Solutions · By capability

Your privacy program, native to Microsoft 365

The records are in SharePoint, the correspondence is in Outlook, the conversations are in Teams — so that's where the access and privacy program should run. AccessPoint operates the whole mandate inside the tenant you already secure.

For most public-sector organizations, Microsoft 365 is where the information actually lives — the documents in SharePoint and OneDrive, the email in Exchange, the conversations in Teams, increasingly even the AI interactions in Copilot. Yet the standard model for privacy and FOI software is to stand up a separate vendor cloud and shuttle copies of that information into it. Every request pays an export-and-upload tax, and your most sensitive records take up residence in an environment your security team doesn't govern.

Microsoft 365 privacy management inverts that model: run the program where the data is. AccessPoint deploys into your own tenant — its backend from a Bicep/ARM template into your Azure subscription, its interface as a SharePoint web part and Teams app — and operates the whole mandate there: access requests, privacy and algorithmic impact assessments, breach response, complaints, and an ISO 31000 risk register, all on one hash-chained audit ledger.

Being native pays twice. Operationally: responsive records attach to a request straight from SharePoint, OneDrive, Outlook, and Teams searches — including Teams chats, OneNote pages, calendars, and Copilot interaction history — and an email in your intake mailbox becomes a fully-formed request in one step. Structurally: authentication is your Entra ID, the database accepts Entra-only authentication with no SQL credentials in existence, and Defender, Sentinel, and Purview govern it all because it's simply workload in your own environment.

What 'Microsoft 365-native' should actually mean

Plenty of tools integrate with M365. Native is a higher bar — here's the checklist to hold any vendor to.

Data plane in your tenant The database, the documents, and the audit history in your own tenant's Azure subscription — not an integration that syncs copies to a vendor cloud.
Collection at the source Search and attach records from SharePoint, OneDrive, Outlook, and Teams directly — including chats, OneNote, and Copilot history — without export-and-upload.
Your identity, end to end Entra ID sign-in, server-side role enforcement, and no second credential store — database access included.
Governed by your existing stack If it runs in your tenant, Defender, Sentinel, and Purview cover it. If it runs elsewhere, you're assessing a second security program.
Works where your people work A SharePoint interface and a Teams app with activity-feed notifications that deep-link to the record — not another browser tab with another login.
No hidden platform taxes No Power Platform or Dataverse licensing dependency, no per-user fees, and Azure costs (~$175/month typical) billed to you at Microsoft's price with no markup.

What runs natively

One platform, every module, inside your tenant.

Access requests

Intake to disclosure with statutory deadlines computed from your legislation, custodian tasking, digital attestations, and a browser-native redaction studio with exemption tagging.

PIAs & AIAs

Screeners, questionnaires with section assignment, embedded risk registers, and regulator-ready summaries — the same engine for privacy and algorithmic impact assessments.

Breach response

Real-risk-of-significant-harm assessment driving a live, statute-computed notification checklist, with containment and remediation tracked to closure.

Complaints & appeals

Commissioner challenges, appeals, and direct complaints with statutory clocks, allegation-level findings, and a two-lane correspondence desk.

Privacy risk & ROPA

An ISO 31000 risk register with KRIs and commitments, plus GDPR Article 30 records and a vendor register on durable privacy subjects.

AI Assist — in your tenant

Optional drafting, triage, redaction analysis, and Ask AccessPoint on Azure OpenAI deployed in your own tenant's subscription — person-decided, disclosed, budget-capped, never trained on.

The security review

The easiest vendor assessment your IT team will run this year

Nothing is hosted by the vendor, so the questions that consume SaaS security reviews largely disappear: no vendor data residency, no subprocessor list, no cross-border transfer of case records, no runtime vendor access.

Hardened by default TLS 1.3, Entra-only database authentication, managed identities — and your own security tooling watching all of it.
Reviewed & tested by Microsoft Sold through Microsoft's commercial marketplace and billed on your existing Microsoft invoice.
Deployed in minutes A one-click Bicep/ARM template in the Azure portal and an app install from the marketplace — no servers, no separate procurement cycle.

Microsoft 365 Privacy Management Questions

What does Microsoft 365 privacy management mean?

Running your access and privacy program natively inside your own Microsoft 365 and Azure tenant instead of a vendor's cloud: the case system deploys into your Azure subscription, the interface lives in SharePoint and Teams, records are collected from where they already are, and your existing identity and security stack governs everything. AccessPoint is built on exactly this model — requests, PIAs, AIAs, breaches, complaints, and risk in one tenant-resident platform.

How is this different from a privacy tool that 'integrates with' Microsoft 365?

Integration usually means a connector that copies your data into the vendor's cloud, where the real processing happens. Native means the data plane itself — database, documents, audit ledger — lives in your Azure subscription, collection happens at the source, and there's no second environment to secure. The practical test: ask where the record physically sits during review. For AccessPoint, the answer is your tenant, always.

Does it require specific Microsoft 365 licensing or the Power Platform?

No dependency on specific M365 licensing tiers, and no Power Platform or Dataverse licensing at all. AccessPoint runs as a SharePoint web part and Teams app against an Azure backend — App Service, Azure SQL, and Blob storage — deployed from a one-click Bicep/ARM template into your own tenant's subscription.

What does it cost to run in our tenant?

Two transparent parts: a flat annual license by organization size — USD $2,990, $7,990, or $14,990, published on the pricing page, no per-user fees — and your own Azure resources, typically around $175 per month for a standard configuration, billed directly by Microsoft with no vendor markup. You control the sizing.

Can it really capture Teams messages and Copilot interactions as records?

Yes — beyond SharePoint, OneDrive, and Outlook, AccessPoint captures Teams chats, OneNote pages, calendars, and Copilot interaction history into a request the same way, which matters as more decision-making happens in those channels. Capture respects your configured permissions, and everything lands in the request's document workspace for review and redaction.

The Program Belongs Where the Records Are.

Try AccessPoint free for 30 days in your own Microsoft 365 tenant — deployed from the marketplace, often within an afternoon.

Start Free Trial