Screenata

Integrations / Communication

Screenata + Microsoft Teams

How do you use Microsoft Teams for SOC 2 and HIPAA compliance?

Quick answer

Microsoft Teams is the surface the compliance program runs on, not a scanned system. It is where briefings land, where evidence gets ingested, and where attestations get chased. A policy existing is not the control. The control is the enforced setting plus the record that it operated for every person across the audit period, which is why the acknowledgment log matters as much as the policy document. Screenata uses Teams to deliver briefings, request evidence, and chase policy attestations, and records that activity as evidence.

Screenata connects to Microsoft Teams as a workflow surface: daily briefings, evidence files ingested and classified where they are dropped, and policy attestation requests chased to completion. Workspace security posture for Teams itself is scanned through the Microsoft 365 integration, so one connection pair covers both the checks and the workflow.

Read-only · signed evidence

What it proves

Microsoft Teams evidence, mapped to controls.

Each area below is scanned on a schedule. A finding is not a green checkmark: it is a signed artifact an auditor can verify, mapped to the exact requirement it satisfies.
Evidence area
What the checks verify
Maps to
Briefings & escalations

Daily readiness briefings and escalations delivered in Teams, so compliance status reaches the people who act on it.

A recorded trail of what was reported and when, evidencing that compliance information flows to the team.

SOC 2CC2.2
Evidence ingestion

Files dropped in Teams are ingested, auto-classified, and filed to the control they evidence.

Long-tail evidence captured where it appears instead of lost in a chat scrollback, signed like any other artifact.

SOC 2CC2.2
Attestation requests

Policy acknowledgment requests sent and chased in Teams, with acknowledgments recorded per person.

The acknowledgment log auditors sample: who was asked, who acknowledged, and when.

SOC 2CC1.5HIPAA§164.308(a)(5)

Control references are the requirements each evidence area supports, via the shared control catalog. Your auditor decides sufficiency; the artifacts are theirs to verify.

How it connects

Read-only, revocable, yours.

You install the Screenata Teams app for briefings, evidence ingestion, and attestation requests. Credentials never touch the Screenata database, and the app can be removed by your administrator at any time. Security posture checks for Teams run through the Microsoft 365 integration.

Read-only by construction

OAuth scopes and IAM roles are scoped to read. Vera never gets write access to your systems.

Signed findings

SHA-256 per artifact, RSA/ECDSA signatures, RFC 3161 timestamps. Verifiable without a Screenata account.

Mapped to controls

Each finding lands on the shared control catalog, so one scan satisfies SOC 2, HIPAA, and ISO 27001 at once.

BAA & attestation status

Microsoft offers a BAA covering in-scope Microsoft 365 services including Teams on eligible business and enterprise plans. That covers Microsoft's own layer. Tenant configuration and retention remain your responsibility, and you have to evidence that those settings operated.

Microsoft Teams FAQ

What teams ask before connecting.

Full provider list on the integrations page.
What access does Screenata need to Microsoft Teams?

The Screenata Teams app, installed by your administrator, with the scopes needed for messages, evidence ingestion, and attestation requests. It can be removed at any time, and security posture checks for Teams itself come through the read-only Microsoft 365 connection.

Does the Teams integration run security checks?

Teams security posture is covered by the Microsoft 365 integration's native checks. The Teams app itself is the workflow surface: briefings, evidence ingestion, and attestations, all recorded and filed to controls.

What are the steps to implement SOC 2 with Microsoft Teams?

Have your administrator install the Screenata Teams app with the scopes for messages, evidence ingestion, and attestation requests. Route the daily readiness briefing to the channel the people who act on it already read. Send evidence requests in Teams so the long-tail artifacts land where the work happens instead of in a chat scrollback. Capture policy acknowledgments per person and let escalation chase the ones that go unanswered. Every delivery, submission, and acknowledgment is recorded as evidence with a timestamp. Teams is where requests and attestations are delivered and recorded; security posture checks for Teams itself run through the read-only Microsoft 365 connection. Then hand the assembled package to an independent auditor. The audit is a separate engagement with a CPA firm; Screenata prepares the evidence and does not issue the report.

Can compliance evidence be collected through Microsoft Teams?

Yes. Files dropped in the conversation are ingested, classified, and filed to the control they evidence, signed and timestamped like evidence from any other source. Policy acknowledgments requested in Teams are recorded per person, so the acknowledgment log auditors sample is built as people respond rather than reconstructed later.

Do auditors accept evidence Screenata collects from Microsoft Teams?

Yes. Every finding is exported as a signed, timestamped artifact, a SHA-256 hash with an RSA or ECDSA signature and an RFC 3161 timestamp, that an auditor verifies outside Screenata with a free CLI. A person reviews and approves the evidence before it reaches the auditor. Screenata collects and signs it; it does not decide the audit result.

Connect and see

Fifteen minutes after connecting Microsoft Teams, you know your real posture.

Pricing

Related: Slack · Microsoft 365 · Azure · Azure DevOps