Microsoft
Global software and cloud provider (Azure, Microsoft 365, Dynamics 365, Power Platform, Intune, Defender) serving enterprise and public sector customers.
Certifications & Accreditations
| Certification | Certifying Body | Scope | Achieved | Expiry | Status |
|---|---|---|---|---|---|
| ISO/IEC 27001:2022 | BSI (accredited certification body) | Azure, Microsoft 365, Dynamics 365, Power Platform, Intune and other in-scope online services | — | — | Current |
| ISO/IEC 27017:2015 | BSI | Cloud-specific information security controls for in-scope online services | — | — | Current |
| ISO/IEC 27018:2019 | BSI | Protection of PII in public cloud for in-scope online services | — | — | Current |
| ISO/IEC 27701:2019 | BSI | Privacy information management system for in-scope online services | — | — | Current |
| ISO 22301:2019 | BSI | Business continuity management system | — | — | Current |
| ISO 9001:2015 | BSI | Quality management system | — | — | Current |
| ISO/IEC 20000-1 | BSI | IT service management system | — | — | Current |
| ISO/IEC 42001:2023 | Independent certification body | AI management system for in-scope AI services | — | — | Current |
| SOC 1 / SOC 2 / SOC 3 | Independent third-party auditor | In-scope online services; SOC 2 Type II covering security, availability, confidentiality and privacy | — | — | Current |
| PCI DSS (Level 1 Service Provider) | Qualified Security Assessor | Azure and in-scope services supporting cardholder data environments | — | — | Current |
| FedRAMP High / DoD SRG IL2-IL5 | 3PAO, JAB and agency authorisations | Azure Government, Azure Commercial and Microsoft 365 Government | — | — | Current |
| HITRUST CSF | HITRUST authorised external assessor | Azure and in-scope healthcare workloads | — | — | Current |
| CSA STAR Certification and Attestation | Cloud Security Alliance / third-party auditor | Cloud Controls Matrix; STAR Level 2 certification and attestation | — | — | Current |
| BSI C5 (Germany) | Independent German auditor | Cloud Computing Compliance Criteria Catalogue for in-scope services | — | — | Current |
| Cyber Essentials Plus (UK) | UK NCSC-accredited certification body | UK-relevant in-scope Microsoft services | — | — | Current |
Compliance Frameworks
Penetration Testing
| Scope | Conducted By | Date | Frequency | Report |
|---|---|---|---|---|
| Microsoft online services and supporting infrastructure - continuous internal red team exercises plus independent assessment under the SOC 2, ISO 27001 and FedRAMP programmes (date shown is the profile capture date) | Microsoft red teams and independent third-party assessors | Aug. 6, 2026 | Annual | On NDA |
| Customer security testing of its own Microsoft online assets, permitted under the Microsoft Security Testing Rules of Engagement (date shown is the profile capture date) | Customer or customer-appointed testing provider | Aug. 6, 2026 | Ad-hoc | Not Available |
Data Handling
Incident & Breach History
| Date | Summary | Impact | Resolution | Report |
|---|---|---|---|---|
| March 2, 2021 | On-premises Microsoft Exchange Server zero-day vulnerabilities (later known as ProxyLogon) were exploited in the wild by a state-sponsored actor Microsoft tracks as Hafnium, and subsequently by other groups. | Widespread compromise of internet-facing on-premises Exchange servers globally; Exchange Online was not affected. | Out-of-band security updates released, mitigation tooling and one-click remediation scripts published, and detection guidance issued with government agencies. | — |
| July 11, 2023 | A China-based actor Microsoft tracks as Storm-0558 used an acquired Microsoft account consumer signing key to forge authentication tokens and access Outlook Web Access and Exchange Online mailboxes. | Unauthorised access to email belonging to approximately 25 organisations, including government agencies, over roughly a month before detection. | The signing key was revoked and key management, token issuance and validation hardened. Detailed cloud audit logging was subsequently made available to all customers at no additional cost. The incident was reviewed by the US Cyber Safety Review Board. | — |
| Jan. 12, 2024 | A nation-state actor Microsoft tracks as Midnight Blizzard (Nobelium/APT29) used a password spray attack against a legacy non-production test tenant account without MFA, then pivoted to a small percentage of Microsoft corporate email accounts. | Exfiltration of some Microsoft corporate email and attachments, including correspondence with a number of customers; some source code repositories and internal systems were also accessed. | Legacy tenants and accounts remediated, MFA and detection controls strengthened, and the Secure Future Initiative accelerated. Affected customers were notified directly. | — |
Security Policies
| Policy | Availability | Link |
|---|---|---|
| Microsoft Privacy Statement | Public | View ↗ |
| Microsoft Product Terms (including Data Protection Terms) | Public | View ↗ |
| Microsoft Products and Services Data Protection Addendum (DPA) | Public | View ↗ |
| Microsoft Security Response Center - Coordinated Vulnerability Disclosure | Public | View ↗ |
| Microsoft Security Testing Rules of Engagement | Public | View ↗ |
| Shared responsibility in the cloud | Public | View ↗ |
| Audit reports (SOC, ISO, PCI DSS, C5) via Service Trust Portal | On Request | View ↗ |
Legal & Privacy
- Privacy Policy View ↗
- DPA Template View ↗
- Terms of Service View ↗
- GDPR Representative Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland - EU/EEA contracting entity and privacy point of contact (Microsoft Privacy Officer, contactable via the Microsoft Privacy Statement).
- Lawful Basis Processor acting on documented customer instructions for customer data under the Microsoft Products and Services DPA (Art. 28 GDPR); independent controller for a defined, limited set of legitimate business operations set out in the DPA. International transfers rely on Standard Contractual Clauses and the EU-US Data Privacy Framework, with the EU Data Boundary keeping in-scope EU/EFTA customer data within Europe.
Contact & Responsible Disclosure
- Security Contact [email protected]
- Responsible Disclosure View policy ↗
- Bug Bounty Platform Microsoft Bug Bounty Program, self-hosted via the MSRC Researcher Portal (Microsoft is also a CVE Numbering Authority)
Trust Portal & Audit Evidence
**Trust portal:** [Microsoft Service Trust Portal](https://servicetrust.microsoft.com/) - hosts SOC 1/2/3 reports, ISO certificates, PCI DSS AoC, C5, FedRAMP and penetration test summaries. Access to most audit reports requires sign-in with a work account tied to an eligible subscription and acceptance of an NDA.
**Public compliance index:** [Microsoft compliance offerings](https://learn.microsoft.com/en-us/compliance/regulatory/offering-home)
**Trust Center:** [microsoft.com/trust-center](https://www.microsoft.com/en-us/trust-center)
**Sub-processors:** Microsoft publishes an Online Services Subcontractor List through the Service Trust Portal (sign-in required), which is why the sub-processor table below is not populated. Microsoft commits under the DPA to notify customers before new sub-processors are authorised.
**Data location:** [microsoft.com/trust-center/privacy/data-location](https://www.microsoft.com/en-us/trust-center/privacy/data-location)
**Status:** [Azure Status](https://azure.status.microsoft/) and the Microsoft 365 admin centre service health dashboard.
Risk Assessment Notes
**Inherent risk drivers**
- Tier 1 / critical dependency covering identity (Entra ID), productivity, email, endpoint management and often hosting - a single vendor concentration across multiple control domains.
- Identity is the highest-impact dependency: compromise of the identity plane affects every connected system.
- Broad data categories likely, including personal and special category data, depending on tenant configuration.
**Mitigating factors**
- Very broad independent assurance: ISO 27001/27017/27018/27701/22301/9001/20000-1/42001, SOC 1-3, PCI DSS, FedRAMP High, HITRUST, C5, Cyber Essentials Plus.
- Mature DPA with SCCs, sub-processor notification commitments and the EU Data Boundary for European data residency.
- Extensive customer-side tooling: Conditional Access, Defender suite, Purview, Sentinel, unified audit logging.
**Concerns to track**
- Repeat nation-state targeting of Microsoft corporate and identity infrastructure (Storm-0558 in 2023, Midnight Blizzard in 2024) with findings critical of security culture in the 2024 US Cyber Safety Review Board report. Confirm progress under the Secure Future Initiative at each review.
- Licensing tier materially affects available security and logging controls - verify that the tenant licence level supports the controls assumed in this assessment.
**Residual customer responsibilities**
- Tenant hardening, Conditional Access and MFA/phishing-resistant authentication, privileged access management.
- Backup and retention beyond native capabilities, data classification and DLP configuration.
- Log retention, monitoring and integration into the customer SIEM.
**Suggested review cadence:** annual, or on notification of a material Microsoft security incident.
Copyright © 2026 SnapGRC