Is Microsoft 365 GxP compliant?

Short answer

No cloud service is GxP certified, and Microsoft says so. Microsoft 365 can support GxP-regulated work: Microsoft publishes Qualification Guidelines that set out its shared responsibility with customers, and its services are audited against standards such as ISO 9001 and ISO/IEC 27001. Compliance depends on how your company defines intended use, configures the service, qualifies it and controls it in operation.

What Microsoft actually says

Microsoft's GxP compliance page states there is no GxP certification for cloud service providers. Instead, Azure and Office 365 undergo independent audits for quality management and information security, including ISO 9001 and ISO/IEC 27001, and Microsoft bases its qualification approach on ISPE GAMP good practice guides and PIC/S PI 011-3.

Microsoft retained Montrium, an independent life-science quality firm, to review its approach. The resulting Qualification Guidelines for Office 365 identify the responsibilities shared by Microsoft and its customers and recommend controls customers can put in place. Microsoft lists Azure, Microsoft 365 and Dynamics 365 as in scope.

Your side of the shared responsibility

Microsoft's own FAQ says customers should determine the GxP requirements that apply based on intended use, then follow their own procedures for qualification and validation. In practice, that means:

  • Define which Microsoft 365 workloads hold GxP records, such as SharePoint document libraries for SOPs or quality records, and which do not.
  • Assess supplier risk and keep Microsoft's audit reports and qualification documents in your supplier file.
  • Configure unique accounts, MFA, permissions, versioning, retention and audit logging to match your requirements.
  • Qualify the configuration with risk-based testing and keep it under change control.
  • Plan for Microsoft's continuous updates: decide how you will assess release changes that could affect GxP use.

Electronic records and signatures

21 CFR Part 11 sets requirements for electronic records and signatures. Microsoft notes that no certification exists for Part 11 compliance; it maps its SOC 1, SOC 2, ISO/IEC 27001 and ISO/IEC 27018 audited controls to the Part 11 requirements it is responsible for, and states that customers who deploy applications subject to FDA regulation are responsible for ensuring those applications meet FDA requirements. Microsoft 365 alone is not a validated electronic signature or document control system; many companies pair it with a purpose-built quality management system or a validated add-on for controlled documents and signatures.

Data integrity in Microsoft 365

The ALCOA+ principles still apply. Every user must be uniquely identified, version history and audit logs must be retained for the record's retention period, and originals must not be overwritten or deleted outside procedure. Retention policies, sensitivity labels and audit log retention in Microsoft Purview are the usual tools. Purview Compliance Manager also offers a premium assessment template for GxP that can help track controls.

Keep the scope small

Not everything in Microsoft 365 needs to be qualified. Email and general collaboration can stay outside GxP scope while a defined set of sites or libraries carries regulated records. The tighter the boundary, the less you have to validate and the easier it is to keep under control.

Collect the evidence once. Microsoft makes its SOC 1 Type 2, SOC 2 Type 2, ISO/IEC 27001 and ISO/IEC 27018 audit reports available through the Service Trust Portal, subject to nondisclosure terms. File them with your supplier assessment and the Qualification Guidelines, and review them on a set cycle so your supplier file stays current.

Common follow-up questions

Can we store SOPs and batch records in SharePoint?

You can, if the libraries that hold them are configured, qualified and controlled for that use: unique access, versioning, retention, audit logging and approval workflows. Many companies use a validated quality system for approvals and signatures and keep SharePoint for working documents.

Does Microsoft validate Microsoft 365 for us?

No. Microsoft qualifies its own infrastructure and processes and documents shared responsibilities. Your company must validate the system for its intended use, including your configuration and procedures, under your quality system.

Is Microsoft 365 Copilot allowed in GxP work?

There is no blanket answer. Treat Copilot like any other new capability: decide its intended use, assess the risk to GxP records and decisions, and keep humans accountable for regulated decisions. Keep it away from GxP records until you have done that assessment.

Need help with this?

LAN Service Group configures and administers Microsoft 365 and SharePoint for life-science companies within a GxP framework, from scoping regulated workloads to retention, audit logging and change control.

Talk to LAN Service Group (888) 281-7243

Sources