m365expertise MICROSOFT SECURITY EXPERTISE
Home · Blog · Compliance
Compliance

Security audits for NIS2 and ISO 27001 compliance

m365expertise·7 April 2026·7 min

Regulations like NIS2 and standards like ISO 27001 increasingly demand evidence, not intentions. A documented, repeatable audit of your Microsoft environment — the tenant and the directory — is one of the most practical ways to produce that evidence.

The shift to evidence

Both NIS2 and ISO 27001 share a theme: it is no longer enough to say you manage risk — you have to demonstrate it. That means documented controls, measurable posture and the ability to show improvement over time. A structured audit produces exactly this kind of artefact.

What NIS2 expects

NIS2 raises the bar on cybersecurity risk management for a broad range of organisations, with real accountability at management level. Among its themes: risk analysis, access control, incident handling readiness and supply-chain security. A Microsoft-environment audit contributes directly to several of these — particularly access control and identity. That means the cloud tenant, but also the on-premises directory that still authenticates most of the estate.

Not legal advice. NIS2 obligations depend on your sector, size and jurisdiction. An audit supports compliance with the technical, identity-related aspects; it does not replace a full legal and organisational assessment.

How an audit maps to ISO 27001

ISO 27001 annex A includes controls on access management, privileged access, logging and monitoring, and configuration. A Microsoft security audit provides technical evidence behind these controls: who has privileged access — in the tenant and in the directory — whether MFA is enforced, how logs are retained, and how configuration compares to a documented baseline. That evidence feeds directly into your ISMS documentation and an external assessment.

Two perimeters, one body of evidence

An organisation running Microsoft rarely runs only one of the two. The cloud tenant and the on-premises directory each carry their own share of the requirement, and an assessor looking only at the first will miss where most of the risk actually sits.

PerimeterWhat it contributes to the requirement
Entra ID & Microsoft 365Authentication strength, Conditional Access, privileged roles, application consent, guest access, mailbox and sharing policy, audit log retention.
Active DirectoryPrivileged group membership, service accounts, ACL delegations, Kerberos configuration, certificate templates, trusts, LAPS coverage — and the escalation paths that connect them.

The mapping to frameworks is the same in both, which is what makes the evidence add up rather than sit in two separate piles.

Why "defensible" matters here

For both regimes, the value of an audit is only as good as its traceability. A score with a documented methodology, controls mapped to recognised frameworks, and a per-control reference is one you can put in front of an assessor. A vague checklist is not.

Repeatability and trend

Compliance is not a one-off. Both NIS2 and ISO 27001 assume ongoing management. Running the same audit periodically — and comparing results over time — demonstrates continuous improvement, which is exactly what assessors and regulators want to see. "We were at 54%, we are now at 78%, here is the evidence" is a powerful statement.

Practical starting point

  1. Run a baseline audit on the two perimeters — the cloud tenant and the directory.
  2. Map the findings to the relevant ISO 27001 annex A controls or NIS2 themes.
  3. Remediate fundamentals first, tracking the weighted score.
  4. Re-audit on a schedule and keep the reports as evidence.
All articles
23 articles on Microsoft security auditing.
Back to the blog →