NIS2 access reviews for Microsoft 365
NIS2 makes access control a management responsibility. It does not prescribe a tool or a review frequency, but it does expect you to show that access is controlled, reviewed and owned. For most organisations that evidence lives in Microsoft 365.
What NIS2 asks for
Article 21(2)(i) of the NIS2 Directive (EU) 2022/2555 lists "human resources security, access control policies and asset management" among the minimum cybersecurity risk-management measures. Article 20 makes the management body approve those measures and oversee their implementation.
In Germany the directive was transposed by the NIS2 Implementation Act (NIS2UmsuCG), in force since 6 December 2025. The measures are in § 30 of the BSI Act (BSIG), and § 38 BSIG places the duty to approve and monitor them on management, with personal liability.
For certain digital-infrastructure and ICT-service providers, Implementing Regulation (EU) 2024/2690 goes further and spells out access-control requirements, including the management and review of access rights.
What that means in Microsoft 365
An assessor looking at access control in a Microsoft 365 tenant will ask versions of the same questions:
- Is there an inventory of shared mailboxes, groups, Teams, sites and service accounts?
- Does each one have an accountable owner, and does that change when people leave?
- Is access reviewed at regular intervals, and who confirmed it, when?
- What happened to objects nobody could justify?
How Ownership Registry produces that evidence
- A scheduled Graph scan (daily, weekly or monthly, your choice) keeps the inventory complete and picks up new objects on the next run.
- Every object gets a primary and a backup owner. Owners who leave are detected on the next scan and the backup takes over automatically.
- Owners confirm each object on a cadence you set per object: monthly for high-risk service accounts, every six or twelve months for lower-risk objects.
- Unanswered or declined objects are escalated by email to your service desk. Nothing is deleted automatically.
- Every step lands in an append-only audit log, so the answer to "who reviewed this, and when?" is a lookup, not a reconstruction.
The tool itself is read-only on your tenant, which keeps it out of your own NIS2 risk register as a new privileged system. Details are on the security page.
What it does not cover
NIS2 access control goes beyond Microsoft 365: physical access, privileged access management, MFA (Art. 21(2)(j)) and access inside business applications. Ownership Registry covers the Microsoft 365 objects and service accounts, and custom object types let you register on-premises service accounts and file shares by hand. For the wider tenant configuration, our Microsoft 365 security assessment is the starting point.
NIS2 questions
How often does NIS2 require access reviews?
Neither the directive nor § 30 BSIG sets a fixed interval. It expects appropriate and proportionate measures, which in practice means a documented cadence based on risk, applied consistently, with evidence. Setting the cadence per object, by risk, is how the registry reflects that.
Does management have to be involved?
Yes. Article 20 of the directive and § 38 BSIG require the management body to approve the risk-management measures and oversee their implementation. A coverage dashboard and a complete audit trail are what makes that oversight possible without a quarterly spreadsheet.
Is an access review tool itself a NIS2 risk?
Any tool with write access to your tenant is. Ownership Registry holds read permissions plus Mail.Send and has no code path that modifies or deletes objects, so it adds no new privileged path into Microsoft 365.
See where your tenant stands
A read-only demo shows your current ownership coverage, the first number a NIS2 access-control review will ask for. Book a demo