Solutions · By capability
Your privacy program, native to Microsoft 365
The records are in SharePoint, the correspondence is in Outlook, the conversations are in Teams — so that's where the access and privacy program should run. AccessPoint operates the whole mandate inside the tenant you already secure.
For most public-sector organizations, Microsoft 365 is where the information actually lives — the documents in SharePoint and OneDrive, the email in Exchange, the conversations in Teams, increasingly even the AI interactions in Copilot. Yet the standard model for privacy and FOI software is to stand up a separate vendor cloud and shuttle copies of that information into it. Every request pays an export-and-upload tax, and your most sensitive records take up residence in an environment your security team doesn't govern.
Microsoft 365 privacy management inverts that model: run the program where the data is. AccessPoint deploys into your own tenant — its backend from a Bicep/ARM template into your Azure subscription, its interface as a SharePoint web part and Teams app — and operates the whole mandate there: access requests, privacy and algorithmic impact assessments, breach response, complaints, and an ISO 31000 risk register, all on one hash-chained audit ledger.
Being native pays twice. Operationally: responsive records attach to a request straight from SharePoint, OneDrive, Outlook, and Teams searches — including Teams chats, OneNote pages, calendars, and Copilot interaction history — and an email in your intake mailbox becomes a fully-formed request in one step. Structurally: authentication is your Entra ID, the database accepts Entra-only authentication with no SQL credentials in existence, and Defender, Sentinel, and Purview govern it all because it's simply workload in your own environment.
What 'Microsoft 365-native' should actually mean
Plenty of tools integrate with M365. Native is a higher bar — here's the checklist to hold any vendor to.
What runs natively
One platform, every module, inside your tenant.
Access requests
Intake to disclosure with statutory deadlines computed from your legislation, custodian tasking, digital attestations, and a browser-native redaction studio with exemption tagging.
PIAs & AIAs
Screeners, questionnaires with section assignment, embedded risk registers, and regulator-ready summaries — the same engine for privacy and algorithmic impact assessments.
Breach response
Real-risk-of-significant-harm assessment driving a live, statute-computed notification checklist, with containment and remediation tracked to closure.
Complaints & appeals
Commissioner challenges, appeals, and direct complaints with statutory clocks, allegation-level findings, and a two-lane correspondence desk.
Privacy risk & ROPA
An ISO 31000 risk register with KRIs and commitments, plus GDPR Article 30 records and a vendor register on durable privacy subjects.
AI Assist — in your tenant
Optional drafting, triage, redaction analysis, and Ask AccessPoint on Azure OpenAI deployed in your own tenant's subscription — person-decided, disclosed, budget-capped, never trained on.
The security review
The easiest vendor assessment your IT team will run this year
Nothing is hosted by the vendor, so the questions that consume SaaS security reviews largely disappear: no vendor data residency, no subprocessor list, no cross-border transfer of case records, no runtime vendor access.
Go deeper
Microsoft 365 Privacy Management Questions
What does Microsoft 365 privacy management mean?
How is this different from a privacy tool that 'integrates with' Microsoft 365?
Does it require specific Microsoft 365 licensing or the Power Platform?
What does it cost to run in our tenant?
Can it really capture Teams messages and Copilot interactions as records?
The Program Belongs Where the Records Are.
Try AccessPoint free for 30 days in your own Microsoft 365 tenant — deployed from the marketplace, often within an afternoon.
Start Free Trial