DORA compliance Microsoft 365

Your tenant is an ICT arrangement. DORA wants it in a register.

DORA (EU 2022/2554) has applied to financial entities since 17 January 2025, and its third-party pillar asks for a register of information covering every ICT arrangement that touches your data. Microsoft 365 is one of them - and so is every OAuth app consented into it and every external organisation it exchanges data with. 1Security measures DORA readiness from the tenant itself: requirement statuses per article, the register slice kept live instead of compiled annually, and a dated evidence pack for the competent authority.

The scenario

The regulator asks for the register. It was compiled last year.

DORA covers some twenty types of financial entities - banks, insurers, investment firms, payment and e-money institutions, crypto-asset service providers - and stands on five pillars: ICT risk management, incident reporting on a fixed initial, intermediate and final cadence, resilience testing, ICT third-party risk, and information sharing. Enforcement runs through national competent authorities, and the critical ICT providers it places under direct oversight can face periodic penalty payments of up to 1% of average daily worldwide turnover. The first thing a supervisor asks for is not a policy. It is the register of information, current.

Here is the part the annual-spreadsheet approach misses: most of the register is already observable. Articles 28 to 30 want every ICT arrangement listed with what it touches - and inside Microsoft 365 that answer is the app inventory and the external-domain map. Every OAuth app with its publisher, reach and the admin who consented it is an ICT service software-side; every organisation seen in guests, shared files and mail is one data-side. Across eleven regulations - DORA next to NIS2, GDPR, ISO/IEC 27001 and the EU AI Act - the obligations collapse into 15 shared requirements, 11 of them measurable directly from tenant data, so the register slice can be live rather than remembered.

The incident pillar runs on the same clock problem as every other regime: the initial, intermediate and final reports rest on evidence, and evidence normally lives in 90-day logs and disconnected admin centers. With up to three years of attributed activity history, reconstructing who did what, from where, touching which regulated data is a sitting, not a project - which is what the reporting cadence quietly assumes you can do.

The walkthrough

From supervisory letter to evidence pack, on screens.

Each beat is a screen with a filter and an artifact at the end, not a workshop.

  1. 01

    Open the DORA framework view

    The Compliance screen scores the tenant against DORA article by article, each article citing the shared requirements that satisfy it - measured statuses for log retention, access control, dormant accounts and the third-party inventories, attested statuses for the four documents. Not evaluated is never counted as a pass, and the worklist orders every open requirement by how many articles it unlocks.

  2. 02

    Build the register slice from what is observed

    The Apps screen lists every OAuth app and integration with publisher, access channel and the admin who consented it - the software half of the register of information. The Domains screen lists every external organisation observed in guests, shared files and mail, resolved to the company behind the domain, with configured standing next to observed activity and drift flagged.

  3. 03

    Drill the incident report before it is real

    Pick one account on the Activity Logs screen and produce its full attributed timeline - actor, resource, app, device, location - then everything it can still reach and how much of that carries regulated data. With up to three years of retained history on standard licenses, the drill takes a sitting, and the initial report deadline stops dictating panic.

  4. 04

    Export the dated evidence

    The whole status document is captured automatically every Monday and on demand, so what was our status on this date has a real answer. The per-framework evidence pack exports as a dated document and is served over the read-only REST API - the same artifact for the supervisor, the auditor and the board.

What makes it work

Three parts of the platform behind the DORA answer.

The same 15 requirements score NIS2, GDPR, ISO/IEC 27001 and the EU AI Act in the same pass - one fix moves every framework that cites it.

  • Compliance monitoring

    Eleven frameworks measured continuously from tenant data, with snapshots, a worklist and a per-framework evidence pack.

    Explore the feature
  • External domain monitoring

    Every organisation the tenant exchanges data with, resolved to a real company with drift flags - the data-side half of the register.

    Explore the feature
  • App governance

    Every third-party app and consent with publisher, reach and the person who let it in - the software-side half of the register.

    Explore the feature

FAQ

Common questions.

We are a small firm. Does DORA really apply to us?

DORA scales its demands - microenterprises are carved out of much of it and some small firms get a simplified risk framework - but the scoping call belongs to your counsel. The practical point stands either way: the register, the access control and the incident evidence DORA asks for are things a financial firm wants measured regardless of where the proportionality line falls.

Does this cover our core banking or trading systems?

No. We measure the Microsoft 365 side: identities, files, mail, apps, agents and the audit trail around them. Core platforms need their own evidence sources. What the tenant holds is the collaboration half of the register of information and a large share of the incident evidence, and the evidence pack is honest about that boundary.

Is Microsoft itself a critical ICT provider under DORA?

DORA gives European supervisors an oversight framework that designates critical ICT third-party providers, and large cloud providers are the category it was written for. Designation changes the obligations of Microsoft, not yours: your register entry, contractual provisions and exit thinking for the Microsoft 365 arrangement stay your responsibility either way.

Do we need E5 licenses for this?

No. The readiness measurement, the retained history and the evidence pack run on the standard read-only connection and the licenses you already own. Where a specific remediation does need a premium Microsoft SKU, the product says so on the action itself instead of letting you find out mid-fix.

How fast do we get the first readiness picture?

The same day the tenant is connected read-only. Readiness is computed from data the platform collects on its own, with deliberately conservative statuses - not evaluated never counts as a pass - so the first picture is one you can already show internally, and weekly snapshots start accumulating from there.

Meet the supervisor with the register already live.

Connect read-only and the DORA requirement statuses, the app and domain inventories and the first evidence pack land the same day - before you have remediated anything at all.

Or keep compiling the register of information once a year.