Cloud Security Stack
Compliance and governance

Compliance

DORA for Microsoft estates: what changes if you are in scope

EU financial entities and their critical ICT providers. The obligations that translate into tenant work, and the register that catches people out.

12 min read · Reviewed 22 August 2026 · EU regulation. Written against the Digital Operational Resilience Act framework.

Who this applies to

The Digital Operational Resilience Act covers EU financial entities: banks, insurers, investment firms, payment institutions and a long tail of others, plus the ICT providers designated as critical to them. If you are a UK firm serving EU clients, or a supplier to one, you may be in scope through the contractual chain rather than directly.

Establish scope before doing anything else. A surprising number of organisations discover they are in scope through a customer contract clause rather than through the regulation itself.

The pillars that translate into real work

01

ICT risk management framework

Documented, board-approved, reviewed. This is governance work, and no Microsoft capability produces it for you.

02

Incident classification and reporting

Major incidents reported on defined timescales. The technical requirement is being able to establish scope and impact quickly, which is a Sentinel and Defender question. The hard part is the decision process.

03

Digital operational resilience testing

Regular testing, and threat-led penetration testing for some entities. Scenario testing against your actual tenant, not a generic assessment.

04

Third-party risk and the register of information

A structured register of all ICT third-party arrangements. This is the one organisations underestimate, because it demands a level of detail most supplier records do not hold.

The register is the part to start early

It requires contract-level detail on every ICT provider, including what function they support and whether it is critical. Most organisations cannot produce this from existing records and discover that late. Start it before the framework documentation, because it takes longer and depends on other people responding.

Where Microsoft helps and where it does not

It helps with evidence: Sentinel for incident timelines, Purview for data location, Entra ID for access records, Intune for device state. All of that supports reporting obligations well.

It does not help with the register, the framework document, the exit strategies for critical providers, or the board approval. That is the majority of the work, and it is why DORA readiness projects are led by risk functions rather than by IT.

The verdict

Our pick

Start with scope and the register of information

Scope determines whether you need to do any of this, and the register has the longest lead time because it depends on other organisations answering you.

Who should skip

Do not start with tooling. DORA is a governance regulation with technical evidence requirements, and buying a product first solves the smaller half of the problem.

Disclosure. Some links on this site are affiliate links. Scoring weights are published before any programme is joined, and commission is never a ranking input. Full policy, and the method behind this guide.