CUI Compliant
0 NIST 800-171 gaps detected. FedRAMP authorized at High impact level. Approved for CUI handling in DoD environments.
Microsoft Teams Video GCC High
by Microsoft
FedRAMP Status
FedRAMP Authorized
Impact Level
High
Category
Video Conferencing
Authorized: December 26, 2024
Overview
Microsoft Teams GCC High video conferencing provides encrypted audio and video meetings on government infrastructure. It is FedRAMP High authorized for classified discussions involving CUI.
CUI Risk Assessment
FedRAMP authorized at High impact level. Approved for CUI handling in DoD environments.
Deployment & Architecture
Deployment Model: Government Cloud (FedRAMP boundary)
Microsoft Teams Video GCC High operates within a FedRAMP-authorized boundary. CUI can be processed within the authorization scope, but contractors must verify their specific use case falls within the system's security boundary as documented in the SSP.
Configuration Checklist
- 1ISSO shall update the System Security Plan to include Microsoft Teams Video GCC High within the authorization boundary, documenting data flows and security controls per NIST 800-171 SC-7 requirements.
- 2System administrator must configure meeting policies to restrict anonymous participant access and require authentication for all external attendees handling CUI per DFARS 252.204-7012.
- 3ISSO shall establish data retention policies for recorded meetings containing CUI, ensuring alignment with contract-specific retention requirements and NIST 800-171 AU-11 audit record retention.
- 4System administrator must disable integration with commercial Office 365 services and configure GCC High tenant isolation to prevent CUI data spillage per NIST 800-171 SC-8 transmission confidentiality.
- 5ISSO shall create procedures for meeting classification and recording governance, including CUI marking requirements and access control documentation per NIST 800-171 MP-3 media marking.
- 6System administrator must configure guest access controls to require sponsor approval and implement time-limited access for external participants per NIST 800-171 AC-2 account management.
- 7ISSO shall update the authorization boundary diagram to reflect Teams GCC High connectivity and data flows within the FedRAMP boundary per NIST 800-171 CA-3 system interconnections.
- 8System administrator must implement audit logging for all meeting activities and configure log forwarding to the organization's SIEM system per NIST 800-171 AU-3 audit content requirements.
- 9ISSO shall develop user training materials covering CUI handling procedures in Teams GCC High and distinction from commercial Teams platforms per NIST 800-171 AT-3 security training.
- 10Contracts officer must verify Teams GCC High usage is properly reflected in SPRS submissions and CMMC assessment scope documentation per DFARS 252.204-7012 compliance requirements.
Other FedRAMP Authorized Video Conferencing Tools
Related Compliance Assessments
Frequently Asked Questions
Is Microsoft Teams video conferencing FedRAMP authorized?
Yes. Microsoft Teams GCC High including video conferencing is FedRAMP High authorized for government and defense contractor use.
Can I discuss CUI on Teams GCC High video calls?
Yes. Teams GCC High video and audio calls are approved for CUI discussions in defense environments with appropriate classification markings.
Run a Full Tech Stack Audit
Check all your enterprise tools at once with our free CUI Compliance Auditor.
Launch CUI AuditorGet a defensible CUI architecture
This Microsoft Teams Video GCC High CUI review flags the gaps. The next step is a compliance architecture review where we map your data flows to FedRAMP-authorized alternatives and CMMC-aligned controls.
Schedule architecture reviewRelated: how much CMMC certification costs — DoD’s own priced figures