SEC/FINRASOC 2 Type IIISO 27001GLBANERC CIP

Regulated Industries

Every Regulated Industry Has the Same M365 Problem.

The platform is powerful. Ungoverned, it is a liability. Whether your regulatory driver is SEC/FINRA record retention, SOC 2 Type II audit requirements, ISO 27001 controls, or GLBA data safeguards — the Microsoft 365 governance and security architecture that underlies compliance is the same. We build it.

The Regulatory Reality

The Compliance Requirements That Apply to Your M365 Environment

Financial Services (SEC/FINRA)

Financial services firms using M365 face specific requirements for electronic communications supervision, records retention, data governance, and cybersecurity risk management under SEC and FINRA rules.

  • FINRA Rule 4511/3110: business communications retention and supervision obligations
  • SEC 17a-4: electronic records retention in non-rewriteable, non-erasable format
  • Reg S-P: customer financial information safeguards and access controls
  • SEC Cybersecurity Rules: risk management, incident reporting, and governance disclosure
SOC 2 Type II

SOC 2 Type II audits examine organizational controls across Trust Services Criteria — Security, Availability, Confidentiality, Processing Integrity, and Privacy. M365 configuration evidence is central to many audit findings.

  • CC6: Logical and physical access controls — Entra ID, Conditional Access, MFA
  • CC7: System operations — audit logging, monitoring, incident detection
  • CC8: Change management — configuration management, approval workflows
  • A1: Availability — uptime, backup, and recovery controls
ISO 27001

ISO 27001 Annex A controls have specific M365 implications across information security policies, access management, cryptography, physical security, and supplier relationships.

  • A.9: Access control — Entra ID, role-based access, least privilege
  • A.10: Cryptography — encryption in transit and at rest for M365 data
  • A.12: Operations security — audit logging, malware protection, monitoring
  • A.13: Communications security — email security, external sharing controls

What We Configure

Industry-Specific Microsoft 365 Configuration

Every Microsoft 365 product we configure maps to the specific compliance controls your industry requires.

Microsoft Purview — Compliance

Records Retention and Supervision

Purview Compliance Manager, retention policies, and in-place holds configured for your specific record retention obligations — SEC 17a-4, FINRA, or internal policy. Communication supervision policies for financial services, legal hold workflows, and eDiscovery-ready configuration.

Microsoft Entra ID

Access Controls and SOC 2 / ISO 27001 Evidence

Access control configuration aligned to SOC 2 CC6 and ISO 27001 A.9 controls — least privilege, MFA enforcement, role-based access reviews, Privileged Identity Management. Audit log configuration for access control evidence during Type II assessment periods.

Microsoft Defender for M365

Threat Detection and Security Operations

Defender for Office 365 Plan 2 configuration for threat hunting, advanced threat protection, and incident detection — supporting SOC 2 CC7 (System Operations) and ISO 27001 A.12 (Operations Security) controls. Automated investigation and response configured for your environment.

Exchange Online

Email Security and Records Compliance

Exchange Online Protection and Defender for Office 365 email security hardening, plus compliance archiving for SEC 17a-4 and FINRA Rule 4511 obligations. Journal rules, email retention policies, and immutable archive configuration for regulated communications.

SharePoint and OneDrive

Information Governance and Data Sovereignty

SharePoint governance framework for regulated data — sensitivity labels, external sharing controls, permission governance, and Purview retention policies. Data residency configuration for organizations with data sovereignty requirements under GDPR, state privacy laws, or industry regulations.

Powered by TenantForge

TenantForge maps your M365 configuration to SOC 2 Trust Services Criteria and ISO 27001 Annex A controls — producing evidence documentation that audit teams can use directly. We use TenantForge to run assessments that identify configuration gaps before your Type II audit window, not during it.

FAQ

Common Questions

Can Microsoft 365 data be used as evidence in a SOC 2 Type II audit?
Yes — and it frequently is. Audit log exports, access review records, Conditional Access policy screenshots, MFA enforcement reports, and Purview retention policy documentation are all standard evidence items in SOC 2 Type II audits. The challenge is having M365 configured and managed in a way that produces clean, auditable evidence throughout the audit period — not just before the auditor arrives.
What does SEC 17a-4 require for email and electronic records in M365?
SEC Rule 17a-4 requires that electronic records be retained in a non-rewriteable, non-erasable (WORM) format and be immediately available for regulatory inspection. Microsoft 365 Compliance (Purview) offers Preservation Lock for retention policies — a WORM-equivalent configuration that prevents modification or deletion of in-scope records. We configure retention policies with Preservation Lock enabled, scoped to the applicable record types and retention periods for your broker-dealer or investment adviser registration.
How does GLBA Safeguards Rule apply to M365 configuration?
The FTC's Gramm-Leach-Bliley Safeguards Rule (16 CFR Part 314) requires financial institutions to implement a written information security program with specific controls for customer financial information. For M365 environments, the most directly applicable controls are access controls (Entra ID, Conditional Access), encryption (M365 encrypts data in transit and at rest, but configuration choices matter), monitoring (audit logging, Defender), and vendor oversight (Microsoft's security practices). We map your M365 configuration to the Safeguards Rule requirements.
Do you work with biotech and life sciences companies outside of 21 CFR Part 11?
Yes. Biotech and pharma companies often have compound compliance requirements — 21 CFR Part 11, GxP validation requirements, SOC 2, and sometimes HIPAA if they handle clinical trial participant data. We assess the full regulatory context and design M365 configuration that addresses multiple frameworks simultaneously — rather than building separate compliance programs for each.
What is your experience with NERC CIP for energy organizations?
NERC CIP (Critical Infrastructure Protection) standards apply to bulk electric system owners and operators. Several NERC CIP standards have M365 implications — particularly CIP-003 (security management controls), CIP-004 (personnel training and physical/electronic access), and CIP-011 (information protection). We assess which NERC CIP standards apply to your organization's M365 use and configure appropriately.

Get a Compliance-Focused M365 Assessment.

Start with a free M365 assessment. We'll identify every gap that matters for your industry and build a remediation roadmap your team can act on.

No commitment required · 5-day turnaround