Registry / Azure OpenAI Service
Azure OpenAI Service
OpenAI GPT models served by Microsoft as "Models sold by Azure" within Microsoft Foundry (formerly Azure OpenAI Service / Azure AI Foundry). Microsoft hosts the models in its own Azure environment; customer data does not flow to OpenAI-operated services, and vendor-trust and data-handling commitments are Microsoft's/Azure's.
Watch-outs 4
The cells where this offering is not a clean public yes. This is what to check before you sign.
- SOC 2 Type II: Yes, sales-gated SOC 2 report is accessed via Microsoft Service Trust Portal (requires login)
- ISO 27001: Partial Azure OpenAI Service is not listed among the in‑scope services, so ISO 27001 covers the platform but not this specific service.
- HIPAA BAA: Yes, sales-gated BAA document is only downloadable via the Microsoft Service Trust Portal, which requires sign‑in (gated access).
- Retention / ZDR: Partial zero-data-retention requires approval via a gated process
Microsoft’s official blog states Azure OpenAI meets SOC 2, and SOC 2 reports are only available through the gated Service Trust Portal, so the report exists but is sales‑gated.
Azure OpenAI already meets a wide range of industry standards and certifications, including **HIPAA**, **SOC 2**, and **FedRAMP**, ensuring that enterprises across industries can trust their AI solutions to remain secure and compliant.
The provider’s official ISO 27001 offering page lists the services covered and excludes Azure OpenAI Service, indicating only partial coverage for this offering.
The Azure ISO/IEC 27001 certificate covers Azure, Dynamics 365, Power Platform, and select Microsoft 365 cloud services.
The Microsoft Azure blog publicly states that the ISO/IEC 42001:2023 certification covers Azure OpenAI models, providing verifiable evidence without any access gate.
By achieving this certification, Microsoft demonstrates that Azure AI Foundry Models, including Azure OpenAI models, and Microsoft Security Copilot prioritize responsible innovation and are validated by an independent third party.
The Microsoft Service Trust Portal publicly hosts an AI Resources page referencing Azure OpenAI, confirming a maintained compliance portal.
Resources describing the approach to Compliance, Security and Privacy in the Artificial Intelligence (AI) solutions such as Copilot and Azure Open AI
Microsoft states Azure OpenAI is covered by its BAA, but the BAA is only accessible through the gated Service Trust Portal, so the agreement is sales‑gated.
Azure OpenAI Service - HIPAA-eligible for text-based inputs. - Covered under Microsoft’s Business Associate Agreement (BAA) through the Microsoft Online Services Data Protection Addendum (DPA)... You can download confirmation documents, including the DPA and BAA, directly from the Microsoft Service Trust Portal. [For reference on BAA Overview](https://aka.ms/baa)
Microsoft publicly provides the DPA (which includes the EU Model Clauses/SCCs) and also publishes a Subprocessor List linked to that DPA, satisfying both requirements.
The Microsoft Online Services Subprocessor List identifies subprocessors authorized to subprocess customer or personal data in Microsoft Online Services. This list is applicable for all Microsoft Online Services governed by the Microsoft Data Protection Addendum. Microsoft makes the EU Model Clauses available to customers as described in the Microsoft Online Services Terms (OST) Data Protection Addendum (DPA).
Microsoft’s Azure OpenAI data‑privacy page publicly states that prompts and completions are not used to train foundation models without customer permission, confirming a public commitment not to train on customer API data by default.
are NOT used to train any generative AI foundation models without your permission or instruction.
Retention is publicly documented (30 days) and zero-data-retention is only offered after a sales/approval process, so the compound question is only partially satisfied.
"The data in the service response, including prompts and completions, is ... retained for 30 days for abuse monitoring purposes." ... "If your application is approved for modified abuse monitoring, prompts and completions will not be stored."
Microsoft docs state that Standard/Regional deployments process data in the specific Azure region of the deployment, allowing region‑level pinning such as to an EU region.
Standard/Regional types: Processed in the region associated with your deployment (not available for batch deployments)
The EC GPAI Code of Practice signatory list on the official EU digital strategy page includes OpenAI, confirming the model developer is a public signatory.
OpenAI
The Art. 53 training-content summary is a developer obligation, and per the knowledge base serving-platform rows (e.g. Azure OpenAI Service) are not_applicable, even though developer OpenAI has published its summary.
In accordance with our obligations under Article 53(1)(d) of the EU AI Act, OpenAI publishes summaries about the content used to train our general-purpose AI models:
Spotted an error? Submit a correction with evidence, corrections with a primary source are folded in and credited in the changelog.