Microsoft 365 Tenant Hardening
Mapped to DORA, NIS2 and NIST CSF 2.0
A practitioner field guide for regulated EU operators running Microsoft 365. Maps DORA Article 9, NIS2 Article 21, NIST CSF 2.0 and the source-linked ITS-M365 control set to tenant controls, evidence and operating routines.
Stripe checkout. The personalised PDF is delivered only after payment confirmation. Digital content terms.
- 69
- pages
- 10
- chapters
- 11
- named sources
€99, VAT included. Refundable in full before the download link is generated, and non-refundable after it, except where the book materially fails to match this page. Refund Policy, section 03.

Evidence-led field guide
Reviewed 18 July 2026 · PDF edition
Michal Jatczak
Published edition
11 references
Technical guidance, not certification
The operating problem
Written for decisions that must survive review.
Microsoft 365 is usually the control plane for identity, email, documents, devices and collaboration. If that tenant is weak, the rest of the stack inherits the weakness.
This book turns the ITSailor Microsoft 365 Security Baseline, NIST CSF 2.0, DORA Article 9 and NIS2 Article 21 into Microsoft 365 work: Conditional Access, PIM, Defender XDR, Sentinel, backup, licence evidence and audit packs.
The operator goal is simple: show the configuration, show the log, show the owner, show the rollback path. Anything else is slideware.
Included working material
More than a manuscript.
The guide ties each topic to decisions, control mappings and evidence that an operator can retain.
10-chapter practitioner guide with a control-by-control hardening path.
ITS-M365 / NIST CSF 2.0 / DORA / NIS2 / GDPR mapping table for Microsoft 365 operators.
Conditional Access policy-as-code starter JSON.
Secure Score and licence-waste PowerShell audit snippets.
Sentinel KQL starter rule for failed sign-in bursts.
Audit-day evidence checklist for identity, endpoint, email, backup and logging controls.
Real page preview
The publication design and the operator detail.
Previewed chapter: Conditional Access Policy-as-Code
Ship policy JSON, not screenshots. Screenshots do not roll back a lockout.
The sample is rendered from the same structured source used by the publication engine. It is not a separate marketing mock-up.

Table of contents
Every chapter answers an operating question.
- ITS-M365 control setNIST CSF 2.0 GV.RM, PR.AA, DE.CM, RC.RP
The Microsoft 365 Hardening Mandate
Three governance languages point at the same operational question: can your tenant resist, detect, recover and prove control?
3 evidence outputs named - ITS-M365 control setMicrosoft Secure Score
Tenant Baseline and Posture Assessment
Score before you spend. A baseline without ownership becomes a screenshot collection.
3 evidence outputs named - ITS-M365-ID-001 to ITS-M365-ID-004NIST CSF 2.0 PR.AA
Conditional Access Policy-as-Code
Ship policy JSON, not screenshots. Screenshots do not roll back a lockout.
3 evidence outputs named - ITS-M365-PA-001 to ITS-M365-PA-005NIST CSF 2.0 PR.AA
JIT Admin and Privileged Identity Management
Standing global admin is not a privilege model. It is a compromise waiting for a password.
3 evidence outputs named - ITS-M365-EP-001 to ITS-M365-EP-005NIST CSF 2.0 PR.PS, DE.CM
Defender XDR Onboarding Order
Wrong order creates blind spots. Deploy detection in a sequence the operations team can absorb.
3 evidence outputs named - ITS-M365-LD-001 to ITS-M365-LD-004NIST CSF 2.0 DE.CM, DE.AE, RS.MA
Sentinel Analytics Rules That Are Not Noise
A rule earns its place when someone knows what to do after it fires.
3 evidence outputs named - ITS-M365-RS-001 to ITS-M365-RS-003NIST CSF 2.0 PR.IR, RC.RP
Microsoft 365 Backups: Native Retention Is Not Enough
Recoverable is not the same thing as backed up. Retention answers policy. Backup answers recovery.
3 evidence outputs named - ITS-M365-GV-001NIST CSF 2.0 GV.RM
License Right-Sizing in Production
Hardening does not always mean E5. It means buying the controls you will configure and operate.
3 evidence outputs named - ITS-M365 control setNIST CSF 2.0 GV.OV, DE.CM, RC.RP
The Audit Day Survival Pack
Audit readiness is the ability to answer the second question without panic.
3 evidence outputs named - ITS-M365-GV-001NIST CSF 2.0 GV.RM
Decision Matrix: Business Premium, E3, E5 and Add-ons
Pick by control surface, not seat count. The right licence is the one your operators can run.
3 evidence outputs named
Source basis
Open the authority behind the claim.
Legal text, standards and vendor guidance are linked directly. Access dates show when the edition last checked each source.
Regulation (EU) 2022/2554, Digital Operational Resilience Act
Primary legal text for DORA. Used for ICT risk, continuity and incident references.
Accessed 5 June 2026
Directive (EU) 2022/2555, NIS2 Directive
Primary legal text for NIS2. Article 21 anchors cybersecurity risk-management measures.
Accessed 5 June 2026
NIST Cybersecurity Framework 2.0
Public risk-management vocabulary used for the ITS-M365 control crosswalk.
Accessed 5 June 2026
Microsoft Secure Score
Microsoft guidance for Secure Score posture measurement and recommended actions.
Accessed 5 June 2026
Microsoft Graph conditionalAccessPolicy API
Used for Conditional Access policy-as-code examples.
Accessed 5 June 2026
Microsoft Entra emergency access accounts
Used for break-glass account guidance.
Accessed 5 June 2026
Microsoft Entra ID Governance overview
Used for privileged access and identity governance framing.
Accessed 5 June 2026
Pilot and deploy Microsoft Defender XDR
Used for Defender XDR pilot and deployment sequencing.
Accessed 5 June 2026
Threat detection in Microsoft Sentinel
Used for analytics rule design, incident framing and the Defender portal transition timeline.
Accessed 5 June 2026
Microsoft Sentinel automation rules
Used for Sentinel incident ownership, assignment and automation guidance.
Accessed 5 June 2026
Microsoft 365 Backup overview
Used for native backup and restore framing.
Accessed 5 June 2026
Scope before claims
This guide is technical guidance, not legal advice. ITS-M365, NIST CSF 2.0, DORA, NIS2 and GDPR mappings help you prepare evidence, but your regulator, auditor, DPO, legal counsel and sector authority decide what is sufficient.
Written and maintained by
Michal Jatczak
ITSailor is the trading brand. The legal publisher is Michal Jatczak, Malta VAT MT32760411. Each edition carries a review date, named sources and an explicit limitation.
About the publisherNeed the environment-specific version?
Book the Architecture & Security Workshop
Use the book to self-assess. Book the workshop when you want the policy exports, evidence pack and remediation plan written against your own tenant.
Start a scoped conversationDORA & NIS2: The Strategic IT Roadmap
The C-level roadmap for mapping ICT risk, scope, third-party concentration, incident reporting and resilience testing to a 90/180/365-day operating plan, in the language each reviewer expects.
Review the companion edition