DORA request in the Microsoft 365 tenant

DORA Requirements in the Microsoft 365 Tenant

DORA requirements in the Microsoft 365 tenant

Securely Implement DORA Requirements in Microsoft 365
17.07.2025
Microsoft 365
Digital Workplace
Security
Insurance & Financial Services

With the EU regulation DORA (EU 2022/2554) coming into force on January 17, 2025, financial companies are facing new regulatory obligations regarding digital resilience. With Entra ID, Purview, Defender and Sentinel, Microsoft 365 offers central tools for technical implementation - but the responsibility for DORA compliance lies with the companies themselves.

DORA at a Glance: The Most Important Facts

  • Binding for financial companies since January 17, 2025

  • Goal: Digital resilience and stability in the financial sector

  • Requirements: ICT risk management, incident reporting, resilience testing

  • Strict third-party management is mandatory

  • Microsoft supports with DORA-specific contract addendum and comprehensive compliance tools

What Is DORA - And Why Action Is Needed Now

DORA (Digital Operational Resilience Act) is an EU regulation to increase digital operational resilience in the financial sector. It affects banks, insurance companies, payment service providers, and their ICT service providers.

The regulation requires comprehensive risk management, reporting obligations, and resilience testing of digital systems. Given the increasing dependence on cloud services such as Microsoft 365, there is an immediate need for action – not least because of the strict testing requirements of the supervisory authority.

 

The central DORA requirements include:

  • Establishment of ICT risk management
  • Notification of serious incidents
  • Execution of regular resilience tests
  • Control of third-party service providers
  • Exchange about cyber threats

 

Further details and a comprehensive overview can be found directly at the German Federal Financial Supervisory Authority (BaFin): To the overview at BaFin

Microsoft’s Reaction: The DORAContract Amendment

Microsoft has responded to the regulatory requirements and published a DORA-specific contract addendum for financial companies. This supplements existing contracts such as the Enterprise Agreement or the Data Protection Agreement (DPA) with a DORA-compliant addendum that regulates the following points, among others:

  1. Transparency in the use of subcontractors and third-party service providers
  2. Extended termination rights for critical changes
  3. Commitment to DORA-compliant data processing
  4. Reporting obligations and control options

 

The contract addendum is available in the Microsoft Service Trust Portal and should be part of every Microsoft 365 contract in the financial sector.

Implement DORA Requirements in the Microsoft 365 Tenant

In order to use Microsoft 365 DORA-compliant, companies must take technical and organizational measures. You can find an overview of the most important steps in the Microsoft Learn article.

 

The most important fields of action are:

Identity and access management

  • Use of Microsoft Entra ID (P2) with:
    • Conditional Access Policies
    • Privileged Identity Management (PIM)
    • Multi-factor authentication (MFA)
  • Centralization of identities to reduce shadow IT
  • Cross-tenant synchronization for group structures

Governance & Compliance

  • Introduction of a central governance model for Microsoft 365
  • Use of Microsoft Purview for the implementation of:
    • Data Loss Prevention (DLP)
    • Discovery & Audit Logs
    • Retention Policies
  • Regular documentation and review of compliance measures

Incident Response & Monitoring

  • Integration of Microsoft Defender for Cloud Apps and Microsoft Sentinel
  • Setting up a reporting process for serious incidents
  • Link to internal emergency plans and response processes

Third-party provider management

  • Identification and evaluation of all third-party providers in the Microsoft 365 tenant (add-ons, APIs, connectors)
  • Contract review and ensuring regulatory requirements
  • Definition of exit strategies and performance of risk analyses

Challenges in Practice

Implementing the DORA requirements in the Microsoft 365 tenant is complex. The clear delineation of responsibilities between the financial company as the client and Microsoft as the service provider is particularly important. Microsoft provides numerous technical requirements, but the regulatory responsibility remains with the company.

 

A practical example shows: Service providers must contractually anchor regulatory requirements, but are not themselves responsible for compliance with the DORA requirements. At the same time, companies must regularly analyze and document their operational and technical risks – also with regard to the cloud services provided by Microsoft.

Recommendations for Financial Companies

Based on internal projects and Microsoft documentation, we recommend:

 

  • Check contractual coverage: Make sure that the DORA contract addendum is part of your Microsoft contract.
  • Review your tenant architecture: Consolidate your Microsoft 365 tenants and establish a centralized governance model.
  • Enable compliance tools: Make full use of Microsoft Purview, Entra ID P2 and Defender products.
  • Simulate ICT incidents: Develop an incident response plan and test it regularly.
  • Documentation & Reporting: Document and audit all measures in a traceable manner.

Conclusion: DORA Is More than Compliance

DORA offers financial companies the opportunity to strengthen their digital resilience in the long term. Who Microsoft 365 with clear governance structures and a DORA-compliant setup not only meets regulatory requirements, but also creates long-term security and trust.

Implement Your DORA Roadmap Professionally with Arvato Systems

Arvato Systems supports financial companies from contract review and technical configurations to the implementation of a DORA-compliant Microsoft 365 tenant.

 

Rely on our expertise and experience in the secure implementation of DORA requirements. Contact us today to strengthen your digital resilience and meet regulatory requirements with confidence.

You May Also Be Interested In

Microsoft Office 365

Discover our Digital Workplace Solutions with Microsoft Office 365.

Microsoft 365

The foundation for your Modern Workplace.

Workplace Security

Protect your Digital Workplace with the smart tools of Microsoft 365 Defender. We'll show you how!

NIS2 Directive Explained Simply

The NIS2 directive and its implementation in Germany have been hotly debated for some time now. But what changes and cybersecurity requirements does NIS2 actually entail and how do companies in Germany need to react in order to meet the new requirements?

Insurance & Financial Services

Arvato Systems is a reliable IT partner for the insurance and finance industry. We help you digitize your services, use cloud technologies, and automate your business processes.

Written by

ArvatoSystems_MA_HeikoSteinweg
Heiko Steinweg
Expert for Microsoft 365