Operational guidance, not legal advice. This page distills named public sources (regulator guidance and industry practice). It is not a legal determination, not a notification decision, and not a substitute for your counsel, insurer, or a retained DFIR firm. Verify applicability and current deadlines for your facts and jurisdiction.
Which Azure artifacts count as security evidence?
Updated
Microsoft Entra ID evidences identity and access, activity and diagnostic logs evidence what happened, Azure Policy evidences configuration standards, and Defender for Cloud aggregates control status against framework references. Microsoft's certifications cover the platform, not your configuration.
Azure evidence map, last verified 10 September 2026 against Microsoft Learn documentation for Microsoft Entra ID sign-in and audit logs, Azure Monitor and diagnostic settings, the Azure activity log, Microsoft Defender for Cloud and its regulatory-compliance dashboard, Azure Policy, Azure Key Vault, Microsoft Purview, and the Service Trust Portal, read alongside the CIS Microsoft Azure Foundations Benchmark, the AICPA Trust Services Criteria, and ISO/IEC 27001:2022 Annex A. Microsoft renames portal blades and repackages capabilities often; Microsoft Learn is the authority. This page is not legal advice, does not determine YOUR obligations, does not start a clock, and does not file with an auditor.
What this page is, and what it is not
Audience: a platform engineer, security engineer, or compliance owner running workloads on Azure who needs to know which Azure artifact answers which audit question, and where Azure stops answering.
This page is not legal advice. It does not determine YOUR obligations, does not decide which frameworks apply to your organisation, does not start a clock, and does not file anything with an auditor. An Azure service listed next to a control is a mapping, not a conclusion that the control operated. Last verified 10 September 2026.
The shared-responsibility split is the framing that matters most. Microsoft is responsible for the physical infrastructure, the host layer, and the managed-service platform, and publishes its own audit reports for that layer through the Service Trust Portal. You are responsible for identities, network configuration, encryption and key management choices, log collection and retention, and your data. A Microsoft SOC 2 or ISO/IEC 27001 certificate is evidence about Microsoft, not about your subscription.
- Azure log evidence has a collection step that AWS and GCP make less obvious: many resource logs are not retained anywhere until you create a diagnostic setting that routes them to a Log Analytics workspace, a storage account, or an event hub. No diagnostic setting means no evidence.
- Entra ID log retention depends on licensing. Sign-in and audit log retention windows in the portal differ by Entra ID plan, so route logs to a workspace or storage if your required retention is longer.
- Management-group and subscription scope matters. An artifact exported at one subscription is an incomplete population for a multi-subscription estate.
- Defender for Cloud's regulatory-compliance dashboard is a status view against Microsoft's mapping of a framework. It is not certification, not an attestation, and not an auditor's conclusion.
Control-to-Azure-service map
Read the first column as the control assertion, the second as the Azure artifact, the third as the portal path, and the fourth as the framework note. Last verified 10 September 2026 against Microsoft Learn. Not legal advice.
| Control assertion | Azure artifact | Where it lives (portal path) | Framework note |
|---|---|---|---|
| Control-plane actions are recorded and attributable | Azure activity log for the subscription, exported through a diagnostic setting so it survives the default retention window | Portal → Monitor → Activity log; export at Monitor → Activity log → Export activity logs. | AICPA TSC CC7.2; ISO/IEC 27001:2022 Annex A 8.15; NIST SP 800-53 Rev. 5 AU family. PCI DSS v4.0.1 Requirement 10 where in scope. |
| Resource-level security events are collected and kept | Diagnostic settings per resource or via Azure Policy at scale, routing resource logs to a Log Analytics workspace, storage account, or event hub, with the workspace retention setting | Portal → the resource → Monitoring → Diagnostic settings; retention at Log Analytics workspace → Usage and estimated costs → Data retention. | AICPA TSC CC7.2; Annex A 8.15. The diagnostic setting is itself the evidence that collection was configured for the period. |
| Only authorised identities hold access, at least privilege | Entra ID role assignments, Azure RBAC role assignments per scope, Privileged Identity Management eligibility and activation records, and group membership | Portal → Microsoft Entra ID → Roles and administrators; Subscription → Access control (IAM) → Role assignments; Entra ID → Privileged Identity Management. | AICPA TSC CC6.1–CC6.3; Annex A 5.15, 5.18 and 8.2; NIST SP 800-53 Rev. 5 AC family; PCI DSS v4.0.1 Requirements 7 and 8 where in scope. |
| Strong authentication is enforced, with conditional controls | Conditional Access policy definitions and their state, multi-factor registration report, and sign-in logs showing the applied policies | Portal → Microsoft Entra ID → Conditional Access → Policies; Entra ID → Monitoring → Sign-in logs; authentication methods activity reports. | AICPA TSC CC6.1; Annex A 5.17; PCI DSS v4.0.1 Requirement 8 where in scope. |
| Privileged access is time-bound and approved | Privileged Identity Management assignment settings, activation approval records, and access-review results for privileged roles | Portal → Microsoft Entra ID → Privileged Identity Management → Azure resources or Entra roles → Assignments and Activation history. | AICPA TSC CC6.1 and CC6.3; Annex A 8.2 privileged access rights. Privileged Identity Management and access reviews are documented as requiring specific Entra ID plans. |
| Access reviews happen and are recorded | Entra ID access-review campaign definitions, reviewer decisions, and the completion report per campaign | Portal → Microsoft Entra ID → Identity Governance → Access reviews. | AICPA TSC CC6.2–CC6.3; Annex A 5.18. Cadence is your choice unless a contract sets it — see the IAM page in this cluster. |
| Joiner, mover, and leaver changes are recorded | Entra ID audit logs for user creation, group membership change, and deletion, plus provisioning logs where an HR-driven or SCIM provisioning connector is used | Portal → Microsoft Entra ID → Monitoring → Audit logs and Provisioning logs. | AICPA TSC CC6.2; Annex A 5.18. |
| Configuration standards are defined and enforced | Azure Policy definitions and initiatives assigned at management group or subscription scope, plus the compliance state history per assignment | Portal → Policy → Definitions and Assignments; state at Policy → Compliance. | AICPA TSC CC7.1 and CC8.1; Annex A 8.9 configuration management; NIST SP 800-53 Rev. 5 CM family. |
| Configuration is measured against a named framework baseline | Defender for Cloud regulatory-compliance dashboard with the applied compliance standard, plus the per-control assessment detail and its export | Portal → Microsoft Defender for Cloud → Regulatory compliance; standards managed under Environment settings → Security policy. | Microsoft publishes standards aligned to CIS, PCI DSS, ISO/IEC 27001 and other references. The alignment is Microsoft's mapping — not certification, not an attestation, and not an auditor's conclusion. Some standards require a Defender for Cloud paid plan. |
| Threats are detected and triaged | Defender for Cloud security alerts with disposition, Defender plan enablement per subscription and resource type, and Microsoft Sentinel incidents where used | Portal → Microsoft Defender for Cloud → Security alerts; plan state at Environment settings → Defender plans. | AICPA TSC CC7.2–CC7.3; Annex A 8.16; NIST SP 800-53 Rev. 5 SI-4. |
| Secrets and keys are protected and their use is recorded | Key Vault access model (RBAC or access policies), purge-protection and soft-delete settings, key rotation policy, and Key Vault diagnostic logs of secret and key access | Portal → the key vault → Settings → Access configuration and Properties; logs via the vault's Diagnostic settings. | AICPA TSC CC6.7; Annex A 8.24 use of cryptography; PCI DSS v4.0.1 Requirements 3 and 4 where in scope. |
| Data is classified and sensitive data is located | Microsoft Purview data map scan results, sensitivity labels and their policies, and the classification report | Purview portal → Data map → Scans; Information protection → Labels and label policies. | AICPA TSC C1.1 confidentiality; Annex A 5.12 classification of information. Classification is a decision Purview records, not one it makes for you. |
| Backups exist and restoration has been demonstrated | Azure Backup vault policies, job history, immutable-vault or soft-delete settings, and a recorded restore test with date and outcome | Portal → Backup center → Backup instances and Jobs; vault settings under the Recovery Services vault → Properties. | AICPA TSC A1.2–A1.3; Annex A 8.13 and 5.29–5.30. The restore record is the evidence; a policy alone is not. |
The shared-responsibility boundary, stated plainly
Microsoft documents the split by service model. What changes with each model is how much you must evidence yourself. Last verified 10 September 2026. Not legal advice.
| Layer | Who evidences it | What you can and cannot rely on |
|---|---|---|
| Datacentres, physical network, host infrastructure, managed-service platform | Microsoft, through its own SOC, ISO/IEC 27001, and other attestations, available through the Service Trust Portal. | You may inherit these controls and cite the report. Record the customer responsibilities the report lists — those are yours to evidence. |
| Identity, Conditional Access, role assignments, privileged access | You. Entra ID provides the mechanism; the policies and reviews are your configuration. | A Microsoft certificate says nothing about whether a global administrator without multi-factor authentication exists in your tenant. |
| Log collection and retention | You, and more actively than on other platforms. Resource logs need a diagnostic setting before they are retained anywhere. | Absence of a diagnostic setting is absence of evidence, regardless of what the platform is capable of. |
| Operating system and application patching | Split by service model: Microsoft patches platform-as-a-service layers; you patch what runs in your virtual machines and containers. | Write the split down per service you use. A generic answer fails when an auditor asks who patched a specific host. |
| Your data, its classification, and who may access it | You, entirely. | No Microsoft attestation and no compliance-dashboard score evidences a classification decision or a customer commitment. |
Legal requirement, guidance, best practice, or our recommendation
A compliance dashboard score is not a legal position. Label the reason each control exists. Last verified 10 September 2026. Not legal advice.
| Statement | Which kind of authority | What it does not mean |
|---|---|---|
| PCI DSS v4.0.1 Requirements 3, 4, 7, 8 and 10 on encryption, access, and logging. | Legal requirement in the contractual sense, for entities in scope through card-brand and acquirer agreements. | Does not apply where no cardholder data is in scope, and does not name any Azure service. |
| NIST SP 800-53 Rev. 5 AC, AU, CM, and SI families. | Regulatory and standards guidance, binding on US federal systems through separate authority. | Does not bind a commercial company that has not contracted to it. |
| CIS Microsoft Azure Foundations Benchmark recommendations. | Industry best practice — a community consensus benchmark from the Center for Internet Security. | Not a law and not a certification. Recorded deviations are acceptable; unrecorded ones are the finding. |
| AICPA Trust Services Criteria and ISO/IEC 27001:2022 Annex A. | Attestation criteria and certification requirements, applying because you sought a report or certification, or a contract requires one. | Neither names an Azure service. The mapping above is yours to own. |
| Apply diagnostic settings through Azure Policy at management-group scope so new resources are collected by default, and enable Defender for Cloud with one named standard. | Industry best practice, and widely expected of a multi-subscription estate. | Not written as a requirement in any framework named here, and not a substitute for working the findings. |
| Export the Conditional Access policy set, privileged-role assignment list, and access-review completion reports on a fixed cadence, each with a named reviewer and date. | ShipReady Metrics recommendation. | Does not make the control effective by itself, and is not required by any framework named here. |
Checklist
A question list for the Azure side of your evidence set. Not a determination that any framework applies to you. Last verified 10 September 2026. Not legal advice.
- Do we have the complete list of tenants, management groups, and subscriptions in audit scope?
- Is the activity log exported beyond its default window, and is that export outside the reach of the teams it describes?
- Does every in-scope resource type have a diagnostic setting, applied by policy rather than by hand?
- Does our Entra ID plan retain sign-in and audit logs for as long as we claim, and if not, are they routed to a workspace or storage?
- Can we list every account holding a privileged directory or subscription role, and show that each was approved?
- Are Conditional Access policies in report-only mode that we describe as enforced?
- Have access reviews for privileged roles completed in the period, with reviewer decisions recorded?
- Which compliance standard is applied in Defender for Cloud, and is the current gap list dispositioned with owners?
- Do key vaults have soft-delete and purge protection, and are key and secret access events collected?
- Has a restore actually been performed and recorded in the period?
What to do now
Ordered so the most-requested artifacts become producible first. None of these steps is a legal determination, and none files anything with an auditor.
- Fix the scope list: tenants, management groups, subscriptions. Population failures cause more Azure evidence findings than misconfiguration does.
- Deploy diagnostic settings through Azure Policy at management-group scope, so log collection follows new resources automatically instead of depending on a person remembering.
- Export the activity log and Entra ID sign-in and audit logs into a retained destination that matches your stated retention, and record the destination and its retention.
- Enable Defender for Cloud with one named standard, then work the failing assessments with owners. Record explicitly that the dashboard is an internal indicator, not certification.
- Put privileged directory and subscription roles behind Privileged Identity Management with approval and expiry where your plan allows, and keep the activation history as evidence.
- Run an access review for privileged roles in this period and keep the completion report — it is the single artifact most often missing on Azure estates.
- Turn on soft-delete and purge protection for every key vault, and collect vault diagnostic logs.
- Re-verify Microsoft Learn for portal paths and plan gating annually, and record the date. Ours says 10 September 2026.
Where this shows up in ShipReady Metrics
Only shipped behaviour is described here. This product does not configure your Azure tenant or subscriptions, does not create diagnostic settings, does not produce an auditor's opinion, and does not file anything with an auditor.
If you already have a session: signed-in app → Compliance holds evidence collection, which records control-mapped artifacts for starter control subsets, and evidence review, where a named human accepting a manual row renders it met and rejecting it renders it a gap, with a timestamp. Azure configuration artifacts are typically manual rows reviewed that way. That overlay is a timestamped compliance artifact — not a forensic chain of custody, not a downloadable evidence binder, and not an auditor's opinion.
The obligation map lists frameworks your organisation marked in-scope. That mark is a scoping input you control, not a legal opinion that a framework applies. Readiness is an internal indicator, not certification.
Vulnerability management in this product covers application and dependency findings from connected sources, ranked with CISA KEV membership, EPSS, and CVSS, with cross-source deduplication and blast-radius search over captured dependencies. It is not an Azure configuration assessor.
Primary sources (last verified 10 September 2026)
Microsoft Learn is the authority for every service behaviour and portal path above; framework references are labelled by the kind of authority they carry.
Microsoft Learn documentation for the Azure activity log, Azure Monitor diagnostic settings and Log Analytics retention, Microsoft Entra ID sign-in and audit logs, Conditional Access, Privileged Identity Management, access reviews, Azure Policy, Microsoft Defender for Cloud and its regulatory-compliance dashboard, Azure Key Vault, Microsoft Purview, Azure Backup, and the Microsoft shared-responsibility guidance, plus the Service Trust Portal for Microsoft's own attestations. The CIS Microsoft Azure Foundations Benchmark is community best practice. AICPA Trust Services Criteria are attestation criteria. ISO/IEC 27001:2022 Annex A is a certification requirement set. NIST SP 800-53 Rev. 5 is guidance for commercial organisations. PCI DSS v4.0.1 binds entities in scope through contract. Not a complete list, and not legal advice.
The AWS and GCP pages in this cluster are the equivalent maps for those platforms. The IAM page covers the access lifecycle, and the log-retention page covers how long to keep what these services produce.
Frequently asked questions
Is this legal advice?
No. It is an operational mapping of Azure artifacts to control assertions, with framework references labelled by the kind of authority they carry. Whether SOC 2, ISO/IEC 27001, PCI DSS, or any statute applies to your organisation is a legal and commercial question for counsel and your contracts. This page does not determine YOUR obligations and does not file anything with an auditor.
Does a high Defender for Cloud regulatory-compliance score mean we are compliant?
No. The dashboard reports your resources against Microsoft's mapping of a framework to technical assessments. It does not test the many controls that are not technical configuration — training, vendor management, change approval, policy governance — and no auditor has looked at it. It is a good gap-finding tool and an internal indicator, not certification and not an attestation.
Why are our Azure resource logs missing for the audit period?
Almost always because no diagnostic setting existed for those resources during the period. Azure resource logs are not retained anywhere until you route them to a Log Analytics workspace, a storage account, or an event hub. Deploy diagnostic settings through Azure Policy at management-group scope so collection follows new resources, and treat the policy assignment itself as evidence that collection was configured.
How long does Entra ID keep sign-in and audit logs?
The portal retention window depends on your Entra ID plan, and Microsoft documents the current periods per plan. Where your required retention is longer than the plan retains, route the logs to a Log Analytics workspace or storage account with your own retention setting, and record that destination in your evidence index. Read Microsoft Learn for the current numbers rather than trusting a figure quoted elsewhere.
Can we rely on Microsoft's ISO/IEC 27001 certificate?
For the platform layer Microsoft operates, yes — that is what inheritance means, and the certificate and reports are available through the Service Trust Portal. For your tenant and subscriptions, no. Microsoft's certificate says nothing about your Conditional Access policies, your role assignments, or your log retention. Record which controls you inherit and the customer responsibilities that inheritance depends on.
Published by ShipReady Metrics, an evidence-based technology and compliance intelligence platform. This guide is educational and vendor-neutral.