Trust, Privacy, and the Service Trust Portal
Back to Learn
SC-900Chapter 14

Microsoft SC-900 Certification Study

Trust, Privacy, and the Service Trust Portal

Privacy principles, trust evidence, audit reports, Microsoft Purview, Compliance Manager, compliance score, and shared responsibility

Suggested study time: 21 minutes • Beginner level • Aligned with the SC-900 study guide and official Microsoft Learn documentation

Microsoft Certified: Security, Compliance, and Identity Fundamentals badge surrounded by cloud, identity, and compliance icons

1. Introduction: from presumed trust to demonstrable trust

In the early corporate technology environments, much of the trust was built locally. The organization bought servers, physically controlled the data center, and knew directly the people responsible for operations. With outsourcing, managed services, and cloud computing, this closeness decreased. The need then arose to replace trust based solely on proximity with contractual commitments, documented controls, independent audits, and verifiable evidence.

This movement was also driven by the growth of data protection laws, by large-scale incidents, and by the perception that personal and corporate information are social and economic assets. Privacy has ceased to be just a legal clause and has begun to influence architecture, security, procurement, governance, and relationships with users.

For the reader, understanding this topic helps evaluate suppliers, interpret reports, and recognize that a does not automatically transfer compliance to the client. For society, and accountability increase trust in digital services used in health, education, finance, government, and communication. At the end of the chapter, you will know where to look for evidence and, above all, how to use it without confusing it with absolute guarantee.

Flow between appointments, controls, independent audits, evidence, and client decision.
Figure 1 - Trust is built through commitments, controls, independent auditing, and verifiable evidence.

2. Fundamental concepts

ConceptPractical definitionExample
TrustWell-founded expectation that a party will fulfill commitments and protect relevant interests.Trust that a service will apply declared controls and notify important changes.
PrivacyRights, choices, and practices related to the collection, use, sharing, retention, and deletion of personal data.Allow access, correction, or deletion of data according to applicable law.
SecurityControls to preserve confidentiality, integrity, and availability.Encryption, authentication, monitoring, and incident response.
ComplianceCompliance with applicable laws, regulations, contracts, standards, and policies.Demonstrate controls required by GDPR, ISO, or internal policy.
TransparencyProvision of understandable information about practices, decisions, and data processing.Publish privacy documentation and audit reports.
AccountabilityAbility to demonstrate decisions, responsibilities, and evidence.Maintain records, responsible parties, tests, and justifications for controls.
Guarantee or assuranceConfidence level obtained through evaluation, evidence, and independent validation.Audit report produced by a third party.

2.1 Privacy and security are not synonyms

Security protects data against unauthorized access, alteration, unavailability, or destruction. Privacy determines whether the collection and use are legitimate, proportional, transparent, and compatible with people's rights. A database can be technically well protected and still be used for a purpose that is incompatible with the consent or the informed legal basis.

2.2 Compliance is not just technology

Technical controls are important, but compliance also involves contracts, processes, training, governance, records, legal analysis, and oversight. Therefore, evidence from the cloud provider is only a part of the set that an organization needs to present.

Key point for the SC-900

The shows how Microsoft demonstrates commitments and controls of its services. It does not configure the client's environment, does not classify data, and does not replace the organization's compliance management.

3. Microsoft Privacy Principles

Microsoft presents its privacy approach as a commitment to valuing, protecting, and defending data. In preparing for the SC-900, it is useful to organize this approach into five complementary ideas: control, , protection, compliance, and responsible use. The documentation may group or name these commitments in different ways, but the central meaning remains consistent.

Microsoft privacy principles: control, transparency, protection, compliance, and responsible use.
Figure 2 - Privacy principles guide how data is collected, used, protected, and made available.

3.1 Control over the data

The customer must maintain meaningful choices about their data, including access, modification, deletion, retention setting, and service selection. In commercial cloud services, Microsoft states contractual commitments to use customer data to provide the agreed services and for purposes compatible with those services.

3.2

allows understanding which data is processed, where it can be stored, how it is protected, which subprocessors participate in the service, and which contractual conditions apply. It does not mean publishing details that would facilitate attacks; it means providing enough information for informed decisions, auditing, and governance.

4. Protection, compliance, and responsible use

4.1 Protection during the life cycle

Data protection involves security at rest, in transit, and during processing, as well as identity, access, segmentation, logging, monitoring, response, and recovery. Microsoft combines physical, operational, and technological controls, but the correct configuration of customer resources and access remains essential.

4.2 Compliance with laws and standards

Microsoft's compliance with standards and regulations provides a foundation for customers subject to similar requirements. Examples include ISO/IEC standards, SOC reports, regulated industry requirements, and commitments related to the GDPR. However, the customer needs to verify whether the service, region, feature, and period under review are within the scope of the evidence.

4.3 Limited and responsible use

Responsible use means limiting processing to the agreed purposes, controlling employee and subprocessors' access, applying minimization and proper retention, and maintaining governance for changes. Microsoft states that it does not share customers' commercial data with advertising-funded services nor exploits it for marketing or advertising.

4.4 Defense against third-party claims

Privacy protection also includes processes to evaluate government and authority requests. Microsoft states that it does not grant direct and unrestricted access to customer data and that it analyzes the legal validity of requests. For the customer, this reinforces the importance of understanding location, jurisdiction, contracts, and sovereignty requirements.

Important

Privacy principles are broad commitments. For a contractual or legal decision, the organization must consult the applicable terms, the , the privacy statement, and specialized advice.

5. Data, roles, and shared responsibility

5.1 Personal data, customer data, and data generated by the service

Personal data is information related to an identified or identifiable person. Customer data is content provided or generated by the customer in the use of the service. Diagnostic data and data generated by the service may be necessary for operation, security, support, and improvement. The categories, purposes, and terms vary by product, so they should be evaluated in the specific documentation.

5.2 Controller and operator/processor

In many legislations, the controller determines the purposes and means of processing, while the operator or processor processes data on behalf of the controller. In a cloud service, the customer often acts as the controller of the data they enter into the service, and Microsoft acts as the processor for the contracted purposes. The exact classification depends on the context and the service.

5.3 Shared compliance responsibility

Microsoft is responsible for the controls under its administration. The customer is responsible for configuration, identities, permissions, classification, retention, purposes, legal bases, internal processes, and the use of data. The division varies depending on the service model and the contract, but it never completely disappears.

Microsoft responsibilities, shared responsibilities, and customer responsibilities.
Figure 3 - Cloud compliance depends on the joint action of Microsoft and the customer.

6. Microsoft

The Microsoft , known by the acronym STP, is Microsoft's public website for publishing reports and other compliance information related to Microsoft cloud services. It helps customers, auditors, risk teams, legal, procurement, and security understand how Microsoft protects data and meets specific commitments.

6.1 What is the portal used for?

  • Download reports produced by external auditors.
  • Check certifications, standards, regulations, and resources by cloud service.
  • Read whitepapers and technical materials written by Microsoft.
  • Locate useful documentation for due diligence, supplier evaluations, and audits.
  • Save documents in a personal library and track download and version history.

6.2 Access and authentication

Some of the content is public, while other materials require authentication with a Microsoft Entra organizational account and acceptance of terms or a confidentiality agreement. Some restricted documents depend on specific roles or permissions.

Service Trust Portal organizes audit reports, certifications, regulations, whitepapers, restricted documents, and history.
Figure 4 - The brings together different categories of trust evidence and resources.

7. reports, certifications, and attestations

7.1 report

An report presents procedures, scope, criteria, period, and conclusions of an evaluation. SOC reports, for example, can examine controls related to security, availability, confidentiality, processing integrity, and privacy. It is essential to observe the type of report, the period covered, the entities, and the services included.

7.2

indicates that a management system, process, or service has been evaluated according to the requirements of a standard. An ISO/IEC does not mean that each customer configuration is correct; it demonstrates that the certified scope meets the criteria evaluated over a certain period.

7.3

Attestation is a formal conclusion issued by a qualified party regarding compliance with specific criteria. In some programs, the term is used when the result is not a traditional but still provides independent .

DocumentWhat demonstratesInterpretation care
SOC ReportEvaluation of controls and test results according to defined criteria.Check type, period, opinion, exceptions, and client controls.
ISO/IEC CertificateCompliance of the certified scope with a standard.Confirm entity, service, location, and validity.
PCI DSS certificate or similarConclusion about specific program requirements.Validate version, scope, and shared responsibilities.
WhitepaperTechnical or compliance explanation written by Microsoft.It is informative; it does not substitute for independent audit opinion.
Regulatory documentMapping or information about law and requirements.It is not legal advice nor automatic proof of client compliance.

8. Portal standards, regulations, and resources

8.1 ISO/IEC

The ISO/IEC family includes standards for security and privacy management. ISO/IEC 27001 deals with information security management systems; ISO/IEC 27018 provides practices for protecting personal information in the public cloud when the provider acts as a processor. The STP helps to locate certificates, scopes, and related materials.

8.2 SOC

SOC reports are widely used in vendor assessments. A Type 1 report analyzes control design at a point in time; a Type 2 evaluates design and operational effectiveness over a period. The reader should look for exceptions, tests, complementary user entity controls, and distribution limitations.

8.3 GDPR

The GDPR establishes principles and rights related to the processing of personal data in the European Union. Microsoft materials may explain contractual commitments, international transfers, security measures, and resources that assist customers. Even so, each organization needs to determine its legal bases and obligations.

8.4 Other programs

The portal also organizes materials related to PCI DSS, FedRAMP, and other standards, sectors, and jurisdictions. Availability varies depending on the service and type of document. For the exam, the most important thing is to understand that the STP centralizes evidence and trust information, not to memorize all existing certifications.

Common trap

A may cover only part of the services, regions, or operations. Always confirm the scope, validity, standard version, and controls that remain under the client's responsibility.

9. Restricted documents, , library, and update

9.1 Why are some documents restricted?

Detailed reports may include sensitive information about controls, architecture, or testing. To balance and security, certain materials require authentication, authorized roles, and acceptance of the Microsoft Non-Disclosure Agreement for Compliance Materials. The restriction does not eliminate ; it reduces the risk of improper disclosure.

9.2 My Library

The library allows saving relevant documents for monitoring. This facilitates periodic reviews, but does not replace a governance repository controlled by the organization. Evidence used in audits must have an owner, version, date, scope, and retention policy.

9.3 Document history and status

The download history helps identify obtained documents and can indicate whether they are active, replaced by a newer version, or removed. As certifications and reports expire or are renewed, compliance evidence needs to be continuously reviewed.

9.4 Care when sharing

Before attaching a report to an , proposal, or internal process, check distribution rights, confidentiality, and access requirements. Documents subject to should not be published in open repositories or forwarded without authorization.

Good practice

Record for each piece of evidence: source, download date, version, covered period, service, region, associated requirement, sharing restriction, and person responsible for review.

10. How to interpret confidence evidence

Downloading a report is just the beginning. The value of evidence depends on its correspondence with the risk and the requirement that the organization needs to demonstrate. A mature analysis checks scope, period, criteria, exceptions, the auditor's opinion, and the client's complementary controls.

QuestionWhy does it matterVerification example
Which service is covered?Products with similar names may have different scopes.Confirm whether Microsoft 365, Azure, or a specific feature appears in the report.
Which period was evaluated?Controls change and evidence ages.Check the start and end dates of the SOC report.
Which regions or entities?Requirements may depend on location and jurisdiction.Confirm data center, region, and contractual entity.
Which exceptions were found?An opinion can contain important observations.Read test results and administration response.
Which controls belong to the client?The provider does not perform all the necessary activities.Set up MFA, retention, logs, and access review.
Is distribution allowed?Some materials are confidential.Check NDA, classification, and authorized audience.
Due diligence flow to request, locate, validate, map, and use evidence.
Figure 5 - Evidence only supports the decision when its scope, period, and responsibilities are interpreted.

11. Microsoft Purview portal

Microsoft Purview is a set of solutions to govern, protect, and manage data. The Microsoft Purview portal offers a unified experience to access data security, data governance, risk, and compliance resources. It is an operational point for the organization to manage its data assets and obligations.

11.1 What can be found on the portal?

  • Information protection solutions, classification, and sensitivity labels.
  • Data Loss Prevention, internal risk, auditing, eDiscovery, and communications compliance.
  • Retention, lifecycle management, and records management.
  • Compliance Manager and information about compliance posture.
  • Data governance solutions, such as Data Map and Unified Catalog, according to licensing and configuration.

11.2 Why is it different from the STP?

STP publishes evidence about Microsoft as a supplier. The Purview portal is used by the client to operate controls over its data, users, content, and processes. In Purview, the organization classifies information, configures policies, investigates events, and monitors risks; in STP, it consults the provider's trust documents.

Summary in one sentence

: evidence about the provider. Microsoft Purview: governance and protection of the organization's data.

12. Microsoft Purview Compliance Manager

Compliance Manager is a Microsoft Purview solution that helps assess and manage compliance in Microsoft and multicloud environments. It organizes requirements into assessments, maps controls, provides improvement actions, and calculates a risk-based score to track progress.

12.1 Main elements

ElementFunction
Regulation or modelIt represents a standard, law, policy, or set of requirements.
EvaluationApplies a model to a specific scope and monitors the service.
ControlRequirement that describes what must be implemented or verified.
Improvement actionRecommended task with guidance, responsible party, status, test, and evidence.
Action managed by MicrosoftControl whose implementation and audit result are presented by Microsoft.
Action managed by the clientActivity that the organization needs to implement, test, and document.
compliance scoreRisk-based progress indicator in the completion of actions; it is not a legal guarantee of compliance.
Flow between regulations and models, evaluation, improvement actions, scoring, and continuous review.
Figure 6 - The Compliance Manager turns requirements into assessments, prioritized actions, and continuous monitoring.

13. : benefits and limitations

13.1 What does the score represent?

The measures progress in completing improvement actions that help reduce risks related to data protection and regulatory requirements. Actions have different weights according to their potential impact. The initial score may consider controls managed by Microsoft and the Microsoft 365 data protection baseline.

13.2 What does punctuation not represent?

A high score does not mean that the organization is fully compliant with a law or standard. It does not replace legal analysis, independent , scope assessment, or external evidence. Microsoft explicitly states that the score should not be interpreted as a guarantee of compliance.

13.3 Practical benefits

  • Prioritize actions with the greatest risk reduction.
  • Assign responsibilities and track deadlines.
  • Store notes, tests, and evidence.
  • Get step-by-step guidance for controls.
  • Consolidate assessments from different regulations and environments.
  • Communicate progress to managers and auditors.

Key point for the exam

measures progress in the implementation of recommended actions. It does not certify the organization and does not eliminate the need to interpret laws, contracts, and specific risks.

14. vs Purview vs Compliance Manager

Comparison between Service Trust Portal, Microsoft Purview portal, and Compliance Manager.
Figure 7 - The three experiences are complementary: evidence, compliance operation, and monitoring.
CriterionService Trust PortalMicrosoft Purview portalCompliance Manager
Main objectivePublish reliable evidence and information from Microsoft.Govern, protect, and manage the organization's data and risks.Evaluate requirements and monitor compliance actions.
Typical contentSOC, ISO, attestations, whitepapers, and regulatory documents.DLP, labels, auditing, eDiscovery, retention, governance, and risk.Evaluations, controls, improvement actions, evidence, and scoring.
Who produces the dataMicrosoft and independent auditors.The organization and the connected services.Microsoft, client and evaluation results.
Main useDue diligence, supplier audit and proof of service.Operation of data controls and compliance.Structured management of the compliance program.
Should not be confused withTenant configuration tool.Microsoft audit report library.Certification or guarantee of compliance.

15. Practical scenario: evaluation of a cloud service

A health company wants to store clinical documents in a Microsoft service. The team needs to assess security, privacy, compliance, and responsibilities before contracting and during operation.

15.1 Step 1 - define requirements

Legal and privacy identify applicable laws, contracts, residency requirements, retention periods, data subject rights, and notification requirements. Security defines technical requirements, such as encryption, MFA, logs, segregation, and recovery.

15.2 Step 2 - consult the

The team locates service reports and certificates, checks the period, scope, regions, exceptions, and complementary controls. Relevant documents are stored in a controlled repository with version tracking and sharing restrictions.

15.3 Step 3 - map shared responsibility

The controls managed by Microsoft are associated with STP evidence. The customer's obligations are transformed into policies and settings: document classification, retention, conditional access, access reviews, DLP, auditing, and incident response process.

15.4 Step 4 - using Purview and Compliance Manager

In the Purview portal, the company configures controls over the data. In Compliance Manager, it creates assessments, assigns actions, records evidence, and monitors progress. The score helps in prioritization, but the final decision takes into account clinical, legal, and operational risk.

15.5 Step 5 - periodic review

Reports, certificates, contracts, settings, and requirements are reviewed periodically. Changes in service, region, subprocessors, legislation, or architecture may require a new assessment.

16. Good practices and limitations

Good practiceReason
Start with the requirement, not with the documentAvoid collecting reports that do not respond to the real risk.
Confirm scope and periodOut-of-scope or expired evidence can lead to incorrect conclusions.
Read client exceptions and controlsThe auditor's opinion does not remove tasks under the organization's responsibility.
Protect restricted documentsMaterials subject to NDA require access and distribution control.
Relate evidence to controlsFacilitates auditing, renewal, and identification of gaps.
Maintain continuous reviewServices, laws, standards, and reports change.
Do not treat score as certificationScore represents progress, not absolute guarantee.
Involve legal, privacy, security, and businessCompliance is multidisciplinary and contextual.

16.1 Limitations that the reader must recognize

Trust documents describe controls and assessments within a defined scope, not all possible risks. Audits are sample-based and retrospective. Certifications may expire. Laws may require local interpretation. Additionally, improper client configurations can negate benefits offered by the service.

16.2 Recurring pitfalls in SC-900

  • Confuse with the operational portal of Microsoft Purview.
  • Claiming that a Microsoft automatically makes the client compliant.
  • Interpret as a legal guarantee of compliance.
  • Ignore controls and actions managed by the client.
  • Confusing an independent report with a produced by the supplier.
  • Thinking that privacy is just encryption or technical security.

17. Quick review for the SC-900 exam

TermObjective memorization
Service Trust PortalAudit reports and compliance information portal for Microsoft services.
Audit reportIndependent evidence with criteria, scope, period, tests, and conclusions.
CertificationRecognition that a scope has been assessed according to a standard.
Microsoft PurviewSet of solutions to govern, protect, and manage data.
Compliance ManagerTool for evaluations, controls, improvement actions, evidence, and score.
compliance scoreRisk-based progress indicator; does not guarantee compliance.
Shared responsibilityMicrosoft and the client have different controls and obligations.
Privacy principlesControl, transparency, protection, compliance, and responsible use of data.

17.1 Final mind map

  • Need to prove how Microsoft protects the service? Check the .
  • Need to set up protection, governance, or investigation for your data? Use the Microsoft Purview portal.
  • Need to turn requirements into assessments, actions, and monitoring? Use Compliance Manager.
  • You need to decide if it is compliant? Combine evidence, controls, legal analysis, risk, and ; do not rely solely on a score.

Synthesis

Cloud trust is a discipline of evidence and accountability. The provider demonstrates its controls; the customer interprets the scope, implements its obligations, and maintains continuous governance.

18. Conclusion

Trust in cloud services should not depend on vague promises. It is strengthened by clear privacy principles, contractual commitments, technical and organizational controls, independent audits, and access to evidence. The Microsoft plays this role by bringing together reports, certifications, attestations, whitepapers, and regulatory information about Microsoft services.

At the same time, vendor evidence does not replace the customer's responsibilities. The Microsoft Purview portal helps the organization operate controls over its data, while Compliance Manager structures assessments, improvement actions, and a score that guides priorities. The three resources are complementary, not competitive.

In my assessment, this is one of the most important topics of the SC-900 because it teaches a mature stance: not to confuse with perfect security, nor score with guaranteed compliance. The professional who knows how to interpret evidence and map responsibilities makes better decisions, reduces risks, and contributes to more transparent and reliable digital services.

Next step on the trail

In Chapter 15, the focus shifts from trust evidence to the direct protection of data with Microsoft Purview: classification, sensitivity labels, encryption, DLP, and data security risk management.

19. Review questions

Question 1: A company needs to obtain a produced by an independent auditor

about a Microsoft service. Which resource should I check?

A) Microsoft Defender portal B) Microsoft C) Microsoft Entra admin center D) Azure Policy

Commented answer

Correct answer: B. The publishes reports and compliance information related to Microsoft cloud services.

Question 2: Which statement correctly describes the Compliance conformity score

Manager?

A) It is a legal of the organization. B) Ensures compliance with all laws. C) Measures progress based on risk in the completion of improvement actions. D) Measures only controls managed by Microsoft.

Commented answer

Correct answer: C. Scoring helps prioritize and track actions, but it is not a guarantee of compliance.

Question 3: What is the main difference between the and the Microsoft Purview portal?

A) STP manages devices; Purview manages networks. B) STP provides evidence about Microsoft controls; Purview helps the organization govern and protect its data. C) Both have exactly the same purpose. D) Purview exclusively publishes SOC reports.

Commented answer

Correct answer: B. STP is a source of vendor evidence, while Purview is an operational platform for data, risk, and compliance.

Question 4: Microsoft has a applicable to the service used by the customer. What

what does this mean for the organization?

A) The client is automatically in compliance. B) No additional control is necessary. C) The is relevant evidence, but the client must still fulfill their own responsibilities. D) The client can ignore the scope and validity of the certificate.

Commented answer

Correct answer: C. Compliance in the cloud is shared and depends on the context, scope, and the client's controls.

20. Essential Glossary

TermMeaning
AssuranceConfidence obtained through evaluation, tests, and evidence.
CertificationFormal conclusion on meeting specific criteria.
AuditSystematic evaluation of controls, processes, and evidence.
compliance scoreProgress scoring in improvement actions in Compliance Manager.
Customer complementary controlActivity that the client needs to implement for the set of controls to be effective.
Data Protection AddendumMicrosoft contractual terms related to the processing and protection of data.
NDAConfidentiality agreement that restricts the use and disclosure of information.
SOC ReportReport on the controls of a service organization according to auditing criteria.
Service Trust PortalMicrosoft portal for audit reports and compliance materials.
SubprocessorThird contractor hired to perform treatment functions in support of the service.
TransparencyClear and accessible information about treatment, controls, and decisions.
WhitepaperExplanatory document produced by the supplier; does not equate to an independent audit.

Official references consulted

  • Microsoft Learn - Study guide for Exam SC-900: Microsoft Security, Compliance, and Identity Fundamentals. Updated in 2026.
  • Microsoft Learn - Get started with Microsoft . Updated on April 6, 2026.
  • Microsoft Trust Center - Microsoft Privacy Principles / Data protection and privacy.
  • Microsoft Learn - Microsoft Purview portal.
  • Microsoft Learn - Microsoft Purview Compliance Manager. Updated on December 3, 2025.
  • Microsoft Learn - Compliance Manager FAQ. Updated on May 21, 2026.
  • Microsoft Learn - Microsoft Purview data compliance solutions.
  • Microsoft Privacy Statement. Updated in March 2026.

Note about update

Portals, product names, licensing, and document availability may change. For actual decisions, always confirm the current documentation, contract, and scope.