Delen via


Get started with Microsoft Service Trust Portal

The Microsoft Service Trust Portal provides a variety of content, tools, and other resources about how Microsoft cloud services protect your data, and how you can manage cloud data security and compliance for your organization.

Tip

If you're not an E5 customer, use the 90-day Microsoft Purview solutions trial to explore how additional Purview capabilities can help your organization manage data security and compliance needs. Start now at the Microsoft Purview compliance portal trials hub. Learn details about signing up and trial terms.

Accessing the Service Trust Portal

The Service Trust Portal is Microsoft's public site for publishing audit reports and other compliance-related information associated with Microsoft’s cloud services. STP users can download audit reports produced by external auditors and gain insight from Microsoft-authored whitepapers that provide details on how Microsoft cloud services protect your data, and how you can manage cloud data security and compliance for your organization. To access some of the resources on the Service Trust Portal, you must log in as an authenticated user with your Microsoft cloud services account (Microsoft Entra organization account) and review and accept the Microsoft Non-Disclosure Agreement for Compliance Materials.

Existing customers

Existing customers can access the Service Trust Portal at https://aka.ms/STP with one of the following online subscriptions (trial or paid):

  • Microsoft 365
  • Dynamics 365
  • Azure

Note

Microsoft Entra accounts associated with organizations have access to the full range of documents and resources like Compliance Manager.

New customers and customers evaluating Microsoft online services

To create a new account or to create a trial account, use one of the following sign-up forms (also used for trial accounts) to get access to the STP.

When you sign up for either a free trial, or a subscription, you must enable Microsoft Entra ID to support your access to the STP.

Using the Service Trust Portal

The Service Trust Portal features and content are accessible from the main menu. The following sections describe each item in the main menu.

Screenshot of the Service Trust Portal - main menu.

Service Trust Portal

The Service Trust Portal link displays the home page. It provides a quick way to get back to the home page.

Certifications, Regulations and Standards

Provides a wealth of security implementation and design information with the goal of making it easier for you to meet regulatory compliance objectives by understanding how Microsoft Cloud services keep your data secure. To review content, select one of the following tiles.

  • ISO/IEC - International Organization for Standardization (ISO) / International Electrotechnical Commission (IEC)
  • SOC - System and Organization Controls (SOC) 1, 2, and 3 Reports
  • GDPR - General Data Protection Regulation
  • FedRAMP - Federal Risk and Authorization Management Program
  • PCI - Payment Card Industry (PCI) Data Security Standards (DSS)
  • CSA Star - Cloud Security Alliance (CSA) Security, Trust and Assurance Registry (STAR)
  • Australia IRAP - Australia Information Security Registered Assessors Program (IRAP)
  • Singapore MTCS - Multi-Tier Cloud Security (MTCS) Singapore Standard
  • Spain ENS - Spain Esquema Nacional de Seguridad (ENS)

Reports, Whitepapers, and Artifacts

General documents relating to the following categories:

  • AI Resources: Resources describing the approach to Compliance, Security and Privacy in the AI solutions such as Microsoft Copilot and Azure Open AI.
  • BCP and DR: Business Continuity and Disaster Recovery.
  • Pen Test and Security Assessments: Attestation of penetration tests and security assessments conducted by third parties.
  • Privacy and Data Protection: Privacy and data protection resources.
  • FAQ and Whitepapers: Whitepapers and answers to frequently asked questions.

Industry and Regional Resources

Documents the apply to the following industries and regions:

  • Financial Services - Resources elaborating regulatory compliance guidance for FSI (by country/region)
  • Healthcare and Life Sciences - Capabilities offered by Microsoft for Healthcare Industry
  • Media and Entertainment - Media and Entertainment Industry Resources
  • United States Government - Resources exclusively for US Government customers
  • Regional Resources - Documents describing compliance of Microsoft's online services with various regional policies and regulations

Resources for your Organization

Documents applying to your organization (restricted by tenant).

  • Resources for your Organization - Documents based on your organization’s subscription and permissions

Resources with the series check mark indicate that the document has multiple versions, which can be viewed once you click on the document and click “view all versions” on the download page.

Document series are marked and can be viewed on the download page.

Filter by date and cloud service - When viewing the available documents, you can filter the results by date range by selecting Dates and then selecting the range you want to use.

Filter available documents by date range.

Document download view - When viewing the available documents, you can filter the results by the applicable Cloud Service.

Filter available documents by cloud service.

Note

Many of the files on the STP require acceptance of a license agreement. Some browser-based PDF viewers do not allow Javascript to run, which prevents the license agreement from being displayed and the file from opening.

All Documents

This section displays all available documents. Select the documents to save into your My Library section. Documents are sorted under the same categories shown under Certifications, Standards, Regulations, and Industry Resources. To view all resources for a particular cloud service use the Cloud Service filter.

Restricted Documents

The Service Trust Portal has documents that, given the nature of their content, are available for users with specific permissions. You need to be assigned one of following roles to view restricted documents:

  • Tenant Admin
  • Compliance Administrator
  • Security Administrator
  • Security Reader

Click the magnifying glass in the upper right-hand corner of the Service Trust Portal page to expand the box, enter your search terms, and press Enter. The Search page is displayed, with the search term displayed in the search box and the search results listed below.

Search for documents and filter results.

By default, the search returns document results. You can filter the results by using the dropdown lists to refine the list of documents displayed. You can use multiple filters to narrow the list of documents. Filters include the specific cloud services, and regions. Click the document name link to download the document.

Note

Service Trust Portal reports and documents are available to download for at least 12 months after publishing or until a new version of document becomes available.

My Library

Use the My Library feature to add documents and resources on the Service Trust Portal to your My Library page. This lets you access documents that are relevant to you in a single place. To add a document to your My Library, click the ellipsis (...) menu to the right of a document and then select Save to library. You can add multiple documents to your My Library by clicking the checkbox next to one or more documents, and then clicking Save to library at the top of the page.

Additionally, the notifications feature lets you configure your My Library so that an email message is sent to you whenever Microsoft updates a document that you've added to your My Library. To set up notifications, go to your My Library and click Notification Settings. You can choose the frequency of notifications and specify an email address in your organization to send notifications to. Email notifications include links to the documents that have been updated and a brief description of the update.

If a document is part of a series, you will be subscribed to the series and will receive notifications when there is an update to that series. You can view the individual documents and Series documents that you have subscribed to, in 2 sections as shown below:

My Library displays the documents you have subscribed to in two sections.

My Download History

On the My Download History tab, you can view and export a download history of documents downloaded from the Service Trust Portal within the last 18 months. The history includes the document title and download date, and the document status, such as whether it is live, has a newer version, or has been deleted. The full download history can be exported to a CSV file.

Localization support

The Service Trust Portal enables you to view the page content in different languages. To change the page language, simply click on the globe icon in the lower left corner of the page and select the language of your choice.

Give feedback

We can help with questions about the Service Trust Portal, or errors you experience when you use the portal. You can also contact us with questions and feedback about Service Trust Portal compliance reports and trust resources by using the Feedback link on the bottom of the STP pages.

Your feedback is important to us. Click on the Feedback button at the bottom of the page to send us comments about what you did or did not like, or suggestions you may have for improving our products or product features.

What kind of feedback do you have.