Blog

Home / Blog / Compliance
Compliance

SOC 2 or ISO 27001 for your Microsoft tenant: where the evidence overlaps

EntraGUARD·2026-07-28·7 min

Sooner or later a customer asks for one. For a company running on Microsoft 365, much of the work is the same tenant configuration seen through two lenses. Knowing where the evidence overlaps saves auditing twice.

Sooner or later a customer asks for one, and you have to decide: SOC 2 or ISO 27001? For a company whose systems run on Microsoft 365 and Entra ID, a lot of the work is the same tenant configuration seen through two different lenses. Knowing where the evidence overlaps saves you from auditing twice.

Two frameworks, one tenant

SOC 2 is an attestation, reported by an auditor against the Trust Services Criteria, and it is the default request from U.S. customers. ISO/IEC 27001 is a certification of an Information Security Management System against an international standard, and it travels better internationally. They differ in form — a SOC 2 report versus an ISO certificate and Statement of Applicability — but on the technical control layer they ask many of the same questions of your identity platform.

Where the evidence overlaps

  • Access control — SOC 2 CC6 and ISO Annex A.5.15 / A.8.2 both want least privilege, provisioning and de-provisioning, and privileged access management. That is the same Entra ID census.
  • Authentication — MFA and credential management satisfy both.
  • Logging and monitoring — CC7 and A.8.15 / A.8.16 both want retained, reviewable logs.
  • Change and configuration — the drift you track between audits feeds both.
SOC 2ISO 27001
OutputAuditor's reportCertificate + SoA
Default audienceUS customersInternational
Identity control homeCC6 / CC7Annex A.5 / A.8
CadenceType II over a periodCert + surveillance audits

Do the tenant work once. Whichever you pursue first, audit the Microsoft tenant against a control set that carries both the SOC 2 criteria and the ISO Annex A clause on each control. Then the second framework is a mapping exercise, not a second assessment.

The part neither framework does for you

Both frameworks care that controls operate over time, not just on audit day. SOC 2 Type II literally samples a period; ISO surveillance audits recur. That is where a recurring tenant audit earns its place: it is the continuous evidence that the access reviews happened, the MFA stayed on, and the admin count did not creep. The framework is the lens; the tenant posture is what it looks at.

Related: SOC 2 in depth and NIS2 & ISO 27001.