Guide
Using the Azure SOC 2 report in your own examination
The Azure SOC 2 report covers Microsoft's controls over its cloud platform. So you can carve out that layer in your own report, but your tenant configuration remains yours to prove.
- Preparation, not the examination
- A licensed CPA firm signs the report
- Plain-English guidance
Where to find the Azure SOC 2 report
Microsoft publishes it on the Microsoft Service Trust Portal. You sign in with a work account, then download the report. Therefore your compliance owner can retrieve it without contacting Microsoft.
What the Azure SOC 2 report covers
It covers Microsoft's controls for the in-scope Azure services. However, your subscriptions, identities and data remain your responsibility.
| Layer | Covered by |
|---|---|
| Physical data centres | Microsoft. |
| Azure platform services in scope | Microsoft. |
| Entra ID users, roles and policies | You. |
| Your data and configuration | You. |
Azure SOC 2 report checklist
Tick what you have done.
Your result appears here as you tick, so you can see what is still open.
Carving out Azure in your report
Your CPA firm will usually carve out Microsoft and rely on its report. So confirm every Azure service you use appears in its scope, and file the report as vendor evidence.
Customer responsibilities in the Azure SOC 2 report
The report lists complementary user entity controls, such as managing access in your tenant. Therefore map each one to a control of yours, or expect questions during fieldwork.
Our role
We map those duties during readiness. However, the examination is performed by a licensed CPA firm, since we are not one. Reference: AICPA guidance on SOC 2.
Keep the version you relied on, with its download date. Microsoft updates its reports periodically, and your CPA firm may ask which period you used. Also check that any new Azure services you adopted appear in the current scope. If one is missing, raise it with your CPA firm early, because it may affect how that part of your system is tested. Finally, note which Microsoft reports cover services outside Azure, such as Microsoft 365, since those may need separate review. A short note in your vendor file recording these checks is usually enough.
Azure SOC 2 report questions
Does the Azure SOC 2 report cover Microsoft 365?
Microsoft publishes separate reports for some services, so check which ones you need.
Is the Azure SOC 2 report free?
Yes, for customers with access to the portal.
Can we rely on it entirely?
No. It covers Microsoft's layer, while your configuration is examined separately.
How current must it be?
Use the latest period available before your examination.
Related guides
Map your Azure duties before fieldwork
Tell us your Azure services. We reply with a written scope and a fixed preparation fee. That map then becomes part of your vendor management evidence.
Scope your preparation