Authorized environment — this is the one Microsoft points CUI holders at
Microsoft 365 Government Community Cloud-High is FedRAMP Certified at Class D (High), and Microsoft states plainly that GCC High and DoD are the environments it offers to contractors holding or processing DoD CUI or subject to ITAR. Expect a reduced feature set relative to commercial, and check each feature you depend on.
Is Microsoft 365 Copilot in GCC High / DoD safe for CUI?
by Microsoft
As of July 27, 2026. FedRAMP authorizations, DoD Impact Level approvals and vendor data-handling terms change. Every finding below links to the primary source it came from — open it and confirm the current status before you make a boundary decision.
What this verdict rests on
The 3 sources the finding above is drawn from, quoted so you can check the reading rather than take our word for it.
Primary source
“Microsoft 365 Government Community Cloud-High Package ID FR1824057433 ... FedRAMP Certified As of 12/26/2024 ... Type Rev5 Path Agency Class Class D (High)”
FedRAMP Marketplace — Microsoft 365 Government Community Cloud-High — Microsoft (Package FR1824057433) · read 2026-07-27
Primary source
“To meet the unique and evolving requirements of the United States Department of Defense, as well as contractors holding or processing DoD controlled unclassified information (CUI) or subject to International Traffic in Arms Regulations (ITAR), Microsoft offers GCC High and DoD environments.”
Microsoft Learn — Office 365 GCC High and DoD service description · read 2026-07-27
Primary source
“The Microsoft 365 Copilot app isn't available as a Mac desktop app for GCC/GCCH/DoD cloud environments. ... Copilot in Outlook: Schedule with Copilot and Themes by Copilot scenarios are not yet available in GCC, GCCH, or DOD.”
Microsoft Learn — Microsoft 365 Copilot service description — feature availability by cloud environment · read 2026-07-27
FedRAMP
Certified — Class D (High), 12/26/2024
DoD Impact Level
DoD environment assessed to SRG IL5
Deployment pattern
Government cloud / sovereign variant
Overview
Microsoft 365 Copilot in GCC High and DoD is the same product idea as commercial Copilot — grounded in your own tenant content — running in the environment Microsoft built for the defence industrial base, on a separate authorization record, with a separately managed feature set.
Where does the data physically go?
The first question in any CUI boundary decision is not whether a product is secure — it is which system boundary the data lands in, and whose authorization covers that boundary.
Data location
Processing stays inside the government cloud, and Microsoft closes the third-party model path that exists in commercial: OpenAI-operated models are not available for use in GCC, GCC High or DoD, and Anthropic models are not available for federal customers in GCC or for any customers in GCC High and DoD. In this environment the inference runs on Microsoft-operated models inside Microsoft's own authorized boundary.
Primary source
“Access to OpenAI operated models isn't currently available for use in government clouds (GCC, GCC High, DoD) or sovereign clouds.”
Microsoft Learn — OpenAI as a subprocessor in Microsoft 365 Copilot · read 2026-07-27
Model training and retention
Microsoft states prompts, responses and Microsoft Graph data are not used to train the foundation models. In the government clouds this sits alongside the stronger fact above — the third-party model subprocessors that serve commercial tenants are not in the path at all.
Primary source
“Anthropic models aren't available for federal customers in GCC or for any customers in GCC High and Department of Defense (DoD) environments. They're also not available in other sovereign clouds.”
Microsoft Learn — Connect to AI subprocessors in Microsoft 365 Copilot · read 2026-07-27
What authorization exists?
A platform-level authorization does not automatically extend to every service running on it. What matters is whether this specific AI service is named in the authorization scope.
FedRAMP authorization
Microsoft 365 Government Community Cloud-High is recorded as FedRAMP Certified as of 12/26/2024, a Rev5 Agency-path authorization at Class D (High). High exceeds the FedRAMP Moderate baseline DFARS 252.204-7012 asks of an external cloud service provider. Confirm on the live record that the Copilot service is inside the package scope for your subscription — service lists on these packages change.
Primary source
“Microsoft 365 Government Community Cloud-High Package ID FR1824057433 ... FedRAMP Certified As of 12/26/2024 ... Type Rev5 Path Agency Class Class D (High)”
FedRAMP Marketplace — Microsoft 365 Government Community Cloud-High — Microsoft (Package FR1824057433) · read 2026-07-27
DoD Impact Level
Microsoft describes the Office 365 DoD environment as carrying the DoD Cloud Computing SRG security controls for information up to Impact Level 5, and GCC High as assessed against NIST SP 800-53 at a FIPS 199 High categorization. Which of the two you are eligible for is set by the validation process, not by a purchase.
Primary source
“Office 365 DoD: The security controls and control enhancements for United States Department of Defense Cloud Computing Security Requirements Guide (SRG) for information up to Impact Level 5 (L5).”
Microsoft Learn — Office 365 GCC High and DoD — assessment basis · read 2026-07-27
Vendor's own position on CUI
This is one of the few places in this checker where a vendor states the CUI position outright: Microsoft offers GCC High and DoD to meet the requirements of DoD and of contractors holding or processing DoD CUI, or subject to ITAR.
Primary source
“To meet the unique and evolving requirements of the United States Department of Defense, as well as contractors holding or processing DoD controlled unclassified information (CUI) or subject to International Traffic in Arms Regulations (ITAR), Microsoft offers GCC High and DoD environments.”
Microsoft Learn — Office 365 GCC High and DoD service description · read 2026-07-27
What DFARS 252.204-7012 and NIST 800-171 require of this pattern
Quoted from the regulation itself, not paraphrased.
DFARS 252.204-7012(b)(2)(ii)(D) — the external cloud service provider test
This is the paragraph that decides most AI questions. The moment an external cloud service provider stores, processes or transmits covered defense information, the contractor must require and ensure that provider meets security requirements equivalent to the FedRAMP Moderate baseline — and that it complies with the clause's incident reporting, malicious software, media preservation, forensic access and damage assessment paragraphs. A commercial AI endpoint is an external cloud service provider. The obligation to ensure equivalency sits on the contractor, not the vendor.
Primary source
“If the Contractor intends to use an external cloud service provider to store, process, or transmit any covered defense information in performance of this contract, the Contractor shall require and ensure that the cloud service provider meets security requirements equivalent to those established by the Government for the Federal Risk and Authorization Management Program (FedRAMP) Moderate baseline ... and that the cloud service provider complies with requirements in paragraphs (c) through (g) of this clause for cyber incident reporting, malicious software, media preservation and protection, access to additional information and equipment necessary for forensic analysis, and cyber incident damage assessment.”
Acquisition.gov (DFARS, MAY 2024 revision) — DFARS 252.204-7012 Safeguarding Covered Defense Information and Cyber Incident Reporting · read 2026-07-27
DFARS 252.204-7012(b)(2)(i) — NIST SP 800-171 on your own systems
Any unclassified system owned or operated by or for the contractor that processes, stores or transmits covered defense information is a "covered contractor information system" and carries the full NIST SP 800-171 requirement set. An AI assistant does not sit outside this because it is new: if CUI reaches it, the system it runs on is in scope, and the revision that applies is the one in effect when the solicitation issued.
Primary source
“Except as provided in paragraph (b)(2)(ii) of this clause, the covered contractor information system shall be subject to the security requirements in National Institute of Standards and Technology (NIST) Special Publication (SP) 800-171 ... in effect at the time the solicitation is issued or as authorized by the Contracting Officer.”
Acquisition.gov (DFARS, MAY 2024 revision) — DFARS 252.204-7012 Safeguarding Covered Defense Information and Cyber Incident Reporting · read 2026-07-27
NIST SP 800-171 — the control set itself
The security requirements DFARS 7012 imports. Rev. 3 (May 2024) is the current final publication; which revision binds a given contract is set by the solicitation, so check the clause in your award rather than assuming. For an AI deployment the load-bearing families are access control, audit and accountability, and system and communications protection — an assistant that reaches CUI must be inside the same access, logging and boundary-protection regime as any other system that touches it.
Primary source
“This publication provides federal agencies with recommended security requirements for protecting the confidentiality of CUI when the information is resident in nonfederal systems and organizations.”
NIST Computer Security Resource Center — NIST SP 800-171 Rev. 3, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations · read 2026-07-27
NIST 800-171 controls this decision turns on
These are the controls an assessor works through when CUI reaches an AI service. They are the controls at stake, not a finding against the vendor.
The compliant pattern
Being in GCC High does not finish the job — it makes the job possible. Three things still fall to you. Record the environment and its authorization in the SSP and the boundary diagram, rather than recording "Copilot". Check every Copilot feature you plan to depend on against the service description's per-environment table, because several are unavailable or delayed in GCC, GCC High and DoD. And keep the access-control work honest: Copilot surfaces exactly what the user can already reach, so an over-shared CUI library becomes an over-shared CUI answer, which lands on your access-control and least-privilege controls rather than on Microsoft.
Patterns with an authorized path for CUI
Sources for this page
Every finding above rests on one of these. Nothing on this page is asserted without one.
- FedRAMP Marketplace — Microsoft 365 Government Community Cloud-High — Microsoft (Package FR1824057433) · read 2026-07-27
- Microsoft Learn — Office 365 GCC High and DoD service description · read 2026-07-27
- Microsoft Learn — Microsoft 365 Copilot service description — feature availability by cloud environment · read 2026-07-27
- Microsoft Learn — OpenAI as a subprocessor in Microsoft 365 Copilot · read 2026-07-27
- Microsoft Learn — Connect to AI subprocessors in Microsoft 365 Copilot · read 2026-07-27
Authorization records move and this page does not. Confirm the Microsoft 365 GCC High record on the FedRAMP Marketplace before you rely on anything above.
Related Compliance Assessments
Frequently Asked Questions
Is Microsoft 365 Copilot in GCC High approved for CUI?
Microsoft states that it offers GCC High and DoD environments to meet the requirements of DoD and of contractors holding or processing DoD CUI or subject to ITAR, and the GCC High package is FedRAMP Certified at Class D (High). Confirm the Copilot service is in your package scope on the live registry record, and confirm your own configuration and access controls separately.
Is Copilot in GCC High the same as commercial Copilot?
No, and Microsoft publishes the differences. Its service description carries a per-environment availability table for Commercial/Worldwide, GCC, GCCH and DoD; the Copilot app isn't available as a Mac desktop app in GCC/GCCH/DoD, and some Outlook scenarios are not yet available in those environments. Check the features you actually depend on before you plan around them.
Which models run behind Copilot in the government clouds?
Not the third-party ones. Microsoft states access to OpenAI-operated models isn't currently available for use in government clouds, and that Anthropic models aren't available for federal customers in GCC or for any customers in GCC High and DoD. For a boundary decision that is a useful, checkable fact: the subprocessor path that exists in commercial is closed here.
Your AI tools are one row in the boundary
Audit the rest of the stack — storage, email, collaboration — against the same FedRAMP test.
Launch CUI AuditorGet a defensible CUI architecture
This Microsoft 365 Copilot in GCC High / DoD CUI review flags the gaps. The next step is a compliance architecture review where we map your data flows to FedRAMP-authorized alternatives and CMMC-aligned controls.
Schedule architecture review