Insights · Microsoft 365

Microsoft 365 governance for regulated firms: a practical baseline

How to govern Microsoft 365 in a DFSA- or FSRA-regulated firm: identity, devices, data, logging and licences, with a 30-day order of work.
The short answer

Microsoft 365 governance is the set of decisions, settings and records that control who can reach your firm’s data, from which devices, how long it is kept and how you would prove it. For a DFSA- or FSRA-regulated firm, a sound baseline is enforced multi-factor authentication, Conditional Access, managed devices, controlled external sharing, labelled and retained data, audit logging and least-privilege administration.

Key points
  • Start with identity: multi-factor authentication for everyone, and Conditional Access to control how sign-ins happen.
  • Manage devices so firm data lands only on devices you can secure and wipe.
  • Control sharing, guests and retention so client data does not leave by accident.
  • Turn on logging and review it. Evidence matters as much as settings.
  • Match licences to the controls you need, not the other way round.

Why Microsoft 365 is the centre of your exposure

For most regulated firms, Microsoft 365 holds the email, documents, chat and calendars that make up client records and internal decisions. It is also an internet-facing service protected mainly by identity. That makes it both your most valuable system and, in a regulator’s eyes, a core part of your control environment.

The expectations you meet elsewhere (access control, multi-factor authentication, patching, monitoring and incident response) apply here too, and Microsoft is itself a third-party provider you need to understand. The split is simple: Microsoft secures the service, and you configure and govern your tenant.

1. Identity and access

  • Require multi-factor authentication for every user, including administrators. Prefer phishing-resistant methods (authenticator app number matching, passkeys or FIDO2 keys) over SMS.
  • Use Conditional Access to block legacy authentication, require MFA and compliant devices, and restrict risky sign-ins.
  • Give administrators separate admin accounts, use the least-privileged role for each job, and keep two emergency (“break-glass”) accounts that are monitored and stored securely.
  • Review who holds which admin roles and who has guest access on a schedule, and keep the record.

2. Devices

Enrol laptops and phones in Microsoft Intune or an equivalent tool. Require disk encryption (BitLocker or FileVault), a screen lock and supported, updated operating systems, then use Conditional Access so only compliant devices reach firm data. For personal phones, app protection policies can separate firm data without managing the whole device. Decide what you allow and write it down.

3. Data: labels, sharing and retention

  • Classify. Sensitivity labels (for example Public, Internal, Confidential, Restricted) travel with files and can drive encryption and sharing rules.
  • Prevent loss. Data loss prevention policies for client identifiers, payment data and other categories you define.
  • Control sharing. Set SharePoint, OneDrive and Teams external sharing to the minimum you need, expire guest access and review guests regularly.
  • Retain and delete on purpose. Retention policies should reflect your record-keeping obligations. Ask your compliance officer for the periods rather than guessing.
  • Protect email. SPF, DKIM and DMARC for your domain, plus anti-phishing and safe-link protection.

4. Logging, monitoring and evidence

Confirm the unified audit log is on and know how long your licence keeps it. Set alerts for high-risk events such as new mail-forwarding rules, admin role changes, mass downloads and sign-ins from unexpected places. Review Microsoft Secure Score monthly and record what you fixed, accepted or deferred, and why. Secure Score is a useful measurement, not a compliance certificate.

5. Licences follow controls

Many governance features depend on the licence. As a rough guide, Microsoft 365 Business Premium includes Conditional Access, Intune and Defender for Business, which covers much of what a small firm needs. Privileged identity management, advanced auditing and insider-risk tooling need higher tiers or add-ons. Microsoft changes its packaging, so check its current licensing guidance and map your control list to licences before you buy.

6. Know where your data lives

Record where your tenant’s data is stored and any regional commitments, and be ready to explain them to your regulator, auditors and clients. We carried out a cross-country Microsoft 365 migration to the UAE for an ADGM-based advisory and investment firm, taking regulatory requirements into account. Read the case study.

A 30-day order of work

A sensible sequence for a firm starting from a basic set-up. Adapt it to your size and risks.

  • Week 1. MFA for everyone, block legacy authentication, create break-glass accounts, tidy admin roles.
  • Week 2. Enrol devices, set compliance rules, enable disk encryption, add Conditional Access for compliant devices.
  • Week 3. Restrict external sharing, review guests, publish sensitivity labels, set up SPF, DKIM and DMARC.
  • Week 4. Turn on audit logging and alerts, agree retention, and record every decision in your evidence pack.

Sources and further reading

Last reviewed 19 September 2026. This guide is general information, not legal or regulatory advice. Rules change, so check the current text and take advice from your compliance officer or legal adviser before relying on it.

Written by
CEO, Cre8 IT
Rob Crossley is CEO of Cre8 IT, a Dubai-born managed IT and cyber security company that has supported businesses across the UAE, Saudi Arabia and the UK since 2012. Cre8 IT is certified to ISO 27001:2022 and ISO 9001 and is a certified Microsoft Partner.
FAQ

Frequently asked questions

Is Microsoft 365 acceptable for a DFSA- or FSRA-regulated firm?

Regulators do not ban cloud services. They expect you to understand where your data is, control access to it, oversee the provider and be able to show that you do. Configuration matters more than the logo on the service. Ask your compliance officer or legal adviser about your specific obligations.

Does a high Microsoft Secure Score mean we are compliant?

No. Secure Score measures how many recommended security settings you have applied. It is useful evidence that you monitor and improve your configuration, but it does not certify compliance with any regulator’s rules.

Which Microsoft 365 controls should a small regulated firm put in place first?

Multi-factor authentication for everyone, blocking legacy authentication, managing the devices that reach firm data, and limiting external sharing. These address the most common ways accounts and client data are compromised, and they line up with the access-control and authentication expectations in the DFSA and FSRA cyber rules.
Related guides

Keep reading

Each guide links to the regulator’s own text and shows when it was last reviewed.
DFSA and DIFC

DFSA cyber and IT requirements: what DIFC firms need to evidence

A plain-English guide to the DFSA’s cyber risk management rules (GEN 5.5), its outsourcing expectations (GEN 5.3.21) and the evidence a DIFC firm should be able to show.
6 min read · Reviewed 19 September 2026
Audit readiness

IT audit readiness for DIFC and ADGM firms: an evidence-first checklist

How to be ready when a regulator, auditor or client asks for proof of your IT and security controls: the evidence pack, a mock audit and a six-week plan.
3 min read · Reviewed 19 September 2026
Cyber Essentials

Cyber Essentials for UAE firms: what it is and when it is worth it

What Cyber Essentials covers, what changed in April 2026, whether it matters for DIFC and ADGM firms, and how it compares with ISO 27001 and the regulators’ own rules.
4 min read · Reviewed 19 September 2026

Talk to a specialist about your obligations

Tell us about your firm and your regulator, and we will suggest a practical first step, whether that is a gap assessment or ongoing support.