Operating Microsoft 365 securely and in compliance with NIS2

Unclear security statuses, a lack of governance and increasing regulatory requirements increase the risk. With a structured NIS2 implementation in Microsoft 365, jovoco creates transparency, security and sustainable compliance.

Customer

Customer benefits

Technology stack

"Thanks to jovoco's structured approach, we were able to clearly recognize for the first time where we stand in terms of security and which measures are really relevant. The implementation was comprehensible and practical and our Microsoft tenant is now NIS2-compliant."
Profil
CIO

Challenges of the customer

The existing IT environment had grown historically and was only partially standardized. It was used with local Active-directory structures, while cloud security functions were only used to a limited extent. Multifactor authentication was implemented inconsistently, Conditional-Access policies were completely lacking and end devices were not managed centrally. In addition, there were too many privileged user accounts without clearly defined roles or time limits.
When the NIS2 directive came into force, there was an acute need for action, as neither the current security status was transparent nor was there a clear roadmap for implementation. At the same time, it had to be ensured that security measures did not affect operations and were accepted by employees.

Our approach

The existing Microsoft 365 tenant was systematically analyzed. The aim was to objectively record the actual level of security and compliance maturity and use this to prioritize a Implementation roadmap to be derived. All measures were aligned with NIS2 requirements and implemented in a technically sound manner.

Structured as-is analysis of the tenant

A technical analysis of the Microsoft 365 tenant was carried out. The current security status was automatically assessed and documented with the help of Microsoft Defender Portal and Secure Score. In addition, manual checks were carried out on identities, role models and device structures.
1

Development of a NIS2 catalog of measures

An individual catalog of measures was created based on the analysis. This assigned all identified gaps to the relevant NIS2 requirements and prioritized them according to risk, dependencies and technical feasibility.
2

Introduction of conditional access & zero trust principles

Conditional access policies were introduced to control access based on context. Location, device status and user behavior were incorporated into the authentication logic. As a result, a zero-trust approach was technically implemented.
3

Device compliance with Microsoft Intune

End devices were managed centrally via Microsoft Intune. Security policies, compliance rules and device statuses were defined and integrated into access control. Non-compliant devices were denied access to company resources.
4

Authorization management & final documentation

Privileged access management was used to assign administrative rights in a time-limited and traceable manner. Finally, the entire implementation was documented and made available to the customer for internal and external verification.
5

Results for the customer

Reduction of privileged user accounts
> 0 %
Increase of the Microsoft Secure Score
> 0 %

Further results:

Do you have a specific project in mind?

Your decision would be the same as that of renowned companies:

Geschaftsfuhrer Matthias vom IT Dienstleister jovoco

Similar case studies

Qualitätsmanagement automatisieren

Power Apps in Quality Management: Automatically Recognize Serial Numbers and Streamline Inspection Processes

Blurry images and manual inspection processes slow down quality assurance. With an optimized Power Apps solution, jovoco enables high-resolution image capture, automatic serial number recognition, and more efficient inspection processes.
IT-Systemhaus Serverwartung

Automating IT Service Processes – Centralized Process Control with Power Apps

As the number of systems under management grows, so does the need for clearly structured IT service processes. A solution based on Power Apps, Dataverse, and Power Automate ensures transparent maintenance cycles and centralized process control.
Immobilienverwaltung Digitalisierung Prozessautomatisierung

Property Management digitizes processes and automates workflows with DOMUS and Microsoft 365

Manual administrative processes created a significant workload in day-to-day operations. With jovoco, the property management company developed a scalable foundation for automated workflows and more structured processes centered around DOMUS and Microsoft 365.