Collaboration of PCI Data from Microsoft 365
Introduction
The Payment Card Industry Data Security Standard (PCI DSS) governs organizations that handle credit, debit, and other card data across 12 requirements, from firewall configuration to access restriction and continuous monitoring. Microsoft has attested Azure, SharePoint Online, and OneDrive for Business for storing and processing PCI data, but Microsoft specifically does not attest Exchange Online as PCI compliant — and email, still the most widely used sharing method, is not PCI DSS compliant at all.
The Collaboration Gap
Ensuring PCI data stays compliant inside structured payment-processing applications is comparatively straightforward. The challenge arises when business lines need to collaborate on this data as unstructured files with users inside and outside the organization. While SharePoint and OneDrive are certified at Service Provider Level 1 for PCI data and support modern, link-based collaboration, many organizations — especially financial services companies — disable external sharing capability entirely due to tenant restrictions and concerns about granularity of controls.
How eSHARE Works
eSHARE is a SaaS solution built on top of Microsoft 365 that extends Microsoft's external collaboration capabilities. Organizations can share PCI data with external parties while keeping it inside their own tenant, without introducing guest accounts. Deep integrations with identity providers, Microsoft Graph, Purview Information Protection, and DLP provide fine-grained controls and full visibility into data usage, allowing highly secure file sharing directly from the native Teams and SharePoint experience — even when native external file sharing is otherwise disabled. eSHARE's Advisory Services also help ensure an organization's M365 environment is configured optimally for PCI compliance from the start.