Reference · Information security
Which Microsoft 365 signals become ISO audit evidence
If your organisation runs on Microsoft 365, a large share of the operational evidence an ISO 27001 auditor asks for already exists — it's just scattered across admin centres and not captured as dated records. This is a plain reference to which parts of the estate map to which controls, and the one step that turns a live setting into actual audit evidence.
Does ISO 27001 work with Microsoft 365?
Yes — and closely. ISO 27001 doesn't mandate any particular technology, but it does require you to evidence that your information security controls operate. Microsoft 365 is where many of those controls already live: identity, access, multi-factor authentication, threat protection, data handling, logging and device management are all configured and running in the tenant. That makes an M365 estate one of the richest sources of ISO 27001 operational evidence most organisations already own.
The mapping
The table below is a practical guide, not an exhaustive or official mapping — every audit is scoped to your organisation and your Statement of Applicability. It shows where common Microsoft 365 areas typically support ISO 27001 control themes.
| Microsoft 365 area | What it shows | ISO 27001 control theme it supports |
|---|---|---|
| Entra ID (users, groups, roles) | Who has access to what; joiners, movers, leavers; privileged roles | Access control; identity management |
| Entra Conditional Access & MFA | Multi-factor coverage; access conditions; sign-in activity | Authentication; secure access |
| Entra access reviews | Evidence access is reviewed periodically | Review of access rights |
| Microsoft Defender | Anti-malware configuration and detections | Protection against malware |
| Microsoft Purview | Data loss prevention, retention, sensitivity labels | Information handling & classification |
| Microsoft Intune | Device compliance and configuration baselines | Endpoint / device security |
| Unified audit log | Tenant-wide activity and events | Logging & monitoring |
| Microsoft 365 backup / retention | Retention and recovery configuration | Backup & availability |
A live setting is not, by itself, evidence. An auditor doesn't just want to see that MFA is on today — they want a dated record showing it was on during the audit period, tied to the relevant control, and kept. The gap between "the tenant is configured" and "we can prove it was" is where most teams lose time before an assessment.
Turning a setting into evidence: the four steps
Whatever tool you use, usable ISO evidence from Microsoft 365 needs four things:
- Capture — take the setting or report out of the admin centre as a record, not a live view.
- Date it — stamp when it was captured, so it proves the state during the audit period.
- Map it — tie it to the specific control it evidences, so the assessor can follow the trail.
- Retain it — keep it so the picture holds up months later, at surveillance audits too.
Done by hand — exports into folders in a pre-audit scramble — this costs hours teams often don't have and goes stale as soon as the estate moves on. Done continuously, the trail simply exists when you need it: peace of mind at a glance, not a green tick that doesn't help the business.
What Microsoft 365 does not cover
The estate evidences operational controls, but ISO 27001 also has management-system records that no tenant produces for you: the Statement of Applicability, the risk assessment and treatment plan, your policies, internal audit reports, management review minutes and corrective actions. A complete ISMS needs both halves — the automated operational evidence and the human management-system records — in one place. For more on what assessors look for overall, see ISO 27001 evidence: what auditors actually want.
Where Kavorly fits
Kavorly reads your Microsoft 365 estate and does the capture-date-map-retain step automatically: evidence is collected from Entra, Defender, Purview, Intune and the audit logs, mapped to the controls it supports, dated and kept — so the operational trail builds itself as you work. The management-system records (SoA, risk, audits, reviews, actions) live in the same platform, so the whole ISMS is in one place rather than spread across admin centres and shared drives.
How the Microsoft 365 connection works → · See how Kavorly runs ISO 27001 →
This reference is a general introduction, not certification advice or an official control mapping. Map controls to your own Statement of Applicability, and refer to the published text of ISO/IEC 27001 or a certification body for authoritative requirements. Microsoft product capabilities vary by licence.