21 CFR Part 11 Compliance with Microsoft 365 and SharePoint
By Thomas Brünger, Managing Partner
Microsoft 365 and SharePoint are widely used to hold documents that fall under FDA 21 CFR Part 11 — standard operating procedures, validation documents, quality records, and controlled forms. On their own they are not 21 CFR Part 11 compliant. The platform provides the building blocks for compliant electronic records and signatures; Part 11 compliance is achieved by configuring those controls for a defined use and validating them, and by dividing responsibility correctly between Microsoft and your organisation.
This article covers what SharePoint and Microsoft 365 can and cannot satisfy natively, the responsibility split, and what a defensible configuration looks like. It focuses on the document and content stack (SharePoint, Microsoft 365, Word); for Part 11 controls inside the ERP itself, see 21 CFR Part 11 and Business Central.
What 21 CFR Part 11 requires
Part 11 applies when electronic records are used to meet an FDA requirement that would otherwise be met on paper. For a document platform, the core requirements are:
- Attributable, tamper-evident audit trail — who did what, when, captured automatically and protected from alteration or deletion.
- Electronic signatures that are unique to one individual, not reused or reassigned, linked to the signed record, and that capture the meaning of the signature.
- Access controls and authority checks — least privilege, no shared accounts, and control over who can perform which action.
- Record integrity and retention across the lifecycle — creation, change, retention, and controlled disposition.
- Validation demonstrating the system performs consistently and as intended for its use.
What Microsoft 365 and SharePoint provide natively
The platform gives you the raw controls to build against these requirements:
- Identity — Microsoft Entra ID as a single identity provider, with conditional access and multi-factor authentication, removes shared logins and underpins attributability.
- Version history — SharePoint retains major and minor versions of a document, so the change history of a controlled document is recoverable.
- Approval and signature — Power Automate approval flows and SharePoint eSignature capture authenticated approvals; Adobe Acrobat Sign and DocuSign integrations add signature-page semantics.
- Audit logging — the Microsoft Purview unified audit log records access and activity across SharePoint and Microsoft 365.
- Retention and records management — Purview retention labels and policies, and the records-management features (declaring items as records, Preservation Lock), control retention and disposition.
- Information protection — sensitivity labels and data loss prevention constrain how controlled content is shared.
What is not satisfied out of the box
The gap is always configuration, control, and evidence:
- The audit trail must be scoped and protected. The unified audit log exists, but you have to define which activities are Part 11-relevant, confirm the retention of the log itself is sufficient, and ensure it cannot be altered — including by highly privileged administrators. A site collection administrator with unmanaged rights is an audit finding, not a control.
- Version history is not an audit trail. Version history can be turned off or trimmed by a user with the right permissions; a Part 11 audit trail must be automatic and tamper-evident. The two work together but are not the same control.
- Signatures must be configured to Part 11 semantics. Re-authentication at the point of signing, the recorded meaning of the signature, and protection of the signed record from later modification are configuration outcomes, not defaults.
- Retention has to be locked. Retention labels can be changed unless records management and Preservation Lock are applied; a defensible configuration removes the ability to quietly shorten or delete a GxP record.
- A Word file alone is not a record. Word becomes part of a compliant record only inside a controlled library with the controls above; the document management system carries the compliance, not the authoring tool.
Who is responsible — Microsoft or you
Part 11 in Microsoft 365 is a shared responsibility:
- Microsoft provides and qualifies the platform — the data-centre, security, and availability controls — and documents them. This is supplier qualification input, not a substitute for your validation.
- Your organisation is responsible for how the service is configured, controlled, used, and validated for its GxP records: the audit-trail scope, the access model, retention locks, the signature controls, user training, and the documented evidence that the configured system performs as intended.
Treat Microsoft's platform controls as an input to your supplier assessment, and validate your configuration and intended use on top of it.
A defensible configuration, in short
- Entra ID as the sole identity provider, least-privilege access, no shared accounts, privileged access reviewed.
- The Purview unified audit log confirmed on, scoped to Part 11-relevant activity, with adequate and protected retention.
- Controlled document libraries with version history, controlled by records management where the content is a GxP record.
- Retention and disposition governed by Purview retention/records policies, with Preservation Lock where deletion must be prevented.
- Electronic signatures (SharePoint eSignature, approval flows, or an integrated signature provider) configured for uniqueness, re-authentication, record linkage, and recorded meaning.
- A validation package — requirements, risk assessment, and testing — covering the configuration and its intended use.
Related reading
- 21 CFR Part 11 and Business Central — the same requirements applied to ERP records inside Business Central.
- GxP validation for Business Central — the validation lifecycle these controls are validated against.
- Is Business Central 21 CFR Part 11 compliant? — the short answer for the ERP layer.
Mapping Part 11 across a mixed Microsoft estate — ERP, SharePoint, and Microsoft 365 — is an architecture and documentation exercise as much as a configuration one. A focused architecture governance engagement can establish where the controls and their evidence sit before an inspection.
Frequently asked questions
- Is SharePoint 21 CFR Part 11 compliant out of the box?
- No. SharePoint and Microsoft 365 are not 21 CFR Part 11 compliant out of the box. The platform provides the building blocks — version history, document approval, retention and records management, a unified audit log, and identity through Entra ID — but Part 11 compliance is achieved by configuring those controls for a defined use and validating them. Microsoft qualifies the platform; the regulated company validates its configuration and use.
- Can you use Microsoft Word for Part 11 electronic records?
- A Word document on its own is not a Part 11 record — it can be edited without an attributable, tamper-evident audit trail. Word becomes part of a compliant record when it is managed inside a controlled SharePoint or records library with version history, controlled access, an audit trail, and, where the process requires a signed record, a validated electronic signature. The control lives in the document management system, not in Word itself.
- Does SharePoint have electronic signatures for Part 11?
- SharePoint eSignature and Power Automate approvals can capture an authenticated, attributable approval, and integrations with Adobe Acrobat Sign or DocuSign add signature-page semantics. For Part 11 the signature still has to be configured so it is unique to one individual, re-authenticated at the point of signing, linked to the specific record, records its meaning (review, approval, responsibility), and cannot be copied or reused. Those are configuration and validation outcomes, not defaults.
- Who is responsible for Part 11 compliance in Microsoft 365 — Microsoft or the customer?
- It is a shared responsibility. Microsoft provides and qualifies the underlying platform and its security and data-centre controls. The regulated company is responsible for how it configures, controls, uses, and validates the service for its GxP records — audit trail scope, access model, retention locks, signature controls, and the documented evidence that the system performs as intended.