CUI Compliant

0 NIST 800-171 gaps detected. FedRAMP authorized at High impact level. Approved for CUI handling in DoD environments.

File Sharing

OneDrive GCC High

by Microsoft

FedRAMP AuthorizedHigh Impact

FedRAMP Status

FedRAMP Authorized

Impact Level

High

Category

File Sharing

Authorized: December 26, 2024

Overview

OneDrive for Business GCC High provides personal cloud file storage and sharing on government infrastructure. It is FedRAMP High authorized and integrates with the Microsoft 365 GCC High ecosystem.

CUI Risk Assessment

FedRAMP authorized at High impact level. Approved for CUI handling in DoD environments.

Deployment & Architecture

Deployment Model: Government Cloud (FedRAMP boundary)

OneDrive GCC High operates within a FedRAMP-authorized boundary. CUI can be processed within the authorization scope, but contractors must verify their specific use case falls within the system's security boundary as documented in the SSP.

Configuration Checklist

  1. 1ISSO must verify OneDrive GCC High tenant is properly segregated from commercial Office 365 services and document boundary controls in the System Security Plan.
  2. 2System administrator should configure Azure Information Protection labels aligned with contractor's CUI categories and marking requirements per NIST 800-171 MP-3.
  3. 3ISSO must implement data loss prevention policies that prevent CUI exfiltration and document these controls under NIST 800-171 SC-7 boundary protection.
  4. 4System administrator should establish audit logging configuration to capture file access, sharing, and modification events per DFARS 252.204-7012 incident reporting requirements.
  5. 5ISSO must update authorization boundary diagram to include OneDrive GCC High data flows and integration points with existing CUI systems.
  6. 6System administrator should configure conditional access policies restricting OneDrive access to government-issued devices and authorized locations per AC-3 access enforcement.
  7. 7Training coordinator must provide CUI handling training to all users covering proper document marking, sharing restrictions, and incident reporting procedures.
  8. 8ISSO must validate encryption-in-transit and encryption-at-rest configurations meet FIPS 140-2 requirements under NIST 800-171 SC-13.
  9. 9System administrator should implement automated backup procedures for CUI stored in OneDrive with appropriate retention periods per NIST 800-171 MP-6.
  10. 10ISSO must conduct penetration testing of configured access controls and update POA&M entries with any residual risks identified during implementation.

Frequently Asked Questions

Is OneDrive GCC High FedRAMP authorized?

Yes. OneDrive GCC High is FedRAMP High authorized as part of Microsoft 365 GCC High.

Can I use OneDrive GCC High with CUI?

Yes. OneDrive GCC High is approved for storing and sharing CUI files within the GCC High environment.

Run a Full Tech Stack Audit

Check all your enterprise tools at once with our free CUI Compliance Auditor.

Launch CUI Auditor

Get a defensible CUI architecture

This OneDrive GCC High CUI review flags the gaps. The next step is a compliance architecture review where we map your data flows to FedRAMP-authorized alternatives and CMMC-aligned controls.

Schedule architecture review

Related: how much CMMC certification costs — DoD’s own priced figures