tools. Simple measures—such as using Microsoft’s built‑in access‑review dashboards, conducting periodic audits, and documenting the rationale for each permission grant—can dramatically reduce exposure.

Looking ahead, the study’s authors anticipate that pressure from regulators and heightened public awareness of data privacy will drive organizations to formalize AI governance frameworks. As AI agents become more autonomous and capable of acting on behalf of users, the need for transparent, auditable permission structures is likely to become a compliance requirement rather than a best‑practice suggestion.

For now, the Syskit study serves as a cautionary reminder that the promise of AI‑enhanced productivity must be balanced with disciplined security oversight. Companies that ignore the permission review step risk undermining the very efficiencies they seek to achieve.

Deepak Chandra Meena — Deepak covers the dark web and underground hacking forums, reporting on marketplace activity and access broker listings. Monitors Tor-based forums and encrypted leak channels.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related