Solutions · By role
The access & privacy system you won't have to security-assess a vendor for
AccessPoint deploys from a Bicep/ARM template into your own tenant's Azure subscription and runs as a SharePoint web part and Teams app — Entra ID for identity, your Defender, Sentinel, and Purview stack for governance, and no vendor cloud holding your data.
When the access and privacy office brings you a tool to approve, the usual questions follow: whose cloud, which region, what assessment, how many licenses. AccessPoint is built to make those questions short. It isn't SaaS — it deploys from a one-click Bicep/ARM template into your own tenant's Azure subscription, presents as a SharePoint web part and Teams app your users already know how to open, and holds every record, document, and audit entry inside your tenancy. There is no vendor cloud to assess, because there is no vendor cloud.
Identity and access run on what you already operate: Microsoft Entra ID for sign-in with your MFA and Conditional Access policies applying in full, granular roles enforced server-side, and Entra-only database authentication — no SQL credentials ever exist. There's no Power Platform or Dataverse licensing dependency and no per-user fees, so adoption by the access office doesn't become a license-sprawl problem. And because it runs as a workload in your subscription, Defender for Cloud, Sentinel, and Purview monitor and govern it like everything else you own — the opposite of shadow IT.
The economics are equally legible. The license is flat per organization, sold through the Microsoft commercial marketplace and billed on your existing Microsoft invoice — no new vendor to onboard. The Azure resources bill directly to you at Microsoft's rates, typically around $175 per month for a standard configuration, with no markup and sizing under your control. If the office wants AI features, they run on Azure OpenAI deployed in your own tenant's subscription — optional, individually switchable, and never training anyone's model.
What you actually need to know before signing off
The due-diligence questions every new system triggers — and how a tenant-resident architecture answers them.
The architecture, in the terms your review will use
What deploys, how it authenticates, and who governs it.
One-click Bicep/ARM deployment
Deploy the Azure backend — App Service, SQL, Blob storage — from a Bicep/ARM template in the Azure portal, and install the web part from AppSource. The deployment script verifies the published SHA-256 of every artifact and aborts on a mismatch.
Tenant-resident by architecture
The database, documents, and audit history live in your subscription and never leave it. The publisher has no runtime access — there is no vendor environment on the data path at all.
Entra ID end to end
Users sign in with your existing Entra ID under your Conditional Access policies; the database accepts Entra-only authentication, so no SQL credentials ever exist. TLS 1.3 throughout, with FTPS and basic authentication disabled from first deployment.
Governed by your existing stack
Defender for Cloud, Sentinel, and Purview see AccessPoint as one of your own workloads, and Microsoft Defender for SQL is on by default. The access office's system lands inside your visibility, not outside it.
SharePoint web part & Teams app
No new front end to operate or train on — staff work from a SharePoint page or a Teams personal app and channel tab, with notifications deep-linking back to the record.
Optional AI, inside the tenant
AI Assist exists only if you deploy it: an Azure OpenAI resource in your own tenant's subscription with managed-identity-only access. You choose where inference is processed, prompts and responses are never stored, Microsoft doesn't train on your content, and a monthly token budget hard-stops spend.
Procurement & assurance
A shorter path through your own gates
Most of the friction in buying line-of-business SaaS is the vendor in the middle — their cloud to assess, their contract to negotiate, their invoice to onboard. AccessPoint removes the middle.
Go deeper
CIOs & Microsoft 365 Leaders Questions
Does AccessPoint store our data in a vendor cloud?
Why doesn't AccessPoint have SOC 2 or ISO 27001?
What Microsoft licensing does it require?
What are the real Azure hosting costs?
How does the optional AI work without sending data outside our tenant?
How does procurement work if there's no vendor contract cycle?
The Easiest Security Review You'll Approve This Year.
Deploy the 30-day trial into your own tenant's Azure subscription and point your own tooling at it — that's the whole assessment surface.
Start Free Trial