SOC 2 policies for Microsoft 365 teams
Microsoft 365 is the system of record for who works at your company, so it appears in the policies about access provisioning, authentication and multi-factor enforcement, and the joiner, mover and leaver steps in HR security.
Identity providers · Referenced by 3 of 22 policies · Generator preset available
The 3 policies that reference Microsoft 365
With Microsoft 365 in your intake, these policies name it in their scope, roles and procedures. The other 19 policies in the set apply to your company regardless of tooling; the template index lists all 22.
- P03 Access Control Policy: Defines how access to systems and data is requested, approved, provisioned, reviewed and removed.
- P04 Authentication and Password Policy: Sets the requirements for passwords, multi-factor authentication, sessions and secrets used by people and systems.
- P18 Human Resources Security Policy: Sets the security requirements that apply to people before, during and after their engagement so that screening, access, training and accountability follow every personnel change.
What the Audit Kit writes for Microsoft 365
The free generator fills in names. The Audit Kit goes further: Claude rewrites section 4 (Policy Statements) and section 5 (Procedures) of each policy using your full intake, so the text describes Microsoft 365 the way you actually run it. The statements below are examples of that output for Microsoft 365; your own answers produce different text, and every statement should be checked against your configuration before management adopts it.
P03 Access Control Policy
Microsoft Entra ID is the identity provider: SaaS applications are integrated as enterprise applications with user assignment required, access is granted through security groups (dynamic groups keyed on department and job title where possible) rather than to individual users, and SCIM provisioning is enabled for every application that supports it.
Global Administrator is limited to two named accounts plus one emergency access account that is excluded from Conditional Access and monitored for any sign-in. All other privileged roles are eligible rather than permanently active and are activated through Privileged Identity Management with justification, approval and a maximum eight-hour duration, and access reviews of privileged roles and guest accounts run quarterly.
Microsoft Entra sign-in, audit and provisioning logs are exported to a Log Analytics workspace with 365-day retention, and alerts fire on role assignments, Conditional Access policy changes, new application consents and additions of guest users. The Security Owner matches each alert to an approved ticket weekly.
P04 Authentication and Password Policy
Conditional Access policies require multi-factor authentication for every user on every sign-in, require the phishing-resistant authentication strength (FIDO2 security keys, passkeys in Microsoft Authenticator or Windows Hello for Business) for administrator roles, block legacy authentication protocols, and require an Intune-compliant device for access to Exchange Online, SharePoint, OneDrive and Teams.
Microsoft Entra Password Protection enforces the global banned password list and a custom banned list containing the company and product names, smart lockout is enabled, self-service password reset requires two registered methods, and Identity Protection user-risk and sign-in-risk policies require a password change or multi-factor authentication when risk is medium or higher.
P18 Human Resources Security Policy
The HR system drives joiner, mover and leaver events through inbound provisioning to Microsoft Entra ID. On the last working day the leaver's sign-in is blocked and sessions are revoked, the mailbox is converted to a shared mailbox for the manager, group memberships are removed, and the Intune-managed device is remotely wiped and retired.
How to use this page
- Open the generator with the Microsoft 365 preset and answer the remaining questions: company, product, headcount, other tools, data types, owners, scope and review cadence.
- Download the 22 policies as Markdown. Read the sections that mention Microsoft 365 with the admin console open and fix anything that is not true of your setup.
- Optionally buy the Audit Kit to have sections 4 and 5 tailored to Microsoft 365 and the rest of your stack, and to get Word documents, the TSC crosswalk, an evidence checklist, acknowledgment forms and a review calendar in one ZIP built on your machine.
- Have management approve the policies, collect acknowledgments, and start producing the evidence the procedures describe. The CPA firm performs the examination.
Other tools
Cloud platforms: AWS, Google Cloud, Microsoft Azure, Vercel, Cloudflare
Source control and CI: GitHub, GitLab
Identity providers: Google Workspace, Okta
Vendors and subprocessors: Supabase, Clerk
Frequently asked questions
- Does Microsoft 365's SOC 2 report cover our own SOC 2?
- No. Microsoft 365's own SOC 2 report covers the controls Microsoft 365 operates for its platform. Your examination covers how your company configures and uses Microsoft 365: who has access, how it is authenticated, what is logged and how data in it is protected. Auditors read the vendor's report to decide what they can rely on, and the Vendor and Third-Party Risk Management Policy tells you to collect it at onboarding and annually.
- What does the generator pre-fill when I arrive from this page?
- The link on this page opens the generator with a preset that sets the identity provider to Microsoft Entra. The other answers (company, product, headcount, owners, data types, scope and review cadence) are yours to fill in. The policies render in your browser as Markdown; nothing is sent to a server and there is no signup.
- Which policies change when I add Microsoft 365 to my answers?
- 3 policies name Microsoft 365 once it is in the intake: Access Control Policy, Authentication and Password Policy, Human Resources Security Policy. The free generator names it in scope, roles and procedures; the Audit Kit ($39 one-time) rewrites sections 4 and 5 of each policy with statements specific to how Microsoft 365 is configured, like the examples on this page. Refunds are available within 14 days on request.
Policyseed provides governance policy templates and AI tailoring. It is not legal advice and not a compliance guarantee. Management adopts the policies; the CPA firm performs the SOC 2 examination.