CloudCompliance

Azure compliance for Canadian companies

On Azure, most audit evidence comes from three places: Microsoft Entra ID for identity, Azure Policy for configuration, and the Activity Log for who changed what. Get those right and the rest follows.

Last reviewed 2026-09-30Written by Jacob Masse, TrazTech Inc.

To pass an audit on Azure you need production in its own subscription under a management group hierarchy, access through Microsoft Entra ID with MFA and Conditional Access, Azure Policy assigned at the management group so new resources inherit the rules, diagnostic settings sending the Activity Log and resource logs to a Log Analytics workspace, and encryption on every data store. Azure's defaults are reasonable. Its retention defaults are not long enough for an audit, which is the most common gap.

What Microsoft covers and what you cover

Microsoft publishes SOC 1, SOC 2 and SOC 3 reports, ISO 27001, 27017 and 27018 certificates and PCI DSS attestations for Azure, downloadable from the Service Trust Portal. Your auditor treats Microsoft as a subservice organization and relies on those reports for the data centres, hardware and platform internals.

Microsoft's shared responsibility model shifts with the service type. On virtual machines you own the operating system, patching and network rules. On App Service and Azure SQL, Microsoft patches the platform and you own configuration and access. Identity, data and endpoint devices are always yours. The shared responsibility page lays the three providers side by side.

Canadian regions on Azure

Azure regions in Canada
RegionLocationAvailability zonesUse
Canada CentralTorontoYesPrimary region, widest service availability
Canada EastQuebec CityNoPaired region for Canada Central, disaster recovery

Canada East has no availability zones, so zone-redundant designs belong in Canada Central. Microsoft Entra ID and some Microsoft 365 services store data by tenant geography rather than by the region your resources sit in; check the data location section of the Microsoft documentation for each one. The Canadian regions guide covers the comparison with AWS and Google Cloud.

The controls auditors test on Azure

Common SOC 2 and ISO 27001 controls on Azure, and their evidence
ControlAzure implementationEvidence the auditor accepts
Unique identities, MFAEntra ID, Conditional Access requiring MFA for all usersConditional Access policy export, sign-in log sample
Privileged accessPrivileged Identity Management with time-bound activationPIM role assignments, activation history
Access reviewsEntra ID access reviews on privileged roles and groupsCompleted review with reviewer and date
Audit loggingActivity Log and resource logs to Log Analytics via diagnostic settingsDiagnostic setting configuration, workspace retention setting, query extract
Configuration baselineAzure Policy initiatives at management group scopePolicy assignment, compliance state over time
Encryption at restPlatform keys by default, customer-managed keys in Key Vault where requiredPolicy compliance results, Key Vault configuration
Encryption in transitMinimum TLS version set on storage, App Service, SQLPolicy results for minimum TLS
Threat detectionMicrosoft Defender for Cloud plans on in-scope resourcesEnabled plans, alert routing, triaged sample
BackupsAzure Backup vaults with soft delete and immutabilityBackup policy, job history, a dated restore test
Change managementBicep or Terraform through a pipeline with approvalsPR history, pipeline service principal permissions

The SOC 2 walk-through for Azure is on SOC 2 on Azure.

Retention is the usual gap

The Azure Activity Log is kept for 90 days on its own. Entra ID sign-in and audit logs are kept for 30 days with a P1 or P2 licence and 7 days without. A SOC 2 Type 2 window is often six or twelve months, and the auditor will sample from the start of it. Send both to a Log Analytics workspace or a storage account with retention set to cover the window plus a margin, from the day the window opens. The audit logging guide gives the settings for all three providers.

Native evidence tooling

Azure Policy evaluates every resource against assigned definitions and keeps compliance history. Defender for Cloud's regulatory compliance dashboard maps those results to standards including ISO 27001, SOC 2, PCI DSS and NIST SP 800-53, with the Microsoft cloud security benchmark as the default. The Azure Policy and Defender guide covers which initiatives to assign and which Defender plans produce evidence you need.

Landing zone

An Azure landing zone is a management group hierarchy with policy, identity, logging and networking set once and inherited by every subscription. Microsoft's reference architecture is more than a 30 person company needs. The Azure landing zone guide covers the minimum structure an auditor will accept.

Is Azure SOC 2 compliant?

Microsoft holds SOC 2 reports for Azure, available from the Service Trust Portal. Those cover Microsoft's infrastructure. Your auditor still tests your own identity, configuration, logging and change controls, and relies on the Microsoft report only for what Microsoft operates.

Do I need Defender for Cloud paid plans for SOC 2?

Not all of them. The free tier gives secure score and policy-based recommendations. Paid plans add threat detection per resource type. Turn on the plans for the resource types that hold customer data, such as servers, databases and storage, and leave the rest until there is a reason.

How long does Azure keep the Activity Log?

Ninety days by default. For an audit, route it to a Log Analytics workspace or storage account through a diagnostic setting at subscription or management group level, with retention covering your audit period plus a margin.

Can we use Canada East only?

You can, but it has no availability zones and fewer services. Most companies run production in Canada Central and use Canada East for backups and disaster recovery, which keeps both copies in Canada.

Get quotes for Azure compliance work

Landing zone, policy baseline, or SOC 2 readiness on Azure.

Get matched