Skip to content
Back to the Handbook
Practitioner Guide - 2026 EditionPublished edition

Microsoft 365 Tenant Hardening

Mapped to DORA, NIS2 and NIST CSF 2.0

A practitioner field guide for regulated EU operators running Microsoft 365. Maps DORA Article 9, NIS2 Article 21, NIST CSF 2.0 and the source-linked ITS-M365 control set to tenant controls, evidence and operating routines.

Preview a real page

Stripe checkout. The personalised PDF is delivered only after payment confirmation. Digital content terms.

69
pages
10
chapters
11
named sources

99, VAT included. Refundable in full before the download link is generated, and non-refundable after it, except where the book materially fails to match this page. Refund Policy, section 03.

Microsoft 365 Tenant Hardening for DORA and NIS2 Operations cover

Evidence-led field guide

Reviewed 18 July 2026 · PDF edition

Named publisher

Michal Jatczak

Visible status

Published edition

Source register

11 references

Scope stated

Technical guidance, not certification

The operating problem

Written for decisions that must survive review.

Microsoft 365 is usually the control plane for identity, email, documents, devices and collaboration. If that tenant is weak, the rest of the stack inherits the weakness.

This book turns the ITSailor Microsoft 365 Security Baseline, NIST CSF 2.0, DORA Article 9 and NIS2 Article 21 into Microsoft 365 work: Conditional Access, PIM, Defender XDR, Sentinel, backup, licence evidence and audit packs.

The operator goal is simple: show the configuration, show the log, show the owner, show the rollback path. Anything else is slideware.

Included working material

More than a manuscript.

The guide ties each topic to decisions, control mappings and evidence that an operator can retain.

  • 10-chapter practitioner guide with a control-by-control hardening path.

  • ITS-M365 / NIST CSF 2.0 / DORA / NIS2 / GDPR mapping table for Microsoft 365 operators.

  • Conditional Access policy-as-code starter JSON.

  • Secure Score and licence-waste PowerShell audit snippets.

  • Sentinel KQL starter rule for failed sign-in bursts.

  • Audit-day evidence checklist for identity, endpoint, email, backup and logging controls.

Real page preview

The publication design and the operator detail.

Previewed chapter: Conditional Access Policy-as-Code

Ship policy JSON, not screenshots. Screenshots do not roll back a lockout.

ITS-M365-ID-001 to ITS-M365-ID-004NIST CSF 2.0 PR.AADORA Article 9

The sample is rendered from the same structured source used by the publication engine. It is not a separate marketing mock-up.

Sample page from Microsoft 365 Tenant Hardening for DORA and NIS2 Operations

Table of contents

Every chapter answers an operating question.

  1. ITS-M365 control setNIST CSF 2.0 GV.RM, PR.AA, DE.CM, RC.RP

    The Microsoft 365 Hardening Mandate

    Three governance languages point at the same operational question: can your tenant resist, detect, recover and prove control?

    3 evidence outputs named
  2. ITS-M365 control setMicrosoft Secure Score

    Tenant Baseline and Posture Assessment

    Score before you spend. A baseline without ownership becomes a screenshot collection.

    3 evidence outputs named
  3. ITS-M365-ID-001 to ITS-M365-ID-004NIST CSF 2.0 PR.AA

    Conditional Access Policy-as-Code

    Ship policy JSON, not screenshots. Screenshots do not roll back a lockout.

    3 evidence outputs named
  4. ITS-M365-PA-001 to ITS-M365-PA-005NIST CSF 2.0 PR.AA

    JIT Admin and Privileged Identity Management

    Standing global admin is not a privilege model. It is a compromise waiting for a password.

    3 evidence outputs named
  5. ITS-M365-EP-001 to ITS-M365-EP-005NIST CSF 2.0 PR.PS, DE.CM

    Defender XDR Onboarding Order

    Wrong order creates blind spots. Deploy detection in a sequence the operations team can absorb.

    3 evidence outputs named
  6. ITS-M365-LD-001 to ITS-M365-LD-004NIST CSF 2.0 DE.CM, DE.AE, RS.MA

    Sentinel Analytics Rules That Are Not Noise

    A rule earns its place when someone knows what to do after it fires.

    3 evidence outputs named
  7. ITS-M365-RS-001 to ITS-M365-RS-003NIST CSF 2.0 PR.IR, RC.RP

    Microsoft 365 Backups: Native Retention Is Not Enough

    Recoverable is not the same thing as backed up. Retention answers policy. Backup answers recovery.

    3 evidence outputs named
  8. ITS-M365-GV-001NIST CSF 2.0 GV.RM

    License Right-Sizing in Production

    Hardening does not always mean E5. It means buying the controls you will configure and operate.

    3 evidence outputs named
  9. ITS-M365 control setNIST CSF 2.0 GV.OV, DE.CM, RC.RP

    The Audit Day Survival Pack

    Audit readiness is the ability to answer the second question without panic.

    3 evidence outputs named
  10. ITS-M365-GV-001NIST CSF 2.0 GV.RM

    Decision Matrix: Business Premium, E3, E5 and Add-ons

    Pick by control surface, not seat count. The right licence is the one your operators can run.

    3 evidence outputs named

Source basis

Open the authority behind the claim.

Legal text, standards and vendor guidance are linked directly. Access dates show when the edition last checked each source.

Primary law

Regulation (EU) 2022/2554, Digital Operational Resilience Act

Primary legal text for DORA. Used for ICT risk, continuity and incident references.

Accessed 5 June 2026

Primary law

Directive (EU) 2022/2555, NIS2 Directive

Primary legal text for NIS2. Article 21 anchors cybersecurity risk-management measures.

Accessed 5 June 2026

Standard

NIST Cybersecurity Framework 2.0

Public risk-management vocabulary used for the ITS-M365 control crosswalk.

Accessed 5 June 2026

Vendor documentation

Microsoft Secure Score

Microsoft guidance for Secure Score posture measurement and recommended actions.

Accessed 5 June 2026

Vendor documentation

Microsoft Graph conditionalAccessPolicy API

Used for Conditional Access policy-as-code examples.

Accessed 5 June 2026

Vendor documentation

Microsoft Entra emergency access accounts

Used for break-glass account guidance.

Accessed 5 June 2026

Vendor documentation

Microsoft Entra ID Governance overview

Used for privileged access and identity governance framing.

Accessed 5 June 2026

Vendor documentation

Pilot and deploy Microsoft Defender XDR

Used for Defender XDR pilot and deployment sequencing.

Accessed 5 June 2026

Vendor documentation

Threat detection in Microsoft Sentinel

Used for analytics rule design, incident framing and the Defender portal transition timeline.

Accessed 5 June 2026

Vendor documentation

Microsoft Sentinel automation rules

Used for Sentinel incident ownership, assignment and automation guidance.

Accessed 5 June 2026

Vendor documentation

Microsoft 365 Backup overview

Used for native backup and restore framing.

Accessed 5 June 2026

Scope before claims

This guide is technical guidance, not legal advice. ITS-M365, NIST CSF 2.0, DORA, NIS2 and GDPR mappings help you prepare evidence, but your regulator, auditor, DPO, legal counsel and sector authority decide what is sufficient.

Written and maintained by

Michal Jatczak

ITSailor is the trading brand. The legal publisher is Michal Jatczak, Malta VAT MT32760411. Each edition carries a review date, named sources and an explicit limitation.

About the publisher

Need the environment-specific version?

Book the Architecture & Security Workshop

Use the book to self-assess. Book the workshop when you want the policy exports, evidence pack and remediation plan written against your own tenant.

Start a scoped conversation
The companion field guide

DORA & NIS2: The Strategic IT Roadmap

The C-level roadmap for mapping ICT risk, scope, third-party concentration, incident reporting and resilience testing to a 90/180/365-day operating plan, in the language each reviewer expects.

Review the companion edition