SOC 2 policies for Microsoft Azure teams

Microsoft Azure hosts your production environment, so it appears wherever the policies talk about who can reach production, how data is encrypted, what is logged, how services recover and how the network is segmented.

Cloud platforms · Referenced by 6 of 22 policies · Generator preset available

The 6 policies that reference Microsoft Azure

With Microsoft Azure in your intake, these policies name it in their scope, roles and procedures. The other 16 policies in the set apply to your company regardless of tooling; the template index lists all 22.

  • P03 Access Control Policy: Defines how access to systems and data is requested, approved, provisioned, reviewed and removed.
  • P08 Encryption and Key Management Policy: Sets minimum encryption standards for data in transit and at rest and defines how cryptographic keys, secrets and certificates are generated, stored, rotated and retired.
  • P12 Logging and Monitoring Policy: Defines which security-relevant events are logged across the product, cloud and corporate systems, how logs are protected and retained, and how alerts are triaged and acted on.
  • P14 Business Continuity and Disaster Recovery Policy: Sets recovery objectives by system tier, defines how a disaster is declared and recovered from, and requires the plan to be tested and maintained.
  • P15 Backup and Recovery Policy: Requires every data set that supports the product and the business to be backed up on a defined schedule, protected, monitored and proven restorable through regular tests.
  • P20 Network and Infrastructure Security Policy: Defines how the cloud networks, compute and supporting infrastructure behind the product are segmented, hardened, administered and monitored.

What the Audit Kit writes for Microsoft Azure

The free generator fills in names. The Audit Kit goes further: Claude rewrites section 4 (Policy Statements) and section 5 (Procedures) of each policy using your full intake, so the text describes Microsoft Azure the way you actually run it. The statements below are examples of that output for Microsoft Azure; your own answers produce different text, and every statement should be checked against your configuration before management adopts it.

P03 Access Control Policy

Azure role assignments are made to Microsoft Entra ID security groups at subscription or resource group scope, never to individual users. The Owner, Contributor and User Access Administrator roles on production subscriptions are held only through Privileged Identity Management with just-in-time activation, approval and a maximum eight-hour duration.

P08 Encryption and Key Management Policy

Storage accounts, managed disks and Azure SQL databases that hold customer data use customer-managed keys stored in Azure Key Vault with soft delete and purge protection enabled. Key Vault uses the Azure RBAC permission model, keys have automatic rotation policies, and Key Vault diagnostic logs are retained for one year.

P12 Logging and Monitoring Policy

Azure Activity Logs, Microsoft Entra sign-in and audit logs, and diagnostic settings for every production resource are sent to a central Log Analytics workspace with 365-day retention. Microsoft Defender for Cloud is enabled on production subscriptions, and High-severity alerts route to the incident channel.

P14 Business Continuity and Disaster Recovery Policy

Production workloads use zone-redundant SKUs and a paired-region strategy: Azure SQL databases use failover groups to the paired region and Azure Storage uses geo-redundant storage. The disaster recovery runbook documents the failover group activation steps, the most recent test date and the measured recovery time.

P15 Backup and Recovery Policy

Azure Backup protects production virtual machines and Azure SQL databases daily in a Recovery Services vault with geo-redundant storage, soft delete and immutability enabled so that recovery points cannot be deleted inside the retention window. Quarterly restore tests into an isolated resource group are recorded as evidence.

P20 Network and Infrastructure Security Policy

Virtual networks use network security groups that deny inbound traffic by default, PaaS services disable public network access in favour of Private Endpoints, and internet-facing applications sit behind Azure Front Door or Application Gateway with the Web Application Firewall in prevention mode using the Microsoft default rule set.

How to use this page

  1. Open the generator with the Microsoft Azure preset and answer the remaining questions: company, product, headcount, other tools, data types, owners, scope and review cadence.
  2. Download the 22 policies as Markdown. Read the sections that mention Microsoft Azure with the admin console open and fix anything that is not true of your setup.
  3. Optionally buy the Audit Kit to have sections 4 and 5 tailored to Microsoft Azure and the rest of your stack, and to get Word documents, the TSC crosswalk, an evidence checklist, acknowledgment forms and a review calendar in one ZIP built on your machine.
  4. Have management approve the policies, collect acknowledgments, and start producing the evidence the procedures describe. The CPA firm performs the examination.

Other tools

Cloud platforms: AWS, Google Cloud, Vercel, Cloudflare

Source control and CI: GitHub, GitLab

Identity providers: Google Workspace, Okta, Microsoft 365

Vendors and subprocessors: Supabase, Clerk

Frequently asked questions

Does Microsoft Azure's SOC 2 report cover our own SOC 2?
No. Microsoft Azure's own SOC 2 report covers the controls Microsoft Azure operates for its platform. Your examination covers how your company configures and uses Microsoft Azure: who has access, how it is authenticated, what is logged and how data in it is protected. Auditors read the vendor's report to decide what they can rely on, and the Vendor and Third-Party Risk Management Policy tells you to collect it at onboarding and annually.
What does the generator pre-fill when I arrive from this page?
The link on this page opens the generator with a preset that sets the cloud platform to Azure. The other answers (company, product, headcount, owners, data types, scope and review cadence) are yours to fill in. The policies render in your browser as Markdown; nothing is sent to a server and there is no signup.
Which policies change when I add Microsoft Azure to my answers?
6 policies name Microsoft Azure once it is in the intake: Access Control Policy, Encryption and Key Management Policy, Logging and Monitoring Policy, Business Continuity and Disaster Recovery Policy, Backup and Recovery Policy, Network and Infrastructure Security Policy. The free generator names it in scope, roles and procedures; the Audit Kit ($39 one-time) rewrites sections 4 and 5 of each policy with statements specific to how Microsoft Azure is configured, like the examples on this page. Refunds are available within 14 days on request.

Policyseed provides governance policy templates and AI tailoring. It is not legal advice and not a compliance guarantee. Management adopts the policies; the CPA firm performs the SOC 2 examination.