Learn · field notes
What we found measuring real Microsoft 365 estates.
Everything here is mined from real engineering or research evidence — measured, not guessed, and never a fabricated number. It’s how we think about governing an estate where the agents move faster than the admin screens. Each piece maps to one of our four commitments.
-
Agent 365 and the Copilot Control System: what Microsoft's native tooling covers — and where it stops
Microsoft now ships real agent governance: the Copilot Control System framework and Agent 365, GA since May 2026. An honest practitioner map of what the native tooling covers, the coverage caveats Microsoft itself documents, and the questions it still leaves open.
-
Orphaned agents: Microsoft ships a "missing owner" filter for a reason
The new Agents dashboard in the Microsoft 365 admin center gives "agents without owners" one of its four top governance cards. Platform vendors don't build UI for hypothetical problems — a short piece on why agents orphan, and why an ownerless agent is worse than an ownerless site.
-
Restricted Content Discovery and the pre-Copilot cleanup: what actually reduces reach
Restricted Content Discovery hides sites from Copilot and search — but Microsoft's own docs say it doesn't change a single permission. A practitioner's playbook for the pre-Copilot cleanup: what merely hides exposure, and what actually reduces it.
-
Copilot can reach everything your users can. That's the whole problem.
Turning on Microsoft Copilot doesn't create new access — it makes existing access answerable. Why your oversharing surface is your AI-exposure surface, measured on a real tenant, and what to check before you flip it on.
-
Delta queries are the whole game: why your second scan should cost ~1% of your first
The first full scan of a tenant is expensive and unavoidable. The second one shouldn't be — Microsoft Graph delta queries let you re-read only what changed. Measured: a phase that took ~63 minutes cold ran in ~26 seconds on delta.
-
Garbage in, confident answer out: the duplicated-content problem
Five copies of the same policy. The 2019 draft beside the 2026 final. AI reads all of it, picks one, and cites it with total confidence. When the wrong version is a click away, data-quality debt stops being cosmetic.
-
Graph Data Connect vs. API scanning: when bulk is the sanctioned answer
Microsoft Graph's own throttling doc tells you to stop scanning and use Data Connect past a certain scale. A practitioner comparison of when API scanning is right and when MGDC is the sanctioned bulk path — on freshness, consent, cost, and honest coverage.
-
Oversharing was always there. AI just made it answerable.
The first crack in the estate you never designed: 'Everyone' grants, forgotten links, and access that outlived its purpose were harmless when finding a file took effort. Copilot removes the effort. The realization, not the mechanics.
-
The agents you can't see
Agent governance is content governance, one layer up. The same sprawl that produced ungoverned files and sites is now producing ungoverned agents — across three control planes, with no single inventory.
-
The estate you never designed: how your Microsoft 365 actually grew
No one architected your Microsoft 365 estate — it accreted through self-service SharePoint, Teams, OneDrive, and Power Platform, one project and one maker at a time. How a decade of default-open growth quietly became the shape of your tenant.
-
The real promise of AI on your own content
Copilot answering from your own documents, agents automating real work — leaders are right to want this, and the upside is real. But AI on your content inherits the exact estate you already have, not a cleaner one.
-
Who attests to any of this? Ownership, orphans, and accountability
When the auditor asks 'who approved this access, and when,' most Microsoft 365 estates have no answer. Orphaned sites, agents with no owner, access never recertified — and attestation as the governance loop that was never closed.
-
The compounding cost of ungoverned growth
Ungoverned Microsoft 365 and Power Platform growth doesn't add risk linearly — it compounds, each layer inheriting the last one's debt. Naming governance debt, and the honest questions a leader should be able to answer about their estate.
-
What scanning ~1M files against Microsoft Graph actually looks like (measured, not guessed)
Measured wire-level data from scanning ~900K files in a real tenant: how SharePoint's two throttles actually behave, why "add more app registrations" hits a deliberate wall, and what delta economics change.
-
Your Microsoft 365 tenant has AI agents you can't see
AI agents in a Microsoft tenant live on at least three control planes, and no single admin screen shows all of them. What we found scanning a real estate, and what an honest agent inventory requires.
-
The confident zero: when governance tools report success while collecting nothing
A governance dashboard saying "0 violations" can mean assurance, blindness, or silent failure. A buyer's checklist for telling them apart, from a tool that reports its own partial failures.
Why we write these. Our whole pitch is depth and honesty, and the fastest way to prove either is to show the wire-level detail a slide deck can’t. If a claim here can’t be traced to evidence, it doesn’t ship.
Want the product behind the writing? See how Polaris works or join the design-partner program.