Identra

Industries / Financial services

Microsoft security for firms with three regulators watching the same tenant.

US financial services firms run Microsoft 365 while answering to the SEC, the FDIC or OCC, and (for New York firms) NYDFS Part 500. Every regulator asks a slightly different question about the same tenant: who can approve production changes, how privileged access is monitored, and how DLP prevents material non-public information from leaving. Identra configures the tenant so each regulator gets a filtered view of the same underlying evidence, produced live from Entra, Purview, and Sentinel.

Regulations
SOX 404, FFIEC IT Handbook, NYDFS 500, GLBA
Vertical scope
Banks, insurers, asset managers, fintech, broker-dealers
License footprint
M365 E5 recommended (Insider Risk, Sentinel)
Delivery
Fixed scope, fixed price

01 / What we configure

Four control patterns for a multi-regulator tenant.

  • 01

    Privileged access governance

    Every privileged Entra role moved to just-in-time PIM activation with approval and MFA. Trading system administrators subject to enhanced logging with alerts on out-of-hours activation. Break-glass accounts documented, monitored, and reviewed monthly by internal audit.

    PIMTrading admin controlsBreak-glass
  • 02

    Communications compliance

    Purview Communications Compliance policies detect regulatory keywords (MNPI markers, unauthorised trade discussions, conflict-of-interest terms) across Teams, Exchange, and Yammer. Reviews route to the compliance team with a defensible workflow that satisfies FINRA supervision rules.

    Communications ComplianceMNPIFINRA supervision
  • 03

    DLP for financial data

    Purview DLP with US financial sensitive-info type templates catches card numbers, ABA routing numbers, bank account numbers, tax IDs. Custom sensitive-info types added for institution-specific identifiers (customer account numbers, wire transfer confirmations, MNPI project codenames).

    Purview DLPCustom SITsFinancial data
  • 04

    NYDFS Part 500 evidence

    Cybersecurity program documentation, CISO annual certification supporting evidence, encryption of NPI, MFA on all privileged access, and audit trail retention meeting Part 500 baseline. Annual filing supporting materials produced from the same tenant configuration used for daily operations.

    Part 500CISO certificationAnnual filing

02 / What it looks like

Three financial services engagements.

Different regulator overlays, same Microsoft 365 configuration challenges.

CISO at a NYSE-listed regional bank

Situation. Concurrent SOX 404 IT audit and NYDFS Part 500 examination. Two internal teams producing overlapping evidence packs from the same underlying tenant. NYDFS examiner flagged inconsistent MFA rollout across privileged accounts.

Outcome. Single Identra evidence pack filters by regulator scope. Consistent MFA rollout completed in 6 weeks with FIDO2 keys on all privileged accounts. Both audits closed with no material findings.

CTO at a broker-dealer

Situation. FINRA exam focused on supervision of electronic communications. Purview Communications Compliance existed but had never been tuned. Every review queue was overloaded with false positives that compliance stopped triaging.

Outcome. Policy retuned with institution-specific keyword lists and machine-learning classifiers. False positive rate dropped from 60% to under 8%. Review queue cleared and stayed clear. FINRA exam closed with a satisfactory finding.

CIO at a mid-market asset manager

Situation. Recent hire from a competitor arrived with a USB drive containing MNPI from the previous employer. Insider Risk indicators flagged the download but the team had no defined response workflow.

Outcome. Insider Risk playbook defined and integrated with HR onboarding. Departing-employee policy triggers reviews on unusual downloads or external transfers in the notice period. Legal team gained defensible evidence path for the current incident.

03 / Frequently asked

What buyers ask first.

Does NYDFS Part 500 apply to us?
NYDFS Part 500 applies to any entity licensed by the New York Department of Financial Services: banks, insurance companies, credit unions, mortgage brokers, and money transmitters. Even out-of-state entities are in scope if they operate in New York. The 2023 amendment added Class A Company obligations (larger firms) with additional endpoint detection, tabletop, and independent audit requirements. Identra scoping identifies which class you fall into and what the delta is against your current tenant.
What is FFIEC and how does it apply to Microsoft 365?
The Federal Financial Institutions Examination Council publishes the FFIEC IT Handbook, which is the reference material examiners from the OCC, FDIC, Federal Reserve, and NCUA use during exams. The IT Handbook covers authentication, information security, business continuity, and audit. Microsoft 365 configuration satisfying the SOX and NYDFS controls above generally also satisfies the FFIEC IT Handbook technical controls; the difference is in policy narrative and board reporting.
Do we need Microsoft 365 E5?
For a financial services firm with regulatory supervision, E5 pays for itself in Communications Compliance, Insider Risk, Purview Audit Premium, and Sentinel. E3 tenants can reach a defensible posture but the supervision workflows around FINRA and NYDFS become manual and error-prone. Most Identra financial services engagements are E5.
How does Insider Risk work for departing employees?
Purview Insider Risk Management runs baseline detection on all users and enhanced detection on users flagged by HR (departing, on performance plan, high-privilege leaving). Indicators include unusual downloads, mass file access, external file sharing, and email to personal addresses. The policy runs in report-only mode until legal and HR agree on the response workflow, then flips to alerting. Identra typically stages the rollout over 8 to 12 weeks with defined false-positive tuning windows.
How long does a financial services engagement take?
Typical engagement runs 12 to 16 weeks. Weeks 1 to 3 map regulator scope and current tenant posture. Weeks 4 to 10 configure PIM, DLP, and Communications Compliance. Weeks 11 to 16 tune false-positive rates and build the per-regulator evidence pack.

Next step

Book a financial services scoping call.

Thirty minutes on your PIM, DLP, and Communications Compliance posture against SOX, FFIEC, and NYDFS Part 500. Written scoping note within two business days.