VendorScore · Productivity suite · Data-access posture
A plain-language answer from Microsoft's public Trust Center and Learn docs. Customer Key is not the same as Microsoft can't read it.
Get the full 5-dimension PDF — join the waitlistEvidence dated 2026-10-06, public docs only, not legal advice.
Short answer
Yes. Microsoft can process and decrypt customer content for service operations, even under Customer Key (availability key, service code). Double Key Encryption (DKE) content is the exception: Microsoft cannot decrypt it.
Scored configuration: Microsoft 365 enterprise with Purview Customer Key and Customer Lockbox. Double Key Encryption (DKE) is noted as a higher bar for limited content.
With Microsoft-managed keys and no Lockbox (the default), the report scores key custody and plaintext access lower.
Higher = more customer control / less inherent vendor read access for the scored configuration. A strong SOC 2 doesn't mean the vendor can't read your data.
Customer Key puts root keys in Azure Key Vault, but Microsoft 365 service code uses them for encryption operations, and Microsoft holds an availability key that service code can use for recovery when customer keys fail.
Evidence: Encryption overview, Availability keyWith Double Key Encryption, the customer holds a second key Microsoft never has, so Microsoft cannot decrypt DKE-protected files. Separately, Customer Lockbox lets customers approve or deny engineer access requests in support scenarios.
Evidence: Double Key Encryption, Customer LockboxGet the full 5-dimension PDF — join the waitlist
PDFs aren't for sale yet. Join the waitlist and we'll email yours when it's ready. No calls.
Yes. Microsoft can process and decrypt customer content for service operations, even under Customer Key (availability key, service code). Double Key Encryption (DKE) content is the exception: Microsoft cannot decrypt it. VendorScore rates Microsoft 365 69/100 overall from public documentation (evidence dated 2026-10-06). Scored configuration: Microsoft 365 enterprise with Purview Customer Key and Customer Lockbox. Double Key Encryption (DKE) is noted as a higher bar for limited content.
Customer Key: no. It gives you control of root keys, but Microsoft 365 service code still uses them, and a Microsoft-held availability key exists for recovery. DKE: yes for DKE-protected files, because you hold a second key Microsoft never has. DKE covers limited content and comes with major usability and search limitations.
Not by default, but access is possible under policy. Microsoft says: "Microsoft engineers don’t have default access to cloud customer data. Instead, they are granted access, under management oversight, only when necessary." Customer Lockbox lets you approve or deny engineer access requests in support scenarios. Service features such as indexing, eDiscovery, DLP and antivirus still process plaintext for non-DKE data.
For Microsoft 365 Copilot, Microsoft's documentation says: "Prompts, responses, and data accessed through Microsoft Graph aren't used to train foundation LLMs, including those used by Microsoft Copilot." VendorScore's Microsoft 365 score doesn't cover Copilot, which needs its own review.
VendorScore doesn't certify compliance; Microsoft 365 publishes a DPA at https://www.microsoft.com/licensing/docs/view/Microsoft-Products-and-Services-Data-Protection-Addendum-DPA. It is the Microsoft Products and Services Data Protection Addendum, which sets the data processing and security terms for products under Microsoft's Product Terms. Microsoft also says its subprocessors must meet GDPR requirements.
Microsoft's Trust Center data-access page (https://www.microsoft.com/en-us/trust-center/privacy/data-access) links the Microsoft Online Services Subprocessor List. Microsoft says it names new subprocessors at least six months before they may access customer or personal data, and that subprocessors may access data only to deliver the functions Microsoft hired them for.
Yes, within limits. The EU Data Boundary is Microsoft's commitment to store and process Customer Data and personal data for its enterprise online services, including Microsoft 365, in the EU and EFTA, with some documented transfers outside it. For Microsoft 365, customers with a sign-up location in an EU or EFTA country are in scope; customers who bought Multi-Geo Capabilities are not.
Every URL cited on this page. Score and key findings: VendorScore report (microsoft-365.md), evidence dated 2026-10-06. FAQ policy links: vendor pages re-checked 2026-10-07.