NYDFS 23 NYCRR 500 on Microsoft 365: what the controls actually map to
23 NYCRR Part 500 is New York's cybersecurity regulation for DFS-licensed entities, and since 1 November 2025 every phase of its Second Amendment is in force. Microsoft is a third-party service provider under section 500.11, not a compliance shortcut: it publishes a mapping document and sells an assessment template, but holds no NYDFS certification. Which Part 500 controls you can actually evidence depends less on which Microsoft products you own than on which licence tier you bought them at — and on how long your logs survive.
01 / 09
What does 23 NYCRR Part 500 require of a Microsoft tenant?
Part 500 requires a documented cybersecurity programme, a named CISO reporting annually to the senior governing body, multi-factor authentication for all authorized users, a tracked asset inventory, encryption of nonpublic information, annual penetration testing, a tested incident response plan, and notice to the Superintendent within 72 hours of determining a reportable event occurred. It does not require any particular vendor.
The timing question is settled. The Second Amendment took effect on 1 November 2023 and phased in over two years: notice obligations from December 2023, the CISO and encryption provisions from November 2024, access privileges and monitoring from May 2025, and finally multi-factor authentication for all authorized users and the asset inventory duty from 1 November 2025. As of August 2026 there are no transitional dates left to hide behind.
What follows is not a summary of the regulation — DFS publishes that itself, and it is short. It is the part that a Microsoft-based firm gets wrong: the distance between owning a product and being able to evidence a control.
02 / 09
Microsoft is a service provider under 500.11, not a certification
This is the finding most likely to change a control document. Microsoft publishes a 23 NYCRR Part 500 compliance offering page, and firms routinely cite it as though it were an attestation. It is not. There is no auditor, no certificate and no report identifier — unlike Microsoft's ISO 27001 or SOC pages. It is a guidance and mapping document.
More importantly, look at what it puts in scope. As at 24 August 2026 the page lists exactly three in-scope platforms: Azure, Microsoft Intune and Microsoft 365 — with the Microsoft 365 applicability table narrowing to eight Commercial workloads. Microsoft Sentinel, Microsoft Purview, the Defender family, Microsoft Entra and Microsoft 365 Copilot do not appear on it at all.
That does not make those products unsuitable. It means the sentence Microsoft says Sentinel is in scope for NYDFS is not supported by the page people cite when they say it.
- The page disagrees with itself. Its prose repeatedly describes the guidance as covering Azure, Microsoft 365, and Power BI — but Power BI is not on the in-scope list. Intune is on the list and is never mentioned in the prose. Both statements are on the same page.
- It is stale in ways worth knowing. Despite a 2026 revision date it links to archived Advanced Threat Analytics documentation and a legacy Security Center URL, and it never discusses the 2023 amendments at all. The deeper whitepaper it points to sits behind a Service Trust Portal login, so whether that covers the amended Part 500 could not be established — check its date before you rely on it in an examination.
- DFS has already closed the delegation argument. Its October 2025 third-party guidance states that covered entities may not delegate responsibility for compliance to an affiliate or a service provider. Microsoft's own shared-responsibility model agrees: you own your data and identities in software as a service, not just infrastructure.
03 / 09
Which tier of firm are you?
Two thresholds change what applies to you, and both are misread often enough to be worth stating precisely.
| Category | Test | What changes |
|---|---|---|
| Class A company | At least $20m gross annual revenue in each of the last two fiscal years from the entity and its in-state affiliate operations, AND either more than 2,000 employees across the entity and all affiliates anywhere, or more than $1bn gross annual revenue across the entity and all affiliates anywhere. | Three extra duties: independent audit of the programme; a privileged access management solution and automated blocking of commonly used passwords; endpoint detection and response plus centralised logging and security event alerting. |
| Covered entity | DFS-licensed and not exempt. | The full regulation applies. This is the default. |
| Limited exemption | Any ONE of: fewer than 20 employees and contractors; less than $7.5m gross annual revenue in each of the last three fiscal years; less than $15m in year-end total assets. The tests are joined by or, not and. | Excused from a specific list of sections only. The programme, policy, access privileges, risk assessment, third-party policy, MFA, asset inventory and notice obligations all still apply. |
04 / 09
The licence tier decides the control, not the product name
Here is where mapping decks go wrong. They answer an examiner with a product name. The regulation is satisfied by evidence, and whether you can produce evidence is usually decided by which tier you bought.
Three examples that catch firms out. Privileged Identity Management requires Entra ID P2 or Entra ID Governance — it is not in P1, so a Business Premium or E3 tenant has no native PIM, which is awkward against a Class A privileged access requirement. Access reviews are worse: Microsoft's licensing page points them at Entra ID Governance and says only that some capabilities might operate with a Microsoft Entra ID P2 subscription. And Microsoft Sentinel is included in no Microsoft 365 licence at all — it is an Azure consumption service, which matters if you are Class A and reading the centralised-logging requirement.
05 / 09
Your evidence horizon is shorter than you think
Part 500 does not set a log retention period. Your examiner's questions do, and they will reach back further than your defaults.
The number that surprises people most: Microsoft Entra sign-in and audit logs are retained for 30 days on P1 and 30 days on P2. Paying for P2 buys you risk detection, not history. Anything beyond 30 days requires exporting to Log Analytics, a storage account or Sentinel — and Microsoft's billing documentation is explicit that while Office 365 audit logs and Defender alerts ingest free, the raw logs for several Entra ID and Defender data types are paid.
| Evidence source | Retention | Tier |
|---|---|---|
| Entra sign-in and audit logs | 7 days free, 30 days on P1, 30 days on P2 | P2 buys detection, not retention. Export is the only way past 30 days. |
| Purview Audit (Standard) | 180 days | Microsoft 365 E3 and Business Premium. |
| Purview Audit (Premium) | One year by default for Entra ID, Exchange, OneDrive and SharePoint | E5-tier plans. |
| Ten-year audit retention | Ten years | Audit Premium plus a separate per-user add-on. Not retroactive — it must be bought and configured before the incident it is meant to cover. |
06 / 09
The 72-hour clock starts twice
Both Microsoft and Part 500 run a 72-hour notification clock, which is precisely why they get conflated. They are not the same clock and neither satisfies the other.
Microsoft commits to notifying affected customers of a breach within 72 hours under the Data Protection Addendum, and its documentation is specific that the commitment begins when the official security incident declaration occurs — Microsoft's declaration, not your discovery. Delivery is a post to your Message Center in the admin centre, with a secondary email to nominated contacts.
Your obligation under section 500.17(a) is to notify the Superintendent within 72 hours of determining that a reportable cybersecurity event occurred. If nobody is reading the Message Center, Microsoft's notice can arrive and age inside your own window without anyone starting your clock. Assign named readers and wire that portal into the incident response plan you are required to test annually.
07 / 09
What NYDFS actually says about AI
If you are deploying Microsoft 365 Copilot inside a DFS-regulated firm, the relevant document is the October 2024 industry letter on cybersecurity risks arising from artificial intelligence. Read what it is first: it states plainly that it does not impose any new requirements beyond those already in Part 500.
What it does is route AI risk into obligations you already have. Your risk assessment under section 500.9 should address AI you use and AI your service providers use. Third-party diligence under section 500.11 should account for AI-related threats to vendors. Annual training under section 500.14(a)(3) should cover AI-enabled social engineering. And data disposal under section 500.13(b) matters more, not less, when a retrieval system can surface anything it can reach.
One specific recommendation deserves attention because it cuts against common practice: DFS points firms towards authentication factors that deepfakes cannot defeat — digital certificates and physical security keys — rather than voice or video verification. In Microsoft terms that is the phishing-resistant authentication strength, which permits FIDO2 security keys, Windows Hello for Business, and certificate-based authentication.
08 / 09
Frequently asked questions
- Is Microsoft 365 NYDFS compliant? No product is. Part 500 regulates your firm, not your vendor. Microsoft publishes a mapping document and sells an assessment template; it holds no NYDFS certification and DFS has said compliance cannot be delegated to a service provider.
- Does the Compliance Manager template cost extra? Yes, for most firms. The template is named New York - 23 NYCRR Part 500 and is classified premium. A5, E5 and G5 customers can choose three premium regulations at no cost; everyone else buys the premium assessment add-on, per regulation, per year.
- We are Business Premium. Can we comply? Broadly yes on the core obligations, and the gaps are specific rather than general: no Privileged Identity Management, no access reviews, audit capped at 180 days, endpoint detection without deep hunting, and no native SIEM. Whether those gaps matter depends on whether you are Class A.
- Do we need Microsoft Sentinel? Only Class A companies are required to centralise logging and security event alerting. Sentinel is one way to satisfy it, is included in no Microsoft 365 licence, and is billed on ingestion — so scope the data before you scope the tool.
- How long do we need to keep logs? Part 500 sets no period. Work backwards from the evidence an examination or a 72-hour notice would need, then check that your tier actually retains that long. Thirty days of sign-in history is rarely enough.
- When is the annual certification due? By 15 April, signed by both the highest-ranking executive and the CISO. If you are not in full compliance you file a written acknowledgment identifying the sections and a remediation timeline instead — which is a legitimate filing, not a failure.
09 / 09
What we would do, and what we sell
Our advice, and it is an opinion rather than regulatory guidance: start with the evidence, not the controls. Pick the five questions an examiner is most likely to ask — who had privileged access in March, when did this account last authenticate, what was on this device, who approved this vendor, when did we determine the event occurred — and check whether your current tier can answer them. That exercise finds licence gaps faster than any control matrix, because it fails concretely rather than theoretically.
Two contradictions in the source material are worth carrying into your own documentation rather than smoothing over. Microsoft's NYDFS page disagrees with itself about whether Power BI and Intune are in scope. And Microsoft's Defender for Business documentation lists core vulnerability management as included, while the Defender Vulnerability Management page states it is not available to Defender for Business customers. If either sits under a control you are claiming, get written confirmation rather than a screenshot.
The disclosure, plainly: we sell this work. Our NYDFS 23 NYCRR 500 readiness engagement is the gap assessment described above, and our regulated FinTech practice covers the remediation underneath it. Everything here is public — the regulation is on the DFS website, the licensing pages are on Microsoft Learn, and both are linked below. Every claim was verified against those primary sources on 24 August 2026; DFS issues guidance several times a year, so check for letters published after that date before you rely on this.
Primary sources
- NYDFS — 23 NYCRR Part 500, Second Amendment adopted text (including the section 500.22 phase-in schedule)
- NYDFS — Cybersecurity Regulation 23 NYCRR Part 500 landing page
- NYDFS — Cybersecurity Risks Arising from Artificial Intelligence and Strategies to Combat Related Risks (16 October 2024)
- NYDFS — Guidance on managing risks arising from third-party service providers (21 October 2025)
- NYDFS — Measures regulated entities should consider in a heightened cybersecurity threat environment (21 May 2026)
- NYDFS — Part 500 requirement checklist for regulated entities with limited exemptions
- Microsoft — Title 23 NYCRR Part 500 compliance offering (the in-scope service list)
- Microsoft Purview — Compliance Manager assessment templates list (New York - 23 NYCRR Part 500 is premium)
- Microsoft Purview — Compliance Manager premium assessment licensing
- Microsoft Entra — ID Governance licensing fundamentals (PIM, access reviews, lifecycle workflows)
- Microsoft Entra — Activity log data retention policies (7, 30 and 30 days)
- Microsoft Entra — Conditional Access authentication strengths (phishing-resistant methods)
- Microsoft Purview — Auditing solutions overview (Standard and Premium retention)
- Microsoft — Defender for Endpoint Plan 1 capabilities
- Microsoft — What is Microsoft Defender for Business?
- Microsoft Sentinel — Plan costs and understand pricing and billing
- Microsoft — Security incident management and the 72-hour notification commitment
- Microsoft — Shared responsibility in the cloud