What DORA requires
DORA has applied to EU financial entities since 17 January 2025. Four of its duties land on the Microsoft estate, on ICT assets and accountability:
Board accountability
The management body defines, approves and oversees the ICT risk framework.
Complete asset view
Identify every ICT asset, map its dependencies and keep that current.
Protection and detection
Monitor ICT systems continuously and catch anomalous activity fast.
Business-built assets count
An agent or flow is an ICT asset, whoever built it.
Who it applies to
Applies to banks, insurers, investment firms and other EU financial entities, and the ICT providers serving them, in force since 17 January 2025.
Where the Microsoft estate breaks it
Most Microsoft tenants grow their fastest ICT assets outside every asset process, and DORA’s duties fail quietly inside that gap:
Agents and flows skip intake
Any licensed user ships a Copilot agent or a Power Platform flow, with no owner and no register entry.
Owners leave, assets stay live
Flows keep running on a departed employee’s connections, and no one is accountable for what they reach.
External access accumulates
Guest accounts and sharing links pile up in the workspaces those agents read, and no one re-reviews them.
Nothing feeds the register
The Art. 8 inventory is kept for servers, while the tenant fills with assets no register has ever seen.
How Rencore maps to DORA
Rencore inventories, governs and evidences the Microsoft slice of your DORA scope, from Copilot and AI agents to Power Platform and Microsoft 365 collaboration; it complements the Microsoft controls you already run and never replaces them.
Full-estate inventory, agents included
Every workspace, app, automation and agent in your tenant, with its owner and the data it can reach: the Microsoft slice of your ICT asset register, kept current.

An owner and an end of life for every asset
Each asset carries a named owner, and orphaned agents and flows are flagged, reassigned or retired instead of running on unattended.

Continuous policy monitoring
Policies run across workspaces, apps and agents, ranking every violation by severity so enforcement follows automatically.

Exportable evidence, not screenshots
The inventory, owners, violations and trend, scheduled or on demand, as documents you can hand to a supervisor.

Mapping at a glance
How each Rencore capability answers a specific article of DORA.
- Full-estate inventory Art. 8
Your ICT asset register for the Microsoft estate, kept current.
- Owners and lifecycle Art. 5
A named owner and an end of life for every asset.
- Policy monitoring Art. 9, 10
Continuous detection with severity-ranked enforcement.
- Exportable evidence Art. 50
Documents a supervisor can act on, on demand.
Inventory, control and exportable evidence for your Microsoft estate.
No tool makes you DORA-compliant on its own; that judgement stays with your entity and its competent authority, on the evidence.
Trusted by security, IT, and platform leaders
Security, IT, and platform leaders use Rencore to see their Microsoft estate, cut cost and risk, and roll out Copilot and agents on a governed foundation.
Frequently asked questions
Is a Copilot agent an ICT asset under DORA?
Does Microsoft’s native tooling maintain the ICT register for me?
What evidence will a supervisor actually ask for?
How does this relate to the EU AI Act obligations we already track?
Related reading
The neighboring EU regulations converge on the same Microsoft inventory. These cover the obligations next door:



