Microsoft Security Compliance Mapper

Map Microsoft 365 security products to NIST CSF 2.0 controls, find your compliance gaps, get priced product recommendations and export the analysis.

Advertisement

Map your Microsoft security licences to compliance framework controls

This tool answers one narrow question: given the Microsoft security products you already own, which controls in a chosen compliance framework do they actually address, and which ones are left open? You pick a framework, tick the products in your tenant, and get a control-by-control coverage view, a per-function breakdown, a ranked list of gaps, and suggestions for which additional Microsoft product would close the most of them.

It is a product-to-control mapper, not a framework-to-framework crosswalk. It will not tell you how ISO 27001 A.8.7 lines up with NIST CSF PR.PS-02. It tells you whether Defender for Endpoint P2 covers PR.PS-02 and how well. If you need a crosswalk between two standards, this is not that tool.

What it maps, exactly

Six frameworks ship with the tool, each with its own control set, its own grouping labels, and its own hand-built product mappings:

FrameworkControls includedWhat the tool calls themProduct mappings
NIST CSF 2.048Controls, grouped by Function (Govern, Identify, Protect, Detect, Respond, Recover)66
HIPAA Security Rule49Implementation Specifications, flagged required or addressable54
SOC 251Criteria, grouped by Trust Services Category39
PCI DSS 4.052Sub-Requirements32
CMMC 2.056Practices45
CIS Controls v856Safeguards43

These are curated subsets, not the complete published control catalogues. NIST CSF 2.0 in full has considerably more subcategories than 48. The tool covers the controls where a Microsoft security product is plausibly relevant, plus the process-only controls it needs to name in order to exclude them honestly. Treat the control list as a working scope, not as an authoritative reproduction of the standard.

On the product side, 22 Microsoft security SKUs are modelled — Entra ID P1/P2 and the Entra Suite, Defender for Business, Defender for Endpoint P1/P2, Defender for Server P1/P2, Defender Vulnerability Management, Defender for Office 365 P1/P2, Defender for Identity, Defender for Cloud Apps, Sentinel, Security Copilot, Azure Information Protection P1/P2, Purview Information Protection, Compliance Manager, Insider Risk Management, Purview Audit (Premium), and Intune P1.

Products carry an includes relationship that the tool resolves transitively. Selecting Defender for Endpoint P2 automatically credits you with P1's coverage; selecting Entra ID P2 credits P1. You do not have to tick both.

Why a control mapping is approximate, and how to say so out loud

This is the part that matters more than the interface. A control in a compliance framework is a statement of intent expressed in the language of that framework, and a product is a set of capabilities. They almost never correspond one to one. A single product often partially satisfies a control, several products together satisfy one control, and one product touches a dozen controls at different depths.

The tool encodes that explicitly with three coverage levels rather than a binary tick, plus two more states for controls no product can reach:

StateMeaningWeight in the overall score
Covered (full)The product substantively implements the control100
PartialThe product implements part of it; something else is still needed50
SupportsThe product provides evidence or telemetry that helps, but does not implement the control25
GapNothing you selected touches it0
Non-technicalA process, policy or governance control no product can satisfyExcluded from the denominator

The overall coverage percentage is the weighted sum of those points divided by the number of assessable controls. Non-technical controls drop out of the denominator entirely — but only while nothing covers them, so a governance control that happens to have a product mapping is counted normally. Per-function percentages use a slightly coarser weighting than the headline figure: there, partial and supports both count as 50 rather than 50 and 25. Expect the function bars and the top-line number to disagree slightly. That is the arithmetic, not a bug.

The design decision worth understanding is why “supports” exists at all. Most vendor coverage matrices collapse it into “covered”, which is how organisations end up telling an auditor they have implemented a control when what they actually have is a log source that would help prove it if they had implemented it. Keeping supports at a quarter weight makes that distinction survive into the score.

How not to over-claim to an auditor

A product mapping is a starting hypothesis about where to look for evidence. It is not evidence, and it is not an assessment. Three specific traps:

  • Owning a licence is not configuring it. Every mapping here assumes the product is deployed and configured to do the thing described. An Entra ID P2 licence assigned to nobody covers zero controls. The tool cannot see your tenant and does not claim to — it maps entitlements, not posture.
  • “Covered” is a capability judgement, not an audit finding. An assessor will ask for configuration screenshots, policy documents, and evidence of operation over a period. The mapping tells you which product to go and pull that evidence from.
  • Never present the percentage as a compliance score. It is a technical-coverage estimate over a curated subset of controls, with a weighting the tool chose. Saying “we are 78% NIST CSF compliant” because a browser tool said 78% is exactly the over-claim this design is trying to prevent.

The defensible way to use the output is the inverse: as a gap register. “These fourteen controls have no Microsoft product behind them, here is what each would need” is a statement you can hand to a compliance lead and act on. Each gap carries a plain-English note explaining why no Microsoft product addresses it and what category of control would — a third-party tool, a documented procedure, a physical control, or a contractual one.

Working through it: the four tabs

Setup. Choose one of the six frameworks, then load a stack. Four presets cover the common starting points:

  • No Microsoft security products — the full unmitigated gap picture for the framework, useful as a baseline before you have bought anything.
  • Microsoft 365 Business Premium — Defender for Business, Defender for Office 365 P1, Intune P1, Entra ID P1, AIP P1.
  • Microsoft 365 E3 — Defender for Endpoint P1, Entra ID P1, Intune P1, AIP P1.
  • Microsoft 365 E5 — Entra ID P2, Intune P1, Defender for Endpoint P2, Defender for Office 365 P2, Defender for Identity, Defender for Cloud Apps, AIP P2, Purview Information Protection, Insider Risk Management, Purview Audit (Premium).

Presets are a starting selection, not a lock — switch to Custom and tick or untick individual products, which is what you want if you are on E3 with a couple of add-ons.

Dashboard. Headline coverage percentage, a bar chart per framework function, and counts of covered, partial, gap, and non-technical controls in each. This is where the shape of the problem shows: a stack that is strong on Protect and empty on Recover looks very different from one that is evenly thin.

Controls. The full list, searchable and filterable by function and by coverage state. Filter to gaps only and you have your work list. Expand any control to see which of your products touch it and the specific capability that does the touching — not just “Intune” but what Intune does for that control.

Recommendations. Products you have not selected, ranked by how many of your current gaps they would close.

How the recommendations are ranked, and where to distrust them

For each unselected product the tool counts two things: gaps it would close outright, and controls currently at partial or supports that it would raise to full. Priority is assigned by gap count alone — four or more gaps is high, two or three is medium, one is low. Coverage gain is computed as (gaps closed × 100 + upgrades × 50) divided by the assessable control count.

Two limits to keep in mind. First, the products are scored independently, so if two candidates both close the same five gaps, both show a five-gap gain — buying both does not double the benefit. Second, the PDF export sums the per-user list price of every recommendation into a “total additional cost to address all gaps” line. That is the cost of buying the entire recommendation list, overlaps and all. It is an upper bound on a shopping list nobody would actually buy, not a budget.

The tool does ship list prices — a per-user-per-month figure for each of the 22 products, used to annotate recommendations. Microsoft list pricing changes and varies by agreement, region, and channel, so read those as the figures the tool was built with rather than as your price. Products with genuinely different billing units are flagged in their descriptions: Defender for Server is licensed per server, Sentinel is billed per GB per day ingested, and Security Copilot is billed per Security Compute Unit per hour. A per-user figure for any of those three is a rough planning proxy, not how you will be invoiced.

Exports and privacy

Two export formats. CSV gives you one row per control — control ID, name, status, covering products, the specific capability text, a gap flag, and the non-Microsoft alternative where one is recorded — which is the right shape to paste into a compliance tracker. PDF produces a formatted assessment with an executive summary, a per-function table, the full control detail, and the recommendations table. Both are generated in your browser and downloaded directly; the tool does not upload your product selections anywhere.

Nothing is saved between visits. Reloading resets the framework and the selected stack, so export before you close the tab if you want the result.

A realistic workflow

  1. Start with the No Microsoft security products preset on your target framework and read the non-technical count. That is the portion of the framework no purchase will ever fix — knowing it up front stops the licensing conversation from being asked to solve policy problems.
  2. Select what you genuinely own today, not what you are entitled to buy. Export the CSV as your baseline.
  3. Filter the Controls tab to gaps and split them: the ones with a Microsoft product available (a licensing decision) and the ones with a non-Microsoft note (a procurement or process decision).
  4. Take the top one or two recommendations, add them to the selection, and re-read the coverage. If two products claim similar gains, check whether they are closing the same controls before assuming the gains add up.
  5. Hand the gap list, not the percentage, to whoever owns the audit.

Used that way the tool does the one thing that is genuinely tedious to do by hand — holding six frameworks, 22 products, and a few hundred mapping relationships in view at once — and leaves the judgement calls where they belong.

This tool is provided for informational and educational purposes only. All processing happens in your browser — no data is sent to or stored on our servers. While we strive for accuracy, we make no warranties about the completeness or reliability of results.
Microsoft Compliance Mapper - M365 to NIST | InventiveHQ