Integrations / Communication
How do you use Microsoft Teams for SOC 2 and HIPAA compliance?
Quick answer
Microsoft Teams is the surface the compliance program runs on, not a scanned system. It is where briefings land, where evidence gets ingested, and where attestations get chased. A policy existing is not the control. The control is the enforced setting plus the record that it operated for every person across the audit period, which is why the acknowledgment log matters as much as the policy document. Screenata uses Teams to deliver briefings, request evidence, and chase policy attestations, and records that activity as evidence.
Screenata connects to Microsoft Teams as a workflow surface: daily briefings, evidence files ingested and classified where they are dropped, and policy attestation requests chased to completion. Workspace security posture for Teams itself is scanned through the Microsoft 365 integration, so one connection pair covers both the checks and the workflow.
Read-only · signed evidence
What it proves
Microsoft Teams evidence, mapped to controls.
Daily readiness briefings and escalations delivered in Teams, so compliance status reaches the people who act on it.
A recorded trail of what was reported and when, evidencing that compliance information flows to the team.
Files dropped in Teams are ingested, auto-classified, and filed to the control they evidence.
Long-tail evidence captured where it appears instead of lost in a chat scrollback, signed like any other artifact.
Policy acknowledgment requests sent and chased in Teams, with acknowledgments recorded per person.
The acknowledgment log auditors sample: who was asked, who acknowledged, and when.
Control references are the requirements each evidence area supports, via the shared control catalog. Your auditor decides sufficiency; the artifacts are theirs to verify.
How it connects
Read-only, revocable, yours.
Read-only by construction
OAuth scopes and IAM roles are scoped to read. Vera never gets write access to your systems.
Signed findings
SHA-256 per artifact, RSA/ECDSA signatures, RFC 3161 timestamps. Verifiable without a Screenata account.
Mapped to controls
Each finding lands on the shared control catalog, so one scan satisfies SOC 2, HIPAA, and ISO 27001 at once.
BAA & attestation status
Microsoft offers a BAA covering in-scope Microsoft 365 services including Teams on eligible business and enterprise plans. That covers Microsoft's own layer. Tenant configuration and retention remain your responsibility, and you have to evidence that those settings operated.
What access does Screenata need to Microsoft Teams?
The Screenata Teams app, installed by your administrator, with the scopes needed for messages, evidence ingestion, and attestation requests. It can be removed at any time, and security posture checks for Teams itself come through the read-only Microsoft 365 connection.
Does the Teams integration run security checks?
Teams security posture is covered by the Microsoft 365 integration's native checks. The Teams app itself is the workflow surface: briefings, evidence ingestion, and attestations, all recorded and filed to controls.
What are the steps to implement SOC 2 with Microsoft Teams?
Have your administrator install the Screenata Teams app with the scopes for messages, evidence ingestion, and attestation requests. Route the daily readiness briefing to the channel the people who act on it already read. Send evidence requests in Teams so the long-tail artifacts land where the work happens instead of in a chat scrollback. Capture policy acknowledgments per person and let escalation chase the ones that go unanswered. Every delivery, submission, and acknowledgment is recorded as evidence with a timestamp. Teams is where requests and attestations are delivered and recorded; security posture checks for Teams itself run through the read-only Microsoft 365 connection. Then hand the assembled package to an independent auditor. The audit is a separate engagement with a CPA firm; Screenata prepares the evidence and does not issue the report.
Can compliance evidence be collected through Microsoft Teams?
Yes. Files dropped in the conversation are ingested, classified, and filed to the control they evidence, signed and timestamped like evidence from any other source. Policy acknowledgments requested in Teams are recorded per person, so the acknowledgment log auditors sample is built as people respond rather than reconstructed later.
Do auditors accept evidence Screenata collects from Microsoft Teams?
Yes. Every finding is exported as a signed, timestamped artifact, a SHA-256 hash with an RSA or ECDSA signature and an RFC 3161 timestamp, that an auditor verifies outside Screenata with a free CLI. A person reviews and approves the evidence before it reaches the auditor. Screenata collects and signs it; it does not decide the audit result.
Connect and see
Fifteen minutes after connecting Microsoft Teams, you know your real posture.
Related: Slack · Microsoft 365 · Azure · Azure DevOps