Register here

NIS2-Compliant M365 Governance: Between Law and Reality

A Teams channel that was shared with "everyone in the company" months ago. A SharePoint site without an owner because the last responsible person left the organization. No one noticed, until now.

With the NIS2 Implementation Act in force since December 6, 2025, situations like these have become a tangible compliance risk. Around 29,500 organizations fall under the supervision of Germany's Federal Office for Information Security (BSI) and must be able to demonstrate governance processes, clear responsibilities, and verifiable controls, including within their Microsoft 365 environments.

The reality in many IT departments looks different: Teams, Groups, and SharePoint sites continue to grow unchecked, ownership is unclear, and organizations struggle to prove who had access to what information and when.

This webinar focuses on exactly this gap between regulatory requirements and day-to-day Microsoft 365 operations.

Our guest speaker, Raphael Köllner, brings a unique combination of expertise. As an attorney, Microsoft Regional Director, and Microsoft MVP, he translates NIS2 requirements into practical guidance for Microsoft 365 administrators and decision-makers.

He will explain what NIS2 actually requires, what the NIS2 frameworks available in Microsoft Purview Compliance Manager can and cannot achieve, and how organizations can establish a sustainable governance foundation for Microsoft 365.

In the second part of the session, we will demonstrate how BCC Affirmatic helps automate governance, lifecycle management, and compliance documentation across Microsoft 365, reducing manual effort while improving control and audit readiness.

What You Will Learn

  • What NIS2 specifically requires from your Microsoft 365 environment, explained from both a legal and technical perspective by an attorney and Microsoft Regional Director
  • How the NIS2 framework in Microsoft Purview Compliance Manager works and where its limitations are
  • Why ownership, lifecycle management, and access governance are critical for compliance and auditability
  • Practical guidance from BCC on establishing sustainable Microsoft 365 governance processes

Who should attend: M365 Admins, Digital Workspace Managers, Heads of IT

Duration: 60 minutes

Language: English

Can't attend live? No problem! Register anyway and receive the recording afterwards.