CUI Compliant

0 NIST 800-171 gaps detected. FedRAMP High as part of Azure Government. Default IAM for M365 GCC High. Provides MFA, conditional access, and privileged identity management.

Identity & Access Management

Microsoft Entra ID (GCC High)

by Microsoft

FedRAMP AuthorizedHigh Impact

FedRAMP Status

FedRAMP Authorized

Impact Level

High

Category

Identity & Access Management

Authorized: December 26, 2024

Overview

Microsoft Entra ID (formerly Azure AD) in GCC High provides identity and access management for the Microsoft government cloud ecosystem. It includes MFA, conditional access policies, privileged identity management, and identity governance — all on FedRAMP High authorized infrastructure.

CUI Risk Assessment

FedRAMP High as part of Azure Government. Default IAM for M365 GCC High. Provides MFA, conditional access, and privileged identity management.

Deployment & Architecture

Deployment Model: Government Cloud (FedRAMP boundary)

Microsoft Entra ID (GCC High) operates within a FedRAMP-authorized boundary. CUI can be processed within the authorization scope, but contractors must verify their specific use case falls within the system's security boundary as documented in the SSP.

Configuration Checklist

  1. 1ISSO must update the System Security Plan to document Entra ID GCC High as the primary identity provider within the authorization boundary per NIST 800-171 IA-2 requirements.
  2. 2System administrator shall configure conditional access policies requiring MFA for all CUI access in compliance with NIST 800-171 IA-2(1) and IA-2(2) requirements.
  3. 3ISSO must implement privileged identity management for all administrative accounts accessing CUI systems per NIST 800-171 AC-2(5) requirements.
  4. 4System administrator shall disable legacy authentication protocols (basic authentication, legacy TLS) to meet NIST 800-171 SC-12 cryptographic standards.
  5. 5ISSO must configure identity governance workflows for automated account provisioning and deprovisioning per NIST 800-171 AC-2 requirements.
  6. 6Security administrator shall implement risk-based authentication policies using Entra ID's risk detection capabilities for NIST 800-171 AC-7 compliance.
  7. 7ISSO must establish break-glass emergency access procedures documented in the SSP per NIST 800-171 AC-1 requirements.
  8. 8System administrator shall configure session management policies including idle timeout and concurrent session limits per NIST 800-171 AC-12 requirements.
  9. 9ISSO must update the authorization boundary diagram to reflect Entra ID GCC High's position within the CUI processing environment.
  10. 10Contracts officer shall verify Entra ID GCC High usage aligns with DFARS 252.204-7012 adequate security requirements in prime and subcontractor agreements.

Frequently Asked Questions

Is Entra ID included with GCC High?

Yes. Microsoft Entra ID is included with M365 GCC High and Azure Government subscriptions. It provides the IAM foundation for NIST 800-171 access control and authentication requirements.

Run a Full Tech Stack Audit

Check all your enterprise tools at once with our free CUI Compliance Auditor.

Launch CUI Auditor

Get a defensible CUI architecture

This Microsoft Entra ID (GCC High) CUI review flags the gaps. The next step is a compliance architecture review where we map your data flows to FedRAMP-authorized alternatives and CMMC-aligned controls.

Schedule architecture review

Related: how much CMMC certification costs — DoD’s own priced figures