Microsoft 365 compliance monitoring

Eleven regulations, measured from your tenant - not a spreadsheet.

NIS2, GDPR, DORA, the EU AI Act, ISO 27001 and six more all ask about the same tenant. 1Security evaluates one shared set of 15 requirements - 11 of them measured live from tenant data, 4 recorded as attestations - and maps the result onto every framework that cites them. You connect read-only, and before anything has been remediated you can already put a dated, honest readiness picture in front of a regulator.

  • 11 frameworks
    EU AI Act, NIS2, GDPR, DORA, SOC 2, NIST CSF 2.0, HIPAA, both ISO standards and both Polish acts
  • 15 requirements
    one shared set behind every framework - fix a requirement once and every article citing it moves
  • 11 of 15
    requirements measured live by an evaluator running against your tenant - not self-graded

The problem

Every framework asks the same questions. You keep answering them separately.

Until now, Microsoft 365 compliance monitoring has mostly meant a ritual: a consultant, a spreadsheet, and weeks of mapping controls to paragraphs by hand - then the same weeks again for the next regulation. NIS2 asks about supply-chain security, DORA asks about ICT third-party risk, GDPR asks about processors, ISO 27001 has two Annex A controls for suppliers. Four framings, one underlying question, four separate proofs.

The mapping also goes stale the day it is finished. A spreadsheet records what someone believed in March. The tenant kept moving: accounts went dormant, an agent lost its owner, a blocked domain stayed active. Self-graded checklists have no mechanism for noticing.

Here is the arithmetic nobody prices in: across the eleven frameworks 1Security evaluates, all the cited controls collapse into 15 shared requirements - things an organization actually does, like "every AI agent has an accountable person" or "activity logs are retained six months". And 11 of those 15 are measurable directly from tenant data. Most of a compliance program is not paperwork. It is tenant facts, and tenant facts can be watched.

What you get

One evaluation, mapped onto every framework that cites it.

Requirements are evaluated once, continuously. Frameworks are views over the same verdicts - so the work is deduplicated by construction.

  • A crosswalk instead of eleven checklists

    Each article in each framework names the requirements that satisfy it, and its status is the worst status among them. Fix a requirement once - an accountable owner on every agent, say - and the EU AI Act, KRiBSI and ISO/IEC 42001 articles citing it move together.

  • Measured, not self-graded

    11 requirements are checked live by an evaluator: agent ownership, log retention against the 183-day floor, restricted-data reachability, the third-party app inventory, external domains, monitoring freshness, protecting labels, device compliance, dormant accounts, Conditional Access coverage, captured agent instructions.

  • Statuses that under-promise

    Met, at risk, not met, not evaluated - and "not evaluated" is honest, never a pass. A verdict that will be shown to an auditor is deliberately conservative, so the number you present is one you can defend.

  • A worklist ranked by what it unlocks

    Every open requirement appears once, worst status first, ordered by how many articles in your scope it closes - with chips naming the frameworks it satisfies, like "NIS2 ×2, DORA, ISO 27001". "What should we fix next" becomes a sorted list.

  • Snapshots and evidence packs

    The whole status document is captured automatically every Monday and on demand. The overview shows what changed since the last capture, and each framework exports a dated evidence pack - the same document the API serves.

  • Frameworks you have not adopted, scored anyway

    Everything outside your scope keeps being evaluated in the background and shows its own readiness percentage - so how close you already are on, say, ISO 27001 is visible before anyone commits to the certification project.

How deep it goes

From a supply-chain article to the two inventories that answer it.

One example, followed end to end - the control that appears in more frameworks than any other.

Every major framework carries a supply-chain control: NIS2 Article 21(2)(d), DORA Article 28, GDPR Article 28, ISO 27001 A.5.19 and A.5.23, ISO/IEC 42001 A.10, SOC 2 CC9.2, NIST CSF 2.0 GV.SC-07, HIPAA business associates. They all reduce to two questions: who has access to us, and who do we hand data to. The screen feeds those articles from both directions - the third-party application inventory for software coming in, including shadow apps nobody approved, and the external domain inventory for data going out, with declared sharing rules checked against observed activity.

Click any requirement and the panel shows its verdict and why, in plain language, with a progress bar where one makes sense - "12 of 15 agents have an accountable person" - plus the exact measurement, the numbers behind the verdict, and next-step links into the screens where the underlying data lives. At the bottom: every article across every framework this requirement satisfies, your scope first.

The 4 manual requirements - an AI impact assessment, an AI usage policy, an incident response procedure, risk management documentation - carry an attestation form instead: status, owner, next review date, an evidence link. One attestation counts in every framework that cites the document. Measured requirements cannot be attested - the data decides, not a person.

In practice

Four steps from first visit to a document an auditor accepts.

The screen is useful on day one, before anything has been fixed.

  1. 01

    Pick your frameworks

    Open Compliance and choose your scope in the framework picker - cards grouped by region, each with who it applies to, its article count and a readiness bar you can inspect before adopting. Until you choose, a sensible default scope applies.

  2. 02

    Read the worklist, not eleven checklists

    Four tiles count your requirements by status; "What to fix" lists every open one exactly once, ranked by how many articles it unlocks. The top row is your best next hour of compliance work.

  3. 03

    Fix where the data lives

    Each requirement links into the screen that moves it - assign owners on Agents, resolve contradictions on Domains, expire what reaches restricted types. As each fix lands, every citing article recomputes on its own.

  4. 04

    Snapshot it and hand it over

    Take a snapshot, export the framework's evidence pack, and answer "what was our status on this date" with a dated document instead of a recollection. The same data is served over the API for whoever asks programmatically.

The difference

What continuous measurement adds over a compliance spreadsheet

The spreadsheet records an opinion about a date. The evaluator records the tenant.

  • One set of 15 requirements behind all eleven frameworks - no control is re-proven per regulation
  • 11 requirements measured live from tenant data; only 4 rely on a human attestation
  • Article status computed as the worst of its cited requirements - never rounded up
  • "Not evaluated" as an honest state that is never counted as a pass
  • A deduplicated worklist ranked by articles unlocked, with framework chips per fix
  • Supply-chain articles fed from both inventories - third-party apps in, external domains out
  • Automatic Monday snapshots plus on-demand, with change-since-last-capture on the overview
  • Per-framework evidence packs as dated exports, also served over the API
  • Out-of-scope frameworks evaluated in the background with their own readiness percentage

Scope and honesty

Computed from data 1Security already collects.

There is nothing to configure, no questionnaire to fill in and no project to run first. Scope selection and the four attestations are the only human input, and neither is required for the screen to be useful on day one. An organization connects its tenant read-only and can put a dated readiness picture in front of a regulator before it has changed a single setting.

  • 183 days
    the activity-log retention floor the evaluator checks - the six-month line the EU AI Act draws
  • 4 statuses
    met, at risk, not met, not evaluated - deliberately conservative, because auditors re-check
  • 52 / year
    automatic Monday snapshots, plus on-demand captures whenever a dated record is needed

Related

Where the verdicts come from

The compliance view reads controls other parts of the product maintain. These three feed more articles than anything else.

  • AI data restriction

    The declared restrictions behind "restricted data types stay unreachable" - with the attestation trail.

    See restrictions
  • App governance

    The third-party application inventory that answers every supply-chain article's first question.

    See app governance
  • AI agent inventory

    Every agent with its owner - the population behind the accountable-person requirement.

    See agents

FAQ

Questions teams ask first

Does this replace Microsoft Purview Compliance Manager?

They answer different questions. Compliance Manager scores your Microsoft 365 configuration against recommended improvement actions and is genuinely useful for that. 1Security measures observed tenant facts - who actually reaches restricted data, which agents actually lack an owner, which blocked domains are still active - and maps one shared set of requirements onto eleven frameworks, including the two Polish acts. Many customers run both.

Do we need an E5 license or Purview for this?

No. The evaluator runs on data 1Security collects through its read-only connection, which works on standard licensing. Where a requirement depends on an optional Microsoft signal - Intune device compliance, for instance - the requirement honestly reports "not evaluated" rather than guessing.

Is "not evaluated" counted against us?

It is never counted as a pass, and it is not a fail either - it means there is no data yet, or a manual requirement has not been attested. Readiness percentages are computed from met, at risk and not met only. The conservative arithmetic is the point: the number you show an auditor should under-promise.

We have not adopted ISO 27001 yet. Can we see where we stand?

Yes. Frameworks outside your scope keep being evaluated in the background and appear with their own readiness percentage. You can open any framework's articles, see which requirements already hold, and decide whether the certification project is a quarter of work or a year - before committing to it.

Who writes the four attested documents?

Your organization does - an AI impact assessment, an AI usage policy and register, an incident response procedure, and risk management documentation are things a regulator expects a human to own. The compliance officer records each attestation once, with owner, review date and an evidence link, and it counts in every framework that cites the document.

See your readiness before the auditor asks for it.

Connect read-only and the evaluator starts scoring all eleven frameworks against your tenant - the worklist, the snapshots and the evidence packs come with it.

Or keep re-mapping the same controls, framework by framework.