CUI Compliant
0 NIST 800-171 gaps detected. FedRAMP High as part of Azure Government. Default IAM for M365 GCC High. Provides MFA, conditional access, and privileged identity management.
Microsoft Entra ID (GCC High)
by Microsoft
FedRAMP Status
FedRAMP Authorized
Impact Level
High
Category
Identity & Access Management
Authorized: December 26, 2024
Overview
Microsoft Entra ID (formerly Azure AD) in GCC High provides identity and access management for the Microsoft government cloud ecosystem. It includes MFA, conditional access policies, privileged identity management, and identity governance — all on FedRAMP High authorized infrastructure.
CUI Risk Assessment
FedRAMP High as part of Azure Government. Default IAM for M365 GCC High. Provides MFA, conditional access, and privileged identity management.
Deployment & Architecture
Deployment Model: Government Cloud (FedRAMP boundary)
Microsoft Entra ID (GCC High) operates within a FedRAMP-authorized boundary. CUI can be processed within the authorization scope, but contractors must verify their specific use case falls within the system's security boundary as documented in the SSP.
Configuration Checklist
- 1ISSO must update the System Security Plan to document Entra ID GCC High as the primary identity provider within the authorization boundary per NIST 800-171 IA-2 requirements.
- 2System administrator shall configure conditional access policies requiring MFA for all CUI access in compliance with NIST 800-171 IA-2(1) and IA-2(2) requirements.
- 3ISSO must implement privileged identity management for all administrative accounts accessing CUI systems per NIST 800-171 AC-2(5) requirements.
- 4System administrator shall disable legacy authentication protocols (basic authentication, legacy TLS) to meet NIST 800-171 SC-12 cryptographic standards.
- 5ISSO must configure identity governance workflows for automated account provisioning and deprovisioning per NIST 800-171 AC-2 requirements.
- 6Security administrator shall implement risk-based authentication policies using Entra ID's risk detection capabilities for NIST 800-171 AC-7 compliance.
- 7ISSO must establish break-glass emergency access procedures documented in the SSP per NIST 800-171 AC-1 requirements.
- 8System administrator shall configure session management policies including idle timeout and concurrent session limits per NIST 800-171 AC-12 requirements.
- 9ISSO must update the authorization boundary diagram to reflect Entra ID GCC High's position within the CUI processing environment.
- 10Contracts officer shall verify Entra ID GCC High usage aligns with DFARS 252.204-7012 adequate security requirements in prime and subcontractor agreements.
Other FedRAMP Authorized Identity & Access Management Tools
Related Compliance Assessments
Frequently Asked Questions
Is Entra ID included with GCC High?
Yes. Microsoft Entra ID is included with M365 GCC High and Azure Government subscriptions. It provides the IAM foundation for NIST 800-171 access control and authentication requirements.
Run a Full Tech Stack Audit
Check all your enterprise tools at once with our free CUI Compliance Auditor.
Launch CUI AuditorGet a defensible CUI architecture
This Microsoft Entra ID (GCC High) CUI review flags the gaps. The next step is a compliance architecture review where we map your data flows to FedRAMP-authorized alternatives and CMMC-aligned controls.
Schedule architecture reviewRelated: how much CMMC certification costs — DoD’s own priced figures