Skip to content

Evidence and scans

What Certaria reads from your Microsoft 365 tenant, on what schedule, and how to tell the difference between no evidence and a failed scan.

Audience: ISMS Admin.

Where: the Certaria app. Scans read your Microsoft 365 configuration in the background.

Why this matters: most of your ISO 27001 evidence already exists in your Microsoft 365 configuration. This is the part of Certaria that finds it, and it runs whether or not anyone is watching, which makes it the part administrators understand least.

Every scan reads seven sources at once:

SourceWhat it evidences
Microsoft Secure ScoreOverall security posture, including the individual control recommendations behind the score
Intune device managementEndpoint and asset controls
Sensitivity labelsInformation classification and handling
Audit loggingMonitoring and logging controls
Conditional AccessAccess control and identity
Directory role assignmentsPrivileged access: who holds administrative roles
OAuth grants and service principalsThird-party application access to your tenant

Each source credits the Annex A controls it supports, and the result lands in Scan History.

WhatWhenNotes
Daily readiness scanOnce a dayStarted by Certaria: Schedule Evidence Scan, which hands the work to the shared scan
On-demand scanWhen you start one yourselfThe same seven sources. Certaria calls this Sync Now
Device compliance top-upEvery dayRefreshes device controls only if device evidence is more than 48 hours old
Device register syncOnce a dayBrings your Intune-managed devices into the asset register

The device top-up is worth understanding. It exists so device evidence never goes stale between full scans, and it does nothing at all when a recent scan has already covered those controls. A day where it does nothing is a day it worked.

The daily device sync adds or updates each Intune-managed device with its compliance state, operating system version, and when it last checked in with Intune. Your asset register stays current without anyone typing into it.

What it does not do is decide anything. Whether a device is in scope, who owns it, and what happens when it falls out of compliance are all yours.

You will receive an email headed “Readiness Scan completed with errors”. The scan finished; one of its sources did not.

  1. Read the error line. It names the source, for example Sensitivity Labels: Failed.
  2. The usual cause is a missing Graph permission. The app registration lacks the permission for that source, or consent was granted as Delegated rather than Application. See Graph consent.
  3. Re-run the scan. A clean run sends no email.

The scan deliberately completes rather than aborting: six sources of evidence collected is better than none, and you get told precisely which one is missing.

“No evidence” and “not applicable” are different things, and only you can tell them apart. A control with no evidence might be one Certaria cannot see, one you have implemented outside Microsoft 365, or one that genuinely does not apply to you. The scan reports what it found. The Statement of Applicability is where you record what it means.

A control evidenced automatically is still your responsibility. Certaria can show your auditor that Conditional Access policies exist. It cannot tell them the policies are the right ones.

SymptomCauseFix
Scan email lists a failed sourceMissing or wrongly typed Graph permissionCheck the permission is under Application permissions with admin consent
Device evidence looks staleThe top-up only fires when evidence is over 48 hours oldExpected. Run a full scan if you need it now
Fewer controls evidenced than last timeA source failed, or something genuinely changed in your tenantCheck Scan History and the most recent scan email
No scans at all in Scan HistoryThe daily schedule flow is switched offTurn it on in the solution’s cloud flows list
Devices missing from AssetsThey are not Intune-managed, so Certaria cannot see themAdd them by hand, or bring them under Intune