VendorScore · Data-access posture
Plain-language data-access score from Microsoft Trust Center and Learn docs. Customer Key ≠ Microsoft cannot read.
Join waitlist for full PDF All vendorsPublic documentation review only. Not a pen test. Not legal advice. Evidence dated 2026-10-06.
Clear answer
Yes — Microsoft can process/decrypt customer content for service operations under Customer Key. DKE content is the exception: Microsoft cannot decrypt it.
Scored config: Microsoft 365 enterprise with Purview Customer Key + Customer Lockbox; DKE noted as higher bar for limited content. Evidence 2026-10-06.
| Dimension | Score |
|---|---|
| Key custody | 62 |
| Plaintext access | 55 |
| Encryption claims | 78 |
| Subprocessors | 58 |
| Auditability | 94 |
| Overall (equal-weight average) | 69 |
Higher = better customer control / less inherent vendor plaintext access for the scored configuration. Strong compliance ≠ no read access.
Yes for typical enterprise content. Under Customer Key, Microsoft 365 service code can still use keys (including an availability key) for service operations. Double Key Encryption (DKE) is the hard exception: Microsoft cannot decrypt DKE-protected files. VendorScore rates Microsoft 365 69/100 overall (evidence 2026-10-06).
No. Customer Key puts root keys in your Azure Key Vault/HSM, but Microsoft documents an availability key and service encryption operations. Do not treat Customer Key as “Microsoft cannot read.” Use DKE when you need Microsoft to be unable to decrypt.
Five equal-weight dimensions: key custody (62), plaintext access (55), encryption claims (78), subprocessors (58), and auditability (94). Overall 69 with Customer Key + Customer Lockbox assumed. Public documentation review only — not a pen test and not legal advice.
Full write-ups with source lists are not for sale yet. Join the waitlist — delivered by email when ready. No Stripe checkout on this page. No calls.
Join waitlist for full PDF