Is Dynamics 365 secure? 9 facts to reassure your IT team

Jacek Szafader Jacek Szafader May 15, 2025
Migrating your CRM to the cloud sounds tempting, but the first questions from the security team are always the same: Where will our data be stored? Who protects it? Will we pass audits?

In this article, we’ve gathered the key facts about certifications, data center locations, backup procedures, and incident response in Dynamics 365 Sales, Customer Insights, and Customer Service. No marketing fluff — just straight answers to help you make an informed decision.

1. Why trust Dynamics 365?

Microsoft builds its business apps on the same infrastructure that powers Azure. This means:

2. Certifications - who audits Microsoft and what do they confirm?

Abbreviation

ISO / IEC 27001

Guarantees
Information security management system
Why it matters
One of the most recognized global standards – it confirms a process-based approach to data protection.

SOC 1 & SOC 2

Independent auditor reports (operational controls)
Transparent proof of how Microsoft meets confidentiality, availability, and integrity requirements.

PCI DSS

Payment card industry standard
Crucial if you store or process transactional data.

HIPAA, FedRAMP

US health and public sector compliance
Proof that the platform meets strict regulatory compliance tests.

3. Where is your data actually stored?

You choose the region when setting up the service – for Polish companies it’s usually Europe (e.g. crm4.dynamics.com).

No cross-continental replication – data and backups stay within your chosen macro-region (Europe, US, APAC, etc.).

Geo-redundancy within the region – backups are stored in Availability Zones to ensure continuity in case of data center failure.

Region changes are only possible during tenant-to-tenant migration – so choose carefully from the start.

4. Physical data center security

These procedures are verified during ISO 27001 and SOC audits.

5. Encryption – at rest and in transit

Data at rest: