Skip to main content
io4 Technologies

io4 glossary

63 Microsoft, Law 25 and cybersecurity definitions.

A reference lexicon for Québec decision-makers. Microsoft terms (Copilot, Defender XDR, Purview, Fabric), Law 25 (Privacy Officer, PIA, CAI, articles 12.1 / 17 / 27 / 93.1), cybersecurity (SOC, EDR, MDR, MTTR), public sector (SEAO, AMP, Treasury Board).

Category

Microsoft

Azure Reserved Instances

RI

A 1- or 3-year commitment on a stable Azure VM or service in exchange for a discount of up to 72% off the pay-as-you-go rate.

1 year: typically 30–40% off. 3 years: 55–72%. Not suitable for workloads that will migrate within 12 months. For variable workloads, prefer Azure Savings Plans (up to 65% off, more flexible, introduced in Oct. 2022).

Azure Virtual Desktop

AVD

Microsoft's virtualized desktop and app service in Azure, accessible remotely from any device.

AVD (and its Windows 365 / Cloud PC variant) centralizes sensitive data and apps in Azure rather than on endpoints, strengthening security and enabling remote work. Data stays hosted in the chosen Azure region (Canada), an asset for Law 25 compliance and organizations with remote sites.

Canada Central / Canada East

The two Microsoft Azure regions in Canada — Toronto (Canada Central) and Québec City (Canada East).

Canada Central has Availability Zones (high availability); Canada East does not. By default, Microsoft 365 hosts the tenant in Canada Central for Canadian organizations. For health information and certain Québec public bodies, Canada East is preferred.

Conditional Access

A set of access rules in Entra ID that evaluates context (user, device, location, risk) before allowing a sign-in.

It can require MFA, block legacy protocols (POP/IMAP/SMTP basic auth), restrict by country, and require an Intune-compliant device. It is the foundation of Zero Trust on Microsoft 365.

Copilot Studio

Microsoft's low-code platform for building custom AI agents connected to Dataverse, SharePoint and business APIs, accessible from Teams or a website.

2025 pricing: US$200/pack/month = 25,000 Copilot Credits, or pay-as-you-go at US$0.01/credit. Typical use cases: HR assistant, Tier 1 IT support, product-catalog FAQ, access to business data without custom development.

Exchange Online

Microsoft 365's cloud email and calendar service, successor to on-premise Exchange servers.

Exchange Online integrates Defender for Office 365 (anti-phishing, Safe Links, Safe Attachments) and Purview compliance policies. Microsoft is progressively retiring legacy protocols (Basic Auth, EWS): migrating to modern authentication and Microsoft Graph is a security project to plan.

Microsoft 365 Business Premium

A Microsoft 365 license for organizations of up to 300 users, combining the Office suite, Intune, Entra ID P1 and Defender for Business.

Business Premium is capped at 300 users and offers the best value/security ratio for an SMB: it covers most cyber-insurance and Law 25 requirements (MFA, encryption, device management). Beyond 300 users, or for advanced document governance, you move to E3 — and to E5 for advanced security (Defender for Endpoint P2, Entra ID P2).

Microsoft 365 Copilot

A generative-AI assistant built into Word, Excel, Outlook, Teams and SharePoint that draws on Microsoft Graph to access the organization's data.

Launched in 2023, Microsoft 365 Copilot requires a license at US$30/user/month (annual commitment) on top of a Microsoft 365 E3/E5/Business Premium or Office 365 E1/E3/E5 base. An SMB variant (Copilot Business) is offered at US$21. The tool requires a prior SharePoint oversharing audit to prevent it from surfacing historically overshared content.

Microsoft 365 Copilot Cowork

Microsoft's “agentic” system that plans and executes a whole task end to end, delivering a finished result rather than a draft.

Generally available worldwide since June 2026, Copilot Cowork runs multi-step tasks across Outlook, Teams, Word, Excel, PowerPoint and SharePoint, using “Work IQ” to ground the work in the organization's real context. It runs on usage-based billing (credits), steerable via a cost dashboard in the Microsoft 365 admin center.

Microsoft Agent 365

Microsoft's platform to register, secure and govern an organization's AI agents, with each agent receiving an identity via Entra Agent ID.

Available since May 2026, Agent 365 addresses “shadow AI” — the sprawl of agents created by teams without oversight. It applies the same controls to agents as to users — identity (Entra Agent ID), conditional access, logging — making agent governance a top security priority.

Microsoft Azure

Azure

Microsoft's cloud platform, offering compute, storage, networking, databases and AI services on demand, billed by usage.

Azure hosts virtual machines, applications, data and AI workloads across global regions, including Canada Central (Toronto) and Canada East (Québec) for data residency. Cost control (FinOps), multi-subscription governance and security (Defender for Cloud) are the key challenges of a healthy Azure environment.

Microsoft Defender XDR

XDR

An eXtended Detection and Response platform that automatically correlates endpoint, identity, email and cloud-app signals.

Microsoft Defender XDR brings together Defender for Endpoint, Defender for Identity, Defender for Office 365 and Defender for Cloud Apps. Included in Microsoft 365 E5 and Business Premium (lighter versions). Microsoft analyzes more than 100 trillion signals per day (Digital Defense Report 2025), which feed detection for every client.

Microsoft Entra ID

Entra ID

Microsoft's cloud identity service (formerly Azure Active Directory) that manages authentication, conditional access and identity governance.

Entra ID includes Conditional Access, MFA, Privileged Identity Management (PIM, P2 license), Identity Protection and SSO federation. It is the cornerstone of the Microsoft security posture: universal MFA + blocking legacy authentication via Conditional Access eliminates more than 99% of account compromises, according to Microsoft.

Microsoft Fabric

Microsoft's unified SaaS analytics platform (GA late 2023) combining lakehouse, data warehouse, data science, real-time analytics and Power BI.

Built around a shared OneLake storage (Delta Parquet). Capacity SKUs from F2 to F2048. F8 ≈ US$1,050/month, F16 ≈ US$2,100/month (pay-as-you-go), about 40% off with a 1-year reservation. Copilot for Power BI requires F64+.

Microsoft Graph

The unified Microsoft 365 API providing permissioned access to users' data and signals (emails, files, calendar, identities, activity).

Microsoft Graph is the foundation Microsoft 365 Copilot relies on to reason over the organization's data, respecting each user's existing permissions. This is precisely why a SharePoint oversharing audit is required before deploying Copilot: Graph only surfaces what the user already has access to.

Microsoft Intune

Microsoft's cloud service for device management (MDM) and application management (MAM), enforcing security, compliance and encryption policies on desktops and mobile devices.

Part of the Microsoft Intune Suite and included in Microsoft 365 Business Premium, E3 and E5, Intune enrolls Windows, macOS, iOS and Android devices, requires a compliant device via Entra ID Conditional Access, deploys apps and patches, and remotely wipes a lost device. It is the foundation of modern endpoint management, replacing or complementing SCCM.

Microsoft Power Platform

Microsoft's low-code suite bringing together Power Apps, Power Automate, Power BI, Power Pages and Copilot Studio to build apps, automations and dashboards.

The Power Platform runs on Dataverse and connects natively to Microsoft 365, Azure and hundreds of third-party connectors. It lets organizations automate business processes and build internal apps without heavy development, but requires governance (environments, DLP policies) to avoid uncontrolled sprawl.

Microsoft Purview

Microsoft's data-governance platform: classification, labeling (Sensitivity Labels), data-loss prevention (DLP), lifecycle management.

Purview is the go-to tool for Law 25 compliance on Microsoft 365: it can automatically label personal information, block it from being sent out via DLP policies, and produce the audit reports requested by the CAI. Available in Microsoft 365 E5 and as an add-on.

Microsoft Security Copilot

Microsoft's security-focused generative-AI assistant, helping analysts investigate, summarize and respond to incidents faster.

Security Copilot integrates with Defender XDR, Sentinel, Intune and Entra to speed up alert triage, threat hunting and incident reporting. Billed by capacity (Security Compute Units), it boosts a SOC's efficiency without replacing the human analyst — a multiplier, not an autopilot.

Microsoft Sentinel

Microsoft's cloud SIEM, a complement to Defender XDR for organizations with non-Microsoft logs or regulatory long-retention requirements.

Sentinel bills on ingestion (GB/day). For most SMBs, Defender XDR alone is enough; Sentinel becomes relevant when there are firewalls/IoT/OT/in-house applications, or for PCI-DSS, ISO 27001.

Power BI

Microsoft's analytics and data-visualization tool, turning varied sources into interactive, shareable dashboards.

Power BI comes as Power BI Pro (included in Microsoft 365 E5) and Power BI Premium/Fabric for large volumes. It integrates with Microsoft Fabric for data warehousing and engineering. Governance (Purview sensitivity labels, workspace management) is essential as soon as reports contain personal information.

Privileged Identity Management

PIM

An Entra ID feature (P2 license) that grants administrator privileges temporarily and with approval (just-in-time) rather than permanently.

PIM reduces the attack surface by removing standing admin rights: an administrator activates their role for a limited time, with justification, approval and logging. It is a key Zero Trust control and a frequent requirement of security audits and cyber-insurers.

SCCM (Configuration Manager)

SCCM

Microsoft's on-premise endpoint management tool (Microsoft Configuration Manager, formerly SCCM/ConfigMgr) for OS, application and patch deployment.

SCCM remains common in large organizations with sizable Windows estates and network or regulatory constraints. The trend is toward co-management with Microsoft Intune, then a gradual shift to cloud management. io4 supports this transition with no service interruption.

SharePoint Online

Microsoft 365's document-management and intranet platform, hosting sites, document libraries and collaborative content.

SharePoint Online underpins Teams and OneDrive files. Its governance — permissions, Purview sensitivity labels, site lifecycle — is decisive for security: poorly controlled external sharing or historical oversharing are the leading sources of personal-information leaks.

Category

Law 25

Anonymization and de-identification

Two distinct treatments: de-identification removes direct identifiers but remains reversible; anonymization makes identification irreversibly impossible.

Law 25 governs both: de-identified information remains personal information (still protected), whereas information anonymized per regulatory criteria falls outside the law's scope. Anonymization must follow recognized standards and be documented — a crucial distinction for analytics and AI projects.

Article 12.1 - Automated decisions

A Law 25 provision (in force since 22 September 2023) that governs decisions made exclusively by an automated system about a person.

If a decision is made 100% by a system (including Copilot or a Copilot Studio agent) without significant human intervention, the organization must: inform the person, allow them to know the factors involved, and allow them to request human review within 30 days. Concrete cases: automated résumé screening, lead scoring, price personalization.

Article 17 - Transfers outside Québec

A Law 25 provision (in force since Sept. 2023) that requires a prior assessment before any transfer of personal information outside Québec.

The assessment covers: the adequacy of legal protection in the destination jurisdiction, contractual measures imposed on the recipient, technical measures (encryption, access controls). Microsoft Azure Canada Central (Toronto) is considered a transfer outside Québec and must therefore be documented.

Commission d'accès à l'information du Québec

CAI

Québec's supervisory authority responsible for enforcing Law 25; it can impose administrative penalties of up to $10M without a trial.

Address: 2045 Stanley Street, Suite 900, Montreal QC H3A 2V4. Phone: 1 888 528-7741. Organizations must notify the CAI without delay in the event of a privacy incident presenting a risk of serious injury.

Confidentiality incident

Unauthorized access, use, disclosure or loss of personal information; Law 25 requires logging it and, where there is a risk of serious injury, reporting it.

Since September 2022, every organization must keep a confidentiality-incident register and notify the Commission d'accès à l'information (CAI) and affected individuals when the incident presents a risk of serious injury. A CAI-ready register and a response procedure are key deliverables of a Law 25 compliance program.

GDPR (General Data Protection Regulation)

GDPR

The European personal-data protection regulation (2018), often compared to Québec's Law 25, which it inspired on several requirements.

Law 25 and the GDPR share common principles (consent, right of access, portability, incident notification, accountability) but differ in scope and penalties. An organization operating in both Québec and Europe — like io4 clients on both sides of the Atlantic — must satisfy both, hosting data in the appropriate region (Azure Canada or Azure France).

Law 25

Québec law modernizing the protection of personal information in the private sector (CQLR c. P-39.1), phased in over three waves: September 2022, 2023 and 2024.

Formerly Bill 64. It imposes 11 main obligations: a designated Privacy Officer, a public policy, PIAs, an incident register, access/rectification/portability rights, transfers outside Québec, granular consent, automated decisions. Administrative penalties up to $10M or 2% of worldwide revenue. Criminal penalties up to $25M or 4%. Private civil remedies since Sept. 2023.

Personal information

Any information about a natural person that allows them to be identified, directly or indirectly — the core concept Law 25 protects.

The definition is broad: name, email, IP address, location data, device identifiers, plus sensitive information (health, biometrics, origin) subject to heightened requirements. An organization must know where this information resides in its Microsoft 365 environment — a mapping Purview helps produce — before it can protect it.

Personal information governance policy

A mandatory document (art. 3.2) describing the roles, responsibilities and processes governing the lifecycle of personal information in the organization.

Since September 2023, every organization must establish and publish governance policies and practices approved by the privacy officer (RPRP). They cover retention, destruction, internal roles and complaint handling — and are often the first deliverable of a Law 25 compliance mandate.

Privacy Impact Assessment

PIA

A mandatory assessment (s. 3.3 Law 25) to carry out before any new project involving personal information — a Copilot rollout, a CRM migration, a new HR application.

The PIA documents: the nature of the project, the types of personal information processed, the purposes, the retention period, security measures, any transfers, residual risks. It must be available to the CAI on request during an inspection.

Privacy Officer

RPRP

A person formally designated by the organization as the guarantor of Law 25 compliance; mandatory since 22 September 2022 (s. 3.1).

By default, the Privacy Officer is the most senior executive. They can delegate to a designated employee but remain accountable. Their name and contact details must be published (usually in the privacy policy). It is the simplest obligation and yet the one most often forgotten by SMBs.

Private civil remedies (art. 93.1)

A Law 25 provision (in force since Sept. 2023) that allows any aggrieved person to sue an organization directly in the civil courts.

Minimum punitive damages of $1,000 per aggrieved person, with no upper cap. Cumulative with the CAI's administrative penalties and penal sanctions. A significant risk for organizations hit by an unmanaged privacy incident.

Right to data portability (art. 27)

A right granted since 22 September 2024 to any person to receive their personal information in a structured, commonly used technological format.

Expected format: JSON, CSV, XML — available within 30 days. The organization may also be required to transfer the information directly to a third party designated by the person, subject to technical feasibility.

Sensitive personal information

Personal information that, by its nature (health, biometrics, origin, orientation) or context, carries a high expectation of privacy and requires heightened protection.

Law 25 requires express consent for sensitive information and proportionate security measures. Creating a bank of biometric characteristics must additionally be disclosed to the Commission d'accès à l'information. Labeling and compartmentalizing this data in Microsoft 365 (via Purview) is a compliance priority.

Category

Cybersecurity

AiTM (Adversary-in-the-Middle)

AiTM

An attack technique that intercepts post-MFA authentication tokens through a reverse proxy, thereby bypassing traditional MFA.

Sharply on the rise in 2024–2025. Countermeasures: phishing-resistant MFA (FIDO2 keys, Windows Hello), Conditional Access with sign-in risk, Defender for Office 365 anti-AiTM, ITDR monitoring. Microsoft 365 Business Premium already provides the necessary baseline.

Business Email Compromise (BEC)

BEC

An attack that impersonates an executive or supplier by email to divert a payment, without relying on malware.

BEC rests on manipulation and impersonation rather than malicious software, which makes it hard to detect. Defense combines phishing-resistant MFA, Defender for Office 365 rules, external-email tagging and dual-approval payment procedures. It is among the costliest attacks for SMBs.

Cyber-insurance

Insurance covering losses from a cybersecurity incident (ransomware, data breach, downtime), whose eligibility depends on minimum security controls.

Insurers now require verifiable prerequisites: MFA on all access, EDR/XDR deployed, immutable backups, patch management and an incident response plan. A posture audit (Secure Score, XDR) documents these controls and eases obtaining or renewing the policy at a reasonable premium.

DLP (Data Loss Prevention)

DLP

Technical policies that block sensitive data (SIN, bank account numbers, credit cards) from being sent out by email, sharing or printing.

On Microsoft 365, configured in Purview. Typical start: the preconfigured 'Canada Financial Data' policy to block card numbers and bank account numbers. A 30-day 'audit' mode to calibrate false positives before 'block' mode.

EDR (Endpoint Detection and Response)

EDR

A detection-and-response solution on workstations and servers. Microsoft Defender for Endpoint is the go-to EDR for Microsoft organizations.

Enabled in EDR in block mode, Defender automatically contains a compromised machine without human intervention. Included in Microsoft 365 Business Premium and E5.

Immutable backup

A backup copy that cannot be modified or deleted for a defined period, guaranteeing recovery even after a ransomware attack.

Ransomware targets backups first. An immutable backup (WORM, object lock, locked retention) ensures a clean copy survives. Combined with the 3-2-1 rule and regularly tested restores, it is the last line of defense and now a standard requirement of cyber-insurance policies.

ITDR (Identity Threat Detection and Response)

ITDR

Detection of threats targeting identities: impossible travel, MFA fatigue, abnormal privilege escalation, account compromise.

Covered by Microsoft Defender for Identity (formerly Azure ATP) and Entra ID Identity Protection. Combined with Defender for Endpoint to form Defender XDR.

Managed SOC (MDR)

MDR

Managed Detection and Response: an outsourced 24/7 security-incident monitoring service, with human triage and active containment.

Unlike an EDR alone (which detects without a human), a managed SOC provides analysts who handle alerts 24/7, dismiss false positives and run predefined remediation actions. io4 SOC operates on Microsoft Defender XDR with an average MTTR of ~8 minutes on a critical incident.

Microsoft Secure Score

A Microsoft score from 0 to 100 measuring the cybersecurity posture of a Microsoft 365 organization, which became the benchmark for Canadian cyber-insurers in 2026.

A non-hardened SMB typically starts at around 40/100. With 12 priority settings (universal MFA, blocking legacy auth, Defender for Office Preset, EDR in block mode, Sensitivity Labels), it reaches 80+ in 30–45 days. Beyond 85, the marginal points cost user friction without real security value.

MTTR / MTTD

Mean Time To Respond (MTTR) and Mean Time To Detect (MTTD): key SOC indicators. The shorter, the better.

Industry: median MTTD of about 204 days without a managed SOC (IBM 2024 report), MTTR about 73 days for full containment. With Defender XDR + io4 managed SOC: MTTR ~8 minutes on a critical incident thanks to automatic XDR correlation and 24/7 human action.

Multi-Factor Authentication (MFA)

MFA

An authentication method requiring at least two distinct factors (password + device or biometrics) that blocks nearly all account-compromise attacks.

According to Microsoft, enabling MFA eliminates over 99% of account-compromise attacks. Phishing-resistant MFA (FIDO2 keys, Windows Hello, passkeys) additionally protects against AiTM attacks. MFA is now a minimum requirement of cyber-insurance policies and a Law 25 compliance prerequisite.

Passwordless authentication (passkeys / FIDO2)

An authentication method that replaces the password with a device-bound cryptographic key (passkey, FIDO2, Windows Hello), resistant to phishing.

Passkeys eliminate password-theft risk and defeat AiTM attacks that bypass classic MFA. In the Microsoft ecosystem they rely on Entra ID, Windows Hello for Business and FIDO2 security keys. They are the recommended target for privileged accounts and, eventually, for all users.

Phishing

An attack technique that impersonates a trusted identity (email, SMS, website) to steal credentials or trigger a malicious action.

Phishing remains the #1 entry vector for incidents. Variants include spear phishing (targeted), BEC (business email compromise) and AiTM phishing that bypasses classic MFA. Defense combines Defender for Office 365 (Safe Links, Safe Attachments), phishing-resistant MFA and ongoing user awareness.

Principle of least privilege

A security principle whereby every user, device or agent is granted only the access strictly needed for their task, and nothing more.

Least privilege limits the blast radius of a compromised account. It is implemented via Entra ID roles, just-in-time access (PIM), periodic access reviews and SharePoint permission segmentation. It is one of the three pillars of Zero Trust, alongside explicit verification and assume-breach.

Ransomware

Malware that encrypts an organization's data and demands a ransom, often paired with data theft (double extortion).

A ransomware attack usually begins with phishing or a compromised access, followed by lateral movement then mass encryption. Defense combines MFA, immutable and tested backups, Defender XDR detection and an incident response plan. In Québec, ransomware affecting personal information triggers Law 25 confidentiality-incident obligations.

SIEM (Security Information and Event Management)

SIEM

A system that centralizes, correlates and analyzes security logs from multiple sources to detect threats and meet compliance requirements.

A traditional SIEM (Splunk, QRadar) requires a dedicated team. Microsoft Sentinel is a cloud-native SIEM, often deployed alongside Defender XDR: XDR natively covers the Microsoft ecosystem, while Sentinel adds external sources (firewalls, Linux servers, line-of-business apps) and the long-term retention some standards require.

Zero Trust

A security model based on “never trust, always verify”: every access is authenticated and authorized by context, with no implicit trust in the internal network.

Zero Trust rests on three pillars: verify explicitly (identity, device, risk), enforce least privilege, and assume breach. At Microsoft it is implemented through Entra ID (Conditional Access, MFA), Intune (compliant devices), Defender XDR and Purview. It is the reference framework most cyber-insurers now expect.

Category

Québec public sector

AMP (Autorité des marchés publics)

AMP

Autorité des marchés publics: the Québec body that issues authorizations to contract with Québec public bodies.

AMP authorization is mandatory for service contracts of $1M or more and construction contracts of $5M or more. A 3-to-6-month process requiring detailed declarations on ownership, history and structures. Without AMP authorization, a supplier is ineligible for large public contracts.

Bill 96 - Charter of the French Language

Bill 14 (formerly Bill 96), strengthening French-language obligations in Québec since 2022.

For a website: the French version must be at least equivalent in content and accessibility to any other language version. For legal documents (privacy policy, legal notices), the French version prevails. There is no obligation to publish an English version — but if one exists, French must dominate.

Conseil du trésor du Québec

SCT

The Québec secretariat that publishes the general terms applicable to public contracts, followed by all organizations bound by them.

The SCT's general terms cover: bid security, language compliance (Bill 96), accessibility (WCAG 2.1 AA), data residency, confidentiality clauses. Almost all suppliers sign these terms without modification — negotiations are rare.

Government cloud hosting (Québec)

The Québec framework governing public bodies' use of cloud computing, favouring qualified services and data residency in Canada.

The Québec government relies on a cloud-brokerage model and framework agreements for public-cloud adoption. Public bodies favour Canadian Azure regions (Canada Central, Canada East) and document the transfer assessments required by Article 17 of Law 25. io4 systematically runs its public-sector mandates in these regions.

Government information security

The Québec framework (Treasury Board / SGQRI directives and standards) governing the protection of information held by public bodies.

This framework defines roles (information officer, security officer), information classification and the protection requirements public bodies and their suppliers must meet. For an IT partner, meeting it means Canada hosting, logging, access management and audit documentation aligned with these standards.

SEAO

Système électronique d'appel d'offres: the Québec government's single portal for publishing and submitting public-procurement bids.

All Québec public bodies (ministries, municipalities, state-owned corporations, health/education networks) publish their RFPs on SEAO. Suppliers must submit their response there in the prescribed format with a bid security, a valid Revenu Québec attestation, and — above $1M — AMP authorization.

Web accessibility (WCAG 2.1)

WCAG

International standards (Web Content Accessibility Guidelines) making web content usable by people with disabilities; level AA is the public-sector target.

Québec public bodies require WCAG 2.1 level AA compliance (contrast, keyboard navigation, alt text, captions) on delivered interfaces. A pre-delivery accessibility audit and training for internal editors are expected in public-sector mandates, in line with Treasury Board directives.

Frequently asked questions

The vocabulary questions we hear most.

Can't find your answer? write to us.

  • Law 25 is Québec's private-sector privacy law (LPRPSP, CQLR c. P-39.1); the GDPR is the European regulation. Both require an accountable officer, impact assessments and incident handling, but Law 25 adds private civil remedies and regulates transfers outside Québec more strictly.

  • Defender XDR detects and blocks attacks on endpoints, identities and mail. Sentinel is the SIEM that correlates signals and keeps the history. Purview classifies and protects the data itself — it is the compliance pillar, not the detection one.

  • An external team that watches your security signals around the clock and acts on a confirmed alert instead of sending you a report. The measure that matters is MTTR, the mean time to respond: at io4 it is around 8 minutes.

    See the SOC offer
  • Multi-factor authentication is the floor. Conditional Access decides when to require it, based on device, location or risk — that is what makes it bearable day to day. FIDO2 passkeys replace the password and resist phishing: that is the target, not the starting point.

  • That data at rest sits in the Azure Canada Central (Toronto) or Canada East (Québec) regions. It is not automatic: it depends on the region chosen when the tenant was created, and some services keep metadata elsewhere.

Let's talk about your project

30 minutes to frame what matters.

A direct conversation with one of our experts. No commitment, no pressure. You leave with a clear, reasoned perspective on your situation.

Or call us directly:+1 888 285 9583
Free assessment