Skip to content
Tenant Excellence

Applies toInternational

ISO 27001

Annex A technical controls of ISO/IEC 27001:2022, evaluated from Entra ID, Exchange Online, SharePoint, Intune, Defender and Azure settings.

From Complete

Scope as evaluated

  • Access control, authentication and privileged access (A.5, A.8)
  • Logging, monitoring and configuration management
  • Information transfer, email and data protection settings

Read from the tenant

  • Conditional Access, MFA and role assignments
  • Audit-log and retention configuration
  • Sharing, DLP and encryption settings

Sample controls

  • A.8.5 Secure authentication
  • A.8.15 Logging
  • A.5.15 Access control
Results are configuration indications drawn from your tenant. They are not an audit opinion or a certification.

In depth

Give the auditor a link, not a folder

Every covered control shows the data Microsoft Graph returned and the endpoint it came from. One click creates a read-only snapshot for one framework; it needs no account and expires after 24 hours.

  • Structured proof per control, with its Graph or ARM source
  • Scoped to one framework, read-only, no sign-in for the auditor
  • Expires after 24 hours; creation is written to the audit log
Learn more

Questions

Questions about ISO 27001

Does a covered control mean we meet ISO 27001?

No. It means the tenant setting behind that control matches the expected value at assessment time. Certification is a decision for your auditor.

Which Annex A controls are out of scope?

Organisational controls that cannot be read from configuration, such as policies, training or supplier contracts. They appear as not assessed.

Can we attach our own evidence?

Yes. Any control accepts text or screenshot evidence, kept with the tenant record and shown in the auditor view.

Request a demo

Which frameworks do you report against?

Tell us in the demo request and we will show the matching controls on a demo tenant.

0 / 2,000