CUI Compliant
0 NIST 800-171 gaps detected. FedRAMP authorized at High impact level. Approved for CUI handling in DoD environments.
Microsoft Teams GCC High
by Microsoft
FedRAMP Status
FedRAMP Authorized
Impact Level
High
Category
Collaboration
Authorized: December 26, 2024
Overview
Microsoft Teams GCC High provides chat, channels, and collaboration on dedicated government infrastructure. It is FedRAMP High authorized and supports CUI and ITAR communication for defense contractors.
CUI Risk Assessment
FedRAMP authorized at High impact level. Approved for CUI handling in DoD environments.
Deployment & Architecture
Deployment Model: Government Cloud (FedRAMP boundary)
Microsoft Teams GCC High operates within a FedRAMP-authorized boundary. CUI can be processed within the authorization scope, but contractors must verify their specific use case falls within the system's security boundary as documented in the SSP.
Configuration Checklist
- 1ISSO must update the System Security Plan (SSP) to include Microsoft Teams GCC High within the authorization boundary and document data flows per NIST 800-171 requirement 3.4.2.
- 2Contracts officer must verify GCC High procurement through authorized Microsoft Cloud Solution Provider with FedRAMP compliance attestation per DFARS 252.204-7012.
- 3System administrator must configure tenant-level external sharing restrictions to prevent CUI disclosure to unauthorized external domains per NIST 800-171 AC-3.
- 4ISSO must implement data loss prevention (DLP) policies to detect and prevent CUI spillage in Teams channels and chat messages per NIST 800-171 requirement 3.3.1.
- 5System administrator must establish information barriers to segregate ITAR-controlled technical data from general CUI processing per DFARS 252.204-7021.
- 6ISSO must configure audit logging for all Teams activities including channel access, file downloads, and meeting recordings per NIST 800-171 AU-2 requirements.
- 7System administrator must disable guest access and external federation capabilities to maintain CUI boundary integrity per NIST 800-171 AC-20.
- 8Training coordinator must deliver 8-hour CUI handling training covering Teams-specific procedures for marking, sharing, and storing controlled information.
- 9ISSO must establish POA&M entries for any Teams GCC High configuration gaps identified during implementation assessment.
- 10System administrator must implement conditional access policies restricting Teams GCC High access to government-furnished or approved devices per NIST 800-171 AC-7.
Other FedRAMP Authorized Collaboration Tools
Related Compliance Assessments
Frequently Asked Questions
Is Microsoft Teams GCC High FedRAMP authorized?
Yes. Microsoft Teams GCC High is FedRAMP High authorized as part of the Microsoft 365 GCC High environment.
Can I use Teams GCC High with CUI?
Yes. Teams GCC High is approved for CUI and ITAR communications, with data stored in US Government Azure datacenters.
Run a Full Tech Stack Audit
Check all your enterprise tools at once with our free CUI Compliance Auditor.
Launch CUI AuditorGet a defensible CUI architecture
This Microsoft Teams GCC High CUI review flags the gaps. The next step is a compliance architecture review where we map your data flows to FedRAMP-authorized alternatives and CMMC-aligned controls.
Schedule architecture reviewRelated: how much CMMC certification costs — DoD’s own priced figures