A customer’s procurement team emails on a Friday afternoon: “Please attach Microsoft’s latest SOC 2 report and bridge letter by Monday.” If you’ve ever looked at that email and wondered which of Microsoft’s seven SOC artifacts you should send, and whether you’re even allowed to forward them, this guide is for you.
We’ll cover what a Microsoft 365 SOC 2 report is, which one to pull (there are several), how to download it from the Service Trust Portal in five steps, and how to use it as evidence without breaking Microsoft’s NDA.
Quick reference
– Report you usually want: Microsoft 365 SOC 2 Type 2 + current bridge letter
– Where: servicetrust.microsoft.com → Trust Documents → Audit Reports → SOC
– Login: Microsoft Entra ID work/school account (no personal Microsoft accounts)
– Public alternative: SOC 3 report (no NDA, freely shareable)
– Refresh cadence: Quarterly – pull a new bridge letter, replace your stored copy
- What a SOC 2 Report Is
- The Microsoft SOC 2 Report Family
- The One Section You Can’t Skip: Complementary User Entity Controls
- How to Download Microsoft 365 SOC 2 Reports from the Service Trust Portal
- Using the Microsoft 365 SOC 2 Report in Your Vendor Reviews
- What’s still on you
- How to send it without breaking the NDA
What a SOC 2 Report Is
SOC stands for System and Organization Controls, and SOC 2 was developed by the American Institute of Certified Public Accountants (AICPA). An independent CPA (Certified Public Accountant) firm checks a service provider’s controls using the Trust Services Criteria and then writes a report about what they found.
There are five Trust Services Criteria:
- Security – is the core requirement and appears in every SOC 2 report. It covers how the company Protecting systems from unauthorized access, controlling who can log in and what they can do, managing software or system changes safely, monitoring for security risks, responding effectively to incidents or attacks
- Availability – The system is reliable and available when customers need it.
- Processing Integrity – Data is processed correctly, completely, on time, and only when authorized.
- Confidentiality – Sensitive business information is protected from unauthorized access or disclosure.
- Privacy – Personal information is collected, used, stored, shared, and deleted responsibly.
Only Security is mandatory. Providers add the others based on what they commit to customers.
SOC 2 reports come in two types:
- SOC 2 Type 1 – controls are designed well at one point in time.
- SOC 2 Type 2 – controls are designed well and working effectively across a period, usually 6 to 12 months.
Type 2 is what enterprise buyers and auditors want to see, and it’s what Microsoft publishes.
The Microsoft SOC 2 Report Family
“The Microsoft SOC 2 report” sounds like one document, but it’s really a family of reports covering different slices of Microsoft’s cloud. Pulling the wrong one is the most common mistake during a vendor review.
Report | What it covers |
|---|---|
|
Microsoft 365 SOC 2 Type 2 (Office 365 Core / Central Services) |
Core Microsoft 365 workloads – Exchange Online, SharePoint Online, OneDrive for Business, Teams, and the identity and platform services that support them. |
|
Microsoft 365 Microservices SOC 2 Type 2 (Additional Services) |
Additional and supporting Microsoft 365 services that sit outside the core report. (Ex : Forms, Planner etc.. |
|
Microsoft Azure SOC 2 Type 2 |
The Azure platform, Dynamics 365, Power Platform, and select Microsoft 365 services running on the same infrastructure. |
|
Azure DevOps SOC 2 Type 2 |
Published separately; customers who can’t access the Service Trust Portal can request it by email. |
|
SOC 1 Type 2 |
Financial reporting controls – relevant when the service is part of a customer’s ICFR scope. |
|
SOC 3 |
A short, public summary of the SOC 2 – no NDA, no login needed. |
|
Bridge letter (gap letter) |
A management-signed letter covering the gap between the last SOC 2 reporting period and today. |
|
A few details that catch teams off guard:
|
The One Section You Can’t Skip: Complementary User Entity Controls
Microsoft’s SOC 2 reports run about 250–350 pages, and you don’t need to read every page. But one section is non-negotiable: the Complementary User Entity Controls (CUECs).
These are the controls you must run for Microsoft’s controls to work, MFA enforcement, admin account governance, timely offboarding, audit log retention, and external sharing policies. Skipping this section is the single biggest reason inheritance breaks down in customers’ own audits.
The CUEC section matters because the Microsoft 365 SOC 2 report only covers what Microsoft runs. Your tenant configuration, Conditional Access, privileged roles, audit log retention, sharing policies – is on you.
What to do: What you should do is take the CUEC section from the report and match each item with a corresponding control in your own SOC 2, ISO 27001, or internal control list.
Any CUEC that is not addressed or matched could become a potential issue or audit finding later.
How to Download Microsoft 365 SOC 2 Reports from the Service Trust Portal
Microsoft publishes SOC 1, SOC 2, and SOC 3 reports, plus bridge letters, on the Service Trust Portal (STP) at servicetrust.microsoft.com. SOC 3 is public. SOC 1 and SOC 2 need a Microsoft Entra ID (Azure AD) work or school account, plus acceptance of the Microsoft Compliance NDA.
Step 1 – Sign in with the right account
Head to servicetrust.microsoft.com and sign in with a Microsoft Entra ID organization account tied to an active or trial Microsoft 365, Azure, or Dynamics 365 subscription. Personal Microsoft accounts (Outlook.com, Hotmail) and consumer Gmail addresses won’t work – STP dropped MSA access for these reports.
Step 2 – Accept the Microsoft Compliance NDA
On first visit, STP prompts you to accept the Microsoft Non-Disclosure Agreement for Compliance Materials. If the prompt doesn’t appear, go directly to servicetrust.microsoft.com/ViewPage/MSComplianceNDA .
This NDA is why downloaded SOC 1 and SOC 2 PDFs are marked Microsoft Confidential and can’t be passed along to your customers or auditors as-is.
Step 3 – Open Audit Reports → SOC
From the STP home page, open Trust Documents → Audit Reports, then click the SOC tab. You’ll see filters for cloud service (Azure, Microsoft 365 / Office 365, Dynamics 365) and report type (SOC 1, SOC 2, SOC 3, bridge letters). Microsoft occasionally redesigns the portal, so if these menu labels differ, go straight to the SOC section.
For a Microsoft 365 SOC 2 report, filter by Office 365 (or Microsoft 365) and SOC 2. For an Azure SOC 2 or Azure SOC2 report, filter by Azure and SOC 2. Every tile lists the coverage period and publication date, check both before you download.
Step 4 – Download the report (and the matching bridge letter)
Click the tile to grab the PDF. While you’re there, also pick up:
- The current bridge letter for the same service extends the assurance provided by the SOC 2 report from its end date through a more recent month-end. Most enterprise reviewers expect this document as evidence of continued compliance during the gap between reporting periods.
- Any additional services report (for example, Microsoft 365 Microservices SOC 2 Type 2) covering workloads outside the core report.
Bridge letters should cover ideally no more than 90 days of gap. Anything longer should make you, and your auditors, uneasy.
Step 5: Just need a public version? Grab the SOC 3
If you don’t need the full Microsoft SOC 2 detail and only want something shareable, download the SOC 3 report instead. Same audit, summarized. No NDA, no login.
Using the Microsoft 365 SOC 2 Report in Your Vendor Reviews
What you can claim
Your customer’s auditor will accept the Microsoft 365 SOC 2 report as evidence that the underlying platform’s controls are designed and operating effectively. That covers data center physical security (CC6.4), hypervisor isolation, patching of Microsoft-managed components, encryption of Microsoft-managed keys (CC6.7), and similar platform-layer controls.
What’s still on you
What doesn’t cover is how you set up the tenant. Your customer will still ask you to prove :
- Logical access (CC6.1): Conditional Access policies forcing MFA and blocking legacy authentication.
- Privileged access (CC6.3): Global Administrators kept to the minimum and reviewed through Privileged Identity Management (PIM).
- User access lifecycle (CC6.2): Terminated user accounts disabled on time.
- System monitoring (CC7.2): Unified audit log enablement and retention.
- Data classification (CC6.7): External sharing controls in SharePoint and OneDrive, plus Microsoft Purview / DLP policies for Exchange, SharePoint, and Teams.
That’s the shared responsibility line: Microsoft proves the platform, you prove your tenant.
How to send it without breaking the NDA
The Microsoft 365 SOC 2 PDF is marked Microsoft Confidential, so you can’t forward it. Instead:
- Send your customer to the STP to download it themselves with their own Microsoft Entra ID account.
- Share the SOC 3 freely – it’s the same audit, summarized, and built for public distribution.
- Reference Microsoft as a subservice organization in your own SOC 2 system description, using the carve-out or inclusive method your auditor recommends.
Your Quarterly SOC 2 Routine
Microsoft proves the platform. You prove your tenant. Set a recurring quarterly task that does three things:
- Pull the latest Microsoft 365 SOC 2 report and bridge letter from STP.
- Re-map the CUECs against your current Conditional Access, PIM, audit log, and sharing settings.
- Refresh the dates in your security questionnaires and trust page.
That single 30-minute routine turns the next vendor questionnaire into a five-minute job instead of a fire drill – and keeps your compliance posture defensible all year.









