Built for Microsoft-centric UK organisations

Your Microsoft tenant already holds the evidence. We collect it for you.

Connect Microsoft 365, Entra ID, Intune, Defender and Azure once — read-only — and around 36 automated checks run on a schedule, file dated evidence against your ISO 27001, SOC 2 and Cyber Essentials controls, and turn every failure into a tracked action with a named owner.

36+
automated Microsoft checks
Read-only
no write permissions requested
Daily
scheduled evidence collection
1 click
failure to tracked action

Most UK small and mid-sized organisations run on Microsoft. Identity is in Entra ID, laptops are managed by Intune, threat protection sits in Defender, and collaboration lives in Microsoft 365. Yet at audit time the same teams re-take the same screenshots, because nothing joins the tenant to the control.

Microsoft evidence automation closes that gap. Each check states plainly what it looks at, why an auditor cares, which clause it supports, and exactly where in the Microsoft admin estate a fix is made. Evidence is dated and retained, so you can show not just today's posture but that the control has operated over the certification period.

What we collect, service by service

Entra ID

MFA coverage across all users, privileged role membership, conditional access posture, legacy authentication, guest accounts, stale sign-ins and password policy.

Intune

Device compliance policies, enrolment coverage, disk encryption (BitLocker/FileVault), OS patch baselines, screen-lock configuration and non-compliant device counts.

Defender

Microsoft Secure Score trend, defender onboarding coverage, unresolved high-severity incidents, safe links and anti-phishing configuration.

Microsoft 365

External sharing controls, anonymous link policy, mailbox audit logging, retention configuration, licence assignment and admin account hygiene.

Azure

Storage account public access, subscription RBAC assignments, key vault protection settings and diagnostic logging on critical resources.

How it works

  1. Step 1

    Connect the tenant

    A Global Administrator approves read-only permissions once. Tenants that block third-party consent can use their own Entra app registration instead — the secret is stored server-side and never returned to the browser.

  2. Step 2

    Collect on a schedule

    Choose daily or weekly. Every run records a pass, warning or failure per check with the underlying numbers, and files dated evidence items into your library automatically.

  3. Step 3

    Fix what fails

    Any failing or warning check becomes a remediation action with a plain-English explanation, suggested owner, due date, implementation checklist and email reminders until it is closed.

  4. Step 4

    Show the auditor

    Export the full check register to CSV, or point the auditor at the mapped control with its evidence history attached. No screenshot hunt the week before the visit.

Evidence mapped to the clause

Collect once, satisfy several frameworks. A sample of the mapping applied automatically:

Automated evidenceSupports
MFA registered and enforced for all usersISO 27001 A.5.17 · SOC 2 CC6.1 · Cyber Essentials
Privileged role membership reviewed and minimalISO 27001 A.5.15, A.8.2 · SOC 2 CC6.3
Conditional access blocks legacy authenticationISO 27001 A.8.5 · SOC 2 CC6.6
Devices encrypted and compliant with policyISO 27001 A.8.1, A.8.24 · Cyber Essentials
Secure Score trend and incident responseISO 27001 A.5.24–A.5.26 · SOC 2 CC7.3
External sharing and anonymous links controlledISO 27001 A.5.14, A.8.12 · SOC 2 CC6.7
Azure storage not publicly accessibleISO 27001 A.8.9, A.8.20 · SOC 2 CC6.6

Microsoft evidence automation FAQ

What access does ISO-STANDARD.app need to my Microsoft tenant?

Read-only application permissions only. We never request write access, never change tenant configuration and never read the contents of files, mailboxes or chats. Connection is by Global Administrator consent, or by your own Entra app registration if your tenant does not allow third-party consent.

Which controls does Microsoft evidence satisfy?

Around 36 automated checks map to ISO 27001:2022 Annex A controls (notably A.5.15–A.5.18 access control, A.8.1–A.8.9 technology controls), SOC 2 CC6 logical access and CC7 monitoring, Cyber Essentials technical controls, and ISO 42001 where AI services are in scope.

How often is evidence collected?

Daily or weekly on a schedule you choose, plus on-demand collection whenever you need a fresh snapshot before an audit. Each run is timestamped and filed into your evidence library automatically.

What happens when a check fails?

Failing and warning checks can be turned into a tracked remediation action in one click, complete with a plain-English explanation, the Microsoft portal deep link where the fix is made, a named owner, a due date and email reminders until it is closed.

Do I need Microsoft 365 E5 or a premium licence?

No. Most checks run on Business Premium and standard Entra ID P1 tenants. A small number of Defender and Identity Protection checks require higher licensing; where a capability is not licensed, the check is reported as not applicable rather than failing.

Is our tenant data stored?

We store the result of each check — a status, a short summary and the metrics behind it — not raw exports of your directory or device inventory. Data stays in UK/EU hosted infrastructure and is scoped to your workspace.

Turn your Microsoft tenant into your audit file

Connect in minutes, collect tonight, and walk into your next audit with dated evidence already filed against every control.

AI-enabled — privacy-respecting

AI does the drafting. You keep the control — and the data.

How we handle data →
  • AI that assists — not replaces

    Assisted drafting for policies, risks, controls and buyer questionnaires. Every AI suggestion is reviewed and approved by you before it lands in the record.

  • Opt-in, workspace-scoped

    AI features run only when you invoke them, only against the workspace you're in. We never mine your data to answer someone else's prompt.

  • Your data stays yours

    Prompts routed via the AI Gateway to model providers whose API terms exclude your content from model training. Nothing is sold or shared for advertising.

  • Isolated by design

    Row-level security enforces workspace boundaries at the database. MFA, SSO, audit logs and least-privilege roles govern who sees what.

We never sell personal information, never share it for advertising, and never use your workspace content to train third-party models. Full sub-processor list and Acceptable Use Policy on the Trust page.

MM
Michael McCarroll
Founder · 25+ years
IT governance · Information security · AI
Why this platform exists

Enterprise-grade governance — built for the SMEs and consultants enterprise GRC forgets.

I've spent 25 years in corporate governance — aligning technology, controls and compliance with what the business is actually trying to do. Time and again, the same pattern: the organisations that win new clients aren't the ones with the biggest GRC budget. They're the ones who can demonstrate trust on demand. This platform is the tool I wanted for the SMEs and consultants I've worked with — institutional-grade governance without an institutional price tag, built on the way audits and buyer reviews actually happen.

© 2026 ISO-STANDARD.app · Intelligent compliance software. Practical governance support. Human-led accountability.