First page of Microsoft's 100,000-partner directory, sorted by responsiveness All 6 Microsoft Solutions Partner designations Microsoft Solutions Partner since 2006 1,100+ organizations under management
Home/Blog/Facilitate Compliance Work with Microsoft Purvie…

Facilitate Compliance Work with Microsoft Purview Compliance Manager

2026-06-16·IT PartnerMicrosoft 365Cloud SecurityComplianceMicrosoft Purview

Compliance is no longer a once-a-year audit exercise. In 2026, organizations need a repeatable way to map regulatory obligations to Microsoft 365 controls, assign improvement work, collect evidence, and show progress. Microsoft Purview Compliance Manager helps bring legal, compliance, security, and IT teams into one shared workflow.

Why compliance work is still hard

Regulated organizations face a practical gap: compliance and privacy teams understand obligations, policies, and audit expectations, while IT and security teams understand configuration, data protection, identity, endpoint management, and investigation tools. Without a shared framework, work becomes fragmented: requirements live in spreadsheets, evidence is collected manually, and auditors receive inconsistent documentation.

Microsoft 365 customers also operate in a shared-responsibility model. Microsoft is responsible for the security and compliance commitments of its cloud services, data centers, and service operations. Your organization remains responsible for how you configure the tenant, manage identities, classify and protect data, retain or delete information, respond to incidents, and prove that required processes are followed. Microsoft Purview Compliance Manager is designed to help manage that customer side of the equation.

What Microsoft Purview Compliance Manager is in 2026

Microsoft Purview Compliance Manager is part of the Microsoft Purview compliance experience. It is not primarily a standalone tool on the old Service Trust Portal workflow. The Service Trust Portal remains important for Microsoft audit reports, certifications, compliance documentation, privacy resources, and trust materials. Purview Compliance Manager is where organizations work with assessments, improvement actions, controls, evidence, scoring, assignments, and reporting.

In practical terms, Compliance Manager helps you evaluate your compliance posture against Microsoft-provided assessment templates, identify Microsoft-managed and customer-managed controls, prioritize improvement actions, assign work to responsible teams, upload evidence, and track progress through a compliance score. The score is useful for prioritization and internal measurement, but it is not a legal certification and does not guarantee compliance.

What the tool can help you do

Microsoft Purview Compliance Manager can help organizations:

  1. Create assessments based on relevant regulations, standards, and internal control frameworks available in the Microsoft Purview template library.
  2. Understand which controls are handled by Microsoft and which actions remain your organization’s responsibility.
  3. Review improvement actions with implementation guidance, testing notes, and mapped controls.
  4. Assign actions to compliance, security, IT, legal, or business owners.
  5. Track implementation and testing status, including planned, implemented, tested, passed, or failed states depending on the assessment workflow.
  6. Upload and manage evidence such as policies, configuration exports, screenshots, meeting records, approvals, or procedure documents.
  7. Use compliance score changes to prioritize high-impact actions.
  8. Export assessment information and supporting evidence for internal reviews, external audits, or regulator discussions.

The most valuable part is coordination. A single technical or procedural action may support multiple frameworks, reducing duplicated work across GDPR, ISO, NIST, HIPAA, industry-specific requirements, and internal policies where applicable.

How it fits with Microsoft Purview and Microsoft 365 security

Compliance Manager is most useful when connected to a broader Microsoft 365 governance and security program. Recommended actions often point to capabilities such as Microsoft Purview Data Loss Prevention, Microsoft Purview Information Protection, sensitivity labels, retention labels and retention policies, Microsoft Purview eDiscovery, audit logging, insider risk features, communication compliance, Microsoft Entra ID access controls, Microsoft Intune device compliance, Microsoft Defender for Cloud Apps, and Microsoft Defender XDR.

For example, a data protection requirement may involve several layers: classify sensitive information with sensitivity labels, restrict sharing with Microsoft Purview DLP, enforce conditional access through Microsoft Entra ID, manage compliant devices with Microsoft Intune, monitor risky cloud usage with Defender for Cloud Apps, and retain records using Purview data lifecycle management. Compliance Manager helps document the obligation and track the action, while the actual control is implemented in the relevant Microsoft 365 or Microsoft security workload.

Compliance Manager and the Service Trust Portal

Use the two resources together:

Microsoft Purview Compliance Manager is for operational compliance management: assessments, improvement actions, assignments, implementation details, evidence collection, testing, score tracking, and reporting.

The Microsoft Service Trust Portal is for trust and assurance documentation: independent audit reports, certifications, data protection documentation, compliance guides, regulatory resources, and Microsoft cloud control information.

During an audit, organizations often use Service Trust Portal documents to show Microsoft’s cloud controls and use Compliance Manager evidence to show how their own tenant, policies, and procedures were implemented.

A modern workflow for assessments

A practical 2026 workflow looks like this:

  1. Select the relevant assessment template in Microsoft Purview Compliance Manager. Start with a Microsoft 365 baseline or a regulation that applies to your industry and region.
  2. Review Microsoft-managed controls to understand what Microsoft has implemented and where supporting trust documentation may be available.
  3. Review customer-managed improvement actions and map them to business owners, IT owners, security owners, or legal/compliance stakeholders.
  4. Prioritize actions by risk, compliance score impact, business importance, regulatory deadlines, and audit findings.
  5. Implement the required technical or procedural control. Examples include enabling sensitivity labels, configuring DLP policies, enforcing multifactor authentication and Conditional Access in Microsoft Entra ID, defining retention policies, or documenting incident response procedures.
  6. Upload evidence and notes. Evidence should be accurate, current, and restricted to authorized users only.
  7. Test and review the control. Compliance or audit teams should validate that the action is actually implemented and operating as expected.
  8. Export reports and evidence packages for audit preparation, management reviews, or remediation planning.

This workflow works best when compliance is treated as an ongoing program rather than a last-minute reporting task.

Permissions and access control

Access should be governed through Microsoft Purview role groups and Microsoft Entra ID identity controls. Organizations should apply least privilege, especially because Compliance Manager may contain sensitive evidence, audit notes, policy documents, and remediation details.

Typical access planning includes separate roles for administrators, assessors, reviewers, readers, security teams, and compliance owners. Use Microsoft Entra ID multifactor authentication, Conditional Access, privileged access practices, access reviews, and role governance where appropriate. Avoid giving broad access to users who only need to review a limited set of actions or reports.

Do not assume that every tenant user should have access. Review current Microsoft Purview permissions, align them with your internal governance model, and document who can upload, view, export, and approve evidence.

Licensing and CSP considerations

Availability of Microsoft Purview capabilities depends on your Microsoft 365 plan, add-ons, and service configuration. Some compliance features, assessment templates, automated testing, advanced eDiscovery, insider risk, communication compliance, audit capabilities, information protection, DLP, and data governance features may require specific Microsoft 365 E5, Microsoft 365 E5 Compliance, or other eligible licenses.

For organizations buying through the Microsoft Cloud Solution Provider program, subscriptions are typically managed under the New Commerce Experience (NCE). NCE affects subscription terms, seat changes, renewal timing, and add-on planning, so compliance feature planning should be reviewed before renewal or tenant-wide rollout. A licensing review is often necessary before building a compliance roadmap around Purview.

Important limitation: this is not legal advice

Microsoft Purview Compliance Manager is a compliance management and risk assessment aid. It provides templates, recommendations, control mapping, scoring, workflow, and documentation support. It does not replace legal advice, industry-specific regulatory interpretation, internal audit, or executive accountability. Passing an assessment inside the tool does not automatically prove compliance with a law, contract, or regulator expectation.

Use Compliance Manager as part of a broader governance program that includes legal review, risk management, policy ownership, security operations, data governance, user training, and periodic testing.

Best starting point for SMB and mid-market organizations

If you are not sure where to begin, start small and build repeatability. Choose a Microsoft 365 baseline assessment, identify the highest-risk improvement actions, confirm licensing, assign owners, and collect evidence as work is completed. Then expand to industry or regional frameworks that matter to your organization.

High-value early actions often include strengthening Microsoft Entra ID authentication, reviewing admin roles, enabling audit logging, defining retention requirements, classifying sensitive data, implementing Microsoft Purview DLP, securing unmanaged cloud app usage, and documenting incident response and data handling procedures. These actions improve both security posture and audit readiness.

Key takeaways

  • Microsoft Purview Compliance Manager is the current Microsoft 365 tool for compliance assessments, improvement actions, evidence tracking, scoring, and audit preparation.
  • The Service Trust Portal is still useful, but mainly for Microsoft trust documentation, audit reports, certifications, and regulatory resources.
  • Compliance Manager helps coordinate work between compliance, legal, security, and IT teams, but it does not guarantee legal or regulatory compliance.
  • Permissions should be managed through Microsoft Purview roles and Microsoft Entra ID identity governance using least privilege.
  • Licensing matters: some Purview compliance capabilities require specific Microsoft 365 plans or add-ons, and CSP customers should consider NCE renewal and subscription rules.

Need help turning Microsoft Purview Compliance Manager into a practical compliance program? IT Partner can assess your Microsoft 365 tenant, review licensing, configure Purview controls, and help your team build an audit-ready evidence workflow.

Questions this article didn’t answer?

Thirty minutes with Mike — our CEO, not a sales rep. Bring the hard version of the question.