Free resiliency assessment

Expert guidance, applied to what you already own

← Field Notes index Field Notes · No. 08 AI governance · Microsoft 365 7 min read

Your Microsoft 365 tenant already knows which AI tools your organization uses.

Somebody in your finance team pasted a forecast into a chatbot this month. You can find out which chatbot, roughly when, and whether it happened twice, using a license you renewed in July. The tooling is already paid for and sits switched off.

Identity boundary · what leaves it

Somebody in your finance team pasted a forecast into a chatbot this month. You can find out which chatbot, roughly when, and whether it happened twice, using a license you renewed in July. The tooling is already paid for and sits switched off.

01The three tenants

Three ways this goes

A few companies have kept AI out entirely. That is rare now and usually regulated, and those organizations should move this quarter, because the moment one department starts on its own the choice stops being theirs.

Others opened it six months ago: a director said yes, nobody wrote anything down, and so far it has been fine. That is the easy case to fix.

The third group opened it a year ago and has stopped asking questions about it, because the answers arrive faster than anyone can file them. People have built chatbots into how they work, with no policy and no record.

Better than the caller feared, and short of fine.

I have walked into the third kind perhaps a dozen times.

02What the telemetry says

The numbers

Four figures worth putting in front of a board.

Roughly 67% of all enterprise AI use runs through accounts outside the company's control, and the figures come from browser telemetry. LayerX, 2025

63% of breached organizations either had no AI policy or were still drafting one. IBM, 2025

Read the 82 percent as a data question. Every paste leaves your boundary for a service outside your agreements, beyond your audit, with no way to pull anything back.

03The entitlements

What you paid for and left switched off

CapabilityWhat you getE3E5
Entra Cloud App DiscoveryInventories and risk-scores 31,000+ cloud appsYesYes
Purview DLP: Exchange, SharePoint, OneDriveData controls across core Microsoft 365YesYes
Purview DSPM for AISensitive material turning up in promptsLimitedYes
Copilot ChatA corporate chatbot inside your identity boundaryFreeFree
Defender for Cloud AppsAnomaly detection, activity policies, session controlNoYes
Purview Endpoint DLPWarns or blocks pasting into AI sitesNoYes
Insider Risk ManagementRisky-AI-usage policy template, Adaptive ProtectionNoYes
Microsoft Security Copilot400 SCUs a month per 1,000 licenses, to a cap of 10,000NoIncluded

E3 runs $39 and E5 runs $60 per user each month. Microsoft moved both on 1 July 2026.

Two rows deserve a paragraph.

Copilot Chat is included at no added charge on any eligible Microsoft 365 subscription. Web-grounded chat, file upload, image generation, page summaries in Edge, and declarative agents pointed at instructions and public sites. All of it inside your identity boundary. (Point an agent at Graph or SharePoint content and it starts metering. Watch that line.)

Now consider why people opened personal accounts. Many of them wanted a chatbot and nobody gave them one. You have one, and it is already on. In the tenants I have reviewed, the announcement email has rarely gone out. One email brings a real slice of the problem back inside the boundary on its own.

Security Copilot ships with E5. Microsoft dates that to November 2025, though most tenants only saw it during the rollout through the first half of this year. I have yet to walk into an E5 tenant with it switched on.

04The order

Do these five in order

The order carries more weight than the tooling. The governance programs I have seen fail usually failed because somebody ran them backwards.

01
Look
02
Find the material
03
Sanction
04
Guard the edges
05
Write it down

01 · Look before you survey. A survey tells you what people will admit to, while Cloud App Discovery tells you what is happening. On E5, Defender for Cloud Apps scores it and lets you act. Filter the catalog to generative AI and you will have the list before lunch. In every tenant I have run this on, the list was longer than the one the team would have written from memory.

02 · Find where the material went. Purview’s AI posture tooling surfaces sensitive content sitting in prompts. This is the step that produces the quiet meeting.

Go into that meeting without a list of names. Whoever pasted the customer file into a chatbot was trying to finish something. Punish that and the behavior moves to phones, beyond your view.

03 · Sanction a short list. Pick two or three tools and fund them properly. If your approved option is worse than what people already use, they will route around it, and you will have spent three months buying visibility you then threw away.

04 · Guard the edges. Endpoint DLP and browser DLP in Edge warn or block on specific content heading to specific places. Edge 144 and later does it natively with no extension and no Purview onboarding, though unmanaged apps need the device under Intune. Pick the twelve categories that would wreck a quarter and guard those. A policy that blocks everything gets switched off within a month by somebody senior enough to demand it. Where devices sit outside Intune, Cloudflare One covers the same edge: it inventories the AI services people reach and applies DLP to what goes into them.

05 · Now write it down. This is where policies usually start, because it is the step you can finish without talking to anybody. Written after the other four, the policy describes your company as it stands, names tools people recognize, and has something behind it.

05Assessment

Sixty-second check

Read these out. Every “no” is something you can close with a license you hold.

The sixty-second check
0/6Unmeasured

Four or more “no” answers is the ordinary result, and it represents about two weeks of work.

06The cost line

What it costs when it costs

I would rather say this now than have you find it in a quote.

No added cost, if you are already licensed: app discovery, the AI inventory, the Copilot Chat rollout, core Purview DLP, baseline AI posture visibility. E5 adds Defender for Cloud Apps, Endpoint DLP, Insider Risk Management, Adaptive Protection and Security Copilot on top.

Money:

Third-party AI monitoring in Purview and unmanaged-app DLP in Edge bill through Azure consumption. Microsoft publishes no flat rate, so get a quote against your headcount rather than relying on a figure you read somewhere.

Endpoint DLP needs E5, or the Purview suite added to E3. If you are on E3 and want enforcement, that is the conversation to have.

Agent 365 runs $15 per user each month, on top of an E5, Business Premium or A5 prerequisite since June.

So the promise that everything is already covered holds for most of this and stops short of all of it. Anyone who tells you it covers all of it is selling something.

07The plan

Thirty days

For anyone who needs to show a board something before the tooling is finished.

Thirty daysMost of it already paid for
Week one
Switch on Cloud App Discovery. Filter to generative AI. Get the list.
Week two
Turn on AI posture visibility and run the baseline. Then email the whole company about Copilot Chat, because that one message moves real usage from personal accounts to company accounts, at zero cost.
Week three
Decide what is approved. Two or three tools. Announce it as something people are now allowed to do, which is true if you gave them Copilot Chat last week.
Week four
Put DLP on the handful of categories that matter. Draft the policy from what you found.

A month, most of it already paid for. The hard part is deciding what you will allow, and that decision gets harder with time.

08A different control plane

What Agent 365 governs

These get conflated constantly, sometimes by people selling both.

Agent 365 went GA on 1 May. It keeps a registry of the agents running in your environment, controls their lifecycle and access through Entra and Purview, blocks malicious coding agents at runtime, and spots local ones through Defender and Intune. If your company is heading toward dozens of agents built by four different teams, and the fifteen-times number above says it is, that is your control plane.

Agent 365 watches the agents. The paste into a personal account is a different stack.

The forecast pasted into a personal Claude account sits outside its view; that belongs to the Purview and Defender stack in section 03.

Two things to know before somebody quotes you a renewal. Agent 365 costs $15 per user each month standalone, with an E5, Business Premium or A5 prerequisite since June. Microsoft 365 E7 at $99 wraps it together with E5, Copilot and the Entra Suite, and E7 is one of several routes to Agent 365.

09The ask

Say it out loud

Six months from now, you will want a record of what you decided.

The companies I have seen end up badly placed on this got there the same way, and none of them were careless. They were keen, and they assumed somebody else was thinking about the governance side.

Usually nobody was. That is the job, and it takes two weeks at the front or a quarter of cleanup at the back.

If your own team has the two weeks, take this and go do it. I would rather it got done than got done by me.

10Primary reading

Sources

Next in Field Notes: Workday and on-prem Active Directory. What Entra already does between them, what it leaves you to build, and why Microsoft’s own documentation answers the hardest part with “write a PowerShell script and schedule it.”

Matt Gordon
ModernOps, LLC · September 2026
10Two weeks

Complimentary Microsoft AI and Automation Assessment.

Two weeks, architect-led, findings are yours either way. We inventory what is running, show you where material has traveled, and hand back a prioritized fix list.

Talk to an engineer. Bring the thing your team stopped complaining about.

← All field notes No. 07 · MO money, fewer problems