Connect Microsoft 365 / Entra ID (formerly Azure AD) read-only and within minutes you have the basis of your inventory: the tenant's devices, users and licences.
The asset inventory is one of the basic controls in any security framework, NIS2 included: the ACN measures require up-to-date inventories of devices, services and software. Yet it’s also the one most SMEs haven’t kept up to date: spreadsheets filled in once and never touched again.
Why it matters
You can’t protect what you don’t know you have. An up-to-date inventory is the prerequisite for managing vulnerabilities, applying patches and proving compliance at audit time.
The manual method (and why it fails)
Traditionally the data is collected by hand: you ask each department, export lists from different systems and paste them into a sheet. The result: weeks of work, and data that is already out of date the next day.
The Nispo method
- Connect Microsoft 365 / Entra ID (formerly Azure AD) with read-only permissions.
- Nispo automatically imports the tenant’s devices, users and licences.
- Add by hand what Microsoft 365 cannot see (servers, network devices, unmanaged software) and assign an owner to each item.
- You get the inventory, updated at every sync for the part that comes from the tenant, ready to export for inspections.
In less than an hour you have a real baseline of your IT environment, not an estimate.
The next step
The inventory is the basis for the asset identification requirements and for the rest of the control register: that’s where the first gaps show up and remediation starts.