Your Microsoft tenant already holds the evidence. We collect it for you.
Connect Microsoft 365, Entra ID, Intune, Defender and Azure once — read-only — and around 36 automated checks run on a schedule, file dated evidence against your ISO 27001, SOC 2 and Cyber Essentials controls, and turn every failure into a tracked action with a named owner.
Most UK small and mid-sized organisations run on Microsoft. Identity is in Entra ID, laptops are managed by Intune, threat protection sits in Defender, and collaboration lives in Microsoft 365. Yet at audit time the same teams re-take the same screenshots, because nothing joins the tenant to the control.
Microsoft evidence automation closes that gap. Each check states plainly what it looks at, why an auditor cares, which clause it supports, and exactly where in the Microsoft admin estate a fix is made. Evidence is dated and retained, so you can show not just today's posture but that the control has operated over the certification period.
What we collect, service by service
Entra ID
MFA coverage across all users, privileged role membership, conditional access posture, legacy authentication, guest accounts, stale sign-ins and password policy.
Intune
Device compliance policies, enrolment coverage, disk encryption (BitLocker/FileVault), OS patch baselines, screen-lock configuration and non-compliant device counts.
Defender
Microsoft Secure Score trend, defender onboarding coverage, unresolved high-severity incidents, safe links and anti-phishing configuration.
Microsoft 365
External sharing controls, anonymous link policy, mailbox audit logging, retention configuration, licence assignment and admin account hygiene.
Azure
Storage account public access, subscription RBAC assignments, key vault protection settings and diagnostic logging on critical resources.
How it works
- Step 1
Connect the tenant
A Global Administrator approves read-only permissions once. Tenants that block third-party consent can use their own Entra app registration instead — the secret is stored server-side and never returned to the browser.
- Step 2
Collect on a schedule
Choose daily or weekly. Every run records a pass, warning or failure per check with the underlying numbers, and files dated evidence items into your library automatically.
- Step 3
Fix what fails
Any failing or warning check becomes a remediation action with a plain-English explanation, suggested owner, due date, implementation checklist and email reminders until it is closed.
- Step 4
Show the auditor
Export the full check register to CSV, or point the auditor at the mapped control with its evidence history attached. No screenshot hunt the week before the visit.
Evidence mapped to the clause
Collect once, satisfy several frameworks. A sample of the mapping applied automatically:
| Automated evidence | Supports |
|---|---|
| MFA registered and enforced for all users | ISO 27001 A.5.17 · SOC 2 CC6.1 · Cyber Essentials |
| Privileged role membership reviewed and minimal | ISO 27001 A.5.15, A.8.2 · SOC 2 CC6.3 |
| Conditional access blocks legacy authentication | ISO 27001 A.8.5 · SOC 2 CC6.6 |
| Devices encrypted and compliant with policy | ISO 27001 A.8.1, A.8.24 · Cyber Essentials |
| Secure Score trend and incident response | ISO 27001 A.5.24–A.5.26 · SOC 2 CC7.3 |
| External sharing and anonymous links controlled | ISO 27001 A.5.14, A.8.12 · SOC 2 CC6.7 |
| Azure storage not publicly accessible | ISO 27001 A.8.9, A.8.20 · SOC 2 CC6.6 |
Microsoft evidence automation FAQ
What access does ISO-STANDARD.app need to my Microsoft tenant?
Read-only application permissions only. We never request write access, never change tenant configuration and never read the contents of files, mailboxes or chats. Connection is by Global Administrator consent, or by your own Entra app registration if your tenant does not allow third-party consent.
Which controls does Microsoft evidence satisfy?
Around 36 automated checks map to ISO 27001:2022 Annex A controls (notably A.5.15–A.5.18 access control, A.8.1–A.8.9 technology controls), SOC 2 CC6 logical access and CC7 monitoring, Cyber Essentials technical controls, and ISO 42001 where AI services are in scope.
How often is evidence collected?
Daily or weekly on a schedule you choose, plus on-demand collection whenever you need a fresh snapshot before an audit. Each run is timestamped and filed into your evidence library automatically.
What happens when a check fails?
Failing and warning checks can be turned into a tracked remediation action in one click, complete with a plain-English explanation, the Microsoft portal deep link where the fix is made, a named owner, a due date and email reminders until it is closed.
Do I need Microsoft 365 E5 or a premium licence?
No. Most checks run on Business Premium and standard Entra ID P1 tenants. A small number of Defender and Identity Protection checks require higher licensing; where a capability is not licensed, the check is reported as not applicable rather than failing.
Is our tenant data stored?
We store the result of each check — a status, a short summary and the metrics behind it — not raw exports of your directory or device inventory. Data stays in UK/EU hosted infrastructure and is scoped to your workspace.
AI does the drafting. You keep the control — and the data.
AI that assists — not replaces
Assisted drafting for policies, risks, controls and buyer questionnaires. Every AI suggestion is reviewed and approved by you before it lands in the record.
Opt-in, workspace-scoped
AI features run only when you invoke them, only against the workspace you're in. We never mine your data to answer someone else's prompt.
Your data stays yours
Prompts routed via the AI Gateway to model providers whose API terms exclude your content from model training. Nothing is sold or shared for advertising.
Isolated by design
Row-level security enforces workspace boundaries at the database. MFA, SSO, audit logs and least-privilege roles govern who sees what.
We never sell personal information, never share it for advertising, and never use your workspace content to train third-party models. Full sub-processor list and Acceptable Use Policy on the Trust page.
Enterprise-grade governance — built for the SMEs and consultants enterprise GRC forgets.
I've spent 25 years in corporate governance — aligning technology, controls and compliance with what the business is actually trying to do. Time and again, the same pattern: the organisations that win new clients aren't the ones with the biggest GRC budget. They're the ones who can demonstrate trust on demand. This platform is the tool I wanted for the SMEs and consultants I've worked with — institutional-grade governance without an institutional price tag, built on the way audits and buyer reviews actually happen.