Solutions · By capability
Your privacy program, native to Microsoft 365
The records are in SharePoint, the correspondence is in Outlook, the conversations are in Teams — so that's where the access and privacy program should run. AccessPoint operates the whole mandate inside the tenant you already secure.
For most public-sector organizations, Microsoft 365 is where the information actually lives — the documents in SharePoint and OneDrive, the email in Exchange, the conversations in Teams, increasingly even the AI interactions in Copilot. Yet the standard model for privacy and FOI software is to stand up a separate vendor cloud and shuttle copies of that information into it. Every request pays an export-and-upload tax, and your most sensitive records take up residence in an environment your security team doesn't govern.
Microsoft 365 privacy management inverts that model: run the program where the data is. AccessPoint deploys into your own tenant — its backend from a Bicep/ARM template into your Azure subscription, its interface as a SharePoint web part and Teams app — and operates the whole mandate there: access requests, privacy and algorithmic impact assessments, breach response, complaints, and an ISO 31000 risk register, all on one hash-chained audit ledger.
Being native pays twice. Operationally: responsive records attach to a request straight from SharePoint, OneDrive, Outlook, and Teams searches — including Teams chats, OneNote pages, calendars, and Copilot interaction history — and an email in your intake mailbox becomes a fully-formed request in one step. Structurally: authentication is your Entra ID, the database accepts Entra-only authentication with no SQL credentials in existence, and Defender, Sentinel, and Purview govern it all because it's simply workload in your own environment.
Sound familiar?
Your records already live in Microsoft 365. These are the signs your program doesn't.
The intranet form that emails a mailbox
The privacy page posts everything to a shared inbox — access requests, breach reports, complaints — triaged by whoever opens Outlook first. By the time someone logs the file, the statutory clock has been running for days without anyone knowing it started.
Case files behind inherited permissions
Breach narratives and PIA drafts sit in a Teams site whose membership has grown, unreviewed, for years. Half the division can open the incident file about the other half — and the privacy office's own records are one click from becoming the next reportable incident.
One mandate, five fragments
Requests in a spreadsheet, PIAs in Word, the breach log in a second spreadsheet, complaints in a folder — all inside Microsoft 365, none of it governed. When leadership asks how the program is doing, assembling the answer is a project in itself.
What 'Microsoft 365-native' should actually mean
Plenty of tools integrate with M365. Native is a higher bar — here's the checklist to hold any vendor to.
What runs natively
One platform, every module, inside your tenant.
Access requests
Intake to disclosure with statutory deadlines computed from your legislation, custodian tasking, digital attestations, and a browser-native redaction studio with exemption tagging.
PIAs & AIAs
Screeners, questionnaires with section assignment, embedded risk registers, and regulator-ready summaries — the same engine for privacy and algorithmic impact assessments.
Breach response
Real-risk-of-significant-harm assessment driving a live, statute-computed notification checklist, with containment and remediation tracked to closure.
Complaints & appeals
Commissioner challenges, appeals, and direct complaints with statutory clocks, allegation-level findings, and a two-lane correspondence desk.
Privacy risk & ROPA
An ISO 31000 risk register with KRIs and commitments, plus GDPR Article 30 records and a vendor register on durable privacy subjects.
AI Assist — in your tenant
Optional drafting, triage, redaction analysis, and Ask AccessPoint on Azure OpenAI deployed in your own tenant's subscription — person-decided, disclosed, budget-capped, never trained on.
See it in AccessPoint
Real screens from the product, running in a Microsoft 365 tenant. Click any one to enlarge.
The security review
The easiest vendor assessment your IT team will run this year
Nothing is hosted by the vendor, so the questions that consume SaaS security reviews largely disappear: no vendor data residency, no subprocessor list, no cross-border transfer of case records, no runtime vendor access.
Go deeper
Microsoft 365 Privacy Management Questions
What does Microsoft 365 privacy management mean?
How is this different from a privacy tool that 'integrates with' Microsoft 365?
Does it require specific Microsoft 365 licensing or the Power Platform?
What does it cost to run in our tenant?
Can it really capture Teams messages and Copilot interactions as records?
Flat annual pricing, published in full. Every feature in every size — access requests, privacy impact assessments, breach response, complaints, video & audio redaction, and AI Assist. No per-user or per-module fees.
- Under 500 employees$2,990/yr
- 500–2,000 employees$7,990/yr
- Over 2,000 employees$14,990/yr
The Program Belongs Where the Records Are.
Try AccessPoint free for 30 days in your own Microsoft 365 tenant — deployed from the marketplace, often within an afternoon.