Three analysts monitor a cybersecurity compliance dashboard in a control room overlooking Dubai’s skyline at sunset.
The Dubai Electronic Security Center (DESC) and Microsoft have launched a Zero Trust assurance dashboard at GISEC Global 2026. It maps Microsoft security signals from participating Dubai government entities against the emirate's Information Security Regulation (ISR). The aim is to replace periodic, self-reported compliance snapshots with continuous evidence and step-by-step fixes. Two entities are onboarded so far, and more than 80 are next. What's new here is the regulator's position. A national-level cyber authority is reading the same telemetry that an agency's own Entra and security admins look at, which turns tenant configuration into regulatory evidence. The trade-off is that the dashboard measures what Microsoft signals can show, while the ISR itself stays technology-neutral.

DESC and Microsoft Turn ISR Compliance Into a Live Dashboard​

According to Microsoft's announcement, the collaboration has produced a purpose-built Zero Trust assurance dashboard. Instead of relying on periodic, self-reported assessments that only capture a single moment in time, DESC can now see continuously updated evidence of how entities are performing against the Dubai Information Security Regulation (ISR) and give their IT teams clear steps to close any gaps. The trade press in the region, including Security MEA, Intelligent CISO and ITP.net, picked up the news around 17 September, the middle of the GISEC show week. Computer Weekly followed on 23 September.

A note on sourcing before going further. Every outlet covering the launch works from the same Microsoft and DESC announcement. That makes the event itself and its described features solid first-party claims. The deployment figures and promised benefits, though, are still what the vendor and regulator report, and nobody has published an independent evaluation.

The old model is familiar to anyone who has sat through a compliance cycle. Computer Weekly describes it this way: compliance with government security frameworks has relied on periodic assessments and self-reported audits, providing only a snapshot of an organisation's security posture at a specific point in time. An entity could pass an audit in March, switch off a Conditional Access policy in April, and nobody at the regulator would know until the next review.

Microsoft UAE general manager Amr Kamel framed the change in one line: "Cyber-resilience cannot rely on point-in-time visibility." DESC's Amer Sharaf, CEO of the Cybersecurity Systems & Services Sector, said the initiative works by bringing together evidence from the security controls already operating across participating government entities. Both are stakeholder statements, not measured results.

What the Dashboard Watches: MFA, Conditional Access, Privileged Access and Device Compliance​

The dashboard's scope reads a lot like a Microsoft 365 tenant hardening checklist. It draws on Microsoft security signals that participating entities already use and turns them into measurable evidence against those ISR controls. It surfaces things like risky identities, multifactor authentication and Conditional Access posture, privileged access, device compliance, active incidents and vulnerabilities.

Microsoft says the platform has 37 finding types. Each one explains what the issue is, why it matters, where to verify it and how to fix it, in plain language. Remediation guidance can be exported in Arabic and English, which matters for an administration that works in both languages. The release does not list the 37 findings. It also doesn't say which Microsoft products or licence tiers feed the dashboard, how often each finding refreshes, or what the "real-time" label means in practice. Treat "real-time" as a description of continuous collection, not a promise of instant updates or complete detection.

Our own inference, not a documented fact: the named categories line up with areas Microsoft customers usually manage through identity, endpoint management and security operations tooling. Risky identities and Conditional Access are identity-platform concepts, device compliance is an endpoint-management concept, and active incidents and vulnerabilities come from security-operations products. The announcement only says "Microsoft security signals", though. It does not name Entra ID, Intune or Defender as the specific sources.

There's a practical consequence for agency admins either way. Once a regulator can see these signals, a lapsed MFA exclusion or a non-compliant device fleet stops being a purely internal housekeeping item. It becomes visible evidence against a regulatory control.

Why a Technology-Neutral ISR Makes Microsoft Mapping a Measurement Aid​

The ISR does not require Microsoft products, and DESC says so directly. Its official description calls the ISR minimum information security requirements for Dubai Government entities across 13 domains, grouped into governance, operation and assurance classes. DESC also states that the regulation is technology-neutral and doesn't handle technological implementation. Each entity handles the technology-specific parts according to its own internal systems.

The ISR also requires every entity to run an applicability review, deciding which domains and controls apply to it and implementing a "right-fit" set of controls based on its risk assessment. It covers government information in any form, printed and verbal included. DESC's page says the regulation was formalised under Resolution No. 13 of 2012, and that DESC maintains and updates it under Dubai Law No. 11 of 2014.

Put those facts next to the dashboard and its limits come into focus. It turns Microsoft telemetry into evidence for the ISR controls that telemetry can speak to. The governance domains, paper records, physical security and non-Microsoft systems are all part of the ISR, and none of them emit Conditional Access signals. The announcement doesn't say how the dashboard handles entities with mixed estates or controls that have no matching signal. So a clean dashboard is best read as strong evidence for part of the ISR, not proof of full compliance.

The Zero Trust label needs the same reading. Computer Weekly sums up the model as one where, rather than assuming users, devices or applications can be trusted by default, identity, access and posture are verified continuously. The dashboard gives assurance about how well those principles are implemented. It does not enforce anything itself, and it doesn't replace the controls, incident response or risk assessments it reports on.

Microsoft's DESC Track Record: CSP Certification and UAE Cloud Regions​

The collaboration builds on earlier certification work. Microsoft Azure, Microsoft 365, and Dynamics 365 have been certified against DESC's Cloud Service Provider Security Standard, and Microsoft operates cloud regions in Abu Dhabi and Dubai.

Microsoft's compliance documentation describes what that standard involves. DESC makes it mandatory for any cloud provider selling to Dubai government and semi-government entities. It draws on ISO/IEC 27001 and 27017, the ISR, and the Cloud Security Alliance Cloud Controls Matrix. Microsoft says it was the first global cloud provider to get the certification. A DESC-accredited third-party auditor carried out the assessment, including physical inspection of datacentres in the UAE Central (Abu Dhabi) and UAE North (Dubai) Azure regions. The services in audit scope were Azure Core Services, Dynamics 365 Core Services and Office 365 Services. That documentation page was last updated in April 2023, so it describes the certification as it stood then, not necessarily today's scope.

The distinction matters to readers. CSP certification is about Microsoft's obligations as a provider. The new dashboard is about the customer side: how each government entity has configured the Microsoft services it uses. A certified cloud doesn't guarantee a well-configured tenant, and that gap is exactly what the dashboard is meant to show.

Where ASAAS 2.0 and the Rollout to 80 Entities Stand​

Coverage has barely touched one point of context. At its Multaqa ISR Officers forum in January 2026, DESC demonstrated ASAAS 2.0, which it calls its next-generation AI-powered auditing engine. DESC said at the time that ASAAS 2.0 was "set to be made available soon" and would support real-time assessments, automated gap analysis and AI-driven recommendations through an interactive dashboard. That sounds a lot like the new Microsoft collaboration. Neither DESC nor Microsoft has said whether the two are separate systems, parts of one programme, or overlapping efforts, so they shouldn't be treated as the same thing.

Rollout is at an early stage. Microsoft says that following an initial pilot phase, two Dubai government entities have already been onboarded to the dashboard, with DESC planning a broader roll-out across more than 80 additional government organisations throughout the emirate. No schedule or phasing for that expansion has been published. For now, the "live view of Dubai government" covers two agencies, and the wider claim is a target.

What this means for you​

The first decision falls on IT teams at Dubai government entities in the rollout queue. Assume your Microsoft security posture will soon be visible to your regulator, and fix the obvious gaps before onboarding rather than after. Teams outside Dubai can take a working pattern from this for their own internal assurance. They can wait on any expectation that other regulators will follow suit, because nothing announced so far points that way.

For comparison, Microsoft offers a free public tool that works along similar lines. Help Net Security describes the Zero Trust Assessment as a free tool that automatically evaluates an organization's Microsoft security configuration against zero trust best practices, identifies weaknesses, and recommends improvements. Microsoft hasn't said the DESC dashboard is built on this tool. But an admin who wants to see roughly how their tenant looks to a posture-scoring system could run it first.

  • Dubai government entities should review MFA coverage, Conditional Access policies, privileged role assignments, device compliance, open incidents and unpatched vulnerabilities, because these are the categories the dashboard is confirmed to surface.
  • ISR officers should keep their applicability reviews and non-Microsoft control evidence up to date, because the ISR is technology-neutral and the dashboard only sees what Microsoft signals can show.
  • Teams should expect remediation guidance that says where to verify each finding and how to fix it, available in both Arabic and English, and should plan who in the organisation will own those actions.
  • Nobody should read a clean dashboard as full ISR compliance, since the governance domains, non-electronic information and non-Microsoft systems sit outside what the announcement describes.
  • Organisations outside Dubai can use the Zero Trust Assessment tool as a free way to get a similar configuration-level view of their own Microsoft tenant.

A regulator reading tenant telemetry is new, and it moves identity and endpoint configuration from internal best practice into regulatory evidence for Dubai's public sector. Whether the model delivers on its promised faster remediation will show once the dashboard moves past its first two entities toward the 80-plus in line. At that point DESC and Microsoft will need to show measured results, not just announce intentions.