Office 365 CDN compliance standards

%3CLINGO-SUB%20id%3D%22lingo-sub-64888%22%20slang%3D%22en-US%22%3EOffice%20365%20CDN%20compliance%20standards%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-64888%22%20slang%3D%22en-US%22%3E%3CP%3EWe%20have%20some%20concerns%20for%20a%20client%20that%20is%20using%20Office%20365%20and%20we%20were%20going%20to%20enable%20the%20Office%20365%20CDN%20(Private)%2C%20however%20we%20noticed%20the%20warning%20message%20that%20it%20is%20a%20feature%20built%20on%20a%203rd-party%20application%20and%20data%20center%20owned%20by%20the%203rd%20party%20with%20privacy%20and%20compliance%20standards%20that%20differ%20from%20the%20commitments%20outlined%20by%20Microsoft%20O365%20Trust%20Center.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ECan%20we%20get%20more%20detail%20on%20this%203rd%20party%20CDN%20provider%20and%20what%20compliance%20standards%20they%20have%3F%20Our%20client%20has%20certain%20regulatory%20compliance%20that%20needs%20to%20be%20met%20and%20we%20need%20to%20verify%20if%20the%203rd%20party%20CDN%20would%20satisfy%20their%20requirements.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThanks%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-72802%22%20slang%3D%22en-US%22%3ERe%3A%20Office%20365%20CDN%20compliance%20standards%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-72802%22%20slang%3D%22en-US%22%3E%3CP%3EWe%20have%20the%20same%20issue%20-%20I%20need%20specifics%20on%20what%20compliance%26nbsp%3B%2F%20security%20policies%26nbsp%3Bthe%20Private%20CDN%20offers.%26nbsp%3B%20Do%20we%20have%20an%20official%20document%20anywhere%3F%26nbsp%3B%20It's%20unlikely%20our%20compliance%20department%20will%20accept%20%22probably%20Akamai%22.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-70547%22%20slang%3D%22en-US%22%3ERe%3A%20Office%20365%20CDN%20compliance%20standards%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-70547%22%20slang%3D%22en-US%22%3E%3CP%3EThanks!%20I%20had%20figured%20it%20was%20probably%20Akamai%20networks.%3C%2FP%3E%3CP%3EI%20was%20concerned%20however%20about%20the%20warning%20that%20appears%20when%20you%20enable%20the%20O365%20CDN%20through%20PowerShell%20about%20it%20not%20being%20covered%20by%20their%20data%2Fsecurity%20policies%20and%20it%20was%20a%203rd%20party%20when%20dealing%20with%20a%20client%20that%20has%20regulatory%20requirements.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-70539%22%20slang%3D%22en-US%22%3ERe%3A%20Office%20365%20CDN%20compliance%20standards%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-70539%22%20slang%3D%22en-US%22%3EHowdy!%20The%20two%20most%20common%20CDN's%20Office%20365%20uses%20are%20Akamai%20and%20Azure.%20Please%20see%20this%20page%20on%20how%20CDN's%20work%20in%20Office%20365%20%3CA%20href%3D%22https%3A%2F%2Faka.ms%2Fo365cdns%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Faka.ms%2Fo365cdns%3C%2FA%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-70535%22%20slang%3D%22en-US%22%3ERe%3A%20Office%20365%20CDN%20compliance%20standards%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-70535%22%20slang%3D%22en-US%22%3E%3CP%3EI%20do%20not%20know%20who%20they%20use%20for%20the%20SPO%20CDN%20capability.%20%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWhat%20I%20do%20know%20is%20that%20if%20you%20are%20using%20an%20Azure%26nbsp%3BCDN%2C%20the%20providers%20are%20Akamai%20and%20Verizon.%20%26nbsp%3BBoth%20are%20listed%20on%20the%20pricing%20page%20for%20the%20Azure%20CDN.%20%26nbsp%3BI'd%20be%20surprised%20if%20it%20is%20not%20one%20of%20those.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CA%20title%3D%22Azure%20Content%20Delivery%20Network%20(CDN)%20Pricing%22%20href%3D%22https%3A%2F%2Fazure.microsoft.com%2Fen-us%2Fpricing%2Fdetails%2Fcdn%2F%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%22%3EAzure%20Content%20Delivery%20Network%20(CDN)%20Pricing%3C%2FA%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-70339%22%20slang%3D%22en-US%22%3ERe%3A%20Office%20365%20CDN%20compliance%20standards%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-70339%22%20slang%3D%22en-US%22%3EBUMP%20-%20Can%20anyone%20provide%20insight%20on%20the%203rd%20party%20used%20for%20the%20CDN%3F%3C%2FLINGO-BODY%3E
Highlighted
Occasional Contributor

We have some concerns for a client that is using Office 365 and we were going to enable the Office 365 CDN (Private), however we noticed the warning message that it is a feature built on a 3rd-party application and data center owned by the 3rd party with privacy and compliance standards that differ from the commitments outlined by Microsoft O365 Trust Center.

 

Can we get more detail on this 3rd party CDN provider and what compliance standards they have? Our client has certain regulatory compliance that needs to be met and we need to verify if the 3rd party CDN would satisfy their requirements.

 

Thanks

5 Replies
Highlighted
BUMP - Can anyone provide insight on the 3rd party used for the CDN?
Highlighted

I do not know who they use for the SPO CDN capability.  

 

What I do know is that if you are using an Azure CDN, the providers are Akamai and Verizon.  Both are listed on the pricing page for the Azure CDN.  I'd be surprised if it is not one of those.

 

Azure Content Delivery Network (CDN) Pricing

Highlighted
Howdy! The two most common CDN's Office 365 uses are Akamai and Azure. Please see this page on how CDN's work in Office 365 https://aka.ms/o365cdns
Highlighted

Thanks! I had figured it was probably Akamai networks.

I was concerned however about the warning that appears when you enable the O365 CDN through PowerShell about it not being covered by their data/security policies and it was a 3rd party when dealing with a client that has regulatory requirements.

Highlighted

We have the same issue - I need specifics on what compliance / security policies the Private CDN offers.  Do we have an official document anywhere?  It's unlikely our compliance department will accept "probably Akamai".