SOC 2 or ISO 27001 for your Microsoft tenant: where the evidence overlaps
Sooner or later a customer asks for one. For a company running on Microsoft 365, much of the work is the same tenant configuration seen through two lenses. Knowing where the evidence overlaps saves auditing twice.
Sooner or later a customer asks for one, and you have to decide: SOC 2 or ISO 27001? For a company whose systems run on Microsoft 365 and Entra ID, a lot of the work is the same tenant configuration seen through two different lenses. Knowing where the evidence overlaps saves you from auditing twice.
Two frameworks, one tenant
SOC 2 is an attestation, reported by an auditor against the Trust Services Criteria, and it is the default request from U.S. customers. ISO/IEC 27001 is a certification of an Information Security Management System against an international standard, and it travels better internationally. They differ in form — a SOC 2 report versus an ISO certificate and Statement of Applicability — but on the technical control layer they ask many of the same questions of your identity platform.
Where the evidence overlaps
- Access control — SOC 2 CC6 and ISO Annex A.5.15 / A.8.2 both want least privilege, provisioning and de-provisioning, and privileged access management. That is the same Entra ID census.
- Authentication — MFA and credential management satisfy both.
- Logging and monitoring — CC7 and A.8.15 / A.8.16 both want retained, reviewable logs.
- Change and configuration — the drift you track between audits feeds both.
| SOC 2 | ISO 27001 | |
|---|---|---|
| Output | Auditor's report | Certificate + SoA |
| Default audience | US customers | International |
| Identity control home | CC6 / CC7 | Annex A.5 / A.8 |
| Cadence | Type II over a period | Cert + surveillance audits |
Do the tenant work once. Whichever you pursue first, audit the Microsoft tenant against a control set that carries both the SOC 2 criteria and the ISO Annex A clause on each control. Then the second framework is a mapping exercise, not a second assessment.
The part neither framework does for you
Both frameworks care that controls operate over time, not just on audit day. SOC 2 Type II literally samples a period; ISO surveillance audits recur. That is where a recurring tenant audit earns its place: it is the continuous evidence that the access reviews happened, the MFA stayed on, and the admin count did not creep. The framework is the lens; the tenant posture is what it looks at.
Related: SOC 2 in depth and NIS2 & ISO 27001.