In scope of the Azure Government authorizations, up to IL5
Microsoft's audit-scope table marks Azure OpenAI in scope across FedRAMP High and DoD IL2, IL4 and IL5 in Azure Government — against FedRAMP High and IL2 only in Azure public. Microsoft also states that FedRAMP High authorized Azure services conform to NIST SP 800-171 and can help deploy CUI workloads.
Is Azure OpenAI Service in Azure Government safe for CUI?
by Microsoft
As of July 27, 2026. FedRAMP authorizations, DoD Impact Level approvals and vendor data-handling terms change. Every finding below links to the primary source it came from — open it and confirm the current status before you make a boundary decision.
What this verdict rests on
The 2 sources the finding above is drawn from, quoted so you can check the reading rather than take our word for it.
Primary source
“Azure Government maintains the following authorizations that pertain to Azure Government regions US Gov Arizona, US Gov Texas, and US Gov Virginia (US Gov regions): FedRAMP High P-ATO issued by the JAB DoD IL2 PA issued by DISA DoD IL4 PA issued by DISA DoD IL5 PA issued by DISA”
Microsoft Learn — Azure, Dynamics 365, Microsoft 365, and Power Platform services in FedRAMP and DoD audit scope · read 2026-07-27
Primary source
“All Azure and Azure Government services that have received FedRAMP High authorization conform to the NIST SP 800-171 requirements, and can help you deploy CUI workloads.”
Microsoft Learn — Azure compliance offering — Defense Federal Acquisition Regulation Supplement (DFARS) · read 2026-07-27
FedRAMP
High (Azure Government JAB P-ATO)
DoD Impact Level
IL2, IL4, IL5
Deployment pattern
Government cloud / sovereign variant
Overview
Azure OpenAI Service in Azure Government exposes OpenAI models through Microsoft's government cloud, inside Microsoft's authorization boundary rather than OpenAI's. It is the clearest worked example of this checker's central point: the same service name carries a different authorization scope depending on which cloud it runs in.
Where does the data physically go?
The first question in any CUI boundary decision is not whether a product is secure — it is which system boundary the data lands in, and whose authorization covers that boundary.
Data location
Inference runs in Azure Government regions — US Gov Arizona, US Gov Texas and US Gov Virginia — under the authorizations Microsoft lists for those regions. Note Microsoft's own caveat that some Azure services in those regions need extra configuration to meet the IL5 compute and storage isolation requirements: IL5 is a configuration you have to reach, not a default you inherit.
Primary source
“Some Azure services deployed in Azure Government regions US Gov Arizona, US Gov Texas, and US Gov Virginia (US Gov regions) require extra configuration to meet DoD IL5 compute and storage isolation requirements”
Microsoft Learn — Azure Government audit scope — Impact Level 5 configuration note · read 2026-07-27
Model training and retention
Not established. We did not fetch and read Microsoft's Azure OpenAI data-privacy page in preparing this entry, so we make no claim here about training or abuse-monitoring retention for this service. Read that page directly — it is the one that answers this — before you rely on an answer.
What authorization exists?
A platform-level authorization does not automatically extend to every service running on it. What matters is whether this specific AI service is named in the authorization scope.
FedRAMP authorization
Azure Government holds a FedRAMP High P-ATO issued by the JAB, plus DoD IL2, IL4 and IL5 provisional authorizations issued by DISA. In Microsoft's audit-scope tables the Azure OpenAI row is marked in scope across all five columns for Azure Government, and across FedRAMP High and DoD IL2 only for Azure public — the same service, two very different scopes depending on which cloud you deploy in.
Primary source
“Azure Government maintains the following authorizations that pertain to Azure Government regions US Gov Arizona, US Gov Texas, and US Gov Virginia (US Gov regions): FedRAMP High P-ATO issued by the JAB DoD IL2 PA issued by DISA DoD IL4 PA issued by DISA DoD IL5 PA issued by DISA”
Microsoft Learn — Azure, Dynamics 365, Microsoft 365, and Power Platform services in FedRAMP and DoD audit scope · read 2026-07-27
DoD Impact Level
IL4 is the Impact Level DoD associates with controlled unclassified information, and Azure Government carries IL4 and IL5 provisional authorizations from DISA with Azure OpenAI marked in scope. Reaching IL5 in practice can require the extra isolation configuration Microsoft calls out.
Primary source
“Azure Government maintains the following authorizations that pertain to Azure Government regions US Gov Arizona, US Gov Texas, and US Gov Virginia (US Gov regions): FedRAMP High P-ATO issued by the JAB DoD IL2 PA issued by DISA DoD IL4 PA issued by DISA DoD IL5 PA issued by DISA”
Microsoft Learn — Azure, Dynamics 365, Microsoft 365, and Power Platform services in FedRAMP and DoD audit scope · read 2026-07-27
Vendor's own position on CUI
Microsoft states that all Azure and Azure Government services that have received FedRAMP High authorization conform to the NIST SP 800-171 requirements and can help you deploy CUI workloads. That is about as direct a vendor CUI statement as this market produces.
Primary source
“All Azure and Azure Government services that have received FedRAMP High authorization conform to the NIST SP 800-171 requirements, and can help you deploy CUI workloads.”
Microsoft Learn — Azure compliance offering — Defense Federal Acquisition Regulation Supplement (DFARS) · read 2026-07-27
What DFARS 252.204-7012 and NIST 800-171 require of this pattern
Quoted from the regulation itself, not paraphrased.
DFARS 252.204-7012(b)(2)(ii)(D) — the external cloud service provider test
This is the paragraph that decides most AI questions. The moment an external cloud service provider stores, processes or transmits covered defense information, the contractor must require and ensure that provider meets security requirements equivalent to the FedRAMP Moderate baseline — and that it complies with the clause's incident reporting, malicious software, media preservation, forensic access and damage assessment paragraphs. A commercial AI endpoint is an external cloud service provider. The obligation to ensure equivalency sits on the contractor, not the vendor.
Primary source
“If the Contractor intends to use an external cloud service provider to store, process, or transmit any covered defense information in performance of this contract, the Contractor shall require and ensure that the cloud service provider meets security requirements equivalent to those established by the Government for the Federal Risk and Authorization Management Program (FedRAMP) Moderate baseline ... and that the cloud service provider complies with requirements in paragraphs (c) through (g) of this clause for cyber incident reporting, malicious software, media preservation and protection, access to additional information and equipment necessary for forensic analysis, and cyber incident damage assessment.”
Acquisition.gov (DFARS, MAY 2024 revision) — DFARS 252.204-7012 Safeguarding Covered Defense Information and Cyber Incident Reporting · read 2026-07-27
DFARS 252.204-7012(b)(2)(i) — NIST SP 800-171 on your own systems
Any unclassified system owned or operated by or for the contractor that processes, stores or transmits covered defense information is a "covered contractor information system" and carries the full NIST SP 800-171 requirement set. An AI assistant does not sit outside this because it is new: if CUI reaches it, the system it runs on is in scope, and the revision that applies is the one in effect when the solicitation issued.
Primary source
“Except as provided in paragraph (b)(2)(ii) of this clause, the covered contractor information system shall be subject to the security requirements in National Institute of Standards and Technology (NIST) Special Publication (SP) 800-171 ... in effect at the time the solicitation is issued or as authorized by the Contracting Officer.”
Acquisition.gov (DFARS, MAY 2024 revision) — DFARS 252.204-7012 Safeguarding Covered Defense Information and Cyber Incident Reporting · read 2026-07-27
NIST SP 800-171 — the control set itself
The security requirements DFARS 7012 imports. Rev. 3 (May 2024) is the current final publication; which revision binds a given contract is set by the solicitation, so check the clause in your award rather than assuming. For an AI deployment the load-bearing families are access control, audit and accountability, and system and communications protection — an assistant that reaches CUI must be inside the same access, logging and boundary-protection regime as any other system that touches it.
Primary source
“This publication provides federal agencies with recommended security requirements for protecting the confidentiality of CUI when the information is resident in nonfederal systems and organizations.”
NIST Computer Security Resource Center — NIST SP 800-171 Rev. 3, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations · read 2026-07-27
NIST 800-171 controls this decision turns on
These are the controls an assessor works through when CUI reaches an AI service. They are the controls at stake, not a finding against the vendor.
The compliant pattern
This is the pattern to reach for when you want frontier-model capability against CUI without building your own inference. Deploy in Azure Government rather than Azure public — the service name is identical and the scope is not — and confirm the Azure OpenAI row in the audit-scope table for the impact level you need. Apply the extra isolation configuration where IL5 requires it, put the deployment inside your documented CUI enclave with the same access control and logging as any other CUI system, and expect newer models to arrive in Azure Government later than in commercial.
Patterns with an authorized path for CUI
Sources for this page
Every finding above rests on one of these. Nothing on this page is asserted without one.
- Microsoft Learn — Azure, Dynamics 365, Microsoft 365, and Power Platform services in FedRAMP and DoD audit scope · read 2026-07-27
- Microsoft Learn — Azure compliance offering — Defense Federal Acquisition Regulation Supplement (DFARS) · read 2026-07-27
Authorization records move and this page does not. Confirm Microsoft package records on the FedRAMP Marketplace before you rely on anything above.
Related Compliance Assessments
Frequently Asked Questions
Is Azure OpenAI approved for CUI?
In Azure Government, Microsoft marks Azure OpenAI in scope for FedRAMP High and DoD IL2, IL4 and IL5, and states that FedRAMP High authorized Azure services conform to NIST SP 800-171 and can help you deploy CUI workloads. In Azure public the same service is marked in scope for FedRAMP High and DoD IL2 only.
Does Azure OpenAI in Azure Government reach IL5 automatically?
Not automatically. Microsoft notes that some Azure services in the Azure Government regions require extra configuration to meet DoD IL5 compute and storage isolation requirements. Treat IL5 as a configuration target with evidence attached, not an inherited property.
How is this different from calling the OpenAI API directly?
The model may be similar; the authorization boundary is not. Here the boundary is Azure Government's — a FedRAMP High JAB P-ATO plus DISA provisional authorizations at IL2, IL4 and IL5 — and that is the boundary you document and your assessor tests.
Your AI tools are one row in the boundary
Audit the rest of the stack — storage, email, collaboration — against the same FedRAMP test.
Launch CUI AuditorGet a defensible CUI architecture
This Azure OpenAI Service in Azure Government CUI review flags the gaps. The next step is a compliance architecture review where we map your data flows to FedRAMP-authorized alternatives and CMMC-aligned controls.
Schedule architecture review