Commercial environment — no CUI authorization established
Microsoft publishes Copilot as a separate offering in each cloud environment — Commercial/Worldwide, GCC, GCC High and DoD — and directs contractors holding CUI to the GCC High and DoD environments. Microsoft also documents that Copilot calls to the model can be routed into other regions when capacity requires it.
Is Microsoft 365 Copilot (commercial cloud) safe for CUI?
by Microsoft
As of July 27, 2026. FedRAMP authorizations, DoD Impact Level approvals and vendor data-handling terms change. Every finding below links to the primary source it came from — open it and confirm the current status before you make a boundary decision.
What this verdict rests on
The 3 sources the finding above is drawn from, quoted so you can check the reading rather than take our word for it.
Primary source
“The Microsoft 365 Copilot app isn't available as a Mac desktop app for GCC/GCCH/DoD cloud environments. ... Copilot in Outlook: Schedule with Copilot and Themes by Copilot scenarios are not yet available in GCC, GCCH, or DOD.”
Microsoft Learn — Microsoft 365 Copilot service description — feature availability by cloud environment · read 2026-07-27
Primary source
“To meet the unique and evolving requirements of the United States Department of Defense, as well as contractors holding or processing DoD controlled unclassified information (CUI) or subject to International Traffic in Arms Regulations (ITAR), Microsoft offers GCC High and DoD environments.”
Microsoft Learn — Office 365 GCC High and DoD service description · read 2026-07-27
Primary source
“Microsoft 365 Copilot calls to the LLM are routed to the closest data centers in the region, but also can call into other regions where capacity is available during high utilization periods.”
Microsoft Learn — Data, privacy, and security for Microsoft 365 Copilot · read 2026-07-27
FedRAMP
Not established for this environment
DoD Impact Level
Not established
Deployment pattern
Commercial multi-tenant SaaS
Overview
Microsoft 365 Copilot in the commercial (worldwide) cloud is the default Copilot most organisations buy: it grounds answers in the tenant's own Microsoft Graph content — mail, files, chats, meetings. The compliance question for a defence contractor is not whether that is well built, but whether the environment it runs in is one where CUI may lawfully sit, and Microsoft answers that by selling a different environment for CUI.
Where does the data physically go?
The first question in any CUI boundary decision is not whether a product is secure — it is which system boundary the data lands in, and whose authorization covers that boundary.
Data location
Prompts are processed inside the Microsoft 365 service, but Microsoft states model calls are routed to the nearest regional data centre and may be sent to other regions during periods of high utilization. For a CUI boundary that is the operative fact: the data path is not pinned to a US boundary by default.
Primary source
“Microsoft 365 Copilot calls to the LLM are routed to the closest data centers in the region, but also can call into other regions where capacity is available during high utilization periods.”
Microsoft Learn — Data, privacy, and security for Microsoft 365 Copilot · read 2026-07-27
Model training and retention
Microsoft states that prompts, responses and Microsoft Graph data are not used to train the foundation models. Training use and authorization boundary are separate questions, though — not training on your data does not put the data inside an authorized boundary.
Primary source
“Prompts, responses, and data accessed through Microsoft Graph aren't used to train foundation LLMs, including those used by Microsoft 365 Copilot.”
Microsoft Learn — Data, privacy, and security for Microsoft 365 Copilot — model training · read 2026-07-27
What authorization exists?
A platform-level authorization does not automatically extend to every service running on it. What matters is whether this specific AI service is named in the authorization scope.
FedRAMP authorization
Not established. We could not establish a FedRAMP authorization covering Microsoft 365 Copilot in the commercial/worldwide environment from Microsoft's own documentation. Microsoft's FedRAMP-certified Microsoft 365 package is the Government Community Cloud-High offering, a different environment. Verify with Microsoft and check the live registry record before relying on this either way.
DoD Impact Level
Not established. Not established. No DoD Impact Level authorization for the commercial environment was found in a primary source. DoD Impact Levels attach to government cloud environments; verify with Microsoft for your specific tenant.
Vendor's own position on CUI
Microsoft does not make a CUI claim for the commercial environment. It states the opposite by construction: GCC High and DoD are the environments it offers to contractors holding or processing DoD CUI, or subject to ITAR.
Primary source
“To meet the unique and evolving requirements of the United States Department of Defense, as well as contractors holding or processing DoD controlled unclassified information (CUI) or subject to International Traffic in Arms Regulations (ITAR), Microsoft offers GCC High and DoD environments.”
Microsoft Learn — Office 365 GCC High and DoD service description · read 2026-07-27
What DFARS 252.204-7012 and NIST 800-171 require of this pattern
Quoted from the regulation itself, not paraphrased.
DFARS 252.204-7012(b)(2)(ii)(D) — the external cloud service provider test
This is the paragraph that decides most AI questions. The moment an external cloud service provider stores, processes or transmits covered defense information, the contractor must require and ensure that provider meets security requirements equivalent to the FedRAMP Moderate baseline — and that it complies with the clause's incident reporting, malicious software, media preservation, forensic access and damage assessment paragraphs. A commercial AI endpoint is an external cloud service provider. The obligation to ensure equivalency sits on the contractor, not the vendor.
Primary source
“If the Contractor intends to use an external cloud service provider to store, process, or transmit any covered defense information in performance of this contract, the Contractor shall require and ensure that the cloud service provider meets security requirements equivalent to those established by the Government for the Federal Risk and Authorization Management Program (FedRAMP) Moderate baseline ... and that the cloud service provider complies with requirements in paragraphs (c) through (g) of this clause for cyber incident reporting, malicious software, media preservation and protection, access to additional information and equipment necessary for forensic analysis, and cyber incident damage assessment.”
Acquisition.gov (DFARS, MAY 2024 revision) — DFARS 252.204-7012 Safeguarding Covered Defense Information and Cyber Incident Reporting · read 2026-07-27
NIST SP 800-171 — the control set itself
The security requirements DFARS 7012 imports. Rev. 3 (May 2024) is the current final publication; which revision binds a given contract is set by the solicitation, so check the clause in your award rather than assuming. For an AI deployment the load-bearing families are access control, audit and accountability, and system and communications protection — an assistant that reaches CUI must be inside the same access, logging and boundary-protection regime as any other system that touches it.
Primary source
“This publication provides federal agencies with recommended security requirements for protecting the confidentiality of CUI when the information is resident in nonfederal systems and organizations.”
NIST Computer Security Resource Center — NIST SP 800-171 Rev. 3, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations · read 2026-07-27
NIST 800-171 controls this decision turns on
These are the controls an assessor works through when CUI reaches an AI service. They are the controls at stake, not a finding against the vendor.
The compliant pattern
Treat the commercial Copilot tenant as outside the CUI boundary and stop CUI reaching it: block the CUI-bearing SharePoint and mailbox locations from Copilot grounding, or run the CUI-bearing workload in a Microsoft 365 GCC High or DoD tenant instead. Copilot only surfaces content the user can already reach, so the boundary control is which repositories a Copilot-licensed user can see — not Copilot itself. If your organisation splits commercial and GCC High tenants, document the split in the SSP and show the flow control at the boundary.
Patterns with an authorized path for CUI
Sources for this page
Every finding above rests on one of these. Nothing on this page is asserted without one.
- Microsoft Learn — Microsoft 365 Copilot service description — feature availability by cloud environment · read 2026-07-27
- Microsoft Learn — Office 365 GCC High and DoD service description · read 2026-07-27
- Microsoft Learn — Data, privacy, and security for Microsoft 365 Copilot · read 2026-07-27
Authorization records move and this page does not. Confirm Microsoft 365 package records on the FedRAMP Marketplace before you rely on anything above.
Related Compliance Assessments
Frequently Asked Questions
Can I use Microsoft 365 Copilot with CUI in a commercial tenant?
Microsoft offers GCC High and DoD environments for contractors holding or processing DoD CUI or subject to ITAR, and we could not establish a FedRAMP authorization covering Copilot in the commercial environment. If your CUI lives in a commercial Microsoft 365 tenant, the Copilot question is downstream of a bigger one: whether that tenant is your CUI boundary at all.
Microsoft says it does not train on my data. Does that make it CUI-safe?
No — those are different questions. DFARS 252.204-7012 asks whether the external cloud service provider meets requirements equivalent to the FedRAMP Moderate baseline and complies with the clause's incident reporting and forensic-access paragraphs. A no-training commitment does not speak to any of that.
Where do Copilot prompts physically go?
Microsoft documents that Copilot calls to the model are routed to the closest data centres in the region, and can also call into other regions where capacity is available during high utilization periods. For a boundary decision, that unpinned data path is the thing to raise with your assessor.
Your AI tools are one row in the boundary
Audit the rest of the stack — storage, email, collaboration — against the same FedRAMP test.
Launch CUI AuditorGet a defensible CUI architecture
This Microsoft 365 Copilot (commercial cloud) CUI review flags the gaps. The next step is a compliance architecture review where we map your data flows to FedRAMP-authorized alternatives and CMMC-aligned controls.
Schedule architecture review