Compliance
Signal-model focused view (not client-scoped).
Question to Signal Mapping
Demo Scenario: The Expanse simulation dataset is active. No live tenant data is being queried.
Mapping Summary

Questions in Scope

75

Dataset Signal Questions

62

Process/Narrative/Governance

13

Question Signal Matrix

Shows the platform signals used to answer each question. Filtering, sorting, and paging are handled by MudDataGrid.

Question Control
Signal Classification Signals Checked
A7.1
Are your users only provided with user accounts after a process has been followed to approve their creation? Describe the process.
Privileged Account Separation
Dataset Signals
Answered using dataset telemetry and control evidence.
  • M365 (Authoritative) Identity platform role assignments and account usage provide the source of truth.
A7.2
Are all your user and administrative accounts accessed by entering unique credentials?
Privileged Account Separation
Dataset Signals
Answered using dataset telemetry and control evidence.
  • M365 (Authoritative) Identity platform role assignments and account usage provide the source of truth.
A7.3
How do you ensure you have deleted, or disabled, any accounts for staff who are no longer with your organisation?
Privileged Account Separation
Dataset Signals
Answered using dataset telemetry and control evidence.
  • M365 (Authoritative) Identity platform role assignments and account usage provide the source of truth.
A7.4
Do you ensure that staff only have the access privileges that they need to do their current job? How do you do this?
Privileged Account Separation
Dataset Signals
Answered using dataset telemetry and control evidence.
  • M365 (Authoritative) Identity platform role assignments and account usage provide the source of truth.
A7.5
Do you have a formal process for giving someone access to systems at an administrator level and can you describe this process?
Privileged Account Separation
Dataset Signals
Answered using dataset telemetry and control evidence.
  • M365 (Authoritative) Identity platform role assignments and account usage provide the source of truth.
A7.6
Are administrative accounts separate from standard user accounts and used only for administrative tasks?
Privileged Account Separation
Dataset Signals
Answered using dataset telemetry and control evidence.
  • M365 (Authoritative) Identity platform role assignments and account usage provide the source of truth.
A7.7
How does your organisation prevent administrator accounts from being used to carry out everyday tasks like browsing the web or accessing email?
Privileged Account Separation
Dataset Signals
Answered using dataset telemetry and control evidence.
  • M365 (Authoritative) Identity platform role assignments and account usage provide the source of truth.
A7.8
Do you formally track which users have administrator accounts in your organisation?
Privileged Account Separation
Dataset Signals
Answered using dataset telemetry and control evidence.
  • M365 (Authoritative) Identity platform role assignments and account usage provide the source of truth.
A7.9
Do you review who should have administrative access on a regular basis?
Privileged Account Separation
Dataset Signals
Answered using dataset telemetry and control evidence.
  • M365 (Authoritative) Identity platform role assignments and account usage provide the source of truth.
A7.10
Where you have systems that require passwords (or where passwords are a backup for a passwordless system), how are they protected from brute-force attacks?
Privileged Account Separation
Dataset Signals
Answered using dataset telemetry and control evidence.
  • M365 (Authoritative) Identity platform role assignments and account usage provide the source of truth.
An unhandled error has occurred. Reload 🗙

Rejoining the server...

Rejoin failed... trying again in seconds.

Failed to rejoin.
Please retry or reload the page.

The session has been paused by the server.

Failed to resume the session.
Please retry or reload the page.