Instiq
Chapter 3 · Security, Compliance, Privacy, and Trust·v2.0.0·Updated 6/3/2026·~8 min

What's changed: Deepened MS-900 Chapter 3 to the AZ-900 baseline (M365 security Entra ID/Defender XDR/Zero Trust + table, identity-first; compliance Purview/Service Trust Portal/data residency + table, shared-responsibility mapping; scenarios, FAQ, SC-900 links). Localized 1 figure

3.2Compliance and Trust

Key points

Understand the elements supporting trust in Microsoft 365—Microsoft Purview compliance (information protection, data lifecycle), the Service Trust Portal, and data residency.

Using Microsoft 365 confidently in business requires compliance and trust (transparency). Microsoft provides mechanisms for both.

3.2.1Compliance and trust tools

Diagram contrasting the Service Trust Portal (Microsoft’s audit reports, certifications, compliance docs) with Microsoft Purview (compliance portal + Compliance Manager and Compliance Score).
Microsoft’s compliance vs. managing your own
  • Microsoft Purview: an integrated suite to manage your compliance—information protection (sensitivity labels), DLP, data lifecycle (retention), eDiscovery, audit.
  • Service Trust Portal: a portal to obtain Microsoft’s audit reports (ISO/SOC), certifications, and compliance documents (verify the cloud-side compliance).
  • Data residency: know the region (geographic location) where data is stored to meet region-specific regulations.

Compliance has two sides—"how Microsoft itself complies" and "how you manage your own compliance"—mapping to Chapter 1’s shared responsibility model. The Service Trust Portal covers the former (obtain Microsoft’s third-party audit/certification evidence); Microsoft Purview covers the latter (classify with sensitivity labels, prevent leaks with DLP, manage lifecycle with retention). Also, data residency—which region data is stored in—matters for country-specific data-protection regulations. These mirror SC-900; MS-900 expects the big picture of how Microsoft 365 supports compliance and transparency.

GoalMechanism
Manage/score your own complianceMicrosoft Purview (Compliance Manager)
Obtain Microsoft’s audit/cert docsService Trust Portal
Check where data is storedData residency
Classify/prevent leaks of sensitive dataSensitivity labels, DLP (Purview)
Example

Scenario: audit and information protection. If a partner asks for the cloud’s ISO certification, obtain it from the Service Trust Portal and submit it. Label your documents "Confidential" and encrypt them with Purview sensitivity labels, block external sending with DLP, and delete after a period with retention. Check the storage region via data residency for regulations. You can demonstrate compliance on both the cloud (Trust Portal) and customer (Purview) sides.

Warning

Watch the mix-ups: (1) Service Trust Portal (Microsoft’s compliance = obtain docs) vs Microsoft Purview (manage your own)—opposite subjects. (2) Purview bundles information protection, DLP, retention, eDiscovery, audit. (3) Data residency is "which region the data physically sits in"—key for regulations.

Note

Q. Purview vs Service Trust Portal? Purview manages your own compliance; the Service Trust Portal provides Microsoft’s compliance documents. Q. Why does data residency matter? Many countries regulate where data is stored. Q. Relation to SC-900? Both cover Purview/Trust Portal—MS-900 the big picture, SC-900 the details.

Exam point

Common: manage your compliance = Microsoft Purview, Microsoft’s compliance docs = Service Trust Portal, where data is stored = data residency (shared with SC-900). Also: shared responsibility "cloud side = Trust Portal / customer side = Purview."

3.2.2Section summary

  • Purview (manage your compliance: labels/DLP/retention/eDiscovery/audit) / Service Trust Portal (Microsoft’s docs)
  • Address region-specific regulations via data residency; mirrors SC-900

Sign in to track progress — Log in.

Quick check

(just a quick review)

Q1. Which Microsoft suite manages your compliance with sensitivity labels, DLP, etc.?

Q2. Where can you obtain Microsoft’s audit reports, certifications, and compliance documents?

Q3. Which concept—the region where data is stored—matters for regulatory requirements?

Check your understandingPractice questions for Chapter 3: Security, Compliance, Privacy, and Trust