What if the scariest security story isn’t someone breaking in, but someone being let in?
A write-up has been making the rounds with a title that stops you mid-scroll: “How I Could’ve Accessed 17 Trillion Microsoft Records,” by Usman Masood Ashraf. The framing of the piece is that recent cybersecurity discussion has been dominated by reports of attackers scaling up operations against enterprise platforms, and that one particularly alarming scenario involves unauthorized access at a scale most of us can’t picture.
Here’s my honest position as someone who explains this stuff for a living: I can’t confirm the 17 trillion number for you. The sources I have don’t verify whether that access was possible, and I’m not going to pretend otherwise. What I can do is explain why a headline like that lands so hard right now, and why the answer has less to do with hackers in hoodies than with a boring question nobody wants to own.
Scale is a permissions problem, not a hacking problem
When you hear a number like trillions of records, your brain probably pictures an enormous effort. Months of work. A team. Something cinematic.
That’s usually backwards. Big numbers in cloud security almost never come from big effort. They come from one account, one token, or one app registration that was quietly given more reach than anyone intended. The volume isn’t the achievement. The volume is just what happens when a key fits a very large door.
This is the part that matters for anyone working with AI agents, which is most of us now, whether we chose it or not.
An agent is a user with no sense of restraint
Think about how you behave inside your work tools. You have access to shared drives you’ve never opened. Old project folders. Mailboxes you were added to for one meeting in 2023. You don’t read them, because you’re a person with limited time and no particular interest.
An AI agent has neither of those limits. Give it your credentials and it can read everything you technically can, as fast as the system will serve it up. It’s not being malicious. It’s being thorough, which is somehow worse, because “thorough” plus “over-permissioned” is how a modest account turns into a very large number.
So the question “could someone access 17 trillion records” is really the question “how many doors does one key open.” For agents, that’s not a hypothetical. It’s the configuration setting you skipped past.
The unglamorous updates are the actual story
Here’s what I find genuinely interesting. Alongside this discussion, Microsoft has been shipping a steady run of changes to Microsoft 365, Microsoft Teams, and Microsoft Entra ID, including new features and security measures, plus changes to data governance and support milestones. None of it is exciting. All of it points in the same direction.
- October 2026 brings inline DLP controls for prompts in Microsoft Foundry apps and agents, through Microsoft Purview. Translation: the company is putting data loss prevention checks on what gets typed into and handled by agents. That’s an admission that prompts are now a data pathway, not just a chat box.
- Microsoft Purview is adding retention based on “last accessed” for OneDrive and SharePoint files. Files nobody has touched in years are pure risk with no upside. Being able to age them out on access rather than creation date is a quiet but real reduction in how much there is to expose.
- Microsoft Teams is introducing a separate attendance report policy for events in October 2026. Smaller, more specific controls instead of one broad switch.
- Custom CSS positioning properties in branded sign-in are being retired. Sign-in pages are a favorite target for imitation, and less freedom to restyle them means fewer ways to make a fake look convincing.
- Copilot Chat Reports had a stretch where they may have been delayed for admins in North America and Europe, with the latest data showing as August 31, 2026. That issue is resolved, but it’s a useful reminder: your visibility into what an AI tool did is itself a system that can lag.
Every one of those is a narrower key or a smaller room. That’s what good security work actually looks like. Nobody writes a thriller about retention policies.
What to do with this if you’re not technical
You don’t need to audit anything. You need to ask three questions whenever an AI agent gets added to your workplace: What can it see? Who approved that? Can we check what it looked at?
If the answer to any of them is a shrug, that’s your finding. A number like 17 trillion isn’t a story about brilliance. It’s a story about nobody asking.
🕒 Published: