Microsoft Service Trust Portal and Privacy Principles
Back to Learn
SC-900Chapter 8

Microsoft SC-900 Certification Study

Microsoft Service Trust Portal and Privacy Principles

Audit evidence, portal content categories, My Library notifications, data control and location, encryption at rest and in transit, and defense against third-party requests

Suggested study time: 32 minutes • Beginner level • Aligned with the SC-900 study guide and official Microsoft Learn documentation

Microsoft Certified: Security, Compliance, and Identity Fundamentals badge surrounded by cloud, identity, and compliance icons

1. What you will learn

Trust in Microsoft cloud services is supported by security, privacy, and compliance practices that customers can examine. The Service Trust Portal gathers evidence and guidance about these practices, while Microsoft privacy commitments explain how customer data is controlled, located, protected, and defended.

  • Explain the purpose and main offerings of the Microsoft Service Trust Portal.
  • Recognize audit reports, security assessments, compliance guides, whitepapers, and tenant-restricted resources.
  • Describe the four privacy commitments emphasized in this module.
  • Choose the correct portal category or privacy principle in an SC-900 scenario.
Security, privacy, and compliance forming a foundation of verifiable cloud trust.
Figure 1 - Cloud trust becomes useful when commitments are supported by evidence.

2. What is the Microsoft Service Trust Portal?

The Microsoft Service Trust Portal, or , is Microsoft’s public site for publishing audit reports and other compliance information about Microsoft cloud services. It helps organizations understand how their data is protected and how to manage cloud security and compliance.

Its resources include reports prepared by independent auditors and Microsoft-authored whitepapers. The first type provides external assurance; the second explains designs, controls, and practices. Neither makes the customer automatically compliant: the organization must still evaluate scope, configure its environment, and meet its own obligations.

3. Access, authentication, and permissions

Some content is public, but protected materials require an authenticated Microsoft cloud services account associated with a Microsoft Entra organization. Depending on the document, the user may also need to accept the Microsoft Non-Disclosure Agreement for Compliance Materials or hold an authorized role.

  • Access is linked to the organization tenant, subscription, and user permissions.
  • Microsoft 365, Dynamics 365, and Azure trial or paid subscriptions can provide access.
  • Restricted evidence must be handled according to its license and confidentiality terms.
  • The Service Trust Portal link in the page header returns the user to the portal home page.

4. The four content categories

The landing page organizes its materials into four areas. Knowing their purpose is more important for the exam than memorizing every document available in each tile.

Service Trust Portal organization
CategoryWhat it containsTypical need
Certifications, Regulations, and StandardsSecurity implementation, design, certifications, standards, and regulatory materials.Verify an ISO, SOC, GDPR, FedRAMP, or PCI-related resource.
Reports, Whitepapers, and ArtifactsContinuity, disaster recovery, penetration testing, security assessments, privacy, FAQs, and technical papers.Examine assurance evidence or understand how a control works.
Industry and Regional ResourcesMaterials organized for industries, governments, and geographic requirements.Find guidance for a regulated sector or region.
Resources for your OrganizationTenant-restricted documents selected according to the organization’s subscriptions and permissions.Find evidence specifically applicable to the customer tenant.
Four Service Trust Portal content categories branching from the portal home page.
Figure 2 - The portal groups evidence by standard, document type, industry or region, and tenant.

5. Certifications, Regulations, and Standards

This area explains how Microsoft cloud services implement and design security to support regulatory objectives. Selecting a tile opens a list of applicable documents with a title, description, cloud-service context, and last-updated date.

  • ISO/IEC: standards and certificates related to security and privacy management.
  • SOC: System and Organization Controls reports, including SOC 1, SOC 2, and SOC 3.
  • GDPR: resources about the General Data Protection Regulation.
  • FedRAMP and PCI: materials for United States federal authorization and payment-card security requirements.
  • Other country, region, or sector programs presented by the portal.

Always verify the service, entity, region, report period, standard version, exceptions, and customer controls. A certificate is relevant evidence, not a guarantee that every customer configuration complies.

6. Reports, Whitepapers, and Artifacts

This category brings together general technical and assurance documents. Business Continuity and Disaster Recovery materials explain resilience planning. Pen Test and Security Assessments contain attestations or reports about penetration tests and third-party security reviews.

Privacy and Data Protection materials address privacy commitments and safeguards. FAQ and Whitepapers provide Microsoft explanations and answers to recurring questions. An independent assessment and a vendor have different assurance value, so readers must identify the author, scope, date, and intended use.

7. Industry, regional, and tenant-specific resources

  • Financial Services: regulatory guidance for financial institutions by country or region.
  • Healthcare and Life Sciences: cloud capabilities and compliance materials for healthcare.
  • Media and Entertainment: resources for that industry’s operational and compliance needs.
  • United States Government: resources reserved for eligible government customers.
  • Regional Resources: documentation about Microsoft online services and regional policies or regulations.
  • Resources for your Organization: documents restricted to the signed-in tenant based on subscription and permissions.

In an exam question asking where to find evidence about regional policies, choose Industry and Regional Resources. If the requirement refers to documents unique to the organization’s tenant, choose Resources for your Organization.

8. and update notifications

centralizes documents that matter to the user. From a document’s ellipsis menu, choose Save to library. This avoids repeatedly locating the same evidence and creates a focused collection for review.

Notification Settings defines the delivery frequency and an organizational email address. When Microsoft updates a saved document, the message includes a link and a short description of the change. Saving a document that belongs to a series also subscribes the user to updates for that series.

A document saved to My Library triggers version tracking and email notifications.
Figure 3 - turns selected evidence into a monitored collection.

Exam distinction

centralizes documents and sends update notifications. It does not edit reports, approve compliance workflows, or share protected documents automatically with external parties.

9. Microsoft’s four privacy commitments

Microsoft states that privacy influences product and service design. The Microsoft Trust Center presents the commitment around four questions: who controls the data, where it is located, how it is secured, and how Microsoft responds to third-party demands.

Four Microsoft privacy commitments: control, location, security, and defense.
Figure 4 - The privacy commitments cover the data lifecycle and legal access requests.

10. You control your data

Customer data remains the customer’s business. The customer can access, modify, or delete it according to the service and contract. Microsoft commits not to use that data without agreement and, when authorized, to use it to provide the selected services.

  • Microsoft does not share commercial customer data with advertising-supported services or mine it for advertising or marketing research.
  • Subcontractors and subprocessors receive only the access needed for the contracted function.
  • Authorized subprocessors are bound by corresponding privacy commitments and assessed against security and privacy requirements.
  • Broad privacy laws and standards, including ISO/IEC 27018 for cloud privacy, reinforce customer control.

11. Know where your data is located

Commercial cloud services offer choices that help organizations select an appropriate service and data location. Microsoft Azure, Microsoft Dynamics 365, and Microsoft 365 provide options that influence where customer data is stored.

Global data-residency choices help organizations satisfy resilience and compliance requirements within geographic boundaries. Contractual commitments and transparency about storage and processing support that decision, but the customer must still map services, data types, jurisdictions, and regulatory obligations.

12. Your data is secured at rest and in transit

Microsoft uses encryption to create barriers against unauthorized access and may apply independent layers so that one compromise does not expose everything. can use capabilities up to AES-256. is protected with standard protocols such as Transport Layer Security and Internet Protocol Security.

Microsoft-managed encryption keys are protected, while services such as Azure Key Vault allow customers to control passwords, cryptographic keys, and other secrets. The organization remains responsible for correct permissions, key lifecycle, rotation, recovery, and application configuration.

Customer data protected at rest by AES encryption, in transit by TLS or IPsec, and with keys in Azure Key Vault.
Figure 5 - Protection combines encryption layers, secure transport, and governed keys.

13. Microsoft defends your data

Microsoft says government requests for customer data should be directed to the customer, not provide authorities with direct or unrestricted access. Requests are reviewed for legal validity and appropriate scope. Disclosure occurs only when directed by the customer or required by law.

When legally allowed, Microsoft promptly notifies the customer, provides a copy of the demand, and directs the requesting authority to seek the data from the customer. Microsoft also commits to challenge government demands for commercial and public-sector customer data when a lawful basis exists, including through the courts.

Transparency about policies, operational practices, and technologies complements these legal and contractual defenses. For a real decision, consult the applicable contract, privacy statement, and current legal guidance.

14. Practical decision map

Match the need to the correct answer
ScenarioBest answer
Independent audit evidence about a Microsoft serviceService Trust Portal
Regional-policy documentationIndustry and Regional Resources
Tenant-specific documentsResources for your Organization
Privacy or data-protection paperReports, Whitepapers, and Artifacts
Receive changes to saved evidence > Notification Settings
Prevent advertising use of customer dataYou control your data
Protect inactive data with encryptionYour data is secured at rest and in transit
Respond to unauthorized or government access demandsMicrosoft defends your data

15. Knowledge check with explanations

1. What is the main benefit of for compliance work?

It provides one place for relevant documents and can notify the organization when those documents change.

2. Where should you look for Microsoft online-service evidence tied to regional policies?

Use Industry and Regional Resources.

3. Which principle directly addresses unauthorized access?

Your data is secured at rest and in transit, because it focuses on encryption and barriers against access.

4. How do you receive updates for saved documents?

Configure Notification Settings inside .

5. Which area contains privacy and data-protection resources?

Reports, Whitepapers, and Artifacts.

6. Why are notifications useful?

They provide timely information about evidence changes, helping the organization keep compliance reviews current.

7. Which commitment covers encryption of data that is not actively moving?

Your data is secured at rest and in transit; the at-rest portion applies.

8. Which feature sends email when a document is updated?

, after Notification Settings are configured.

9. Which commitment says customer data will not be used for advertising?

You control your data.

16. Chapter summary

  • The Service Trust Portal publishes Microsoft cloud audit reports and compliance materials.
  • The four portal categories separate standards, general artifacts, industry or regional resources, and tenant-specific documents.
  • saves selected documents and can send change notifications, including updates to a document series.
  • Microsoft’s privacy commitments emphasize customer control, data-location transparency, encryption at rest and in transit, and defense against improper third-party access.
  • Provider evidence supports customer compliance but does not replace customer configuration, governance, or legal responsibility.

17. Essential glossary

Terms to remember
TermMeaning
Microsoft site for cloud audit reports and compliance information.
Independent record of scope, tests, controls, period, and conclusions.
Microsoft-authored explanatory material; it is not an independent audit opinion.
Personalized collection of saved portal documents with optional update notifications.
The geographic location where data is stored or processed under applicable service choices.
A contracted party that processes data to perform a defined service function.
Stored data, protected with controls such as AES encryption.
Data moving across networks, protected with protocols such as TLS or IPsec.

Official references

  • Microsoft Learn - Study guide for Exam SC-900: Microsoft Security, Compliance, and Identity Fundamentals.
  • Microsoft Learn - Get started with the Microsoft Service Trust Portal.
  • Microsoft Trust Center - Data protection and privacy.
  • Microsoft Learn - Azure Key Vault documentation.

Portal features, document availability, roles, and product terms can change. Confirm current Microsoft documentation before making an operational, contractual, or legal decision.