Microsoft Compliance Manager
Assess your compliance posture with Compliance Manager, interpret the compliance score, and create improvement actions mapped to specific regulatory controls.
Microsoft Compliance Manager is a free Cloud & IT Cert Prep lesson on CoddyKit — lesson 3 of 4. You can read the complete lesson below for free — then practise it hands-on in the browser with a built-in code editor and a 24/7 AI tutor. It is part of the Cloud & IT Cert Prep learning path, one of 4 lessons in the course, and your progress syncs across the web and the CoddyKit app.
What Is Compliance Manager?
Microsoft Compliance Manager is a tool within the Microsoft Purview compliance portal that helps organisations assess, monitor, and improve their compliance posture against regulatory frameworks. It provides a compliance score — a numeric measure of how well your organisation's controls align with the requirements of selected standards. Compliance Manager is available to organisations with Microsoft 365 or Azure subscriptions.
Accessing Compliance Manager
Compliance Manager is accessed through the Microsoft Purview compliance portal at compliance.microsoft.com. The home dashboard shows your overall compliance score, a breakdown by category (data protection, access control, incident management), and a list of assessments. You do not need to be a compliance expert to use the tool — it guides you step by step through the requirements of each standard.
# Access path:
# compliance.microsoft.com -> Compliance Manager
#
# Permissions required:
# - Global Admin, Compliance Admin, or Compliance Data Admin role in Entra ID
# - Or Compliance Manager Assessor role for read-only + improvement actionsAssessments in Compliance Manager
An assessment in Compliance Manager represents an evaluation of your organisation against a specific regulatory framework (e.g., ISO 27001, GDPR, HIPAA). Each assessment contains a set of controls drawn from the regulation, along with Microsoft-managed actions (controls handled by Microsoft for you) and customer-managed actions (controls you must implement yourself). You can create assessments for multiple regulations simultaneously.
The Compliance Score
The compliance score is a percentage (0-100%) that represents how well your organisation's controls are implemented relative to the assessments you have created. Points are awarded for:
- Microsoft-managed actions — automatically credited when Microsoft's controls are in place
- Customer-managed actions — credited when you mark an action as implemented and optionally upload evidence
A higher score means better control coverage, but it does not guarantee actual regulatory compliance.
Improvement Actions
Improvement actions are specific steps you can take to improve your compliance score. Each action includes a description of what to implement, the regulation it maps to, the number of points it is worth, implementation guidance (often with links to Microsoft documentation), and a field to record your implementation status. Actions are grouped by categories like Protect Information, Manage Devices, and Control Access.
Evidence Collection
For customer-managed actions, Compliance Manager allows you to upload evidence documents — screenshots, audit reports, policy documents, or test results — that demonstrate the control is implemented. This creates a compliance evidence trail that can be shared with auditors or inspectors. Evidence documents are stored in the Compliance Manager portal and can be downloaded at any time.
Templates for Additional Regulations
Compliance Manager includes over 300 regulation templates that you can use to create assessments. Templates range from global standards (ISO 27001, NIST CSF) to industry-specific regulations (PCI DSS, HIPAA) to regional laws (GDPR, LGPD, CCPA). Premium templates covering regulations beyond Microsoft 365 require an additional licence (e.g., Microsoft 365 E5 Compliance or Compliance Manager add-on).
Testing Controls and Implementation Status
For each improvement action, Compliance Manager tracks:
- Implementation status — Not implemented, Implemented, Alternative implementation, Planned
- Test status — Not tested, Passed, Failed, No assessment
- Test date — when the last test was performed
Marking an action as 'Implemented' without uploading evidence awards points but may be questioned during a formal audit — always back up your status with actual evidence.
Delegating Actions to Team Members
Compliance Manager supports role-based delegation — you can assign specific improvement actions to individual team members or groups. This is useful for large organisations where different teams own different control areas (security team owns access controls, HR team owns policy training, IT operations owns infrastructure controls). Assigned users receive notifications and can update their action status directly.
Compliance Manager vs. Azure Policy
Compliance Manager and Azure Policy address different aspects of compliance:
- Compliance Manager — tracks organisational controls against regulatory frameworks; focuses on people and process controls as well as technical controls; operated from the Purview compliance portal
- Azure Policy — enforces and audits technical configuration of Azure resources; automates compliance for infrastructure; operated from the Azure portal
Both are needed for a complete compliance programme.
Exporting Compliance Reports
Compliance Manager allows you to export assessment results to Excel for sharing with auditors, management, or regulators. The export includes the full list of controls, their status, test results, and links to evidence. Many organisations use this export as the basis for their Statement of Applicability (SoA) — a document required by ISO 27001 that lists all controls and their implementation status.
Quick Check
Test your understanding of Microsoft Azure Fundamentals (AZ-900) concepts from this lesson.
Lesson Recap
In this lesson you learned: Compliance Manager provides a compliance score and improvement actions mapped to over 300 regulatory frameworks; Microsoft-managed actions are automatically credited while customer-managed actions require you to implement and document controls; and evidence documents can be uploaded to build an audit trail. Next up we explore GDPR-specific requirements and how to implement them on Azure.
Frequently asked questions
Is the “Microsoft Compliance Manager” lesson free?
Yes — the full text of “Microsoft Compliance Manager” is free to read here on the web, and the Cloud & IT Cert Prep course includes 4 lessons in total. To practise it interactively (a built-in code editor and a 24/7 AI tutor) and unlock the rest of the Cloud & IT Cert Prep course, upgrade to CoddyKit PRO.
What will I learn in “Microsoft Compliance Manager”?
Assess your compliance posture with Compliance Manager, interpret the compliance score, and create improvement actions mapped to specific regulatory controls. You practise Cloud & IT Cert Prep with hands-on code you run directly in the browser, and a 24/7 AI tutor answers your questions as you work through the lesson.
Do I need any experience to start Cloud & IT Cert Prep?
No prior experience is required. Cloud & IT Cert Prep on CoddyKit is structured for beginners through advanced learners; this is — lesson 3 of 4, so you can start here or from the beginning and move at your own pace.
How long does the “Microsoft Compliance Manager” lesson take?
Most CoddyKit lessons take about 5–10 minutes. Each one is bite-sized and interactive, so you make steady progress and pick up exactly where you left off across the web and the app.
Can I write and run code in this Cloud & IT Cert Prep lesson?
Yes. Every Cloud & IT Cert Prep lesson includes a built-in code editor, so you write and run real code right in your browser and get instant AI feedback — no local setup required.
All lessons in this course
- Azure Compliance Frameworks
- Microsoft Purview and Data Governance
- Microsoft Compliance Manager
- GDPR on Azure