The MSP Microsoft 365 Reality Report

Microsoft 365 is the backbone of most small and midsize businesses, and the managed service providers (MSPs) behind them are the ones keeping it running and secure, often across dozens or hundreds of separate client tenants. What that work actually looks like day-to-day has been surprisingly hard to see.

To find out, Augmentt surveyed 193 MSP professionals about how they manage Microsoft 365 across their clients. The answers point to sprawling environments that are still largely built by hand and to a wave of AI that is arriving before many practices are ready for it.

Key takeaways

  • AI and Copilot governance is the fastest-growing client request, named No. 1 by 40% of MSPs, ahead of security and compliance (24%).
  • 47% of MSPs had an AI or Copilot-related data exposure or near miss in a client tenant in the past 12 months.
  • 58% of MSPs set up a new client tenant’s security baseline manually or with custom scripts rather than automatically.
  • Stale accounts after offboarding tops the list of security and compliance gaps, cited by 53% of MSPs.
  • Consistency and standardization are the top Microsoft 365 priorities for 52% of MSPs, while onboarding and offboarding are the biggest sources of repetitive daily work (33%).
  • 63% of MSPs had a Microsoft change create unplanned work or break something in a client environment in the past 12 months.
  • Data security and the risk of oversharing are the top barriers to offering AI or Copilot as a service, cited by 35% of MSPs.

Most MSPs still run Microsoft 365 by hand, one tenant at a time

The typical Microsoft 365 practice is bigger and more manual than the tidy managed-services label suggests.

Infographic showing MSP Microsoft 365 scale, how security baselines are applied, top sources of repetitive work, and the share of proactive work.

Scale is the first surprise. More than 2 in 5 MSPs (43%) manage more than 50 client tenants, and 41% manage more than 1,000 licensed seats, yet most still stand each one up by hand. Overall, 58% set a new tenant’s security baseline manually or with custom scripts rather than pushing it automatically. Among the largest shops managing 251 or more tenants, that figure climbs to 60%.

That manual footing shows up in how the work feels. Just 17% of MSPs call their Microsoft 365 work mostly proactive. The rest (83%) are mostly reactive or run on a mix of both proactive and reactive. Among owners and C-suite respondents, the not-proactive share is 81% and rises to 85% among Tier 1 and Tier 2 technicians. Among MSPs managing 251 or more client tenants, only 8% describe their Microsoft 365 work as mostly proactive.

The number of team members actively working inside a client’s Microsoft 365 environment on a typical day is as follows:

  • 1 member (2%)
  • 2 to 3 members (14%)
  • 4 to 6 members (35%)
  • 7 to 10 members (19%)
  • More than 10 members (30%) 

Onboarding and offboarding are the single biggest sources of repetitive daily work at 33%, ahead of MFA and security configuration (23%) and license management (17%). At the largest MSPs, the sheer number of hands adds up: 56% of those managing 251 or more tenants have more than 10 people working in client environments on a typical day, compared with 50% of those managing 101 to 250 tenants and 14% of those managing 1 to 10 tenants.

The disconnect between priorities and daily reality

Standardization remains a top priority for most MSPs, yet daily reactive tasks continue to create operational friction. This disconnect often leads to security vulnerabilities and inconsistencies in client tenant management.

Ask MSPs what matters most, and 52% name consistency and standardization, above margin, scale, or upsell. Ask what the day actually holds, and technicians most often point to onboarding and offboarding (33%). The distance between those two answers shows up as security drift. The most common weak spots MSPs report are:

  • Stale accounts left active after offboarding (53%)
  • Over-permissioned users or guest access (48%)
  • Configuration drift over time (40%)

MSPs most often price their Microsoft 365 security and management work on a project-based, as-needed basis (36%). Others treat it as a separate line item on the client invoice (32%), bundle it into the standard managed-services fee at no additional charge (30%), or don’t offer it as a formal service (3%).

When it comes to proving the work done, only 42% of MSPs show clients security results through automated reporting. The rest assemble reports by hand (28%), cover it verbally (16%), lean on screenshots (10%), or don’t report on it (4%).

Confidence is thin. More than three-quarters of MSPs (77%) are not fully sure that every client tenant meets their own security baseline. And this rises to 83% among MSPs with 25-49 employees. Part of the problem is friction: 41% say a single technician loses 3 or more hours a week just switching between client tenants and portals, climbing to 56% among MSPs managing 251 or more tenants.

AI is arriving before the Microsoft 365 foundation is ready

Copilot and AI are now the fastest-moving client demand, landing on top of environments that many MSPs can’t yet fully see.

 Infographic on MSP AI readiness, AI-related exposure incidents, barriers to selling AI, and the fastest-growing client requests.

AI has moved to the front of the queue. AI and Copilot governance is the client request MSPs most often rank as their fastest-growing, named number one by 40%, ahead of security and compliance (24%).

The trouble is readiness. Just 10% of MSPs say more than three-quarters of their client tenants are ready for Copilot today, and only 3% say all of them are. Meanwhile, 47% have already had an AI or Copilot-related data exposure or near miss in a client tenant in the past 12 months. More than half of service delivery managers (56%) report the same.

It’s not that MSPs doubt the tools. More say Copilot reduces their workload than increases it (43% vs. 24%). The bigger holdup is trust in the underlying environment. Data security and oversharing risk are the top barriers to offering AI as a service, named by 35% overall and 39% of senior or Tier 3 engineers.

That caution tracks with how much the platform itself moves: 63% of MSPs had a Microsoft change create unplanned work or break something in a client environment in the past year, and 53% had a security incident or near miss unrelated to AI over the same period. When it comes to staying ahead of constant Microsoft 365 changes, MSPs feel somewhat confident (56%), very confident (31%), not very confident (13%), or falling behind (1%).

As AI spreads, data oversharing (41%) is the single thing MSPs worry about most. They are also concerned about clients adopting AI before governance is in place (14%), compliance exposure (13%), incorrect permissions (11%), shadow AI (11%), and staff lacking AI expertise (10%).

Getting the basics right is the new prerequisite

The through-line across all of this is that the fundamentals are not yet solved. MSPs are managing sprawling Microsoft 365 estates largely by hand. They are mostly reacting rather than getting ahead, and confidence in basic security posture is low, all before AI raises the stakes.

For MSPs, the practical read is that standardizing and gaining real visibility into every client tenant is no longer a nice-to-have. It’s now the groundwork that makes secure AI adoption, provable security, and profitable growth possible. The practices that close that gap first will be the ones ready for whatever Microsoft ships next.

Methodology

Augmentt surveyed 193 Managed Service Provider professionals in August 2026 to explore how MSPs manage Microsoft 365 across their client tenants, where security and standardization gaps show up, and how AI and Microsoft Copilot are affecting their day-to-day work and risk. All respondents currently worked for an MSP.

About Augmentt

Augmentt gives managed service providers one place to manage and secure Microsoft 365 across every client tenant, so security work becomes something MSPs can standardize, prove, and bill for instead of quietly absorbing. Learn more about Secure Autopilot today.

Fair use statement

You are welcome to share the findings and visuals from this report for noncommercial purposes. When you do, please link back to this page so readers can view the full study and provide an attribution to Augmentt.

SUBSCRIBE for more resources

Related Content

Augmentt & M365 Conditional Access Policies: Everything

In this video, we dive into the world of Microsoft conditional access policies and how MSPs can streamline their implementation and

The MSPs Guide to Preventing 99% of Microsoft 365 Cyber

5 Easy Steps to Protect your Clients

The Security Benefits of Microsoft Premium Licenses

Placing your clients on the path to preventing 99% of breaches