Activate ISO/IEC 27001:2013 Template in Compliance Manager

Answer Correct answer: C — Add recommended assessments to activate the ISO/IEC 27001:2013 regulatory template in Compliance Manager.

You have a Microsoft 365 E3 subscription. You plan to assess compliance with ISO/IEC 27001:2013. From Compliance Manager, you discover that the ISO/IEC 27001:2013 regulatory template for Microsoft 365 is inactive. What should you do?

  1. Purchase a Microsoft 365 E5 subscription.
  2. Add a data connector.
  3. Add recommended assessments. Correct Answer
  4. Create a trainable classifier.

Community Votes

A
54%
C
46%

54% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Tests knowledge of Compliance Manager licensing tiers, specifically distinguishing between 'Premium' templates (E5) and standard templates available in E3 that require activation via recommended assessments.

Resolves the issue of an inactive regulatory template in Microsoft 365 Compliance Manager for E3 subscribers by activating recommended assessments. Establishes that upgrading to E5 is not required to access or activate the ISO/IEC 27001:2013 template.

Choosing to upgrade to Microsoft 365 E5 because users mistakenly believe all regulatory templates are exclusive to the E5 license tier.

Community Discussion (5 comments)

thetootall 👍 4 Selected: A
The key here is that an E3 is in the environment, and Regulatory templates do not come with E3. Licensing always comes first!
JimboJones99 👍 3 Selected: A
You need to uplift to an E5 licence. Regulatory templates do not come with E3 but you have 3 templates included with E5, if you need more you need to purchase them on top of the E5 licence. https://learn.microsoft.com/en-us/purview/compliance-manager-regulations-list#premium-regulations
Sibimsh 👍 3
You cannot add a a recommended assessments via E3 in the compliance center so you would need an E5!
Amin4799 👍 4 Selected: C
C. Add recommended assessments. Adding recommended assessments might be helpful, but the primary step is to activate the template itself. This will provide the core set of controls and assessments specific to achieving ISO/IEC 27001 compliance within the context of Microsoft 365.
Ruslan23 👍 2 Selected: C
C is the correct answer

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

The ISO/IEC 27001:2013 template is a standard compliance template included with Microsoft 365 E3 licenses. When such a template appears as 'inactive', it means the specific assessments have not yet been added to your workspace. The correct action is to select 'Add recommended assessments' to populate the template with the relevant controls and start the compliance tracking process.

Why the Other Options Are Wrong

Upgrading to Microsoft 365 E5 (Option A) is unnecessary for this specific task. While E5 includes additional premium templates (like HIPAA or GDPR), the ISO/IEC 27001:2013 template is accessible to E3 users. Creating a trainable classifier (Option D) is used for content classification, not compliance assessment management. Adding a data connector (Option B) is unrelated to enabling regulatory templates.

Community Comment Notes

Many learners incorrectly voted for Option A, influenced by the misconception that regulatory templates are exclusively an E5 feature. As one commenter noted, 'Regulatory templates do not come with E3,' which is factually incorrect for the ISO template; only premium templates require E5. Another user correctly pointed out that you can add recommended assessments in E3, confirming that Option C is the functional step required.

Official Reference

Exam Strategy

Always check if a regulatory template is a 'Standard' (E3/E4) or 'Premium' (E5) offering before considering license upgrades. If a standard template is inactive, the immediate solution is almost always to add its recommended assessments.

Frequently Asked Questions

Why is the ISO/IEC 27001 template inactive in my E3 environment?

It is inactive because the specific assessments have not been added to your workspace yet. You must click 'Add recommended assessments' to enable it.

Do I need Microsoft 365 E5 to use the ISO/IEC 27001 template?

No. The ISO/IEC 27001:2013 template is included in E3. Only specific premium templates like HIPAA require E5 licensing.

Related Analysis

← Back to SC-400 Study Guide