13.1 Data Residency and Regulatory Compliance
Key Takeaways
- Data residency is the geographic location where Microsoft 365 customer data is stored at rest — not the billing address and not a promise that every workload lives in the sign-up country
- The tenant Default Geography comes from the country/region chosen when the Microsoft Entra ID tenant is created and cannot be changed later
- Microsoft provisions each service from that Default Geography plus the Geographies the service actually deploys to; check the Data Location Card rather than assuming every workload matches the sign-up country
- Durable commitments on data location come from Product Terms, the EU Data Boundary, Advanced Data Residency, and Multi-Geo — Multi-Geo is one tenant with user-level satellite locations; ADR commits eligible local-region tenants to a broader in-scope service list
- Buying Microsoft 365 does not make an organization GDPR-compliant. For Customer Data in the Online Services the customer is typically the controller and Microsoft is the processor; the Service Trust Portal publishes Microsoft’s SOC, ISO, and similar attestations, but the customer still configures the tenant
Quick Answer: Data residency is the geographic location where customer data is stored at rest. Microsoft chooses that location from two facts: the tenant Default Geography (the country/region you pick when the Microsoft Entra ID tenant is created) and which Geographies a given Microsoft 365 service actually deploys to. You see the live picture on the Data Location Card in the Microsoft 365 admin center. Stronger Durable Commitments on Data Location come from Privacy and Security Product Terms, the EU Data Boundary, Advanced Data Residency (ADR), and Multi-Geo. Buying Microsoft 365 does not automatically make you GDPR-compliant. For Customer Data in the Online Services, the customer is typically the controller and Microsoft is the processor.
The April 30, 2025 MS-900 outline asks you to describe how Microsoft supports data residency to ensure regulatory compliance. This is a vocabulary and responsibility skill. You will not be asked to pick a datacenter city for a mailbox move or recite Microsoft’s full Local Region Geography catalog. You will be asked what residency means, where the Default Geography comes from, why some workloads may not sit in that same country, which official programs add stronger commitments, where Microsoft publishes audit reports, and why a subscription is not a regulation certificate.
MS-900 retired on March 31, 2026. The last official skills outline is still the April 30, 2025 list. Data residency sits in the Describe security, compliance, privacy, and trust domain (25–30%). Keep this section at fundamentals depth. The next section covers Microsoft Priva. This section is not legal advice — it teaches Microsoft’s published shared-responsibility model so you can pick the right exam sentence.
What data residency is
Official Learn (Microsoft 365 data residency overview) starts with a simple picture. Microsoft 365 cloud services run on data centers around the world and serve customers around the world. Customer data might be stored in multiple data centers. Data residency refers to the geographic location where customer data is stored at rest. That sentence is the scoring key. Residency is about where mailboxes, SharePoint site content, OneDrive files, and Teams data live when they are sitting still. It is not the country printed on a purchase order, and it is not the same question as “which network path did this one API call take.”
Microsoft is explicit about why the topic exists. Government, public sector, education, and regulated commercial customers often must follow laws, regulations, or industry standards that explicitly govern the location of data storage. The General Data Protection Regulation (GDPR) is the usual classroom example of a privacy regulation that raises location and processing questions. It is not the only regulation, and passing MS-900 is not the same as completing a GDPR program.
Microsoft decides where to persistently store customer data based on two official factors:
- The Default Geography of the tenant
- Available Geographies for a given service
Default Geography — chosen at sign-up, then locked
When a customer creates a new Microsoft Entra ID tenant (the directory behind every Microsoft 365 tenant; formerly Azure Active Directory), the customer enters a country/region during creation. Official Learn: that country/region defines the Default Geography for the tenant. Tenants can be created through Entra ID forms, Microsoft 365 trials, and other sign-up paths. Once a tenant is created, the Default Geography cannot be changed.
That lock is an exam favorite. A Global Administrator cannot later “move the tenant country” by editing the organization display name. If the business later needs some users’ content at rest in additional countries, or a stronger written commitment that in-scope data stays in a local region, Microsoft documents add-on programs — Multi-Geo and Advanced Data Residency — not a Default Geography rewrite.
All Microsoft 365 services use the Default Geography when they decide where specified tenant data will be provisioned and stored. Official Learn splits the practical result in two:
- Microsoft 365 Core Services — Exchange Online, SharePoint and OneDrive, Microsoft Teams, and Microsoft 365 Copilot and Copilot Chat — are widely deployed across Geographies.
- Other services choose where to deploy based on customer volume, regional affiliations, and software architecture. When a customer first uses a service in that second category, provisioning logic uses the Default Geography plus the service’s supported Geographies.
Over time a service may add Geographies for new customers. Official Learn is careful: that does not necessarily move existing customer data to the new Geography. So the exam trap is: “we signed up selecting France, therefore every Microsoft 365 workload stores every byte in France.” False. Some workloads may store data in other regions because the service is not deployed in every local geography. Microsoft publishes service-by-service data maps. You do not memorize an unofficial city list for MS-900. You name the rule, then you look the service up.
How you see where data actually is
Microsoft documents the Data Location Card in the Microsoft 365 admin center: Admin > Settings > Org settings > Organization profile > Data location. A Global Tenant Admin can see the Primary Provisioned Geography for Exchange Online, SharePoint, OneDrive, Microsoft Teams, Microsoft 365 Copilot, the built-in security features for all cloud mailboxes (formerly Exchange Online Protection), and Viva Connections. Additional service maps live on the official Learn page Where your Microsoft 365 customer data is stored. Trust Center pages cover services that are not on that Microsoft 365 list.
Two official vocabulary words sit next to the card:
| Term | What it means on the exam |
|---|---|
| Current Geography | Where core and expanded-service data is stored now |
| Committed Geography | Where Microsoft will store in-scope customer data at rest under the Durable Commitments that apply to the tenant |
| Primary Provisioned Geography | The Geography a service picked by combining Default Geography with that service’s provisioning map |
| Preferred Data Location (PDL) | Multi-Geo only: the admin-set property that says where a user or shared resource’s in-scope data should sit at rest |
During migration, license-validity changes, or while a Local Region Geography is still coming online, Current and Committed can differ. That is why Microsoft tells admins to read the card instead of assuming the sign-up country is the whole story.
Microsoft organizes locations conceptually as Macro Region Geographies (the Data Location Card labels examples such as Europe, Asia Pacific, Americas, and European Union/EFTA) and Local Region Geographies (individual countries or regions where Microsoft offers more local commitments). Do not memorize a country catalog. Microsoft publishes the current lists and updates them when a new local region launches. For MS-900, know that the lists exist, that eligibility for Advanced Data Residency starts from a Default Geography that is a published Local Region Geography, and that the card plus official Learn maps are the source of truth.
Durable commitments — four official methods
Official Learn lists four Durable Commitments on Data Location — documented methods that keep a tenant’s service data location from drifting without a program behind it:
- Privacy and Security Product Terms — contractual residency language in Microsoft’s product terms
- European Union Data Boundary (EUDB) — Microsoft’s Trust Center commitment to help EU and EFTA customers store and process customer data in the EU/EFTA region and reduce cloud data flows out of the EU
- Advanced Data Residency (ADR) — a licensed add-on that expands which services and Customer Data are covered and commits in-scope data at rest to an eligible Local Region Geography
- Microsoft 365 Multi-Geo Capabilities — a licensed add-on that lets one tenant store customer data at rest in more than one Geography
Product Terms are the baseline contractual story every customer already has. EUDB is the regional European program. ADR and Multi-Geo are add-ons for customers who need more than default provisioning. MS-900 wants the names and the job of each, not a quote from a volume-licensing exhibit.
Multi-Geo versus Advanced Data Residency
Microsoft 365 Multi-Geo Capabilities let enterprise customers expand a single existing tenant into multiple Geographies. Official intent: satisfy residency in more than one place while keeping single-tenant administration and collaboration. In a Multi-Geo tenant there is a Primary Provisioned Geography (where the subscription was originally provisioned) plus one or more Satellite Geography locations. A Global Tenant Admin sets a Preferred Data Location (PDL) so a user’s or shared resource’s in-scope data is stored at rest in the chosen Geography. Multi-Geo is documented for the Microsoft 365 Core Services — Exchange Online, SharePoint/OneDrive, Teams, and Microsoft 365 Copilot and Copilot Chat — and can also apply to shared resources such as SharePoint sites, Microsoft 365 Groups, shared mailboxes, and Teams teams.
Licensing facts that stay at fundamentals level: Multi-Geo is a user-level add-on for each user you host in a satellite Geography. Enterprise Agreement and Cloud Solution Provider purchases have a published minimum coverage (Microsoft currently documents a quantity at least 5 percent of eligible users). Small Business products do not currently qualify, even when they contain related plan names. Shared resources do not need their own Multi-Geo SKU once enough user licenses exist. Official Learn also notes that customers who have purchased or used Multi-Geo are not in scope for the EU Data Boundary, even if the tenant country is in the EU or EFTA — do not treat Multi-Geo and EUDB as the same switch.
Advanced Data Residency is a different add-on. Official purpose: eligible customers get expanded coverage of Microsoft 365 services and Customer Data, committed residency for local country/region datacenter regions, and prioritized tenant migration. Eligibility starts with a Tenant Default Geography that is one of the published Local Region Geographies, plus qualifying Microsoft 365 / Office 365 (or related) licenses. In-scope ADR services officially include the core workloads plus expanded services such as Microsoft 365 web apps, Defender for Office P1 / built-in mailbox security, Viva Connections, and selected Microsoft Purview services (as of Microsoft’s February 2026 list: Audit Standard and Premium, Data Lifecycle Management, DLP, Information Barriers, and Information Protection). Additional Purview services are not currently supported under that ADR list — do not invent coverage.
Commercial tenants must cover 100 percent of eligible paid seats — purchased seats, not only assigned seats — to establish and keep the durable commitment. There is no separate minimum seat count that qualifies on its own. If in-scope data is not already in the Local Region Geography, a Global Admin opts in to migration on the Data Location Card; Microsoft treats the move as a back-end operation and documents a reasonable-effort target measured in months, not an instant failover. Multi-Geo seats count toward ADR’s 100 percent coverage so a customer is not double-charged for the same seat.
| Program | Exam one-liner | Typical “pick this” stem |
|---|---|---|
| Default Geography + Product Terms | Sign-up country plus the contract’s baseline residency language | “Where does Microsoft start from when it provisions the tenant?” |
| EU Data Boundary | EU/EFTA store-and-process commitment for in-scope cloud data | “We need customer data handled inside the EU/EFTA boundary.” |
| Multi-Geo | One tenant, many user-level at-rest locations via PDL | “German mailboxes in Germany, U.S. mailboxes in the United States, one tenant.” |
| Advanced Data Residency | Eligible local-region tenant, broader in-scope service list, migration into that local region | “Keep this country’s in-scope Microsoft 365 data at rest locally, including more than just Exchange.” |
Neither add-on changes the locked Default Geography. Neither is “buy E5 and residency is automatic.”
Privacy regulations, processor versus controller
GDPR is the example regulation Microsoft uses in Trust Center and Learn material. Official terminology you should be able to paraphrase:
- Controller — determines the purposes and means of processing personal data
- Processor — processes personal data on behalf of the controller
- Personal data / data subject — information relating to an identified or identifiable natural person
- Customer Data — data produced and stored in the day-to-day operations of the business
- Data Subject Request (DSR) — a formal request by a person that the controller access, change, restrict, export, or delete their personal data
Official Learn: as a data processor, Microsoft processes personal data on behalf of the data controller (the customer). Microsoft processes Customer Data to provide the Online Services according to the customer’s documented instructions in the Product Terms and the Microsoft Products and Services Data Protection Addendum (DPA). Data controllers assess privacy risk and decide appropriate uses. Microsoft provides information and tools. Microsoft must implement technical and organizational measures that help the controller respond to data-subject rights.
That split is the exam point. In typical Microsoft 365 use, the customer organization is the controller for the personal data it puts in Exchange, SharePoint, Teams, and OneDrive. Microsoft is the processor for that Customer Data. Microsoft is not “the GDPR department” for your company. GDPR also gives people rights that the controller must answer in time — access, correction, erasure, restriction, portability. Microsoft’s job is to offer capabilities (today’s documented DSR search path is Microsoft Purview eDiscovery, covered with Priva in the next section) and contractual processor terms. Your job as the customer is still the compliance program.
Buying Microsoft 365 does not automatically make you GDPR-compliant. Say that sentence the way Microsoft says the parallel HIPAA sentence. Official HIPAA guidance: Microsoft offers a Business Associate Agreement (BAA) for in-scope services to covered entities and business associates, and using Microsoft services does not by itself achieve HIPAA compliance. Your organization still needs an adequate program and has to use the services in a way that matches the law. There is no HHS-approved “HIPAA certified” stamp for a cloud business associate. Treat GDPR the same way on MS-900: tools + contract + attestations ≠ “we are done.”
Service Trust Portal and compliance offerings
The Microsoft Service Trust Portal (servicetrust.microsoft.com, also aka.ms/STP) is Microsoft’s public site for audit reports and other compliance-related information about Microsoft cloud services. Authenticated customers with a Microsoft 365, Dynamics 365, or Azure organization account can download independent auditor reports and Microsoft-authored whitepapers after accepting the compliance-materials NDA where required. The portal groups certifications, regulations, and standards that commonly appear on fundamentals exams: ISO/IEC (including ISO 27001), System and Organization Controls (SOC) 1, 2, and 3 reports, GDPR documentation, FedRAMP, PCI DSS, and others. Separate libraries cover privacy and data protection papers, business continuity, and third-party penetration-test attestations.
Microsoft also publishes a compliance offerings catalog — descriptions of how Microsoft’s cloud is independently assessed against national, regional, and industry frameworks. SOC reports speak to operational controls. ISO 27001 speaks to an information security management system. A HIPAA BAA is a contract for protected health information, not a government certification of your hospital.
The customer still configures the tenant. Publishing an ISO report does not turn on your retention labels, DLP policies, Multi-Geo PDLs, or Priva policies. Microsoft Purview Compliance Manager (previous chapter) helps you track improvement actions against templates. The Service Trust Portal is where you collect Microsoft’s evidence. Your auditors still have to apply that evidence to your processing.
Realistic exam-style scenarios
Signed up in one country, one service lives elsewhere. A tenant’s Default Geography is Australia. Exchange shows Australia on the Data Location Card, but a smaller workload is provisioned in a Macro Region Geography because that service is not locally deployed. That is expected. Use the official service maps.
One company, employees in two countries. Legal wants German users’ mailboxes at rest in Germany and U.S. users’ mailboxes in the United States, with one tenant and one address book. That is Multi-Geo and Preferred Data Location, not a second tenant and not “change Default Geography.”
Eligible local-region customer wants a broader written commitment. The Default Geography is a published Local Region Geography and leadership wants more services covered and a migration into that local region. That is Advanced Data Residency after they meet the 100 percent coverage rule.
“We bought E3, we are GDPR done.” False. Microsoft is typically the processor; the customer is the controller. The customer still answers DSRs, configures protection, and documents its own processing.
Auditor asks for SOC 2. Point them at the Service Trust Portal, not the Defender incident queue and not Windows Update.
Exam traps
- Residency is at-rest location, not the billing address and not “data never moves on the wire.”
- Default Geography is chosen at tenant creation and cannot be changed.
- Not every Microsoft 365 service stores data in the Default Geography.
- Multi-Geo and ADR are different add-ons. Product Terms and EUDB are the other durable-commitment methods.
- Do not invent unofficial country lists. Use Learn maps and the Data Location Card.
- Buying Microsoft 365 is not automatic GDPR or HIPAA compliance.
- Microsoft’s SOC/ISO reports attest Microsoft’s services. They do not certify your tenant configuration.
- This is not legal advice and not an SC-900 control-mapping lab.
Official sources
- Overview and definitions — Microsoft 365 data residency — residency at rest; Default Geography; Current vs Committed; four durable commitments
- Where your Microsoft 365 customer data is stored — official service maps; ADR-eligible versus other services
- Microsoft 365 Multi-Geo — one tenant, satellite Geographies, Preferred Data Location
- Advanced Data Residency in Microsoft 365 — eligibility, 100 percent coverage, migration, in-scope services
- General Data Protection Regulation — controller vs processor; DSR, DPIA, breach notification
- Get started with the Microsoft Service Trust Portal — SOC, ISO, GDPR, and other audit reports
- HIPAA and the HITECH Act — BAA is not automatic customer compliance
- Microsoft EU Data Boundary — EU/EFTA store-and-process commitment
- Study guide for Exam MS-900 — describe how Microsoft supports data residency
A compliance lead asks what Microsoft means by data residency for Microsoft 365 customer data. Which statement matches official Learn?
A company created its Microsoft Entra ID tenant two years ago and now wants to change the tenant Default Geography to a different country. Which statement is correct?
A privacy officer says that purchasing Microsoft 365 makes the company automatically compliant with the GDPR. What is the accurate fundamentals statement?
An auditor asks where Microsoft publishes independent SOC and ISO attestations so the customer can use them in its own compliance file. Where should the administrator look?