Microsoft 365 SOC 2 Reports: What They Cover and How to Download Them

8 min read

Microsoft 365 SOC 2 Reports: What They Cover and How to Download Them


By Narasima Perumal Chandramohan

Microsoft MVP (10+ Years) | Co-Founder & Technical Lead, Apps4.Pro

A customer’s procurement team emails on a Friday afternoon: “Please attach Microsoft’s latest SOC 2 report and bridge letter by Monday.” If you’ve ever looked at that email and wondered which of Microsoft’s seven SOC artifacts you should send, and whether you’re even allowed to forward them, this guide is for you.

We’ll cover what a Microsoft 365 SOC 2 report is, which one to pull (there are several), how to download it from the Service Trust Portal in five steps, and how to use it as evidence without breaking Microsoft’s NDA.

Quick reference

Report you usually want: Microsoft 365 SOC 2 Type 2 + current bridge letter

Where: servicetrust.microsoft.com → Trust Documents → Audit Reports → SOC

Login: Microsoft Entra ID work/school account (no personal Microsoft accounts)

Public alternative: SOC 3 report (no NDA, freely shareable)

Refresh cadence: Quarterly – pull a new bridge letter, replace your stored copy

What a SOC 2 Report Is

SOC stands for System and Organization Controls, and SOC 2 was developed by the American Institute of Certified Public Accountants (AICPA). An independent CPA (Certified Public Accountant) firm checks a service provider’s controls using the Trust Services Criteria and then writes a report about what they found.

There are five Trust Services Criteria:

  • Security – is the core requirement and appears in every SOC 2 report. It covers how the company Protecting systems from unauthorized access, controlling who can log in and what they can do, managing software or system changes safely, monitoring for security risks, responding effectively to incidents or attacks
  • Availability – The system is reliable and available when customers need it.
  • Processing Integrity – Data is processed correctly, completely, on time, and only when authorized.
  • Confidentiality – Sensitive business information is protected from unauthorized access or disclosure.
  • Privacy – Personal information is collected, used, stored, shared, and deleted responsibly.

Only Security is mandatory. Providers add the others based on what they commit to customers.

SOC 2 reports come in two types:

  • SOC 2 Type 1 – controls are designed well at one point in time.
  • SOC 2 Type 2 – controls are designed well and working effectively across a period, usually 6 to 12 months.

Type 2 is what enterprise buyers and auditors want to see, and it’s what Microsoft publishes.

The Microsoft SOC 2 Report Family

“The Microsoft SOC 2 report” sounds like one document, but it’s really a family of reports covering different slices of Microsoft’s cloud. Pulling the wrong one is the most common mistake during a vendor review.

Report

What it covers

Microsoft 365 SOC 2 Type 2 (Office 365 Core / Central Services)

Core Microsoft 365 workloads – Exchange Online, SharePoint Online, OneDrive for Business, Teams, and the identity and platform services that support them.

Microsoft 365 Microservices SOC 2 Type 2 (Additional Services)

Additional and supporting Microsoft 365 services that sit outside the core report.

(Ex : Forms, Planner etc..

Microsoft Azure SOC 2 Type 2

The Azure platform, Dynamics 365, Power Platform, and select Microsoft 365 services running on the same infrastructure.

Azure DevOps SOC 2 Type 2

Published separately; customers who can’t access the Service Trust Portal can request it by email.

SOC 1 Type 2

Financial reporting controls – relevant when the service is part of a customer’s ICFR scope.

SOC 3

A short, public summary of the SOC 2 – no NDA, no login needed.

Bridge letter (gap letter)

A management-signed letter covering the gap between the last SOC 2 reporting period and today.

A few details that catch teams off guard:

  • The Microsoft 365 SOC 2 report covers all five Trust Services Criteria, including Privacy.
  • Microsoft 365 SOC 2 runs on a rolling 12-month audit window with annual reports, plus bridge letters in between.
  • Need the Microsoft Azure SOC 2 report instead? That’s a separate document, the Azure SOC 2 Type 2 covers Azure, Dynamics 365, Power Platform, and select Microsoft 365 services, and unlike the Microsoft 365 report it spans four criteria (Security, Availability, Processing Integrity, and Confidentiality, no Privacy). On the Service Trust Portal, filter by Azure rather than Office 365.
  • Azure SOC reports usually refresh semi-annually (period ends around 31-Mar and 30-Sep), with about a six-week lag before the new report shows up.

 

The One Section You Can’t Skip: Complementary User Entity Controls

Microsoft’s SOC 2 reports run about 250–350 pages, and you don’t need to read every page. But one section is non-negotiable: the Complementary User Entity Controls (CUECs).

These are the controls you must run for Microsoft’s controls to work, MFA enforcement, admin account governance, timely offboarding, audit log retention, and external sharing policies. Skipping this section is the single biggest reason inheritance breaks down in customers’ own audits.

The CUEC section matters because the Microsoft 365 SOC 2 report only covers what Microsoft runs. Your tenant configuration, Conditional Access, privileged roles, audit log retention, sharing policies – is on you.

What to do: What you should do is take the CUEC section from the report and match each item with a corresponding control in your own SOC 2, ISO 27001, or internal control list.

Any CUEC that is not addressed or matched could become a potential issue or audit finding later.

How to Download Microsoft 365 SOC 2 Reports from the Service Trust Portal

Microsoft publishes SOC 1, SOC 2, and SOC 3 reports, plus bridge letters, on the Service Trust Portal (STP) at servicetrust.microsoft.com. SOC 3 is public. SOC 1 and SOC 2 need a Microsoft Entra ID (Azure AD) work or school account, plus acceptance of the Microsoft Compliance NDA.

Step 1 – Sign in with the right account

Head to servicetrust.microsoft.com and sign in with a Microsoft Entra ID organization account tied to an active or trial Microsoft 365, Azure, or Dynamics 365 subscription. Personal Microsoft accounts (Outlook.com, Hotmail) and consumer Gmail addresses won’t work – STP dropped MSA access for these reports.

Step 2 – Accept the Microsoft Compliance NDA

On first visit, STP prompts you to accept the Microsoft Non-Disclosure Agreement for Compliance Materials. If the prompt doesn’t appear, go directly to servicetrust.microsoft.com/ViewPage/MSComplianceNDA .

This NDA is why downloaded SOC 1 and SOC 2 PDFs are marked Microsoft Confidential and can’t be passed along to your customers or auditors as-is.

Step 3 – Open Audit Reports → SOC

From the STP home page, open Trust Documents → Audit Reports, then click the SOC tab. You’ll see filters for cloud service (Azure, Microsoft 365 / Office 365, Dynamics 365) and report type (SOC 1, SOC 2, SOC 3, bridge letters). Microsoft occasionally redesigns the portal, so if these menu labels differ, go straight to the SOC section.

For a Microsoft 365 SOC 2 report, filter by Office 365 (or Microsoft 365) and SOC 2. For an Azure SOC 2 or Azure SOC2 report, filter by Azure and SOC 2. Every tile lists the coverage period and publication date, check both before you download.

Step 4 – Download the report (and the matching bridge letter)

Click the tile to grab the PDF. While you’re there, also pick up:

  • The current bridge letter for the same service extends the assurance provided by the SOC 2 report from its end date through a more recent month-end. Most enterprise reviewers expect this document as evidence of continued compliance during the gap between reporting periods.
  • Any additional services report (for example, Microsoft 365 Microservices SOC 2 Type 2) covering workloads outside the core report.

Bridge letters should cover ideally no more than 90 days of gap. Anything longer should make you, and your auditors, uneasy.

Step 5: Just need a public version? Grab the SOC 3

If you don’t need the full Microsoft SOC 2 detail and only want something shareable, download the SOC 3 report instead. Same audit, summarized. No NDA, no login.

Using the Microsoft 365 SOC 2 Report in Your Vendor Reviews

What you can claim

Your customer’s auditor will accept the Microsoft 365 SOC 2 report as evidence that the underlying platform’s controls are designed and operating effectively. That covers data center physical security (CC6.4), hypervisor isolation, patching of Microsoft-managed components, encryption of Microsoft-managed keys (CC6.7), and similar platform-layer controls.

What’s still on you

What doesn’t cover is how you set up the tenant. Your customer will still ask you to prove :

  • Logical access (CC6.1): Conditional Access policies forcing MFA and blocking legacy authentication.
  • Privileged access (CC6.3): Global Administrators kept to the minimum and reviewed through Privileged Identity Management (PIM).
  • User access lifecycle (CC6.2): Terminated user accounts disabled on time.
  • System monitoring (CC7.2): Unified audit log enablement and retention.
  • Data classification (CC6.7): External sharing controls in SharePoint and OneDrive, plus Microsoft Purview / DLP policies for Exchange, SharePoint, and Teams.

That’s the shared responsibility line: Microsoft proves the platform, you prove your tenant.

How to send it without breaking the NDA

The Microsoft 365 SOC 2 PDF is marked Microsoft Confidential, so you can’t forward it. Instead:

  • Send your customer to the STP to download it themselves with their own Microsoft Entra ID account.
  • Share the SOC 3 freely – it’s the same audit, summarized, and built for public distribution.
  • Reference Microsoft as a subservice organization in your own SOC 2 system description, using the carve-out or inclusive method your auditor recommends.

Your Quarterly SOC 2 Routine

Microsoft proves the platform. You prove your tenant. Set a recurring quarterly task that does three things:

  1. Pull the latest Microsoft 365 SOC 2 report and bridge letter from STP.
  2. Re-map the CUECs against your current Conditional Access, PIM, audit log, and sharing settings.
  3. Refresh the dates in your security questionnaires and trust page.

That single 30-minute routine turns the next vendor questionnaire into a five-minute job instead of a fire drill – and keeps your compliance posture defensible all year.

Migrate Everything to Microsoft 365

Exchange Online SharePoint Online OneDrive For Business Microsoft Teams Microsoft Planner Viva Engage (Yammer) Microsoft Bookings Microsoft Forms Power Automate Microsoft Power BI Exchange Online SharePoint Online OneDrive For Business Microsoft Teams Microsoft Planner Viva Engage (Yammer) Microsoft Bookings Microsoft Forms Power Automate Microsoft Power BI
  • No Data Loss
  • Zero Downtime
  • ISO-Certified Protection

Start your free 15-days trial today !


4.5 out of 5

Bot Logo

Apps4.Pro Bot

Hey!👋 Ready to make your Microsoft 365 migration journey easier? Tell me what you’re looking.

What gets migrated?
I have a sales question
I'm here for tech support
Learn about Apps4.Pro