SOC 2 on Microsoft 365: Mapping the Trust Services Criteria to Entra, Intune, Purview and Defender Evidence
A customer's procurement team asks for your SOC 2 report, and you run on Microsoft 365. A well-configured tenant already produces most of the technical evidence an auditor wants. None of it counts until someone exports it, on a schedule, for the whole observation period, and Microsoft's own SOC 2 report covers Microsoft, not you. This article maps the criteria to the Entra, Intune, Purview and Defender features that generate evidence, lists what auditors ask for, names the gaps Microsoft 365 cannot close, and explains why Type I versus Type II is a decision about when you start collecting.
What SOC 2 asks, in plain terms
SOC 2 is an attestation, not a certification. A CPA firm examines your controls against the AICPA's Trust Services Criteria and issues a report your customers read under NDA. The criteria cover five categories: security, availability, processing integrity, confidentiality and privacy. Security is mandatory; the other four are in scope only if you put them there, and most 20 to 500-seat firms scope security plus availability and confidentiality. The current criteria are the AICPA's 2017 Trust Services Criteria with revised points of focus issued in 2022, a revision the AICPA describes as changing the points of focus, not the criteria. We could not open the AICPA page today, so check the category list and dates there before quoting them.
A Type I report covers the design of your controls as of one date. A Type II adds testing of whether they operated over a period, commonly three to twelve months.
SOC 2 does not prescribe controls. You define the system in scope and the controls you claim, and the auditor tests those. A Microsoft 365 tenant is therefore a good starting point and a bad finishing point: it offers controls you can claim with evidence, and nothing for the policies, vendor reviews and risk assessments the criteria also require.
The evidence map: criteria area to Microsoft 365 control
This is the mapping we use in readiness work, grouped by the areas the security criteria cover.
- Logical access: Conditional Access, MFA registration state, admin roles with no standing membership, Privileged Identity Management for time-bound elevation, and periodic access reviews. Our Conditional Access design patterns and Entra ID governance articles cover the design.
- Provisioning and deprovisioning: lifecycle workflows or a documented HR-to-IT process, the account-disabled timestamp in the Entra audit log, and license removal the same day.
- Endpoints: Intune compliance policies and the compliance report by device, plus Defender for Business or Defender for Endpoint onboarding status and alert history. Unmanaged devices reaching company data are the finding auditors write first.
- Confidentiality: Purview sensitivity labels, DLP policies and their match reports, retention policies, and external-sharing settings.
- Monitoring and incident response: Defender XDR incidents and their disposition, the unified audit log, and a ticket trail showing an incident was triaged and closed. A managed detection service supplies the overnight-watch evidence a 40-person firm cannot staff.
- Change management: the Entra and Intune audit logs record who changed which policy when; for your own product, the auditor wants source control and the deployment pipeline.
- Subservice organization: Microsoft's SOC 2 Type 2 reports for Microsoft 365 and Azure are downloadable from the Service Trust Portal with an active subscription; your auditor will want the current one plus the bridge letter.
What auditors ask for, and why retention sets your start date
A typical evidence request: an export of every Conditional Access policy plus sign-in log entries showing them applying; the MFA registration report with exceptions explained; privileged role membership at several dates, PIM activation history and completed access review results; the Intune compliance report and Defender device inventory with gaps explained; DLP and label policy lists with a sample of matches; Defender incidents with their resolution; and Microsoft's SOC 2 Type 2 report with your review notes. Every item is an export or a dated screenshot from inside the observation period.
Retention decides when you must start. Microsoft's Entra documentation (ms.date 6 January 2026) states that sign-in and audit logs are kept for 30 days with Entra ID P1 or P2 and seven days without, and that longer retention means routing them to a storage account or Log Analytics, or using Purview Audit (Premium). For the unified audit log, Microsoft's Security Blog post of 18 October 2023 set the Audit (Standard) default at 180 days and kept Audit (Premium) at one year with an option to ten. A six-month Type II window is longer than the Entra sign-in log lives, so the export starts on day one of the period. If your tenant were breached today, what could you prove and the cyber insurance questionnaire article show the same exports from other angles.
The gaps Microsoft 365 alone cannot close
A readiness assessment typically finds the technical controls two-thirds done and the organizational controls not started:
- Written policies (security, access control, acceptable use, incident response, change and vendor management, business continuity) with approval dates, annual review and acknowledgment records.
- A dated risk assessment with owners, ratings and treatments; Secure Score is input, not a substitute.
- Vendor management: every vendor that touches customer data, with a risk tier and evidence you reviewed its SOC 2 or equivalent. Microsoft is one entry.
- Security awareness training with completion records and phishing simulation results; our Managed Security Awareness Training and Phishing Simulation service ($3 per user per month plus $375 per tenant per month) produces those records.
- Backup and restore testing for Microsoft 365 data; retention policies are not backups in an auditor's eyes.
- Your own product: source control, code review, CI/CD, production access and application logging.
If your firm also faces HIPAA, NYDFS Part 500 or the FTC Safeguards Rule, the technical evidence overlaps almost entirely; see our HIPAA implementation model, NYDFS Part 500 and FTC Safeguards checklist articles.
Licensing the evidence usually needs
SOC 2 requires no particular Microsoft license, but some make the evidence easier. Microsoft list prices, September 2026 price list, annual commitment, per user per year:
- Conditional Access, Intune and endpoint protection: Microsoft 365 Business Premium ($264.00) carries Entra ID P1, Intune Plan 1 and Defender for Business; Microsoft 365 E3 ($468.00) carries Entra ID P1, Intune and Defender for Endpoint Plan 1.
- PIM and access reviews: Microsoft Entra ID P2 ($120.00), or the Entra P2 Add On for Microsoft 365 E3 ($36.00). Entra ID P1 vs P2 explains the split; P2 for the admins who hold privileged roles is usually enough.
- One-year audit retention without exporting: Microsoft 365 E5 ($720.00) or the Microsoft 365 E5 eDiscovery and Audit add-on ($72.00), which Microsoft lists among the licenses that enable Audit (Premium).
Do not let a SOC 2 project become an E5 project; the E3 vs E5 article explains where the E5 stack goes unused.
Type I vs Type II timing, and the order of work
A first SOC 2 on Microsoft 365, in our experience, runs nine to twelve months, and the order matters more than the speed.
- Scope and readiness (weeks 1 to 4): choose the categories, define the system boundary, and list tenant findings and policy gaps with owners.
- Remediation (weeks 4 to 12): fix the tenant, write and approve the policies, stand up training and vendor review, and switch on log export.
- Start the observation period only now; nothing before the controls exist counts.
- Type I (optional) early in the period if a customer needs a report soon.
- Monthly evidence collection through the period. This step fails when it is nobody's job.
- Type II fieldwork after the period closes, then the report.
The trap is starting the period before remediation; the auditor does not overlook the first two months, and the period restarts.
Frequently asked questions
Is Microsoft 365 SOC 2 compliant?
Microsoft's services, including Microsoft 365 and Azure, are examined under SOC 2 Type 2 and the reports are on the Service Trust Portal for subscribers. That covers Microsoft's controls as your subservice organization. Your own report is about your controls, policies and people; the tenant configuration is evidence in it, not a substitute for it.
Do I need Microsoft 365 E5 for SOC 2?
No. Business Premium or Microsoft 365 E3 provides Conditional Access, Intune and endpoint protection. Add Entra ID P2 (or the $36.00 E3 add-on) for admins, and either export audit logs or buy the E5 eDiscovery and Audit add-on ($72.00) for one-year retention.
What is the difference between SOC 2 Type 1 and Type 2?
A Type I reports on the design of your controls as of one date. A Type II reports on whether they operated effectively over a period, commonly three to twelve months, based on the auditor's sample testing. Enterprise customers generally require Type II.
Can Microsoft Purview Compliance Manager do my SOC 2?
Compliance Manager can host a SOC 2 assessment template and track improvement actions against your tenant, which helps readiness. It does not replace the auditor, the policies or the exports, and premium templates are licensed separately.
Sources
- AICPA & CIMA, "2017 Trust Services Criteria (With Revised Points of Focus – 2022)" (title and the statement that the revisions do not alter the criteria as summarized in search results on 27 September 2026; site not reachable from our writing environment; verify on aicpa-cima.com)
- Microsoft Security Blog, "New Microsoft Purview Audit enhancements increase security visibility," 18 October 2023 (opened; Audit (Standard) 180 days, Audit (Premium) one year, extension to ten)
- Microsoft Learn, "Microsoft Entra data retention" (ms.date 6 January 2026; opened via the MicrosoftDocs GitHub source; 30-day retention with P1/P2, seven days otherwise, Audit (Premium) licenses)
- Microsoft Learn, SOC 2 Type 2 compliance offering, and Compliance Manager regulations page (not opened; as summarized in search results on 27 September 2026; verify on Microsoft Learn)
- Microsoft, Commercial price list, September 2026 (our CSP price sheet)
- IT Partner blog: microsoft-365-breach-forensics-prove-scope; entra-id-p1-vs-p2-conditional-access-pim-identity-protection-compliance
- IT Partner engineering notes from SOC 2 readiness engagements, September 2026
| Criteria area | Microsoft 365 control | Evidence artifact | License that carries it |
|---|---|---|---|
| Logical access | Conditional Access, MFA, blocked legacy auth | Policy export; sign-in log sample; MFA registration report | Entra ID P1 (in Business Premium, E3) |
| Privileged access | PIM, access reviews, role membership | Activation history; review results; role membership at three dates | Entra ID P2 or the E3 P2 add-on |
| Endpoints | Intune compliance, encryption, Defender onboarding | Compliance report; device inventory; alert history | Intune Plan 1 plus Defender for Business or Endpoint |
| Confidentiality | Sensitivity labels, DLP, retention, sharing settings | Policy lists; match sample; sharing configuration | Business Premium or E3 |
| Monitoring | Defender XDR incidents, unified audit log | Incident list with disposition; audit export; ticket trail | Audit (Standard) 180 days; Audit (Premium) one year with E5 or the add-on |
| Policies, risk, vendors, training, backup | Not in Microsoft 365 | Approved documents, risk register, vendor list, training records, restore test | None; process and third-party tools |
Key takeaways
- SOC 2 tests the controls you claim; Microsoft 365 supplies evidence for logical access, devices, data protection and monitoring, and nothing for policies, risk assessment, vendor review or training.
- Every artifact must exist for dates inside the observation period; Entra sign-in logs live 30 days with P1/P2 and Audit (Standard) keeps 180 days, so log export starts on day one of the period.
- Type I reports on control design as of one date; Type II on operation over three to twelve months; plan nine to twelve months to a first Type II and do not start the period before remediation is done.
- You do not need E5: Business Premium or Microsoft 365 E3, Entra ID P2 for admins ($120.00, or the $36.00 E3 add-on), and a log export or the E5 eDiscovery and Audit add-on ($72.00) cover the technical side.
- Microsoft's own SOC 2 Type 2 report from the Service Trust Portal is your subservice-organization evidence, not your compliance.
If a customer has asked for your report, the SOC 1, SOC 2, ISAE 3402 Pre-Audit Readiness Assessment ($4,000 per project, ten days) maps your tenant and your organization against the criteria and hands you the remediation list with owners. The Compliance Evidence and Audit Readiness Retainer ($950 per month) does the monthly export and evidence filing through the observation period, and for a firm that needs the full program built, the SOC Compliance Readiness Check ($15,000 per project, thirty days) covers policies, risk assessment and vendor review as well as the tenant. Book a call and bring the customer's questionnaire.
Questions this article didn’t answer?
Thirty minutes with Mike — our CEO, not a sales rep. Bring the hard version of the question.