If your organisation runs on Microsoft 365, a large share of your audit evidence already sits in Entra ID, Purview and the Defender portal. For ISO 27001 surveillance you do not need an expensive GRC suite; you mainly need to know which evidence lives where and be able to export it reproducibly. This article shows which controls M365 covers and how to turn it into evidence a certification body recognises.
Which controls does Microsoft 365 cover?
A surprisingly large part of Annex A can be covered with standard M365:
- Access management (A.5.15–A.5.18): Entra roles, MFA reports, access reviews.
- Logging and monitoring (A.8.15–A.8.16): unified audit log, sign-in logs, Defender alerts.
- Data classification and DLP (A.5.12–A.5.13): Purview sensitivity labels and DLP policies.
- Configuration (A.8.9): Secure Score and conditional-access policies.
Link these sources to your Statement of Applicability so you know, per control, which export delivers the evidence.
Evidence auditors recognise
An auditor wants a sample, not a dump. Make sure you can show one representative example per source: a quarterly access review with approval, a sign-in log of a suspicious login with the follow-up, a DLP incident with resolution. The message is not “look how much we log”, but “look, this is what we saw and this is what we did about it”.
Build a reproducible evidence folder
The difference between stress and calm at an audit is preparation. Set fixed export moments — for example quarterly — and store the exports in an evidence folder with the same structure as your SoA. That way both your internal and external auditor find the evidence in the same place, and you can show it happens periodically and repeatably rather than once, just before the audit. Note briefly per export: which source, which period, who ran it.
Pitfalls
- Audit-log retention: it depends on your licence (sometimes only 90 days). Check it matches your own retention policy and what NIS2 or contracts require — otherwise you miss evidence exactly when you need it.
- Secure Score is a tool, not a standard: a high score is not a certificate and does not automatically cover your Annex A requirements.
- Orphaned accounts: make sure conditional-access policies and roles are correct for contractors, interns and externals too. Accounts left active after departure are a classic finding.
- Technology without process: M365 delivers the data, but the auditor also wants to see a human looking at it and deciding.
From evidence to demonstrable operation
Collecting evidence is step one; showing it works is step two. Take the key signals — access reviews, MFA coverage, DLP incidents, Secure Score trend — into your management review. That links the M365 data to decision-making and improvement, exactly the PDCA cycle ISO 27001 expects. It lifts your evidence from “we have logs” to “we act on what the logs say”.
Getting started
Start with an inventory: go through your applicable Annex A controls and note, per control, which M365 export delivers the evidence. Then schedule your first quarterly export. That alone makes your next surveillance audit noticeably calmer. Want to know more about audit preparation? See the ISO 27001 route or take the free readiness scan.
