IT Pro Expert
Search
IT · 10 Sep 2026 · 12 min read

Giving AI Agents Access to Your System

Ai agent risks

Sooner or later, someone in your business will click "Connect" on an AI assistant and Microsoft will ask whether that app can read your organisation's email, files and calendars. This is what that approval actually hands over, how it goes wrong in practice, and what it costs to make sure you can undo the damage.

The prompt usually appears without warning. A member of staff signs into ChatGPT, Claude or a similar tool, chooses to connect Microsoft 365 so it can summarise their inbox or search their documents, and lands on a Microsoft consent screen. If your tenant is configured properly, they see "Need admin approval" and the request comes to you. If it isn't, they approve it themselves and you never hear about it.

None of this means AI connectors are a bad idea. Used well, they save real time. But the approval is a permissions decision, not a software preference, and it should be treated like giving a new supplier a key to the building.

What you are actually approving

That screen comes from Microsoft Entra ID. It is the gate that decides whether a third-party application may use Microsoft Graph — the interface that reaches every part of Microsoft 365 — to get at your data. The publisher tick beside the app name confirms who is asking. It says nothing about what they are asking for.

There are two kinds of permission, and the difference matters. Delegated permissions mean the app acts as the signed-in person and inherits exactly what they can reach. Application permissions mean the app has its own access to the tenant, independent of any user, which deserves far more scrutiny. Most AI connectors ask for delegated access, and people assume that makes it modest. Often it doesn't.

  • Mail.Read — every message in that person's mailbox, including anything forwarded to them in confidence.
  • Files.Read.All and Sites.Read.All — not "their own files". Every file and every SharePoint site that person is able to open.
  • offline_access — the connection keeps working in the background without asking anyone again, until someone revokes it.
  • Consent granted for the organisation — applies across the tenant, not only to the person who asked for it.

The risks, in plain terms

It sees what the user sees

Approve it for a director, an office manager or an IT account and the assistant's reach is as wide as theirs — which in most small businesses is very nearly everything.

Sloppy sharing becomes findable

Files shared too widely have always been a problem, but nobody stumbled across them. AI search makes them turn up in seconds. Permissions decide access; they don't understand intent.

Copies leave your tenant

Content is sent out to be processed. What is retained, and whether it can be used to improve a model, depends on the plan and settings — a personal account and a business one are not the same thing.

Access outlives the reason for it

Consent doesn't expire on its own. The connection carries on quietly after the project ends, or after the person who wanted it has left, because nothing visible happens to prompt a review.

Three ways this actually goes wrong

Most of the worry about AI and company data is either vague or overheated. It helps to separate it into three things that behave differently and need different controls.

Exposure: what was buried becomes searchable

The assistant doesn't break permissions. It exercises them. Nearly every business has material that is technically open to more people than anyone intended — a payroll spreadsheet in a shared department site, an old grievance folder, a "share with everyone in the organisation" link created in a hurry three years ago. It stayed private in practice because nobody went looking. Ask an assistant a plain question and it will find that material in seconds and summarise it helpfully. It can also assemble an answer from fragments across a dozen documents that no single document contained, which is a disclosure nobody ever approved.

Leakage: content leaves your control

Whatever the assistant reads is sent out of your tenant to be processed. Where it goes, how long it is held, whether it can be used to improve a model and who the sub-processors are all depend on the product and the settings — and a personal subscription is not the same product as a business one. There is a second version of this that matters just as much: the answer it produces can be pasted into a chat window, a personal account or a message to a supplier, and at that point it has left both Microsoft's audit trail and yours. Staff pasting confidential text into consumer AI tools is the commonest form of leakage in small businesses, and a connector doesn't cause it — but a business that has never said anything about AI use tends to have both problems at once.

Going off the rails: when the assistant can act

"Rogue AI" is the wrong picture. The realistic failures are duller and far more likely:

  • It does what it was asked, at scale, with poor judgement. A tidy-up that deletes hundreds of files, a bulk rename that breaks every link, a reply sent on someone's behalf to the wrong distribution list.
  • It is confidently wrong, and somebody acts on the summary without opening the source document.
  • It follows instructions it found rather than instructions you gave it. Text planted in an incoming email, a shared document or a web page can be read as a command — prompt injection. No malware, no stolen password, nothing for antivirus to catch.
  • Its access is inherited by someone else. A stolen token or a compromised connector hands an attacker the same standing, pre-approved reach without ever touching a password or triggering multi-factor authentication.

What to have in place before you approve anything

  1. Get a genuine backup running first

    Not afterwards. If an agent, or the person driving it, deletes or overwrites at scale, your ability to undo that is decided before it happens, not after.

  2. Stop staff approving apps for themselves

    In Entra ID, restrict user consent to low-impact permissions from verified publishers, and switch on the admin consent request workflow. Requests then arrive with a named requester and a reason, and you have a record of every decision.

  3. Grant the least, to the fewest

    Approve per app and per action rather than everything at once — calendar without SharePoint, for example. Scope document connectors to named sites instead of the whole tenant, start with a small pilot group, keep it read-only, and apply your existing conditional access rules to it.

  4. Make sure you can see what it did

    Confirm auditing is on and check how long those logs are kept. Alert on new consent grants so a second connector can't appear unnoticed, and diary a quarterly review of every application listed in Entra ID with permissions to your data.

Why native recovery is not a backup

Microsoft 365 has recovery features, and they are worth using, but they are retention rather than backup. Deleted files sit in the SharePoint and OneDrive recycle bins for 93 days across both stages, and that period isn't configurable. Deleted mail is kept for 14 days by default, extendable to 30. A OneDrive or a document library can be rolled back to a point in the last 30 days, and version history will undo an individual file. All fine for a mistake spotted quickly. None of it helps with a bulk change nobody noticed for four months, and none of it survives a determined clear-out by someone with admin rights.

What protection costs: a worked example

Take a ten-person business with a fairly ordinary footprint: 30 GB of mail each, a 500 GB SharePoint estate spread across roughly 50,000 files, and 3 GB in each person's OneDrive. That is 830 GB to protect. Prices below were accurate at the time of writing and should be checked before you commit to a budget; sterling figures assume around $1.35 to the pound.

830 GBdata to protect
$0.15per GB per month, Microsoft's list rate
~£1,100Microsoft 365 Backup, first year

Microsoft 365 Backup

Microsoft's own add-on covers Exchange mailboxes, SharePoint sites and OneDrive accounts. It is billed on consumption rather than per user, holds restore points for up to a year — roughly every ten minutes for the previous fortnight and weekly after that for SharePoint and OneDrive, and every ten minutes across the whole year for Exchange — and restores are free. Teams chat messages are not covered, though channel files stored in SharePoint are.

  • 10 mailboxes at 30 GB — 300 GB
  • SharePoint — 500 GB
  • 10 OneDrive accounts at 3 GB — 30 GB
  • 830 GB at $0.15 per GB per month — about $125 a month, or $1,494 a year. Call it £92 a month, £1,105 a year.

Two things to budget around. Billing counts more than the live size — recycle bins, online archives and deleted content held for the retention year all count, so assume ten to twenty per cent on top as the year goes on. And it is paid through an Azure subscription on pay-as-you-go billing, so somebody has to own that bill before you can switch it on.

A second copy on your own hardware

A small mirrored NAS is the usual answer for a business of this size. Two 8 TB drives in RAID 1 gives 8 TB usable — nearly ten times the live footprint, which is the point: the headroom is what buys you years of version history rather than one flat copy that overwrites itself.

  • UniFi UNAS 2 (two bays, RAID 1, powered over Ethernet) — $199 list, so budget roughly £200 delivered. If it needs to be rack-mounted, the UNAS Pro 4 and the seven-bay UNAS Pro are both listed at $499.
  • Two 8 TB CMR NAS drives — around £150 to £200 each, so £300 to £400 for the pair. Match the capacities, and never put desktop drives in a RAID array.
  • Something to run the backup software on — the UNAS is storage only, so it holds the files but doesn't pull them from Microsoft 365. Nothing extra if you have a server or a spare machine; £250 to £400 for a small always-on box if you don't.
  • A UPS — £120 to £180. A mirror does not enjoy being switched off mid-write.
  • Backup software — Veeam Backup for Microsoft 365 Community Edition is free for up to 10 users, 10 Teams and 1 TB of SharePoint data, which this example fits almost exactly. Beyond those limits, expect a per-user licence.
  • One-off, all in: roughly £600 to £1,000. Running costs are about £40 to £60 a year in electricity, plus setting aside for drive replacement at around the five-year mark.

Four things people get wrong with this setup. A mirror is not a backup — RAID 1 survives a drive failing, not a deletion, a ransomware run or a burglary, so it is the versioning and retention policy that make it a backup rather than the second drive. "Offsite" means another building; sitting in your office it is still an independent copy of cloud data, which is most of the value, but a fire takes it along with everything else. Give it its own credentials, entirely separate from Microsoft 365 — if your compromised admin account can also empty the backup, you have one failure away from nothing. And when you test a restore, remember that 50,000 files is the number that decides how long it takes, not 500 GB; item counts are what turn a restore into a full day.

Both, not either

For most small businesses the sensible answer is to run both, and it is not extravagant. Microsoft 365 Backup gives fast, tenant-wide recovery in place, which is what you want at nine o'clock on a bad morning. The local mirror gives you a copy outside Microsoft's boundary, under different credentials, kept for as long as you choose. For the example above that is somewhere around £1,200 a year plus £600 to £1,000 up front — roughly £10 per user per month to turn an AI mistake, a ransomware run or a departing employee's clear-out into an inconvenience rather than a disaster.

If it goes wrong, this is the order to work in

  1. Revoke the consent and kill the sessions. Removing the application's permissions is only half of it; existing tokens can keep working until they expire, so revoke sign-in sessions for the affected accounts as well.
  2. Work out what was touched. Use your audit logs to establish which mailboxes, sites and files were accessed or changed, and when. This is why the retention period on those logs matters long before an incident.
  3. Restore from a known-good point. Recycle bin or version history for something small and recent; backup for anything larger or older.
  4. Deal with the obligations. If client or personal data reached somewhere it shouldn't have, there may be contractual or regulatory notifications to make, on a clock that starts when you become aware.

The practical position is simple enough. AI access to Microsoft 365 is worth having, provided it is granted deliberately, scoped narrowly, logged properly and backed by something that can put the data back. Approved on the hoof by whoever happened to click the button, it is an open-ended supplier relationship nobody in the business has read the terms of.

Related reading: cyber security, Microsoft 365 migration and management and data recovery.

Not sure what has already been approved in your tenant?

We can audit which applications hold permissions to your Microsoft 365 data, tighten the consent settings, and design and test a backup that actually restores.

Get in touch