Compliance Dashboard
The Compliance page gives you an automated, framework-mapped view of how your Microsoft 365 environment measures up against common regulatory standards. Instead of manually gathering evidence before an audit, Tenaxis checks your configuration and access data continuously and presents findings per control clause.
Supported Frameworks
| Framework | Description |
|---|---|
| ISO 27001 | Information security management — access control, asset management, supplier relationships |
| GDPR / AVG | Data protection requirements — data minimization, access limitation, breach preparedness |
| NIS2 | Network and information systems directive — access control, incident handling, supply chain |
How It Works
When you open the Compliance page and select a framework, Tenaxis runs a set of automated control checks against your live data. Each control maps to a specific clause in the framework and returns one of three statuses:
| Status | Meaning |
|---|---|
| Pass | The control is satisfied based on current configuration and data |
| Warning | The control is partially met, or there is a condition that needs attention |
| Fail | The control is not met — action is required |
Each result includes:
- The clause ID (e.g.
A.9.2.6for ISO 27001) - A plain-language finding explaining what was checked and what was found
- A Fix link that takes you directly to the relevant page in Tenaxis to resolve the issue (where applicable)
Example Controls Checked
The following are examples of what the compliance engine evaluates. The exact control set depends on the selected framework.
- Periodic access reviews are enabled and completing — checks whether access reviews are configured and whether recent reviews have been completed rather than expired
- Disabled accounts have been offboarded — checks whether any site members with disabled Entra ID accounts are still present
- Expired guest access is being cleaned up — checks for guest/visitor records past their expiry date
- High-risk sites have been reviewed — checks whether sites above the risk score threshold have had their access reviewed recently
- Lifecycle management is active — checks whether stale site detection is enabled
- Sharing is restricted on sensitive sites — checks whether sites classified as sensitive have appropriate sharing settings
Reviewing Findings
- Go to Compliance in the left sidebar
- Select a framework from the dropdown
- Review the list of controls — failing and warning controls are shown first
- Click Fix → on any control to jump to the relevant Tenaxis page
- After resolving an issue, you can re-run the check by refreshing the page
Evidence Export
For auditors who need a downloadable evidence package, click Export Evidence Bundle. This generates a ZIP archive containing:
- A summary report (CSV) of all control statuses for the selected framework
- A site access report (CSV) listing all sites, members, and roles
- The audit log export (CSV) for the period you select
The ZIP file is named tenaxis-evidence-<framework>-<date>.zip and is ready to hand to an auditor or attach to your compliance management system.
What the Compliance Dashboard Does Not Replace
The compliance checks are based on the data Tenaxis has — site metadata, membership lists, access review records, and audit logs. They do not:
- Scan your Microsoft 365 tenant for security settings outside of what Tenaxis manages (e.g. Conditional Access policies, MFA enforcement, DLP rules)
- Replace a formal audit performed by a qualified assessor
- Guarantee regulatory compliance — findings are informational signals, not legal opinions
Use the dashboard as a continuous monitoring tool and as a starting point for preparing audit evidence.
Tips
- Run the check before your audit window to identify gaps early and give yourself time to fix them
- Enable access reviews — many controls across all frameworks check whether periodic reviews are configured and completing
- Enable lifecycle management — stale site controls fail when this is turned off
- Address sole-owner sites — several controls flag sites with no active owner as a risk