SC-900 - Microsoft Compliance Solutions (22% of the exam) - Section 4.1

Describe the Service Trust Portal and Microsoft privacy principles.

Describe the Service Trust Portal as the resource that provides audit reports, compliance documentation, and trust information about Microsoft cloud services. Recognise Microsoft's core privacy principles and how Microsoft Priva helps organisations manage personal data and privacy risks at scale.

Service Trust PortalMicrosoft privacy principlesMicrosoft Priva

Practice question for this objective

Free sampleMicrosoft Compliance Solutionseasy

A compliance analyst is preparing for an audit and wants to use the Service Trust Portal as the public face of Microsoft's trust and compliance information. Which TWO kinds of material does the Service Trust Portal make available to support this work? Select TWO.

  • AIndependent third-party audit reports covering Microsoft cloud services Correct
  • BCompliance documents and whitepapers describing how Microsoft protects customer data Correct
  • CDirect access to Microsoft datacentres so that a customer's own staff can run their own audits
  • DPer-tenant insider risk alerts raised in a customer's environment
  • EEditable improvement actions that raise the tenant compliance score
The Service Trust Portal publishes independent audit reports and Microsoft compliance documents so customers can evaluate cloud service trust and security. The Service Trust Portal is a documents library: it surfaces independent third-party audit reports and Microsoft-written compliance whitepapers, so those two are correct. It never grants hands-on access to Microsoft datacentres, and tenant operations such as insider risk alerts and compliance-score improvement actions live in Microsoft Purview, not the portal, so the rest are wrong.

Why A is correct: The Service Trust Portal publishes external audit reports so customers can review how Microsoft cloud services are independently assessed.

Why B is correct: It hosts Microsoft-authored compliance guides and whitepapers that explain the security and privacy controls behind the services.

Why C is wrong: Tempting because audits are the theme, but the portal supplies audit reports and documentation, never physical or hands-on access to Microsoft datacentres, which customers never receive.

Why D is wrong: Insider risk alerts come from Microsoft Purview Insider Risk Management inside a tenant, not from the public Service Trust Portal.

Why E is wrong: Improvement actions belong to Compliance Manager; the Service Trust Portal is a documents resource, so this conflates two distinct tools.

See more SC-900 practice questions, answers explained.

Exam traps in Microsoft Compliance Solutions

Answers that look right on this material and are not. Each one is a distractor from a different question in the SC-900 bank for this domain.

  • The Microsoft Priva portal, which publishes audit reports and compliance information for Microsoft cloud services.

    Why it is wrong: The Priva portal hosts privacy risk management capabilities for an organisation's own data, not the published audit reports and compliance whitepapers about Microsoft cloud services.

  • Microsoft Entra Conditional Access policies that are evaluated and applied at user sign-in.

    Why it is wrong: Conditional Access governs access to resources at sign-in; it does not classify content to find personal data the way Purview classifications and sensitive information types do.

  • The Service Trust Portal, which gives visibility into privacy risks and policies to identify and remediate them.

    Why it is wrong: The Service Trust Portal publishes audit reports and compliance whitepapers about Microsoft cloud services; it does not run privacy risk policies over an organisation's own data.

Examworthy is not affiliated with or endorsed by Microsoft. Original, blueprint-aligned practice material only.