Reference · Information security

Which Microsoft 365 signals become ISO audit evidence

If your organisation runs on Microsoft 365, a large share of the operational evidence an ISO 27001 auditor asks for already exists — it's just scattered across admin centres and not captured as dated records. This is a plain reference to which parts of the estate map to which controls, and the one step that turns a live setting into actual audit evidence.

Does ISO 27001 work with Microsoft 365?

Yes — and closely. ISO 27001 doesn't mandate any particular technology, but it does require you to evidence that your information security controls operate. Microsoft 365 is where many of those controls already live: identity, access, multi-factor authentication, threat protection, data handling, logging and device management are all configured and running in the tenant. That makes an M365 estate one of the richest sources of ISO 27001 operational evidence most organisations already own.

The mapping

The table below is a practical guide, not an exhaustive or official mapping — every audit is scoped to your organisation and your Statement of Applicability. It shows where common Microsoft 365 areas typically support ISO 27001 control themes.

A live setting is not, by itself, evidence. An auditor doesn't just want to see that MFA is on today — they want a dated record showing it was on during the audit period, tied to the relevant control, and kept. The gap between "the tenant is configured" and "we can prove it was" is where most teams lose time before an assessment.

Turning a setting into evidence: the four steps

Whatever tool you use, usable ISO evidence from Microsoft 365 needs four things:

Done by hand — exports into folders in a pre-audit scramble — this costs hours teams often don't have and goes stale as soon as the estate moves on. Done continuously, the trail simply exists when you need it: peace of mind at a glance, not a green tick that doesn't help the business.

What Microsoft 365 does not cover

The estate evidences operational controls, but ISO 27001 also has management-system records that no tenant produces for you: the Statement of Applicability, the risk assessment and treatment plan, your policies, internal audit reports, management review minutes and corrective actions. A complete ISMS needs both halves — the automated operational evidence and the human management-system records — in one place. For more on what assessors look for overall, see ISO 27001 evidence: what auditors actually want.

Where Kavorly fits

Kavorly reads your Microsoft 365 estate and does the capture-date-map-retain step automatically: evidence is collected from Entra, Defender, Purview, Intune and the audit logs, mapped to the controls it supports, dated and kept — so the operational trail builds itself as you work. The management-system records (SoA, risk, audits, reviews, actions) live in the same platform, so the whole ISMS is in one place rather than spread across admin centres and shared drives.

How the Microsoft 365 connection works → · See how Kavorly runs ISO 27001 →


This reference is a general introduction, not certification advice or an official control mapping. Map controls to your own Statement of Applicability, and refer to the published text of ISO/IEC 27001 or a certification body for authoritative requirements. Microsoft product capabilities vary by licence.

Next step

See how much evidence your estate already holds.

Check your ISO 27001 readiness free, or book a walkthrough to see Kavorly pull evidence from your own Microsoft 365.