Continuous Compliance Is Not a Slogan — Here's What It Actually Looks Like Inside Microsoft 365

8/22/2026 · Compliance365

"Continuous compliance" gets used by almost every GRC vendor as a slogan and almost none as a literal description. Most compliance programs are still, mechanically, a point-in-time exercise — a scramble every 12 months to reconstruct evidence nobody kept current in between.

This post skips the marketing framing and describes the actual mechanism: what runs unattended, on what schedule, where the data goes, and who gets told what — inside Checkpoint, running entirely in your own Microsoft 365 tenant.


The default state most organisations are actually in

A control gets marked “Implemented” at certification time, evidence gets attached, and then — nothing checks it again until the next audit cycle. A vendor’s SOC 2 report expires quietly. An overdue remediation action sits in a spreadsheet with an owner’s name against it that nobody follows up. None of this is negligence; it’s just what happens when the only thing driving a re-check is a human remembering to look.

Auditors read this pattern correctly: a control that hasn’t been re-verified in fourteen months reads the same as one that was never properly implemented, regardless of what actually happened in between.

What actually runs on a schedule

An optional Azure Function — deployed into your own Azure subscription, not ours — re-runs the same posture checks the interactive app runs, daily, with no browser open and no user signed in:

Daily posture re-scan

Reads live Entra, Intune and Defender signals and writes a new scored scan record — the same evidence trail as a manual scan, on autopilot.

Drift alerts

A check that scored pass yesterday and fails today raises an alert the moment it happens — not at next quarter's review.

Overdue-work chasing

Overdue remediation actions, controls due for re-verification, stalled policy attestation campaigns — each raised as its own alert, once, until acknowledged.

Vendor review chasing

A vendor's reassessment due date, or the expiry of the SOC 2 report / certificate you're relying on for them, gets chased the same way — 30 days ahead, and again if it's missed.

Findings land in the same alerts register the interactive app already shows on the Dashboard — and, as of this week, can also post straight into a Microsoft Teams channel, so the people who need to see it see it where they’re already working, not in an inbox they check once a day.

Where the evidence actually goes

Every one of those scheduled scans writes to the same SharePoint lists your interactive sessions write to — in your own tenant, not ours. There’s no separate “automation database” to reconcile against your manual records, because there’s only ever one record. Evidence behind each check is hashed (SHA-256) at the moment it’s captured, so what an auditor is shown a year later is provably the same thing the scan actually saw, not a document that could have been edited in between.

What this replaces

The honest comparison Without this, "continuous compliance" means a practitioner opening a browser tab periodically and hoping they remember everything that's drifted since the last time. With it, drift gets reported the day it happens, overdue work gets chased without anyone having to remember to chase it, and the evidence an auditor eventually asks for was already filed, dated, and hashed — months before the audit, not the week before it.

The one thing this deliberately doesn’t do is write anything on your behalf. Every alert is a nudge to a human, not an automated remediation — a control gets marked Implemented, an action gets closed, a policy gets approved, only when a practitioner actually does it. The automation’s job is making sure nothing sits silently overdue, not taking the decision out of anyone’s hands.

Where to start

This is entirely optional and additive — Checkpoint works exactly the same without it, as an on-demand tool a practitioner runs interactively. Turning it on just adds the unattended half. If you’re already running Checkpoint, it’s a short deployment guide away. If you’re not yet, book a free 30-minute call and we’ll show you the whole thing running against a demo tenant.

About Compliance365

We deliver ISO 27001, Essential Eight, SOC 2, ISO 42001 and ISO 27701 for Australian mid-market organisations — fixed-price, inside your existing Microsoft 365 environment, with audit-ready evidence at every step. Explore our services →

Share this article: Share on LinkedIn

Found this useful? Get the ISO/Privacy/AI readiness checklists.

Browse resources

Ready to take the next step?

ISO 27001 Certification

Full ISMS implementation and Stage 1/Stage 2 audit support. Typically certified in 12–16 weeks.

Learn more Book a free call

Free monthly digest

Get the monthly Australian compliance digest

Practical updates on ISO 27001, Essential Eight, Privacy Act and AI governance — delivered once a month. No spam, unsubscribe any time.

No spam. Unsubscribe any time. We never share your email.

Microsoft Teams