Compliance

Microsoft 365 access reviews for NIS2

NIS2 widened the net: essential and important entities across the EU — energy, transport, health, digital infrastructure, manufacturing, and their supply chains — now carry explicit cybersecurity risk-management duties, and access control is on the list. One obligation recurs in every serious reading of it: periodically review who can access what, and be able to show that you did. In a Microsoft 365 tenant, external sharing is a large — and constantly changing — part of exactly that surface.

What NIS2 asks for (the access-control slice)

Article 21 obliges in-scope entities to take proportionate technical and organisational measures, and its minimum list names access-control policies alongside procedures to assess whether your measures actually work. Read together, that is not a one-off exercise: an access-control policy nobody re-checks is a document, not a measure. The uncomfortable property of access state is that it drifts daily — every share, every guest invitation, every new file under an already-shared folder moves it — so a review performed once before an audit describes last year's exposure, not this quarter's.

The external-sharing surface

SharePoint and OneDrive are where a tenant's working documents live, and external access to them takes shapes that are easy to grant and hard to see again: "Anyone" links that outlive their purpose, guest grants left over from finished projects, guests reaching whole sites through Microsoft 365 group membership, and inherited access — where a grant on a parent folder silently covers every file added beneath it. That is a live access-control risk, and for NIS2 purposes it has to be reviewable, on a recurring basis, not archaeologically reconstructed when someone asks.

A periodic review a human can perform

TRACER365 makes the external-access review a working practice rather than a heroic one-off:

  • Complete inventory, read-only: every external exposure across all SharePoint sites and OneDrives — anonymous links, guest grants, inherited access, pending invitations — from a locally installed app that changes nothing in the tenant.
  • A review a reviewer can finish: cascade de-duplication collapsed roughly 91% of raw findings as duplicates in our testing. A periodic review is only real if the person doing it can get through the list.
  • Recurring by construction: scheduled scans and email reports to the person responsible — including a non-IT reviewer via the viewer role — so the cadence survives busy quarters.
  • Point-in-time and change-over-time: scan history shows both the current state and the trend; new or expanded sharing is flagged for review again.
  • No new data flow: the audit runs locally and its data never leaves your environment, so the evidence-gathering itself adds no new processor or data flow to account for.
The honest boundary: compliance is an organisational property, not a product feature. TRACER365 provides evidence for the access-control side of NIS2 — it does not read sensitivity labels, does not classify data, and no tool makes you "NIS2 compliant". The same access-review evidence also serves GDPR Article 32, ISO 27001 access-rights reviews (A.5.18), and — for financial entities — DORA access management, where those apply to you.

Make the periodic review performable

Complete external-sharing evidence across SharePoint and OneDrive, de-duplicated, on a schedule, without your data leaving your environment. Free 30-day trial at launch.