Try For Free
DORA, Regulation (EU) 2022/2554

Prove DORA control of your Microsoft 365 and AI estate

DORA makes financial entities identify, risk-manage and evidence every ICT asset, and the agents, automations and workspaces in your Microsoft tenant are ICT assets most registers have never seen.

The Rencore Governance dashboard for Microsoft 365: an inventory tile counting 1,150 users, 380 groups, 12 sensitivity labels, 13 subscriptions, 527 service assignments, 428 message center messages, 77 apps, 6,918 user activity records, 50 deleted users, 4 deleted groups and 3 rooms and equipment, each with its change over the period; a compliance summary donut at 81 percent with 949 high, 2,701 medium and 15 low violations against 16,307 compliant items; and policy cards for users with a Power Platform premium licence, external users with pending acceptance, and disabled user accounts at 110 violations found.

Trusted by the world’s leading organizations

  • MAPAL
  • bam
  • VDL
  • Wacker
  • Grundfos
  • Amgen
  • Lufthansa
  • thyssenkrupp
  • Sunrise
  • Pattern

What DORA requires

DORA has applied to EU financial entities since 17 January 2025. Four of its duties land on the Microsoft estate, on ICT assets and accountability:

Art. 5

Board accountability

The management body defines, approves and oversees the ICT risk framework.

Art. 8

Complete asset view

Identify every ICT asset, map its dependencies and keep that current.

Art. 9, 10

Protection and detection

Monitor ICT systems continuously and catch anomalous activity fast.

Art. 3(7)

Business-built assets count

An agent or flow is an ICT asset, whoever built it.

Who it applies to

Applies to banks, insurers, investment firms and other EU financial entities, and the ICT providers serving them, in force since 17 January 2025.

Where the Microsoft estate breaks it

Most Microsoft tenants grow their fastest ICT assets outside every asset process, and DORA’s duties fail quietly inside that gap:

Agents and flows skip intake

Any licensed user ships a Copilot agent or a Power Platform flow, with no owner and no register entry.

Owners leave, assets stay live

Flows keep running on a departed employee’s connections, and no one is accountable for what they reach.

External access accumulates

Guest accounts and sharing links pile up in the workspaces those agents read, and no one re-reviews them.

Nothing feeds the register

The Art. 8 inventory is kept for servers, while the tenant fills with assets no register has ever seen.

How Rencore maps to DORA

Rencore inventories, governs and evidences the Microsoft slice of your DORA scope, from Copilot and AI agents to Power Platform and Microsoft 365 collaboration; it complements the Microsoft controls you already run and never replaces them.

DORA Art. 8

Full-estate inventory, agents included

Every workspace, app, automation and agent in your tenant, with its owner and the data it can reach: the Microsoft slice of your ICT asset register, kept current.

The Rencore Governance object inventory, expanded for Microsoft 365: 1,150 users, 380 groups, 12 sensitivity labels, 13 subscriptions, 527 service assignments, 428 message center messages, 77 apps, 6,918 user activity records, 50 deleted users, 4 deleted groups and 3 rooms and equipment, each row expandable to the objects behind the count.
DORA Art. 5

An owner and an end of life for every asset

Each asset carries a named owner, and orphaned agents and flows are flagged, reassigned or retired instead of running on unattended.

Rencore Governance policy reading "Every Power App (Canvas App) where App Type equals Canvas that has no PowerApp Co-Owners and no PowerApp Owners": 24 ownerless apps found, up 9 or 60 percent, with a bar chart of total, new and removed ownerless apps from late April to mid July 2026.
DORA Art. 9, 10

Continuous policy monitoring

Policies run across workspaces, apps and agents, ranking every violation by severity so enforcement follows automatically.

The Rencore Governance Policies view for the Security category: a compliance score of 67 percent, up 21 percent over the period, and a Top Issues table ranking violations by severity: 13,566 SharePoint files shared with external users, 49 mailbox folders shared with default or anonymous users, 38 groups with external owners, 33 mailbox delegations granted to external users and 30 external sharing risks, each with its trend.
DORA Art. 50

Exportable evidence, not screenshots

The inventory, owners, violations and trend, scheduled or on demand, as documents you can hand to a supervisor.

The Rencore Governance report library for Microsoft 365: reports for users by type and by region at 1,150 each, internal users at 941, external users at 99, email domains of external users at 99, suspended and disabled subscriptions, distribution groups and groups with Teams at 92, each row showing its category, current value and trend line.

Mapping at a glance

How each Rencore capability answers a specific article of DORA.

  • Full-estate inventory Art. 8

    Your ICT asset register for the Microsoft estate, kept current.

  • Owners and lifecycle Art. 5

    A named owner and an end of life for every asset.

  • Policy monitoring Art. 9, 10

    Continuous detection with severity-ranked enforcement.

  • Exportable evidence Art. 50

    Documents a supervisor can act on, on demand.

Inventory, control and exportable evidence for your Microsoft estate.

No tool makes you DORA-compliant on its own; that judgement stays with your entity and its competent authority, on the evidence.

Trusted by security, IT, and platform leaders

Security, IT, and platform leaders use Rencore to see their Microsoft estate, cut cost and risk, and roll out Copilot and agents on a governed foundation.

  • With Rencore's scalable automation solutions, organizations can not only meet current challenges but also prepare themselves for future technological advancements.
    Case Study
    Philipp Widmer Philipp Widmer Head of Platform Services Universitätsspital Basel
  • 26% vs 3%

    Organizations that govern Microsoft 365 well realize significant Copilot value 26% of the time, versus 3% for those that do not.

    Gartner, 2025 Microsoft 365 Copilot Survey
  • As we continue to expand our cloud capabilities, the foundation laid by Rencore Governance will undoubtedly play a crucial role in ensuring that each step forward is taken with confidence, security, and compliance in mind.
    Case Study
    Claude Bisdorff Claude Bisdorff Head of IT Systems Ville de Luxembourg
  • 116%

    ROI from Microsoft 365 Copilot once the program is adopted and governed, in Forrester’s Total Economic Impact study.

    Forrester Total Economic Impact
  • I currently estimate that we save around €80k per year by freeing up our IT admin team to do the work that counts.
    Case Study
    Undisclosed Undisclosed Former Lead O365 Competence Center Royal BAM
  • 71%

    of enterprises name security and governance among their top challenges to deploying Microsoft 365 Copilot.

    Gartner
  • Rencore's centralized governance tool excelled at ensuring secure data in Microsoft 365 and minimizing the risk of unauthorized access.
    Case Study
    Greg Bowles Greg Bowles IT Operations Manager Specialist Risk Group
  • 150,000+

    AI agents in use at the average Fortune 500 company by 2028. Agent sprawl is the next sprawl.

    Gartner
  • With Rencore Governance we are able to reduce manual governance activities, improve our service quality and generate valuable insights across our Microsoft service stack.
    Undisclosed Undisclosed Head of AI & Process Automation Wacker Chemie AG

Frequently asked questions

Is a Copilot agent an ICT asset under DORA?
DORA defines an ICT asset as a software or hardware asset in the network and information systems the entity uses (Art. 3(7)). A Copilot agent runs in your tenant, reads business data at the permissions granted to it and acts on that data, so it sits inside that definition, and Art. 8 requires you to identify it like any other asset. The same reasoning covers Power Platform flows and custom apps.
Does Microsoft’s native tooling maintain the ICT register for me?
Each Microsoft admin surface lists its own objects, per service and per environment. The Art. 8 duty is different in kind: one current view of all ICT assets, with owners and dependencies, feeding your register. Rencore builds that consolidated inventory across Microsoft 365, Power Platform and Copilot and keeps it current, complementing the Microsoft controls (Purview, Entra) you already run.
What evidence will a supervisor actually ask for?
Requests follow the articles: the ICT asset inventory with owners and dependencies (Art. 8), proof that the management body directs and reviews ICT risk (Art. 5), evidence that protection policies are monitored and enforced (Art. 9 and 10), and the register of information on ICT third-party arrangements (Art. 28(3)). Rencore exports the Microsoft-estate part of each as reports you can hand over.
How does this relate to the EU AI Act obligations we already track?
The two regulations meet in the same estate. DORA asks whether an agent is identified, owned and monitored as an ICT asset; the EU AI Act asks how the AI system itself is classified and overseen. One current inventory of your agents and the data they depend on serves both, which is why the same Rencore inventory backs our EU AI Act coverage.

See your estate the way a supervisor will

Start with the inventory: every agent, automation and workspace in your Microsoft tenant, with owners, access and the data they reach, ready to feed your ICT register.

The Rencore Governance compliance summary for Microsoft 365 Copilot: a donut at 75 percent, with 9 high, 865 medium and 0 low violations against 2,652 compliant items, and an information row at 0.