How to produce DORA audit evidence in Microsoft 365
A process for producing the documented, retained evidence DORA expects from a Microsoft 365 estate: map requirements to controls, capture configuration baselines, retain access and change logs, and package it for auditors.
DORA evidence in Microsoft 365 is the documented, retained proof that connects tenant configuration and activity to the Digital Operational Resilience Act's ICT risk and resilience requirements. It is less about any single control and more about the audit trail: showing who had access, what changed, and how issues were handled, over time. Producing it reliably means capturing configuration, permissions, and activity as durable, reviewable records rather than reconstructing them under audit pressure.
The pattern from the first year of DORA enforcement in financial services is consistent: the gaps are rarely in the technology choices, they are in the evidence trail that connects Microsoft 365 configuration to DORA’s ICT risk and resilience requirements.
That reframes the work. Good configuration is necessary but not sufficient. You also have to demonstrate control over time: who had access, what changed, and how issues were handled. The steps below build that evidence continuously, so an audit becomes a packaging exercise rather than a reconstruction under pressure.
Steps
-
Map DORA requirements to M365 controls
Translate the relevant DORA ICT risk and resilience requirements into the concrete Microsoft 365 controls and configurations that satisfy them, so every requirement has an owner and a control it maps to.
-
Capture configuration baselines
Record the baseline configuration of the controls that matter, so you can show what 'good' looked like and detect drift away from it, rather than only seeing the current state.
-
Retain access and change logs
Ensure access grants, permission changes, sharing events, and administrative actions are captured and retained for the period DORA expects, because the audit trail is the evidence.
-
Review evidence on a cadence
Review the collected evidence on a fixed schedule, not just before an audit, so gaps are found and closed while they are cheap to fix and the trail stays continuous.
-
Package for auditors
Assemble the mapped controls, baselines, and logs into a reviewable package an auditor can follow from requirement to proof, turning the audit into a handover rather than an investigation.