Microsoft Service Trust Portal and Privacy Principles
Audit evidence, portal content categories, My Library notifications, data control and location, encryption at rest and in transit, and defense against third-party requests
Suggested study time: 32 minutes • Beginner level • Aligned with the SC-900 study guide and official Microsoft Learn documentation
By João Ricardo Dutra••Complete material
1. What you will learn
Trust in Microsoft cloud services is supported by security, privacy, and compliance practices that customers can examine. The Service Trust Portal gathers evidence and guidance about these practices, while Microsoft privacy commitments explain how customer data is controlled, located, protected, and defended.
Explain the purpose and main offerings of the Microsoft Service Trust Portal.
Describe the four privacy commitments emphasized in this module.
Choose the correct portal category or privacy principle in an SC-900 scenario.
Figure 1 - Cloud trust becomes useful when commitments are supported by evidence.
2. What is the Microsoft Service Trust Portal?
The Microsoft Service Trust Portal, or , is Microsoft’s public site for publishing audit reports and other compliance information about Microsoft cloud services. It helps organizations understand how their data is protected and how to manage cloud security and compliance.
Its resources include reports prepared by independent auditors and Microsoft-authored whitepapers. The first type provides external assurance; the second explains designs, controls, and practices. Neither makes the customer automatically compliant: the organization must still evaluate scope, configure its environment, and meet its own obligations.
3. Access, authentication, and permissions
Some content is public, but protected materials require an authenticated Microsoft cloud services account associated with a Microsoft Entra organization. Depending on the document, the user may also need to accept the Microsoft Non-Disclosure Agreement for Compliance Materials or hold an authorized role.
Access is linked to the organization tenant, subscription, and user permissions.
Microsoft 365, Dynamics 365, and Azure trial or paid subscriptions can provide access.
Restricted evidence must be handled according to its license and confidentiality terms.
The Service Trust Portal link in the page header returns the user to the portal home page.
4. The four content categories
The landing page organizes its materials into four areas. Knowing their purpose is more important for the exam than memorizing every document available in each tile.
Service Trust Portal organization
Category
What it contains
Typical need
Certifications, Regulations, and Standards
Security implementation, design, certifications, standards, and regulatory materials.
Verify an ISO, SOC, GDPR, FedRAMP, or PCI-related resource.
Examine assurance evidence or understand how a control works.
Industry and Regional Resources
Materials organized for industries, governments, and geographic requirements.
Find guidance for a regulated sector or region.
Resources for your Organization
Tenant-restricted documents selected according to the organization’s subscriptions and permissions.
Find evidence specifically applicable to the customer tenant.
Figure 2 - The portal groups evidence by standard, document type, industry or region, and tenant.
5. Certifications, Regulations, and Standards
This area explains how Microsoft cloud services implement and design security to support regulatory objectives. Selecting a tile opens a list of applicable documents with a title, description, cloud-service context, and last-updated date.
ISO/IEC: standards and certificates related to security and privacy management.
SOC: System and Organization Controls reports, including SOC 1, SOC 2, and SOC 3.
GDPR: resources about the General Data Protection Regulation.
FedRAMP and PCI: materials for United States federal authorization and payment-card security requirements.
Other country, region, or sector programs presented by the portal.
Always verify the service, entity, region, report period, standard version, exceptions, and customer controls. A certificate is relevant evidence, not a guarantee that every customer configuration complies.
6. Reports, Whitepapers, and Artifacts
This category brings together general technical and assurance documents. Business Continuity and Disaster Recovery materials explain resilience planning. Pen Test and Security Assessments contain attestations or reports about penetration tests and third-party security reviews.
Privacy and Data Protection materials address privacy commitments and safeguards. FAQ and Whitepapers provide Microsoft explanations and answers to recurring questions. An independent assessment and a vendor have different assurance value, so readers must identify the author, scope, date, and intended use.
7. Industry, regional, and tenant-specific resources
Financial Services: regulatory guidance for financial institutions by country or region.
Healthcare and Life Sciences: cloud capabilities and compliance materials for healthcare.
Media and Entertainment: resources for that industry’s operational and compliance needs.
United States Government: resources reserved for eligible government customers.
Regional Resources: documentation about Microsoft online services and regional policies or regulations.
Resources for your Organization: documents restricted to the signed-in tenant based on subscription and permissions.
In an exam question asking where to find evidence about regional policies, choose Industry and Regional Resources. If the requirement refers to documents unique to the organization’s tenant, choose Resources for your Organization.
8. and update notifications
centralizes documents that matter to the user. From a document’s ellipsis menu, choose Save to library. This avoids repeatedly locating the same evidence and creates a focused collection for review.
Notification Settings defines the delivery frequency and an organizational email address. When Microsoft updates a saved document, the message includes a link and a short description of the change. Saving a document that belongs to a series also subscribes the user to updates for that series.
Figure 3 - turns selected evidence into a monitored collection.
Exam distinction
centralizes documents and sends update notifications. It does not edit reports, approve compliance workflows, or share protected documents automatically with external parties.
9. Microsoft’s four privacy commitments
Microsoft states that privacy influences product and service design. The Microsoft Trust Center presents the commitment around four questions: who controls the data, where it is located, how it is secured, and how Microsoft responds to third-party demands.
Figure 4 - The privacy commitments cover the data lifecycle and legal access requests.
10. You control your data
Customer data remains the customer’s business. The customer can access, modify, or delete it according to the service and contract. Microsoft commits not to use that data without agreement and, when authorized, to use it to provide the selected services.
Microsoft does not share commercial customer data with advertising-supported services or mine it for advertising or marketing research.
Subcontractors and subprocessors receive only the access needed for the contracted function.
Authorized subprocessors are bound by corresponding privacy commitments and assessed against security and privacy requirements.
Broad privacy laws and standards, including ISO/IEC 27018 for cloud privacy, reinforce customer control.
11. Know where your data is located
Commercial cloud services offer choices that help organizations select an appropriate service and data location. Microsoft Azure, Microsoft Dynamics 365, and Microsoft 365 provide options that influence where customer data is stored.
Global data-residency choices help organizations satisfy resilience and compliance requirements within geographic boundaries. Contractual commitments and transparency about storage and processing support that decision, but the customer must still map services, data types, jurisdictions, and regulatory obligations.
12. Your data is secured at rest and in transit
Microsoft uses encryption to create barriers against unauthorized access and may apply independent layers so that one compromise does not expose everything. can use capabilities up to AES-256. is protected with standard protocols such as Transport Layer Security and Internet Protocol Security.
Microsoft-managed encryption keys are protected, while services such as Azure Key Vault allow customers to control passwords, cryptographic keys, and other secrets. The organization remains responsible for correct permissions, key lifecycle, rotation, recovery, and application configuration.
Microsoft says government requests for customer data should be directed to the customer, not provide authorities with direct or unrestricted access. Requests are reviewed for legal validity and appropriate scope. Disclosure occurs only when directed by the customer or required by law.
When legally allowed, Microsoft promptly notifies the customer, provides a copy of the demand, and directs the requesting authority to seek the data from the customer. Microsoft also commits to challenge government demands for commercial and public-sector customer data when a lawful basis exists, including through the courts.
Transparency about policies, operational practices, and technologies complements these legal and contractual defenses. For a real decision, consult the applicable contract, privacy statement, and current legal guidance.
14. Practical decision map
Match the need to the correct answer
Scenario
Best answer
Independent audit evidence about a Microsoft service
Service Trust Portal
Regional-policy documentation
Industry and Regional Resources
Tenant-specific documents
Resources for your Organization
Privacy or data-protection paper
Reports, Whitepapers, and Artifacts
Receive changes to saved evidence
> Notification Settings
Prevent advertising use of customer data
You control your data
Protect inactive data with encryption
Your data is secured at rest and in transit
Respond to unauthorized or government access demands
Microsoft defends your data
15. Knowledge check with explanations
1. What is the main benefit of for compliance work?
It provides one place for relevant documents and can notify the organization when those documents change.
2. Where should you look for Microsoft online-service evidence tied to regional policies?
Use Industry and Regional Resources.
3. Which principle directly addresses unauthorized access?
Your data is secured at rest and in transit, because it focuses on encryption and barriers against access.
4. How do you receive updates for saved documents?
Configure Notification Settings inside .
5. Which area contains privacy and data-protection resources?
Reports, Whitepapers, and Artifacts.
6. Why are notifications useful?
They provide timely information about evidence changes, helping the organization keep compliance reviews current.
7. Which commitment covers encryption of data that is not actively moving?
Your data is secured at rest and in transit; the at-rest portion applies.
8. Which feature sends email when a document is updated?
, after Notification Settings are configured.
9. Which commitment says customer data will not be used for advertising?
You control your data.
16. Chapter summary
The Service Trust Portal publishes Microsoft cloud audit reports and compliance materials.
The four portal categories separate standards, general artifacts, industry or regional resources, and tenant-specific documents.
saves selected documents and can send change notifications, including updates to a document series.
Microsoft’s privacy commitments emphasize customer control, data-location transparency, encryption at rest and in transit, and defense against improper third-party access.
Provider evidence supports customer compliance but does not replace customer configuration, governance, or legal responsibility.
17. Essential glossary
Terms to remember
Term
Meaning
Microsoft site for cloud audit reports and compliance information.
Independent record of scope, tests, controls, period, and conclusions.
Microsoft-authored explanatory material; it is not an independent audit opinion.
Personalized collection of saved portal documents with optional update notifications.
The geographic location where data is stored or processed under applicable service choices.
A contracted party that processes data to perform a defined service function.
Stored data, protected with controls such as AES encryption.
Data moving across networks, protected with protocols such as TLS or IPsec.
Official references
Microsoft Learn - Study guide for Exam SC-900: Microsoft Security, Compliance, and Identity Fundamentals.
Microsoft Learn - Get started with the Microsoft Service Trust Portal.
Microsoft Trust Center - Data protection and privacy.
Microsoft Learn - Azure Key Vault documentation.
Portal features, document availability, roles, and product terms can change. Confirm current Microsoft documentation before making an operational, contractual, or legal decision.