Does the information that I allow azure open ai service to access stay inside my tenant?

Kevin M 20 Reputation points
2025-10-22T22:49:49.5766667+00:00

Could you provide links to materials that discuss the data security related to using the azure open ai service? Should I feel like data that I provide to the azure open ai service is as secure on my tenant as data that I have stored on a sharepoint folder inside my tenant?

Azure OpenAI Service
Azure OpenAI Service
An Azure service that provides access to OpenAI’s GPT-3 models with enterprise capabilities.
0 comments No comments
{count} votes

Answer accepted by question author
  1. SRILAKSHMI C 8,295 Reputation points Microsoft External Staff Moderator
    2025-10-23T02:17:35.5233333+00:00

    Hello Kevin M,

    Welcome to Microsoft Q&A and thank you for reaching out.

    It sounds like you’re concerned about the data security and privacy of the information you provide when using the Azure OpenAI Service. That’s an excellent question especially when comparing it to data stored securely within your tenant (for example, in SharePoint).

    Data Security in Azure OpenAI

    Azure OpenAI is built on the same enterprise-grade security, compliance, and privacy framework as all other Azure services. Here are the key points about how your data is handled:

    Data Isolation: Your prompts, completions, and any uploaded or fine-tuned data remain exclusive to your tenant. They are not accessible to other customers and are not used by Microsoft or OpenAI to train or improve models without your explicit consent.

    Data Residency & Encryption: Data is stored and processed within your selected Azure region, protected by encryption at rest and in transit using Microsoft-managed keys or your own key (if configured via customer-managed key options).

    Compliance: Azure OpenAI adheres to Microsoft’s comprehensive security and compliance framework, which includes certifications such as SOC, ISO, HIPAA, and GDPR.

    Authentication & Access Control: You can control access using Microsoft Entra ID (Azure AD), role-based access control (RBAC), and private networking options like VNets and private endpoints for full network isolation.

    Comparing to SharePoint Security

    From a data protection standpoint, Azure OpenAI data is secured to the same level as your SharePoint data within your tenant:

    Both services operate under the same Microsoft Trust Boundary and Azure compliance commitments.

    Both ensure logical isolation of your data from other tenants.

    Both follow identical encryption, access control, and privacy policies.

    So yes, when properly configured (especially with private networking and regional deployment), you can feel as confident in the security of your Azure OpenAI data as you do with data stored in SharePoint.

    For deeper details, please refer this official Microsoft documents you can review and share with your security team:

    1. Data Retention Policies in Azure OpenAI
    2. FAQs on Azure OpenAI Data and Privacy
    3. Data, privacy, and security for Azure Direct Models in Azure AI Foundry
    4. Enterprise trust in Azure OpenAI Service strengthened with Data Zones
    5. Azure security baseline for Azure OpenAI

    I Hope this helps. Do let me know if you have any further queries.


    If this answers your query, please do click Accept Answer and Yes for was this answer helpful.

    Thank you!

    0 comments No comments

0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.