Doug Morrison | VP | Modern Workplace | Braintree | mail me |
Microsoft 365 is embedded in a significant number of South African organisations, but adoption doesn’t mean value. The difference between the two is showing up as cost and risk.
There’s a reason companies invest in technology. It should deliver measurable gains across key areas such as productivity, cost and time savings, and operational optimisation.
Companies invest in technology so they can write key phrases such as ‘significant gains’, ‘integrated security’ and ‘positive financial impact’ into board reports and return on investment analyses. However, reality often diverges from these promises because implementation quality, adoption, integration and data readiness determine value. This is where successful Microsoft 365 adoption either succeeds or falls short.
The gap between adoption and value
The gap between what a platform can deliver and what it actually delivers comes down to how it was deployed and what happened afterwards.
Organisations often treat migration as a project with a defined end date. They assign licences at go-live and rarely revisit them. They also leave security settings at the out-of-the-box defaults. While the platform runs reliably in the background, nobody actively manages it and the organisation around it changes continuously.
People join and leave the business, roles change, teams restructure, and new security threats emerge. Yet the platform keeps running on the configuration and licence structure it started with. This approach accumulates cost and risk while drifting away from business needs. The result is a platform that looks as though it is operating optimally until something goes wrong. Unfortunately, it eventually will.
The cost of poor licence management
The most immediate and recoverable problem is licensing. When organisations do not optimise licensing for usage or business requirements, they can significantly overspend on their platform. This is a massive waste of budget that companies can avoid.
For example, many companies are sitting on a higher licence tier than their users need because they have not reviewed their licences since deployment. Addressing this issue is relatively simple. Organisations can assess their usage, ensure that each user’s profile has the right licence, and then downgrade licences that are not relevant or necessary.
If organisations understand their licence structure and per-user requirements, they can save as much as $5 to $12 per user on Microsoft 365. Effective Microsoft 365 adoption depends on this kind of ongoing governance.
Security and the rise of grey AI
Of course, security presents another challenge. Microsoft 365 includes a built-in benchmark called Secure Score. It provides a continuously updated measure of how well an environment aligns with Microsoft’s recommended security practices.
The average Secure Score across surveyed Microsoft 365 users typically sits between 30 and 45 points. Understanding this score gives organisations a clear picture of their security posture and what they need to do to close the gaps. Organisations can lift their profile from as low as 34 points to 85 points very quickly and at little to no cost.
Another challenge is grey Artificial Intelligence (AI). These AI tools are not sanctioned by the business and often include free versions of popular solutions such as ChatGPT, Gemini or Claude. However, these free versions are not secure. They do not sit behind a firewall or within a walled garden and expose businesses to serious risk.
Employees simply use the most accessible tools at their disposal. However, the data going into these tools sits outside every governance, compliance and security control that organisations have in place. As businesses accelerate Microsoft 365 adoption and AI strategies, managing these risks becomes increasingly important.
Data protection and long-term value
Finally, there is the problem of backups and data. When it comes to Microsoft 365, many organisations believe that Microsoft is responsible for the data. However, Microsoft explicitly states that businesses own their data and identities and remain responsible for protecting them.
Microsoft provides the infrastructure, but what happens to the data after an attack comes down to the organisation itself. Unfortunately, many companies only realise this when it is too late because they underestimate backup requirements and often implement the wrong tools.
Unpacking and unpicking these problems is worth the effort. It is also worth partnering with a provider that understands the most common mistakes and why they happen. When organisations close these gaps, they start to see proven value. According to a 2025 Forrester Total Economic Impact study, a well-managed Microsoft 365 environment delivers time savings of 1.5 hours on collaboration, a 90% reduction in IT help desk ticket time, and three-year benefits exceeding $519,000 through business user automation.
In conclusion
For companies with AI ambitions, this foundation has also delivered measurable value. The Forrester study on Microsoft 365 Copilot showed an ROI of 116% over three years within a well-governed environment that has clean data, correct access controls and a sound security posture.
Achieving this value does not require new technology or additional licences. Instead, it requires an actively governed Microsoft 365 environment that is tuned to the business, consistently managed and properly documented.
By partnering with a managed services provider, organisations can close the gap, stabilise and predict their costs and extract far more value from Microsoft 365 than they do today. Ultimately, successful Microsoft 365 adoption depends on governance, visibility and continuous optimisation.
























