Capability, Compliance, and the Gap Between Them

Microsoft 365 is frequently described as an “ISO 27001–aligned platform”. In isolation, that statement is not incorrect. Microsoft 365 provides a wide range of technical capabilities that can support many of the controls expected under ISO 27001.

Where organisations get into difficulty is assuming that capability equates to compliance.

ISO 27001 does not certify platforms. It certifies management systems — the people, processes, and governance structures that ensure information security is deliberate, repeatable, and continuously improved. Microsoft 365 can support that system, but it cannot replace it. Treating the platform itself as evidence of compliance is one of the most common reasons audits fail or stall.

This article examines where Microsoft 365 genuinely helps with ISO 27001, where responsibility remains firmly with the organisation, and why the gap between tooling and compliance is wider than many teams expect.

What ISO 27001 Actually Requires

ISO 27001 is often misunderstood as a technical standard. In reality, it is a risk management framework.

At its core, ISO 27001 requires organisations to:

  • Identify information security risks
  • Decide how those risks will be treated
  • Assign ownership for controls
  • Review effectiveness over time
  • Retain evidence of all of the above

Technical controls are important, but they exist in service of this broader system. A perfectly configured control that is not reviewed, owned, or evidenced does not meaningfully satisfy the intent of the standard.

This distinction becomes critical in cloud environments, where capability is abundant but governance is optional.

Where Microsoft 365 Helps (Genuinely)

Microsoft 365 provides strong foundational capability across several Annex A domains, including:

  • Identity and access management
  • Authentication and conditional access
  • Audit logging and activity tracking
  • Data protection and classification
  • Policy-based enforcement

These features can be mapped to ISO 27001 controls, and auditors generally accept that Microsoft provides a secure underlying platform.

However, mapping capability to controls is only the starting point. ISO 27001 assesses how those capabilities are:

  • Selected based on risk
  • Implemented consistently
  • Reviewed regularly
  • Improved over time

A tenant with features enabled but no surrounding governance may appear compliant on paper, while failing in practice.

The Compliance Fallacy: “Microsoft Covers That”

A common moment in ISO audits comes when an assessor asks how a particular risk is managed and the response begins with:

Microsoft handles that.

Joe BloggsTypical Organisation

This answer is rarely sufficient.

Microsoft secures the service infrastructure. The organisation secures:

  • Tenant configuration
  • Access decisions
  • Logging retention
  • Monitoring and response
  • Evidence production

ISO 27001 explicitly assumes shared responsibility. Vendor assurances do not remove the need for organisational control. Auditors will expect clarity on what Microsoft provides and what the organisation actively manages.

This is not a technical issue — it is a governance one.

Interpretation:
Microsoft supplies tools and signals. ISO 27001 requires demonstrable management.

Evidence: The Real Audit Battleground

Most ISO audits do not fail because a control is missing. They fail because organisations cannot demonstrate that controls are understood and maintained.

Auditors routinely ask:

  • Why was this control chosen?
  • When was it last reviewed?
  • Who owns it?
  • How would failure be detected?

Screenshots, dashboards, and Secure Score percentages rarely answer these questions. Evidence must show continuity, not just existence.

Microsoft 365 can generate the necessary data, but only if processes exist to capture, interpret, and retain it.

Continuous Improvement in a Moving Platform

ISO 27001 requires continual improvement, but Microsoft 365 is not static. Defaults change. Features evolve. Licensing tiers shift.

This creates a subtle risk: the platform improves, but the organisation’s understanding does not.

Without structured review cycles, controls may drift out of alignment with risk, even as tooling becomes more capable. Compliance quietly degrades while confidence increases — a dangerous combination.

Final Thoughts: Microsoft 365 Is a Foundation, Not a Certificate

Microsoft 365 can absolutely support ISO 27001 compliance. What it cannot do is deliver it automatically.

Compliance is not inherited through licensing. It is built through:

  • Risk-aware design
  • Clear ownership
  • Repeatable review
  • Evidence-based assurance

Organisations that recognise this early treat Microsoft 365 as a powerful foundation rather than a shortcut. Those that do not often discover the gap during audit — when it is hardest to close.

Want to secure your most critical asset?

Take the next step to securing your organisation

David Morgan

Founder & Consultant

Trusted Microsoft Cloud Security Advisor with 27 years experience | Empowering Businesses to Embrace Cloud Innovation with Confidence

Skills chart of the author David Morgan, high level expertise in Cyber Security, Network Security, Azure, Microsoft 365, Penetration Testing & Breach Attack Simulation

Related Posts