Compliance

DORA and Microsoft 365 data access: gathering the evidence

DORA — the EU's Digital Operational Resilience Act — applies in full to financial entities: banks, insurers, investment firms, and many of the ICT providers that serve them. At its core is ICT risk management, and access management is part of it: knowing, and reviewing, who can reach the systems and data a financial entity depends on. In a Microsoft 365 tenant, external sharing across SharePoint and OneDrive is a live, changing slice of exactly that, and keeping it reviewed is the entity's own obligation.

What DORA asks for (the access-management slice)

DORA's ICT risk-management framework expects financial entities to identify, protect, and monitor access to the ICT systems and information supporting their critical functions — including access granted to third parties. External sharing is precisely a third-party access channel: a guest account, an outside firm, an "Anyone" link. The uncomfortable property of that access is that it drifts daily — every share, every guest invitation, every new file under an already-shared folder moves it — so a picture taken once is out of date by the next quarter.

The external-sharing surface

SharePoint and OneDrive hold the working documents of a financial entity — deal files, customer records, contracts, board material. External access to them takes shapes that are easy to grant and hard to see again: "Anyone" links that outlive their purpose, guest grants left over from finished engagements, outside parties reaching whole sites through Microsoft 365 group membership, and inherited access — where a grant on a parent folder silently covers every file added beneath it. For DORA purposes that surface has to be reviewable, on a recurring basis, with evidence.

A periodic review a human can perform

TRACER365 makes the external-access review a working practice rather than a heroic one-off, and its output an artefact an auditor can read:

  • Complete inventory, read-only: every external exposure across all SharePoint sites and OneDrives — anonymous links, guest grants, inherited access, pending invitations — from a locally installed app that changes nothing in the tenant.
  • A review a reviewer can finish: cascade de-duplication collapsed roughly 91% of raw findings as duplicates in our testing. A review is only real if the person doing it can get through the list.
  • Recurring by construction: scheduled scans and email reports to the person responsible — including a non-IT reviewer via the viewer role — so the cadence survives busy quarters.
  • Point-in-time and change-over-time: scan history shows both the current state and the trend; new or expanded third-party sharing is flagged for review again.
  • No new data flow: the audit runs locally and its data never leaves your environment, so the evidence-gathering itself adds no new ICT arrangement to account for.
The honest boundary: meeting DORA is an organisational obligation, not a product feature. TRACER365 provides evidence for the access-control side — who can access what, externally, on a schedule — it does not read sensitivity labels, it does not classify data, and no tool delivers DORA on your behalf. The same access-review evidence also serves GDPR Article 32, NIS2, and ISO 27001 access-rights reviews, where those apply to you.

Make the third-party access review performable

Complete external-sharing evidence across SharePoint and OneDrive, de-duplicated, on a schedule, without your data leaving your environment. Free 30-day trial at launch.