Azure compliance for Canadian companies
On Azure, most audit evidence comes from three places: Microsoft Entra ID for identity, Azure Policy for configuration, and the Activity Log for who changed what. Get those right and the rest follows.
To pass an audit on Azure you need production in its own subscription under a management group hierarchy, access through Microsoft Entra ID with MFA and Conditional Access, Azure Policy assigned at the management group so new resources inherit the rules, diagnostic settings sending the Activity Log and resource logs to a Log Analytics workspace, and encryption on every data store. Azure's defaults are reasonable. Its retention defaults are not long enough for an audit, which is the most common gap.
What Microsoft covers and what you cover
Microsoft publishes SOC 1, SOC 2 and SOC 3 reports, ISO 27001, 27017 and 27018 certificates and PCI DSS attestations for Azure, downloadable from the Service Trust Portal. Your auditor treats Microsoft as a subservice organization and relies on those reports for the data centres, hardware and platform internals.
Microsoft's shared responsibility model shifts with the service type. On virtual machines you own the operating system, patching and network rules. On App Service and Azure SQL, Microsoft patches the platform and you own configuration and access. Identity, data and endpoint devices are always yours. The shared responsibility page lays the three providers side by side.
Canadian regions on Azure
| Region | Location | Availability zones | Use |
|---|---|---|---|
| Canada Central | Toronto | Yes | Primary region, widest service availability |
| Canada East | Quebec City | No | Paired region for Canada Central, disaster recovery |
Canada East has no availability zones, so zone-redundant designs belong in Canada Central. Microsoft Entra ID and some Microsoft 365 services store data by tenant geography rather than by the region your resources sit in; check the data location section of the Microsoft documentation for each one. The Canadian regions guide covers the comparison with AWS and Google Cloud.
The controls auditors test on Azure
| Control | Azure implementation | Evidence the auditor accepts |
|---|---|---|
| Unique identities, MFA | Entra ID, Conditional Access requiring MFA for all users | Conditional Access policy export, sign-in log sample |
| Privileged access | Privileged Identity Management with time-bound activation | PIM role assignments, activation history |
| Access reviews | Entra ID access reviews on privileged roles and groups | Completed review with reviewer and date |
| Audit logging | Activity Log and resource logs to Log Analytics via diagnostic settings | Diagnostic setting configuration, workspace retention setting, query extract |
| Configuration baseline | Azure Policy initiatives at management group scope | Policy assignment, compliance state over time |
| Encryption at rest | Platform keys by default, customer-managed keys in Key Vault where required | Policy compliance results, Key Vault configuration |
| Encryption in transit | Minimum TLS version set on storage, App Service, SQL | Policy results for minimum TLS |
| Threat detection | Microsoft Defender for Cloud plans on in-scope resources | Enabled plans, alert routing, triaged sample |
| Backups | Azure Backup vaults with soft delete and immutability | Backup policy, job history, a dated restore test |
| Change management | Bicep or Terraform through a pipeline with approvals | PR history, pipeline service principal permissions |
The SOC 2 walk-through for Azure is on SOC 2 on Azure.
Retention is the usual gap
The Azure Activity Log is kept for 90 days on its own. Entra ID sign-in and audit logs are kept for 30 days with a P1 or P2 licence and 7 days without. A SOC 2 Type 2 window is often six or twelve months, and the auditor will sample from the start of it. Send both to a Log Analytics workspace or a storage account with retention set to cover the window plus a margin, from the day the window opens. The audit logging guide gives the settings for all three providers.
Native evidence tooling
Azure Policy evaluates every resource against assigned definitions and keeps compliance history. Defender for Cloud's regulatory compliance dashboard maps those results to standards including ISO 27001, SOC 2, PCI DSS and NIST SP 800-53, with the Microsoft cloud security benchmark as the default. The Azure Policy and Defender guide covers which initiatives to assign and which Defender plans produce evidence you need.
Landing zone
An Azure landing zone is a management group hierarchy with policy, identity, logging and networking set once and inherited by every subscription. Microsoft's reference architecture is more than a 30 person company needs. The Azure landing zone guide covers the minimum structure an auditor will accept.
Is Azure SOC 2 compliant?
Microsoft holds SOC 2 reports for Azure, available from the Service Trust Portal. Those cover Microsoft's infrastructure. Your auditor still tests your own identity, configuration, logging and change controls, and relies on the Microsoft report only for what Microsoft operates.
Do I need Defender for Cloud paid plans for SOC 2?
Not all of them. The free tier gives secure score and policy-based recommendations. Paid plans add threat detection per resource type. Turn on the plans for the resource types that hold customer data, such as servers, databases and storage, and leave the rest until there is a reason.
How long does Azure keep the Activity Log?
Ninety days by default. For an audit, route it to a Log Analytics workspace or storage account through a diagnostic setting at subscription or management group level, with retention covering your audit period plus a margin.
Can we use Canada East only?
You can, but it has no availability zones and fewer services. Most companies run production in Canada Central and use Canada East for backups and disaster recovery, which keeps both copies in Canada.
Get quotes for Azure compliance work
Landing zone, policy baseline, or SOC 2 readiness on Azure.
Get matched