What is Microsoft 365 Data Residency?

Data Residency refers to the geographic location where an organization's data is stored or processed. For Microsoft 365, Data Residency defines where your Customer Data is kept within Microsoft's global datacenter infrastructure.

Organizations increasingly need to know—and often control—where their data resides. Microsoft 365 offers several options to help meet these requirements.

For definitions of terms used in this article, see Key terms and definitions.

Data at rest

Data at Rest refers to data that is stored persistently in a specific location, such as in databases, file systems, or cloud storage. This is distinct from data that is actively moving across a network or being processed.

For the Microsoft 365 services covered by this article, Microsoft determines where to store your Data at Rest based on two primary factors:

  1. The Default Geography of your Microsoft 365 Tenant - When your organization creates a Microsoft 365 Tenant, a country or region is provided during sign-up. This country or region establishes the Default Geography for Microsoft 365 services.

  2. Available Geographies for each service - Microsoft 365 services are deployed across datacenters worldwide, but not all services are available in every location. The provisioning logic uses the Default Geography combined with service availability to determine where data is stored.

Note

This article describes Data Residency for Microsoft 365 services. Dynamics 365 and Power Platform have separate data residency behavior and documentation. For more information, see Microsoft Dynamics 365 and Power Platform data residency documentation.

Data in processing

Data in processing refers to data that is actively being used, computed, or transformed by a service—as opposed to data sitting in storage. While Data at Rest focuses on where data is stored, data in processing addresses where computational operations occur.

For example, Microsoft 365 Copilot processes prompts and generates responses. With the appropriate configuration, this processing occurs within the same geographic boundary as your stored data, helping organizations meet data handling requirements that extend beyond storage.

Note

Detailed documentation for data in processing is coming soon.

Why data residency matters

Organizations consider Data Residency for several reasons:

  • Regulatory compliance - Many industries and jurisdictions have regulations that require data to be stored within specific geographic boundaries. Examples include GDPR in the European Union, data localization laws in certain countries or regions, and sector-specific regulations in healthcare and finance.

  • Data sovereignty - Governments and public sector organizations often require that citizen data remain within national borders, subject to local laws and oversight.

  • Organizational policy - Some organizations establish internal policies about data location based on risk management, customer commitments, or business strategy.

  • Customer and stakeholder expectations - End customers and business partners may require assurances about where their data is stored as part of contractual agreements.

Microsoft 365 provides multiple options to address these considerations, ranging from default commitments included with your subscription to add-on services that provide expanded geographic control.

Microsoft 365 Durable Commitments on Data Location

There are three methods for ensuring that the Tenant data location for a particular Microsoft 365 service doesn't change.

  1. Product Terms: See the Product Terms Data Residency page for specific details.
  2. Multi-Geo subscription: allows customers to assign data location for Exchange Online, SharePoint, OneDrive, Microsoft Teams, and Microsoft 365 Copilot and Microsoft 365 Copilot Chat to any supported Geography. For specific commitments, see Multi-Geo Capabilities data commitments.
  3. Advanced Data Residency subscription: provides Data Residency commitments for certain Microsoft 365 Core Services and Microsoft 365 Expanded Services in Local Region Geographies. Refer to Advanced Data Residency: Data commitments for specific eligibility and commitments.

For detailed comparisons, see Service coverage by offering and Data residency commitments by Geography. For datacenter city locations, see Microsoft 365 datacenter locations.

General data and privacy FAQ

The following questions cover broader data, privacy, and security topics. For more information about these topics, see the Microsoft Trust Center. For data location–specific questions, see Data Location FAQ.

How does Microsoft define data?

Select to expand

Review our definitions for different types of customer data on the Microsoft Trust Center. In the Product Terms, Microsoft makes contractual commitments regarding Customer Data/your Tenant and user data. We refer to Customer Data as the Customer Data that is committed to be stored at rest only within a Tenant's region according to the Product Terms.

Does the location of your customer data have a direct impact on your end users' experience?

Select to expand

The performance of Microsoft 365 isn't simply proportional to a Tenant user's distance to data center locations. Microsoft's continued investments in its global cloud network, global cloud infrastructure, and the Microsoft 365 services architecture help provide users with a singular, consistent experience independent of where Customer Data is stored at rest. If your users are experiencing performance issues, you should troubleshoot those in depth. Microsoft has published guidance for Microsoft 365 customers to plan for and optimize end-user performance on the Office Support web site.

How does Microsoft help me comply with my national, regional, and industry-specific regulations?

Select to expand

To help a Tenant comply with national, regional, and industry-specific requirements governing the collection and use of individuals' data, Microsoft 365 offers the most comprehensive set of compliance offerings of any global cloud productivity provider. Review our compliance offerings and more details in the Microsoft Purview section on the Microsoft Trust Center. Also, certain Microsoft 365 plans offer further compliance solutions to help a Tenant manage their data, comply with legal and regulatory requirements, and monitor actions taken on their data.

Who can access your data and according to what rules?

Click to expand

Microsoft implements strong measures to help protect a Tenant's Customer Data from inappropriate access or use by unauthorized persons. This includes restricting access by Microsoft personnel and subcontractors, and carefully defining requirements for responding to government requests for Customer Data. However, you can access your Tenant's Customer Data at any time and for any reason. More details are available on the Microsoft Trust Center.

Does Microsoft access your data?

Select to expand

Microsoft automates most Microsoft 365 operations while intentionally limiting its own access to Customer Data. This helps us manage Microsoft 365 at scale and address the risks of internal threats to Customer Data. By default, Microsoft engineers have no standing administrative privileges and no standing access to Customer Data in Microsoft 365. A Microsoft engineer may have limited and logged access to Customer Data for a limited amount of time, but only when necessary for normal service operations and only when approved by a member of senior management at Microsoft (and, for customers who are licensed for the Customer Lockbox feature, by the customer).

How does Microsoft secure your data?

Select to expand

Microsoft has robust policies, controls, and systems built into Microsoft 365 to help keep your information safe. Review the Microsoft 365 security section on the Microsoft Trust Center to learn more.

Does Microsoft 365 encrypt your data?

Select to expand

Microsoft 365 uses service-side technologies that encrypt customer Data at Rest and in transit. For customer Data at Rest, Microsoft 365 uses volume-level and file-level encryption. For Customer Data in transit, Microsoft 365 uses multiple encryption technologies for communications between data centers and between clients and servers, such as Transport Layer Security (TLS) and Internet Protocol Security (IPsec). Microsoft 365 also includes customer-managed encryption features.

Why do I see my Microsoft 365 service requests for my data at rest connecting to servers in countries or regions outside of my region?

Click to expand

On occasion, a customer request may be handled by servers in a different region than the location where a Tenant's Customer Data is stored at rest. This may happen where network routing decisions choose a different server for the request processing, but in these cases such Tenant's Customer Data is not moved to a new at rest location.

Next steps