Solutions · By role

The access & privacy system you won't have to security-assess a vendor for

AccessPoint deploys from a Bicep/ARM template into your own tenant's Azure subscription and runs as a SharePoint web part and Teams app — Entra ID for identity, your Defender, Sentinel, and Purview stack for governance, and no vendor cloud holding your data.

When the access and privacy office brings you a tool to approve, the usual questions follow: whose cloud, which region, what assessment, how many licenses. AccessPoint is built to make those questions short. It isn't SaaS — it deploys from a one-click Bicep/ARM template into your own tenant's Azure subscription, presents as a SharePoint web part and Teams app your users already know how to open, and holds every record, document, and audit entry inside your tenancy. There is no vendor cloud to assess, because there is no vendor cloud.

Identity and access run on what you already operate: Microsoft Entra ID for sign-in with your MFA and Conditional Access policies applying in full, granular roles enforced server-side, and Entra-only database authentication — no SQL credentials ever exist. There's no Power Platform or Dataverse licensing dependency and no per-user fees, so adoption by the access office doesn't become a license-sprawl problem. And because it runs as a workload in your subscription, Defender for Cloud, Sentinel, and Purview monitor and govern it like everything else you own — the opposite of shadow IT.

The economics are equally legible. The license is flat per organization, sold through the Microsoft commercial marketplace and billed on your existing Microsoft invoice — no new vendor to onboard. The Azure resources bill directly to you at Microsoft's rates, typically around $175 per month for a standard configuration, with no markup and sizing under your control. If the office wants AI features, they run on Azure OpenAI deployed in your own tenant's subscription — optional, individually switchable, and never training anyone's model.

What you actually need to know before signing off

The due-diligence questions every new system triggers — and how a tenant-resident architecture answers them.

Where the data lives Every record, document, and audit entry stays in your Azure and Microsoft 365 tenant. No third-party cloud, no cross-border transfer to paper over, and residency follows your subscription's region.
What identity it runs on Entra ID sign-in with your MFA and Conditional Access in force, server-side role enforcement, and Entra-only SQL authentication — no SQL credentials exist to leak or rotate.
Who can touch it at runtime The publisher has no runtime access to your environment. Operational access is whatever your own tenancy grants — nothing else.
How your security stack sees it It's a workload in your subscription, so Defender for Cloud, Sentinel, and Purview monitor, audit, and govern it like anything else you run — no bolt-on security tooling.
What you have to license No Power Platform or Dataverse licensing, no dependency on specific Microsoft 365 tiers, no per-user fees. A SharePoint web part and Teams app against an Azure backend you deploy.
What it costs to run Flat annual license via the Microsoft marketplace, plus Azure resources billed to you directly — typically around $175 per month, sized and controlled by you.

The architecture, in the terms your review will use

What deploys, how it authenticates, and who governs it.

One-click Bicep/ARM deployment

Deploy the Azure backend — App Service, SQL, Blob storage — from a Bicep/ARM template in the Azure portal, and install the web part from AppSource. The deployment script verifies the published SHA-256 of every artifact and aborts on a mismatch.

Tenant-resident by architecture

The database, documents, and audit history live in your subscription and never leave it. The publisher has no runtime access — there is no vendor environment on the data path at all.

Entra ID end to end

Users sign in with your existing Entra ID under your Conditional Access policies; the database accepts Entra-only authentication, so no SQL credentials ever exist. TLS 1.3 throughout, with FTPS and basic authentication disabled from first deployment.

Governed by your existing stack

Defender for Cloud, Sentinel, and Purview see AccessPoint as one of your own workloads, and Microsoft Defender for SQL is on by default. The access office's system lands inside your visibility, not outside it.

SharePoint web part & Teams app

No new front end to operate or train on — staff work from a SharePoint page or a Teams personal app and channel tab, with notifications deep-linking back to the record.

Optional AI, inside the tenant

AI Assist exists only if you deploy it: an Azure OpenAI resource in your own tenant's subscription with managed-identity-only access. You choose where inference is processed, prompts and responses are never stored, Microsoft doesn't train on your content, and a monthly token budget hard-stops spend.

Procurement & assurance

A shorter path through your own gates

Most of the friction in buying line-of-business SaaS is the vendor in the middle — their cloud to assess, their contract to negotiate, their invoice to onboard. AccessPoint removes the middle.

On your existing Microsoft invoice Sold through the Microsoft commercial marketplace by a Microsoft Partner, reviewed and tested by Microsoft before listing — flat annual pricing published on the site, no per-user fees, no new vendor to onboard.
Assurance that actually applies SOC 2 and ISO 27001 attest to how a vendor protects data in its own cloud. AccessPoint holds none of your data — the assurance that matters is your own Microsoft environment's, which you already have. The architecture maps to ITSG-33 and GC Cloud Guardrails for teams that need the control detail.
Evaluate it in your own tenant The surest review is your own: deploy the 30-day trial into your environment and point your security tooling at it before anyone commits.

CIOs & Microsoft 365 Leaders Questions

Does AccessPoint store our data in a vendor cloud?

No. Everything — requests, documents, assessments, incidents, complaints, and the audit ledger — lives in the Azure and Microsoft 365 tenant you deploy it into. There is no vendor-side environment on the data path, no cross-border transfer to manage, and the publisher has no runtime access to your environment. Data residency follows the Azure region of your own tenant's subscription.

Why doesn't AccessPoint have SOC 2 or ISO 27001?

Because those certifications attest to how a vendor protects customer data held in the vendor's own cloud — and AccessPoint holds none of your data. It runs entirely in your tenant, so the hosting assurance that matters is the one your own Microsoft 365 and Azure environment already gives you. For teams that need control-level detail, the architecture documentation maps to ITSG-33 and the GC Cloud Guardrails.

What Microsoft licensing does it require?

No Power Platform or Dataverse licensing, and no dependency on specific Microsoft 365 tiers. AccessPoint runs as a SharePoint web part or Teams app against an Azure backend — App Service, Azure SQL, and Blob storage — deployed from a Bicep/ARM template into your own tenant's subscription. The AccessPoint license itself is flat per organization with no per-user fees.

What are the real Azure hosting costs?

Typically around $175 per month for a standard configuration, scaling with your size and usage — App Service, Azure SQL, and storage billed directly to you by Microsoft at Microsoft's rates, with no vendor markup. You control the sizing yourself, unlike SaaS tools that bundle marked-up hosting into per-user fees.

How does the optional AI work without sending data outside our tenant?

Deploying AI Assist adds an Azure OpenAI resource to your own tenant's subscription with managed-identity-only access — nothing goes to the vendor or any third-party AI service, and Microsoft does not train models on your content. You choose at deployment where inference is processed (globally, or bounded to the EU/US data zone), prompts and responses are never stored, each feature is individually switchable, a monthly token budget you control caps all AI processing, and an administrator acknowledges the terms once per tenant, recorded with user and date. If you run a government cloud, this doesn't have to be the component you drop: Microsoft offers Azure OpenAI in Azure Government's US Gov Virginia and US Gov Arizona regions, approved within the FedRAMP High authorization for Azure Government and DISA's DoD Impact Level 4 and 5 provisional authorization. Model and feature availability differs between Government and commercial regions, so confirm the specific components you want for your region with us before you plan around them.

How does procurement work if there's no vendor contract cycle?

AccessPoint is sold through the Microsoft commercial marketplace by a Microsoft Partner and reviewed and tested by Microsoft before listing. You buy it through your existing Microsoft billing relationship, so it lands on the Microsoft invoice you already pay — flat annual pricing published on the site (USD $2,990 / $7,990 / $14,990 by organization size), with a 30-day free trial you can deploy and evaluate in your own tenant first. If your organization buys differently, the licence can follow: we can set up a private offer targeted to your tenant, or you can purchase through your existing cloud solution provider — useful where an enterprise agreement, a reseller relationship, or a government cloud shapes how software gets bought.

The Easiest Security Review You'll Approve This Year.

Deploy the 30-day trial into your own tenant's Azure subscription and point your own tooling at it — that's the whole assessment surface.

Start Free Trial