How MSPs are shaping the future of the digital workplace

Here’s why businesses are increasingly turning to outside experts for AI support and what to expect of the digital workplace as those experts modernize their service offerings in response.According to JLL’s 2026 Future of Work Survey, most C-suite and corporate real estate leaders now expect AI to redesign roles and grow headcount rather than reduce it. While this is likely a relief for those who previously worried about AI making their roles obsolete, it also creates new pressure on organisations to integrate AI into their operations. This pressure is increasing the demand across the board for managed service providers (MSPs). At the same time, it is increasing the scope of responsibilities modern MSPs are now expected to offer. Here’s why businesses are increasingly turning to outside experts for AI support and what to expect of the digital workplace as those experts modernize their service offerings in response.

The clearest example of the shift described above involves Microsoft Copilot, an AI assistant that exists specifically to support businesses running in Microsoft 365 environments. Copilot provides meaningful advantages to these organisations compared to other consumer-grade AI tools, but buying a licence alone does not guarantee readiness. Copilot functions according to the rules of the environment where it is deployed: it reads what each user is already permitted to read, applies whatever data protection policies are already configured, and operates within whatever identity model the organisation has established.

An estate with strong governance, clean permissions, well-managed identity, and standardised Microsoft 365 configurations gets an AI assistant that behaves predictably. Conversely, an estate that has grown through years of restructures, acquisitions, and one-off exceptions often lacks key policies or configurations that should prevent Copilot from being able to access privileged data. In these environments, the wrong prompt from anyone in the organisation can potentially cause a breach.

The patterns behind this are remarkably consistent. Almost every unprepared tenant I have ever seen contains at least one legacy site shared with “everyone except external users,” folders with broad permissions inherited years ago because somebody shared a single document with their manager, or accounts belonging to people who left the business but were never properly deprovisioned. Acquisitions are the worst offenders, because permissions tend to be imported wholesale during migration and nobody revisits them once the deal closes.

None of this is anyone’s fault, and none of it mattered much when finding a document required knowing where to look. But all of these are potential data security risks when an AI can access files across an organization’s Microsoft 365 environment.

In most of the cases I’ve witnessed, the consequences of these errors are relatively minor. They involve a pilot user finding a document they were never meant to see, a leadership team discovering that a superseded policy is being summarised as current, or an internal audit conversation that stops a rollout for a quarter while permissions are reviewed. But the risk exists nonetheless.

More important is the fact that even in such incidents where the technical damage may be limited, the damage to confidence often is not. People who watch an AI assistant make privacy or security errors soon after launch are less likely to rely on it, even weeks or months later when the underlying data has been tidied. This can hamper Copilot adoption and threaten ROI for the organisation.

So while businesses cannot afford to ignore the capabilities tools like Copilot provide, they also cannot afford to incur the consequences that come with poorly deploying or maintaining them. Many have turned to MSPs for precisely this kind of support.

 

How Managed Services Moved from the Sidelines to Centre Stage

The traditional relationship between businesses and their IT providers was primarily reactive. Something broke, a ticket was raised, an engineer fixed it, and success was measured by how quickly they were able to close the loop.

That kind of reactive, break-fix support still exists, but it is fundamentally different from a managed service model. Today, the role of an MSP extends well beyond resolving technical issues. Increasingly, MSPs help determine whether organisations can adopt AI safely: they are responsible for identity architecture, sharing defaults, device compliance, data lifecycles, and policy configurations across every tenant they manage.

These are not set-and-forget tasks; they are ongoing responsibilities that require significant time and expertise to correctly perform. As more businesses realise that this kind of expertise is necessary for them to reap the benefits of AI tools like Copilot while mitigating the risks, a brand new use case for MSPs has emerged.

 

With Great Power Comes Great Responsibility: How Modern MSPs Are Meeting the Moment

Although this shift has created unprecedented opportunity for MSPs, it has also posed challenges. A single organisation tidying its own permissions is a finite project with an end date, but an MSP must often perform that work across dozens or hundreds of tenants simultaneously.

Each tenant comes with its own history, its own accumulated exceptions, and its own rate of drift away from whatever baseline was applied at onboarding. Managing each one manually through separate admin portals stops scaling quickly.

Expectations around response have also tightened. A client that has handed over identity, endpoints, and data governance reasonably expects its provider to notice when something goes wrong, and to resolve the issue quickly.

The result of these pressures is that while MSPs are now considered essential partners for a wider range of businesses, they must also adapt to the demands of a changing digital landscape. In response, many have embraced multi-tenant management platforms that provide single-pane visibility for their entire tenant stack, allowing them to apply security baselines, identify configuration drift, and remediate at scale rather than one portal at a time.

Platforms with these capabilities enable MSPs to offer Copilot readiness assessment as a relatively cost-effective service, lowering the barrier to entry for smaller organisations. Many now include threat detection and response options as well, which streamline a provider’s ability to react in cases where gaps in policies, permissions, or configurations still allow AI to access something it shouldn’t be able to touch.

Tooling only addresses half of the problem, though. In my view, organisations planning to embrace AI tools should treat readiness as a governance problem with a technology component rather than a technology problem with a governance appendix. If their internal teams need support keeping their cloud environments secure enough to safely use AI or remediating incidents, they need to partner with experts who bring efficient solutions to the table.

Change management is no longer the part of a workplace technology rollout that gets budgeted last and cut first. Where AI is concerned, it may actually determine the outcome more directly than the technology itself does.

Image: JLL Manchester