Nearly half of managed service providers surveyed by Augmentt say an AI or Microsoft Copilot related data exposure, or a near miss, occurred inside a client's Microsoft 365 tenant during the past year, according to Augmentt, a company that builds governance and security tooling for MSPs managing Microsoft 365 environments.

The finding sits inside a broader study Augmentt conducted of 193 managed service provider professionals in August 2026, examining how MSPs manage Microsoft 365 across client tenants, where standardization gaps persist, and how artificial intelligence tools are changing daily risk. According to Augmentt, 47% of respondents reported an AI or Copilot related data exposure or near miss in a client tenant within the prior 12 months. Among service delivery managers specifically, that figure climbed to 56%, a gap that separates the people closest to day-to-day tenant operations from the wider respondent pool that included owners and technicians in other roles.

By comparison, 53% of MSPs reported a security incident or near miss unrelated to AI during the same period, according to Augmentt. The two figures sit close enough together that AI-linked exposure now runs at roughly the same rate as the security incidents MSPs have handled for years, rather than trailing behind as a marginal, emerging risk.

What MSPs worry about most

Data oversharing topped the list of concerns MSPs volunteered when asked what worries them most as AI spreads through client environments. According to Augmentt, 41% named oversharing as the single thing they worry about most. Behind that, 14% cited clients adopting AI before governance controls exist, 13% pointed to compliance exposure, 11% named shadow AI, another 11% flagged incorrect permissions as AI tools spread, and 10% cited a shortage of staff AI expertise.

The same worry shows up on the commercial side of the business. Asked what stops them from offering AI as a formal managed service, 35% of MSPs cited data security and oversharing risk as the single biggest barrier, ahead of client readiness at 27%, a lack of governance tooling at 13%, unclear return on investment at 11%, the pace of constant change at 10%, and gaps in their own team's skills at 4%. Among senior or Tier 3 engineers specifically, the figure citing data security and oversharing risk as the top barrier rose to 39%, according to Augmentt, suggesting the people with the deepest technical exposure to client tenants are also the most cautious about scaling AI services before governance catches up.

Copilot demand is outrunning tenant readiness

The survey's Copilot-specific findings describe a demand curve moving faster than the environments meant to support it. Only 3% of MSPs said every one of their client tenants is ready for Copilot today, and just 10% said more than three-quarters of their tenants had reached that state, according to Augmentt. That leaves the large majority of MSPs managing a client base where Copilot readiness is partial, inconsistent, or largely absent, even as demand for the tool continues to build.

Workload effects cut in both directions but tilt positive. According to Augmentt, 43% of MSPs said Copilot reduces their workload, while 24% said it increases their workload, a gap of 19 percentage points in Copilot's favor. Despite that net benefit, governance has become the request MSPs hear most often from clients. Forty percent of MSPs ranked AI and Copilot governance as their fastest-growing client request, ahead of security and compliance at 24%, general support at 15%, licensing and cost at 12%, and onboarding and offboarding at 10%.

Microsoft's own change pace adds to the load

Separate from AI specifically, the survey found that Microsoft's pace of product change inside Microsoft 365 is itself generating unplanned work. According to Augmentt, 63% of MSPs said a Microsoft change created unplanned work or broke something in a client environment during the past 12 months. Confidence in staying ahead of that change cycle split unevenly: 56% felt somewhat confident, 31% felt very confident, 13% felt not very confident, and 1% said they were falling behind entirely.

That backdrop matters for reading the AI findings. MSPs are absorbing Microsoft's ordinary product cadence as a source of operational friction even before layering AI and Copilot governance on top of it, and the survey's authors frame both pressures as compounding rather than separate problems.

Security baselines vary by client, and the gap is wide

A separate section of the study measured how consistently MSPs enforce their own security baseline across every client tenant they manage. According to Augmentt, 77% of MSPs said they were not fully confident that every client tenant currently meets their own security baseline. That share rose to 83% among MSPs with 25 to 49 employees, the survey's mid-sized segment.

The specific gaps MSPs reported were concrete. Fifty-three percent pointed to stale accounts left active after offboarding as a security and compliance gap, 48% cited over-permissioned users or guest access, 40% reported configuration drift accumulating over time, 31% said multi-factor authentication was not being enforced consistently, 23% cited license sprawl, and 20% reported missing data loss prevention or sensitivity labeling.

How MSPs apply a security baseline to a new client tenant also varies. According to Augmentt, 58% set up a new tenant's baseline manually or with custom scripts rather than pushing it automatically, with 36% relying on custom scripts and 22% applying it manually, tenant by tenant. Only 38% use a platform to push the baseline automatically. The manual pattern persists even at scale: among MSPs managing 251 or more tenants, 60% still rely on manual work or custom scripts rather than automatic deployment, a detail that runs against the usual assumption that larger operations automate more aggressively as their tenant count grows.

The switching cost of managing many tenants

The study also measured a cost that rarely appears in security reporting: the time technicians lose simply moving between client tenants and portals. According to Augmentt, 41% of MSPs said a single technician loses three or more hours per week to that switching alone. Among MSPs managing 251 or more tenants, the figure rose to 56%.

Scale varies widely across the sample. Forty-three percent of MSPs manage more than 50 client Microsoft 365 tenants, and 41% manage more than 1,000 licensed Microsoft 365 seats in total, according to Augmentt. Staffing patterns follow a similar spread: 30% of MSPs have more than 10 team members actively working inside client Microsoft 365 environments on a typical day, while 35% have four to six, 19% have seven to 10, 14% have two to three, and 2% work with a single person handling that load. Larger operations concentrate staff accordingly. Among MSPs managing 251 or more tenants, 56% have more than 10 people working in client environments daily, compared with just 14% among MSPs managing one to 10 tenants.

Proactive management remains the exception

Despite the operational and security pressures the survey documents, most MSPs describe their Microsoft 365 work as reactive rather than proactive. According to Augmentt, only 17% described their work as mostly proactive, while 67% called it a balance of proactive and reactive work, and 16% described it as mostly reactive.

The gap widens by role and scale. Eighty-one percent of owners and C-suite respondents did not describe their Microsoft 365 work as mostly proactive, and 85% of Tier 1 and Tier 2 technicians gave the same answer. Among MSPs managing 251 or more client tenants, only 8% described their work as mostly proactive, suggesting that growth in tenant count correlates with less proactive management rather than more, even though larger MSPs might be expected to have more resources to invest in prevention.

Consistency across clients ranks as the field's top stated priority regardless. Fifty-two percent of MSPs said standardization across clients is their top Microsoft 365 priority, according to Augmentt. Repetitive work still concentrates in core administrative tasks: 33% cited onboarding and offboarding as their biggest source of repetitive work, 23% cited multi-factor authentication and security configuration, 17% cited license management, 14% cited mailbox and permissions changes, 8% cited reporting, and 4% cited alert response.

How MSPs report security results, and how they charge for the work

Security reporting to clients splits between automated and manual delivery. According to Augmentt, 42% of MSPs show clients security results through automated reporting, 28% assemble reports manually, 16% report results verbally, 10% use screenshots, and 4% do not report security results to clients at all.

Commercially, Microsoft 365 security and management work is sold through three main models. Thirty-six percent of MSPs price the work on a project basis as needed, 32% bill it as a separate line item on the client invoice, and 30% bundle it into the standard managed-services fee at no additional charge. Only 3% do not offer Microsoft 365 security and management as a formal service, according to Augmentt.

Methodology and sourcing

Augmentt surveyed 193 managed service provider professionals in August 2026, with all respondents currently working for an MSP. The company builds a platform that manages and secures Microsoft 365 across client tenants for MSPs. The dataset was shared with PPC Land as an exclusive by Fractl, the marketing agency handling distribution of the study on Augmentt's behalf; Fractl did not conduct the underlying research and is not the source of the findings reported here. Augmentt has not published a full public breakdown of the survey instrument or the complete response set alongside the figures summarized above.

Why this matters for marketing organizations

PPC Land has tracked a wider pattern of enterprise AI adoption running ahead of the governance layer meant to contain it. A separate study covered by PPC Land found that 78% of organizations reported an AI-related security incident or identified vulnerability, with roughly half lacking formal AI governance policies, a figure that sits in the same range as Augmentt's MSP-specific findings despite covering a broader set of enterprise IT and cybersecurity roles rather than MSPs alone.

The governance gap is not unique to Microsoft 365 or to MSPs. PPC Land's reporting on agentic AI infrastructure across advertising platforms has documented a parallel dynamic: AI agents gaining direct, permissioned access to live campaign data, customer records, and operational systems faster than the audit trails and access controls needed to govern that access can mature. Microsoft itself has pushed deep into this territory. PPC Land reported that Microsoft CEO Satya Nadella disclosed the company is exposing more than 650,000 Model Context Protocol actions across sales, finance, supply chain, human resources, and customer service through Dynamics 365, letting AI agents act on business data under the same permissions and audit trails as a human user, at least in principle.

For marketing organizations that operate as, or rely on, managed service arrangements for their Microsoft 365 environments, the Augmentt findings carry direct operational relevance. Marketing teams routinely store campaign data, customer segments, and creative assets inside Microsoft 365 tenants managed by third-party providers, and the survey's finding that 77% of MSPs are not fully confident every client tenant meets their own security baseline implies that a meaningful share of those environments carry unaddressed gaps regardless of whether AI tools are in active use. Agencies evaluating Copilot deployment for content generation, reporting automation, or client communication now have a specific, sourced reference point for how prepared the broader MSP market actually is: not very, according to the 3% of respondents who called their entire client base ready.

The finding that 40% of MSPs rank AI and Copilot governance as their fastest-growing client request also signals where budget and attention are shifting inside the channel that many small and mid-sized marketing organizations depend on for IT support. If governance requests are growing faster than security and compliance requests generally, as the survey suggests, marketing leaders working through MSP relationships may see governance-specific line items appear on invoices that previously bundled security work into a flat fee.

Timeline

  • August 2025 - DigiCert commissions Propeller Insights to survey 1,001 IT and cybersecurity decision makers on AI trust and governance.
  • July 7, 2026 - DigiCert publishes findings that 78% of organizations experienced an AI-related security incident or identified an AI-related vulnerability.
  • July 30, 2026 - Microsoft CEO Satya Nadella discloses that Dynamics 365 exposes more than 650,000 Model Context Protocol actions across enterprise functions.
  • August 2026 - Augmentt surveys 193 managed service provider professionals on Microsoft 365 management, security baselines, and AI governance.
  • August 26, 2026 - Fractl sends the Augmentt study and full dataset to PPC Land as an exclusive.
  • September 1, 2026 - Fractl follows up with PPC Land confirming the dataset remains available and unpublished elsewhere.

Summary

Who: Augmentt, a company building Microsoft 365 governance and security tooling for managed service providers, conducted the survey. Fractl, a marketing agency, distributed the findings to PPC Land as an exclusive on behalf of Augmentt.

What: A survey of 193 managed service provider professionals found that 47% experienced an AI or Copilot related data exposure or near miss in a client Microsoft 365 tenant within the past 12 months, that 77% lack full confidence every client tenant meets their own security baseline, and that only 3% consider their entire client base ready for Copilot.

When: Augmentt conducted the survey in August 2026. Fractl shared the dataset with PPC Land on August 26, 2026, and followed up on September 1, 2026.

Where: The findings concern managed service providers managing Microsoft 365 environments for clients, without a stated geographic restriction in the material provided.

Why: The survey quantifies a governance gap that enterprise IT teams, MSPs, and by extension the marketing organizations that depend on them, are navigating as AI tools gain broader access to business data faster than permissioning and oversight controls have matured to contain that access.