Microsoft Entra ID (formerly Azure AD) · Trust Center
Azure Ad Trust Center
Trust center
Microsoft Entra ID (formerly Azure AD) maintains a public trust center documenting FedRAMP, NIST SP 800-53, HIPAA / HITECH, and SOX compliance.
AuthenticationAuthorizationIdentityOpenID ConnectSingle Sign-On
Certifications & Compliance
FedRAMPNIST SP 800-53HIPAA / HITECHSOX
Source
Trust Center
generated: '2026-09-06'
method: searched
source: >-
https://www.microsoft.com/en-us/trust-center (probed 200),
https://servicetrust.microsoft.com/ (probed 200),
https://learn.microsoft.com/en-us/entra/standards/standards-overview,
https://learn.microsoft.com/en-us/azure/compliance/
provider: Azure Active Directory (Microsoft Entra ID)
providerId: azure-ad
trust_center:
url: https://www.microsoft.com/en-us/trust-center
http_status: 200
probed: '2026-09-06'
audit_portal:
name: Microsoft Service Trust Portal
url: https://servicetrust.microsoft.com/
http_status: 200
probed: '2026-09-06'
note: >-
Where the actual audit reports (SOC 1/2/3, ISO certificates, FedRAMP
packages, penetration-test summaries) are downloaded. Access to the reports
requires sign-in with a Microsoft account; the portal itself is public.
compliance_catalog:
url: https://learn.microsoft.com/en-us/azure/compliance/offerings/
claim: >-
"There are 90 Azure compliance certifications ... Azure has 35 compliance
offerings for key industries" — quoted from
https://learn.microsoft.com/en-us/entra/standards/standards-overview
industries_named:
- Health
- Government
- Finance
- Education
- Manufacturing
- Media
certifications:
- name: FedRAMP
scope: US Federal Risk and Authorization Management Program
evidence: https://learn.microsoft.com/en-us/azure/compliance/offerings/offering-fedramp
- name: NIST SP 800-53
scope: US federal information systems control catalog
evidence: https://learn.microsoft.com/en-us/azure/compliance/offerings/offering-nist-800-53
- name: HIPAA / HITECH
scope: US healthcare
evidence: https://learn.microsoft.com/en-us/azure/compliance/offerings/offering-hipaa-us
- name: SOX
scope: Sarbanes-Oxley Act of 2002
evidence: https://learn.microsoft.com/en-us/compliance/regulatory/offering-sox
certifications_note: >-
Only the frameworks Microsoft's own Entra standards page names directly are
listed above with evidence URLs. Microsoft's wider catalogue (ISO/IEC 27001,
27017, 27018, 27701, SOC 1/2/3, PCI DSS, CSA STAR and the rest of the 90) is
published per-offering under
https://learn.microsoft.com/en-us/azure/compliance/offerings/ and is
downloadable from the Service Trust Portal; it is not restated here because it
was not read item by item during this pass.
shared_responsibility:
note: >-
Microsoft states plainly that compliance is shared: Azure certification is a
starting point, and the customer must still configure Microsoft Entra ID to
meet the identity standard they are held to. Entra publishes per-standard
configuration guidance (for example NIST authenticator assurance levels and
FedRAMP High) under https://learn.microsoft.com/en-us/entra/standards/.
privacy:
privacy_statement: https://www.microsoft.com/en-us/privacy/privacystatement
gdpr: https://learn.microsoft.com/en-us/compliance/regulatory/gdpr
data_residency: https://learn.microsoft.com/en-us/entra/identity/data-residency-and-customer-data
sovereign_clouds:
- name: Microsoft Azure Government (US Gov L4 / L5 DoD)
- name: Microsoft Azure operated by 21Vianet (China)
sovereign_clouds_note: >-
Relevant to agent surfaces: the Microsoft MCP Server for Enterprise is global
service only and is NOT available in US Gov L4, US Gov L5 (DOD) or 21Vianet —
see mcp/azure-ad-mcp.yml availability.
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for security posture
4 MCP tools reach this
find_securityBrowse and filter every security artifact in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
This security artifact
curl "https://apis.io/api/v1/security/azure-ad-trust-center"
All security posture
curl "https://apis.io/api/v1/security?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.