Privacy principles, trust evidence, audit reports, Microsoft Purview, Compliance Manager, compliance score, and shared responsibility
Suggested study time: 21 minutes • Beginner level • Aligned with the SC-900 study guide and official Microsoft Learn documentation
By João Ricardo Dutra••Complete material
1. Introduction: from presumed trust to demonstrable trust
In the early corporate technology environments, much of the trust was built locally. The organization bought servers, physically controlled the data center, and knew directly the people responsible for operations. With outsourcing, managed services, and cloud computing, this closeness decreased. The need then arose to replace trust based solely on proximity with contractual commitments, documented controls, independent audits, and verifiable evidence.
This movement was also driven by the growth of data protection laws, by large-scale incidents, and by the perception that personal and corporate information are social and economic assets. Privacy has ceased to be just a legal clause and has begun to influence architecture, security, procurement, governance, and relationships with users.
For the reader, understanding this topic helps evaluate suppliers, interpret reports, and recognize that a does not automatically transfer compliance to the client. For society, and accountability increase trust in digital services used in health, education, finance, government, and communication. At the end of the chapter, you will know where to look for evidence and, above all, how to use it without confusing it with absolute guarantee.
Figure 1 - Trust is built through commitments, controls, independent auditing, and verifiable evidence.
2. Fundamental concepts
Concept
Practical definition
Example
Trust
Well-founded expectation that a party will fulfill commitments and protect relevant interests.
Trust that a service will apply declared controls and notify important changes.
Privacy
Rights, choices, and practices related to the collection, use, sharing, retention, and deletion of personal data.
Allow access, correction, or deletion of data according to applicable law.
Security
Controls to preserve confidentiality, integrity, and availability.
Encryption, authentication, monitoring, and incident response.
Compliance
Compliance with applicable laws, regulations, contracts, standards, and policies.
Demonstrate controls required by GDPR, ISO, or internal policy.
Transparency
Provision of understandable information about practices, decisions, and data processing.
Publish privacy documentation and audit reports.
Accountability
Ability to demonstrate decisions, responsibilities, and evidence.
Maintain records, responsible parties, tests, and justifications for controls.
Guarantee or assurance
Confidence level obtained through evaluation, evidence, and independent validation.
Audit report produced by a third party.
2.1 Privacy and security are not synonyms
Security protects data against unauthorized access, alteration, unavailability, or destruction. Privacy determines whether the collection and use are legitimate, proportional, transparent, and compatible with people's rights. A database can be technically well protected and still be used for a purpose that is incompatible with the consent or the informed legal basis.
2.2 Compliance is not just technology
Technical controls are important, but compliance also involves contracts, processes, training, governance, records, legal analysis, and oversight. Therefore, evidence from the cloud provider is only a part of the set that an organization needs to present.
Key point for the SC-900
The shows how Microsoft demonstrates commitments and controls of its services. It does not configure the client's environment, does not classify data, and does not replace the organization's compliance management.
3. Microsoft Privacy Principles
Microsoft presents its privacy approach as a commitment to valuing, protecting, and defending data. In preparing for the SC-900, it is useful to organize this approach into five complementary ideas: control, , protection, compliance, and responsible use. The documentation may group or name these commitments in different ways, but the central meaning remains consistent.
Figure 2 - Privacy principles guide how data is collected, used, protected, and made available.
3.1 Control over the data
The customer must maintain meaningful choices about their data, including access, modification, deletion, retention setting, and service selection. In commercial cloud services, Microsoft states contractual commitments to use customer data to provide the agreed services and for purposes compatible with those services.
3.2
allows understanding which data is processed, where it can be stored, how it is protected, which subprocessors participate in the service, and which contractual conditions apply. It does not mean publishing details that would facilitate attacks; it means providing enough information for informed decisions, auditing, and governance.
4. Protection, compliance, and responsible use
4.1 Protection during the life cycle
Data protection involves security at rest, in transit, and during processing, as well as identity, access, segmentation, logging, monitoring, response, and recovery. Microsoft combines physical, operational, and technological controls, but the correct configuration of customer resources and access remains essential.
4.2 Compliance with laws and standards
Microsoft's compliance with standards and regulations provides a foundation for customers subject to similar requirements. Examples include ISO/IEC standards, SOC reports, regulated industry requirements, and commitments related to the GDPR. However, the customer needs to verify whether the service, region, feature, and period under review are within the scope of the evidence.
4.3 Limited and responsible use
Responsible use means limiting processing to the agreed purposes, controlling employee and subprocessors' access, applying minimization and proper retention, and maintaining governance for changes. Microsoft states that it does not share customers' commercial data with advertising-funded services nor exploits it for marketing or advertising.
4.4 Defense against third-party claims
Privacy protection also includes processes to evaluate government and authority requests. Microsoft states that it does not grant direct and unrestricted access to customer data and that it analyzes the legal validity of requests. For the customer, this reinforces the importance of understanding location, jurisdiction, contracts, and sovereignty requirements.
Important
Privacy principles are broad commitments. For a contractual or legal decision, the organization must consult the applicable terms, the , the privacy statement, and specialized advice.
5. Data, roles, and shared responsibility
5.1 Personal data, customer data, and data generated by the service
Personal data is information related to an identified or identifiable person. Customer data is content provided or generated by the customer in the use of the service. Diagnostic data and data generated by the service may be necessary for operation, security, support, and improvement. The categories, purposes, and terms vary by product, so they should be evaluated in the specific documentation.
5.2 Controller and operator/processor
In many legislations, the controller determines the purposes and means of processing, while the operator or processor processes data on behalf of the controller. In a cloud service, the customer often acts as the controller of the data they enter into the service, and Microsoft acts as the processor for the contracted purposes. The exact classification depends on the context and the service.
5.3 Shared compliance responsibility
Microsoft is responsible for the controls under its administration. The customer is responsible for configuration, identities, permissions, classification, retention, purposes, legal bases, internal processes, and the use of data. The division varies depending on the service model and the contract, but it never completely disappears.
Figure 3 - Cloud compliance depends on the joint action of Microsoft and the customer.
6. Microsoft
The Microsoft , known by the acronym STP, is Microsoft's public website for publishing reports and other compliance information related to Microsoft cloud services. It helps customers, auditors, risk teams, legal, procurement, and security understand how Microsoft protects data and meets specific commitments.
6.1 What is the portal used for?
Download reports produced by external auditors.
Check certifications, standards, regulations, and resources by cloud service.
Read whitepapers and technical materials written by Microsoft.
Locate useful documentation for due diligence, supplier evaluations, and audits.
Save documents in a personal library and track download and version history.
6.2 Access and authentication
Some of the content is public, while other materials require authentication with a Microsoft Entra organizational account and acceptance of terms or a confidentiality agreement. Some restricted documents depend on specific roles or permissions.
Figure 4 - The brings together different categories of trust evidence and resources.
7. reports, certifications, and attestations
7.1 report
An report presents procedures, scope, criteria, period, and conclusions of an evaluation. SOC reports, for example, can examine controls related to security, availability, confidentiality, processing integrity, and privacy. It is essential to observe the type of report, the period covered, the entities, and the services included.
7.2
indicates that a management system, process, or service has been evaluated according to the requirements of a standard. An ISO/IEC does not mean that each customer configuration is correct; it demonstrates that the certified scope meets the criteria evaluated over a certain period.
7.3
Attestation is a formal conclusion issued by a qualified party regarding compliance with specific criteria. In some programs, the term is used when the result is not a traditional but still provides independent .
Document
What demonstrates
Interpretation care
SOC Report
Evaluation of controls and test results according to defined criteria.
Check type, period, opinion, exceptions, and client controls.
ISO/IEC Certificate
Compliance of the certified scope with a standard.
Confirm entity, service, location, and validity.
PCI DSS certificate or similar
Conclusion about specific program requirements.
Validate version, scope, and shared responsibilities.
Whitepaper
Technical or compliance explanation written by Microsoft.
It is informative; it does not substitute for independent audit opinion.
Regulatory document
Mapping or information about law and requirements.
It is not legal advice nor automatic proof of client compliance.
8. Portal standards, regulations, and resources
8.1 ISO/IEC
The ISO/IEC family includes standards for security and privacy management. ISO/IEC 27001 deals with information security management systems; ISO/IEC 27018 provides practices for protecting personal information in the public cloud when the provider acts as a processor. The STP helps to locate certificates, scopes, and related materials.
8.2 SOC
SOC reports are widely used in vendor assessments. A Type 1 report analyzes control design at a point in time; a Type 2 evaluates design and operational effectiveness over a period. The reader should look for exceptions, tests, complementary user entity controls, and distribution limitations.
8.3 GDPR
The GDPR establishes principles and rights related to the processing of personal data in the European Union. Microsoft materials may explain contractual commitments, international transfers, security measures, and resources that assist customers. Even so, each organization needs to determine its legal bases and obligations.
8.4 Other programs
The portal also organizes materials related to PCI DSS, FedRAMP, and other standards, sectors, and jurisdictions. Availability varies depending on the service and type of document. For the exam, the most important thing is to understand that the STP centralizes evidence and trust information, not to memorize all existing certifications.
Common trap
A may cover only part of the services, regions, or operations. Always confirm the scope, validity, standard version, and controls that remain under the client's responsibility.
9. Restricted documents, , library, and update
9.1 Why are some documents restricted?
Detailed reports may include sensitive information about controls, architecture, or testing. To balance and security, certain materials require authentication, authorized roles, and acceptance of the Microsoft Non-Disclosure Agreement for Compliance Materials. The restriction does not eliminate ; it reduces the risk of improper disclosure.
9.2 My Library
The library allows saving relevant documents for monitoring. This facilitates periodic reviews, but does not replace a governance repository controlled by the organization. Evidence used in audits must have an owner, version, date, scope, and retention policy.
9.3 Document history and status
The download history helps identify obtained documents and can indicate whether they are active, replaced by a newer version, or removed. As certifications and reports expire or are renewed, compliance evidence needs to be continuously reviewed.
9.4 Care when sharing
Before attaching a report to an , proposal, or internal process, check distribution rights, confidentiality, and access requirements. Documents subject to should not be published in open repositories or forwarded without authorization.
Good practice
Record for each piece of evidence: source, download date, version, covered period, service, region, associated requirement, sharing restriction, and person responsible for review.
10. How to interpret confidence evidence
Downloading a report is just the beginning. The value of evidence depends on its correspondence with the risk and the requirement that the organization needs to demonstrate. A mature analysis checks scope, period, criteria, exceptions, the auditor's opinion, and the client's complementary controls.
Question
Why does it matter
Verification example
Which service is covered?
Products with similar names may have different scopes.
Confirm whether Microsoft 365, Azure, or a specific feature appears in the report.
Which period was evaluated?
Controls change and evidence ages.
Check the start and end dates of the SOC report.
Which regions or entities?
Requirements may depend on location and jurisdiction.
Confirm data center, region, and contractual entity.
Which exceptions were found?
An opinion can contain important observations.
Read test results and administration response.
Which controls belong to the client?
The provider does not perform all the necessary activities.
Set up MFA, retention, logs, and access review.
Is distribution allowed?
Some materials are confidential.
Check NDA, classification, and authorized audience.
Figure 5 - Evidence only supports the decision when its scope, period, and responsibilities are interpreted.
11. Microsoft Purview portal
Microsoft Purview is a set of solutions to govern, protect, and manage data. The Microsoft Purview portal offers a unified experience to access data security, data governance, risk, and compliance resources. It is an operational point for the organization to manage its data assets and obligations.
11.1 What can be found on the portal?
Information protection solutions, classification, and sensitivity labels.
Data Loss Prevention, internal risk, auditing, eDiscovery, and communications compliance.
Retention, lifecycle management, and records management.
Compliance Manager and information about compliance posture.
Data governance solutions, such as Data Map and Unified Catalog, according to licensing and configuration.
11.2 Why is it different from the STP?
STP publishes evidence about Microsoft as a supplier. The Purview portal is used by the client to operate controls over its data, users, content, and processes. In Purview, the organization classifies information, configures policies, investigates events, and monitors risks; in STP, it consults the provider's trust documents.
Summary in one sentence
: evidence about the provider. Microsoft Purview: governance and protection of the organization's data.
12. Microsoft Purview Compliance Manager
Compliance Manager is a Microsoft Purview solution that helps assess and manage compliance in Microsoft and multicloud environments. It organizes requirements into assessments, maps controls, provides improvement actions, and calculates a risk-based score to track progress.
12.1 Main elements
Element
Function
Regulation or model
It represents a standard, law, policy, or set of requirements.
Evaluation
Applies a model to a specific scope and monitors the service.
Control
Requirement that describes what must be implemented or verified.
Improvement action
Recommended task with guidance, responsible party, status, test, and evidence.
Action managed by Microsoft
Control whose implementation and audit result are presented by Microsoft.
Action managed by the client
Activity that the organization needs to implement, test, and document.
compliance score
Risk-based progress indicator in the completion of actions; it is not a legal guarantee of compliance.
Figure 6 - The Compliance Manager turns requirements into assessments, prioritized actions, and continuous monitoring.
13. : benefits and limitations
13.1 What does the score represent?
The measures progress in completing improvement actions that help reduce risks related to data protection and regulatory requirements. Actions have different weights according to their potential impact. The initial score may consider controls managed by Microsoft and the Microsoft 365 data protection baseline.
13.2 What does punctuation not represent?
A high score does not mean that the organization is fully compliant with a law or standard. It does not replace legal analysis, independent , scope assessment, or external evidence. Microsoft explicitly states that the score should not be interpreted as a guarantee of compliance.
13.3 Practical benefits
Prioritize actions with the greatest risk reduction.
Assign responsibilities and track deadlines.
Store notes, tests, and evidence.
Get step-by-step guidance for controls.
Consolidate assessments from different regulations and environments.
Communicate progress to managers and auditors.
Key point for the exam
measures progress in the implementation of recommended actions. It does not certify the organization and does not eliminate the need to interpret laws, contracts, and specific risks.
14. vs Purview vs Compliance Manager
Figure 7 - The three experiences are complementary: evidence, compliance operation, and monitoring.
Criterion
Service Trust Portal
Microsoft Purview portal
Compliance Manager
Main objective
Publish reliable evidence and information from Microsoft.
Govern, protect, and manage the organization's data and risks.
Evaluate requirements and monitor compliance actions.
Typical content
SOC, ISO, attestations, whitepapers, and regulatory documents.
DLP, labels, auditing, eDiscovery, retention, governance, and risk.
Evaluations, controls, improvement actions, evidence, and scoring.
Who produces the data
Microsoft and independent auditors.
The organization and the connected services.
Microsoft, client and evaluation results.
Main use
Due diligence, supplier audit and proof of service.
Operation of data controls and compliance.
Structured management of the compliance program.
Should not be confused with
Tenant configuration tool.
Microsoft audit report library.
Certification or guarantee of compliance.
15. Practical scenario: evaluation of a cloud service
A health company wants to store clinical documents in a Microsoft service. The team needs to assess security, privacy, compliance, and responsibilities before contracting and during operation.
15.1 Step 1 - define requirements
Legal and privacy identify applicable laws, contracts, residency requirements, retention periods, data subject rights, and notification requirements. Security defines technical requirements, such as encryption, MFA, logs, segregation, and recovery.
15.2 Step 2 - consult the
The team locates service reports and certificates, checks the period, scope, regions, exceptions, and complementary controls. Relevant documents are stored in a controlled repository with version tracking and sharing restrictions.
15.3 Step 3 - map shared responsibility
The controls managed by Microsoft are associated with STP evidence. The customer's obligations are transformed into policies and settings: document classification, retention, conditional access, access reviews, DLP, auditing, and incident response process.
15.4 Step 4 - using Purview and Compliance Manager
In the Purview portal, the company configures controls over the data. In Compliance Manager, it creates assessments, assigns actions, records evidence, and monitors progress. The score helps in prioritization, but the final decision takes into account clinical, legal, and operational risk.
15.5 Step 5 - periodic review
Reports, certificates, contracts, settings, and requirements are reviewed periodically. Changes in service, region, subprocessors, legislation, or architecture may require a new assessment.
16. Good practices and limitations
Good practice
Reason
Start with the requirement, not with the document
Avoid collecting reports that do not respond to the real risk.
Confirm scope and period
Out-of-scope or expired evidence can lead to incorrect conclusions.
Read client exceptions and controls
The auditor's opinion does not remove tasks under the organization's responsibility.
Protect restricted documents
Materials subject to NDA require access and distribution control.
Relate evidence to controls
Facilitates auditing, renewal, and identification of gaps.
Maintain continuous review
Services, laws, standards, and reports change.
Do not treat score as certification
Score represents progress, not absolute guarantee.
Involve legal, privacy, security, and business
Compliance is multidisciplinary and contextual.
16.1 Limitations that the reader must recognize
Trust documents describe controls and assessments within a defined scope, not all possible risks. Audits are sample-based and retrospective. Certifications may expire. Laws may require local interpretation. Additionally, improper client configurations can negate benefits offered by the service.
16.2 Recurring pitfalls in SC-900
Confuse with the operational portal of Microsoft Purview.
Claiming that a Microsoft automatically makes the client compliant.
Interpret as a legal guarantee of compliance.
Ignore controls and actions managed by the client.
Confusing an independent report with a produced by the supplier.
Thinking that privacy is just encryption or technical security.
17. Quick review for the SC-900 exam
Term
Objective memorization
Service Trust Portal
Audit reports and compliance information portal for Microsoft services.
Audit report
Independent evidence with criteria, scope, period, tests, and conclusions.
Certification
Recognition that a scope has been assessed according to a standard.
Microsoft Purview
Set of solutions to govern, protect, and manage data.
Compliance Manager
Tool for evaluations, controls, improvement actions, evidence, and score.
compliance score
Risk-based progress indicator; does not guarantee compliance.
Shared responsibility
Microsoft and the client have different controls and obligations.
Privacy principles
Control, transparency, protection, compliance, and responsible use of data.
17.1 Final mind map
Need to prove how Microsoft protects the service? Check the .
Need to set up protection, governance, or investigation for your data? Use the Microsoft Purview portal.
Need to turn requirements into assessments, actions, and monitoring? Use Compliance Manager.
You need to decide if it is compliant? Combine evidence, controls, legal analysis, risk, and ; do not rely solely on a score.
Synthesis
Cloud trust is a discipline of evidence and accountability. The provider demonstrates its controls; the customer interprets the scope, implements its obligations, and maintains continuous governance.
18. Conclusion
Trust in cloud services should not depend on vague promises. It is strengthened by clear privacy principles, contractual commitments, technical and organizational controls, independent audits, and access to evidence. The Microsoft plays this role by bringing together reports, certifications, attestations, whitepapers, and regulatory information about Microsoft services.
At the same time, vendor evidence does not replace the customer's responsibilities. The Microsoft Purview portal helps the organization operate controls over its data, while Compliance Manager structures assessments, improvement actions, and a score that guides priorities. The three resources are complementary, not competitive.
In my assessment, this is one of the most important topics of the SC-900 because it teaches a mature stance: not to confuse with perfect security, nor score with guaranteed compliance. The professional who knows how to interpret evidence and map responsibilities makes better decisions, reduces risks, and contributes to more transparent and reliable digital services.
Next step on the trail
In Chapter 15, the focus shifts from trust evidence to the direct protection of data with Microsoft Purview: classification, sensitivity labels, encryption, DLP, and data security risk management.
19. Review questions
Question 1: A company needs to obtain a produced by an independent auditor
about a Microsoft service. Which resource should I check?
A) Microsoft Defender portal B) Microsoft C) Microsoft Entra admin center D) Azure Policy
Commented answer
Correct answer: B. The publishes reports and compliance information related to Microsoft cloud services.
Question 2: Which statement correctly describes the Compliance conformity score
Manager?
A) It is a legal of the organization. B) Ensures compliance with all laws. C) Measures progress based on risk in the completion of improvement actions. D) Measures only controls managed by Microsoft.
Commented answer
Correct answer: C. Scoring helps prioritize and track actions, but it is not a guarantee of compliance.
Question 3: What is the main difference between the and the Microsoft Purview portal?
A) STP manages devices; Purview manages networks. B) STP provides evidence about Microsoft controls; Purview helps the organization govern and protect its data. C) Both have exactly the same purpose. D) Purview exclusively publishes SOC reports.
Commented answer
Correct answer: B. STP is a source of vendor evidence, while Purview is an operational platform for data, risk, and compliance.
Question 4: Microsoft has a applicable to the service used by the customer. What
what does this mean for the organization?
A) The client is automatically in compliance. B) No additional control is necessary. C) The is relevant evidence, but the client must still fulfill their own responsibilities. D) The client can ignore the scope and validity of the certificate.
Commented answer
Correct answer: C. Compliance in the cloud is shared and depends on the context, scope, and the client's controls.
20. Essential Glossary
Term
Meaning
Assurance
Confidence obtained through evaluation, tests, and evidence.
Certification
Formal conclusion on meeting specific criteria.
Audit
Systematic evaluation of controls, processes, and evidence.
compliance score
Progress scoring in improvement actions in Compliance Manager.
Customer complementary control
Activity that the client needs to implement for the set of controls to be effective.
Data Protection Addendum
Microsoft contractual terms related to the processing and protection of data.
NDA
Confidentiality agreement that restricts the use and disclosure of information.
SOC Report
Report on the controls of a service organization according to auditing criteria.
Service Trust Portal
Microsoft portal for audit reports and compliance materials.
Subprocessor
Third contractor hired to perform treatment functions in support of the service.
Transparency
Clear and accessible information about treatment, controls, and decisions.
Whitepaper
Explanatory document produced by the supplier; does not equate to an independent audit.
Official references consulted
Microsoft Learn - Study guide for Exam SC-900: Microsoft Security, Compliance, and Identity Fundamentals. Updated in 2026.
Microsoft Learn - Get started with Microsoft . Updated on April 6, 2026.
Microsoft Trust Center - Microsoft Privacy Principles / Data protection and privacy.
Microsoft Learn - Microsoft Purview portal.
Microsoft Learn - Microsoft Purview Compliance Manager. Updated on December 3, 2025.
Microsoft Learn - Compliance Manager FAQ. Updated on May 21, 2026.
Microsoft Learn - Microsoft Purview data compliance solutions.
Microsoft Privacy Statement. Updated in March 2026.
Note about update
Portals, product names, licensing, and document availability may change. For actual decisions, always confirm the current documentation, contract, and scope.