Managed service providers · 19 August 2026 · 4 min
The audit trail is no longer internal — it is something your clients buy
Cyber insurance questionnaires, your clients' auditors and tightening EU requirements now put the same question to the MSP: prove who had access, who approved, and what was done. "We have a process" is no longer an answer.
Something has changed in who asks about access governance. Audit trails used to be an internal quality concern. Now the questions come from outside, from three directions at once — and they land on the MSP, because the MSP holds the keys.
The insurers first. Cyber insurance questionnaires have become concrete: how is privileged access governed, how are departures documented, who at the provider has admin access. The client's answers to those questions are, in practice, about you — and imprecise answers can affect both premium and insurability. An MSP that lets its client answer precisely is worth more than one that lets its client answer "we have routines for that."
Then the auditors. When the client's audit tests IT general controls, access management is a classic: show us that access changes are approved, and that what was approved is what was executed. In an operating model with a ticketing system, manual execution and Entra logs in three separate systems, each such question is an archaeological project — billable to no one, irritating to everyone.
And the regulation. EU regulation in finance and critical infrastructure is pulling in the same direction, with tightening requirements on access governance, supplier oversight and traceability — requirements that propagate down the supply chain to the MSPs who actually hold the environments. [Be precise before publication: concrete claims about what NIS2/DORA require must be verified against the legal texts — the direction is right, but the wording has to survive a lawyer.]
The common denominator is that all three ask for the same evidence: a coherent chain from justification to executed change. And that is exactly what an order model produces as a by-product of ordinary operations. In Entra Logic, every change in every client tenant is born as a structured order with a sender and a justification, approved by the right party in that tenant's flow, and executed automatically against Microsoft Graph — with the whole chain in one trail. Nobody holds standing admin rights that need explaining, and "what was approved is what was executed" is not a claim about discipline but a property of the architecture.
Note what this is not: Entra Logic is not a certification or attestation product. It does not run periodic recertification campaigns and does not enforce segregation-of-duties rules — if your client needs that, dedicated tools exist for it. What Entra Logic provides is the evidence base most of the questions are actually about: continuous, complete and queryable, not reconstructed after the fact.
That opens a commercial opportunity MSPs have been slow to take: make the traceability part of the offering. "Audit-ready access management" — insurance questionnaire answered in hours, auditor trails in minutes — is a service that clients in finance, energy and the public sector have budget for now. Your competitors deliver operations. You can deliver operations that can be proven.
Norwegian version: Les artikkelen på norsk
Related reading
- Copilot credits turn group hygiene into a budget question
Managed service providers · 4 min
- Self-service for the client's employees is the service desk's best cost cut
Managed service providers · 4 min
- One console, many tenants: what MSPs actually need from Entra ID tooling
Practice · 6 min