MFA coverage
Who actually has multi-factor authentication enforced across your users. Evidence toward A.8.5 Secure authentication.
Microsoft 365 · Entra · SharePoint · Teams
MFA policies, admin roles, device compliance, Secure Score — the technical evidence an ISO 27001 auditor asks for is already sitting in your Microsoft 365 tenant. Both Kavorly Compliance and Kavorly Ops connect to and read it straight from your own tenant, every day, and turn it into audit-ready proof you can trust at a glance — without hours of manual exports before surveillance.
Sign in with Microsoft
Kavorly supports single sign-on with Microsoft Entra (Azure AD), so your team uses their existing Microsoft 365 work or school accounts — no new passwords to manage. Sign-in matches against your directory identity, not a free-form email address, so a changed or spoofed address can't be used to impersonate a real user.
Evidence that collects itself — daily
Kavorly reads your live Microsoft 365 security posture through the Microsoft Graph every day, using your own tenant — in both Kavorly Compliance and Kavorly Ops. Each signal is automatically mapped to the ISO 27001:2022 Annex A control it evidences, so your technical controls are backed by dated, current proof — not a pile of one-off exports that go stale the moment the day job moves on. In Kavorly Ops, the same signals are collected and shown as your live Microsoft 365 security posture, and mapped to ISO 27001 wherever your organisation runs it — never dressed up as a control claim for a standard it doesn't belong to.
Who actually has multi-factor authentication enforced across your users. Evidence toward A.8.5 Secure authentication.
Who holds elevated directory roles, and how many. Evidence toward A.8.2 Privileged access rights.
Which enrolled devices meet your compliance policies. Evidence toward A.8.1 User endpoint devices.
Microsoft's own measure of your security posture, tracked over time. Evidence toward A.8.8 Technical vulnerabilities.
Accounts that haven't signed in and should be reviewed or removed. Evidence toward A.5.18 Access rights.
The access policies that gate sign-in by risk, location and device. Evidence toward A.5.15 Access control.
External guests with access to your tenant, surfaced for review. Evidence toward A.5.16 Identity management.
The difference that matters
Some tools will show a control as "passed" whether or not they could actually read the underlying data. A missing permission or licence quietly becomes a green tick — which looks tidy on a dashboard but doesn't help when someone asks how it was measured, or what to fix next.
If Kavorly can't read a signal — a Graph permission or licence you haven't granted yet — it shows a clear warning that names the exact permission to grant. It never invents a pass. What you see is what your tenant actually reports, or an honest "we couldn't check this yet" — so you know you're looking at real posture, not a box that only looks complete.
SharePoint, governed
Point Kavorly at the SharePoint files that are your policies and records. It works on least-privilege Sites.Selected access — Kavorly can only see the specific sites you grant, never your whole tenant — and it verifies that a drive genuinely belongs to your site before it touches anything.
Link a signed-off document once, so the record in Kavorly always points at the real source of truth in SharePoint.
Get flagged the moment the live file moves away from the version you approved — no silent changes slipping past a review.
Bring documents across in bulk and let Kavorly's AI suggest how each one is classified, so you're not sorting a library by hand.
When you ask, Kavorly's AI reads the contents of a linked file on demand to help you place and understand it — fetched when needed, governed and access-logged.
Kavorly warns you before the credential behind your SharePoint connection expires, so the link never breaks silently.
Spot where a file's real placement or permissions don't match how it's meant to be governed.
Your tenant, your data
Your data is kept to your organisation — never mixed in with another customer's.
Kavorly asks only for the permissions it needs to read the signals it shows you — SharePoint access is limited to the specific sites you choose.
Connecting requires a Microsoft 365 administrator to grant consent — a deliberate, single approval, nothing switched on behind your back.
Outbound connections are checked against a safe host allowlist to guard against server-side request forgery.
Alerts where you work
Kavorly sends notifications by email when a finding or control needs attention, so people see it in the Microsoft estate they already use.
Next step
Book a walkthrough and we'll show you the signals Kavorly reads from a tenant like yours. The free three-minute check is a self-score of your ISO 27001 (or 9001 / Cyber Essentials) system — ten questions, no sign-up, and it does not connect to Microsoft 365.