Solutions Who We Serve Insights & Events About Contact
Published on August 20, 2026 8 min read

Microsoft GCC, GCC High, and Azure Government: Drawing the CUI Boundary

Close-up of advanced data center equipment with energy storage and cooling technology. Represents cloud computing, AI infrastructure, power efficiency, and digital transformation.

Summary: For DoW work, Microsoft 365 GCC stops short: no DFARS flow down commitments, no export control assurance, nothing above IL2, and no compute counterpart at all. GCC High holds the CUI your people create; Azure Government holds what your systems process. Most DIB contractors need both, and determining that early keeps your CMMC scope, your assessment, and your budget under control.

If you handle Controlled Unclassified Information (CUI) for the Department of Defense (DoD)/Department of War (DoW), one of the most consequential decisions you will make is where your data lives and who can touch it. For most of the Defense Industrial Base (DIB), that comes down to two Microsoft environments: Microsoft 365 GCC High and Azure Government.

However, the two are often conflated. GCC High is where your people work (e.g., Outlook, Teams, SharePoint, OneDrive), while Azure Government is where your systems run (e.g., virtual machines, databases, and the applications that process CUI). How each differs from Microsoft’s Government Community Cloud (GCC) is central to a defensible Cybersecurity Maturity Model Certification (CMMC) posture.

Where Microsoft GCC Fits and Where It Stops

Microsoft 365 GCC is built for U.S. public sector organizations and the contractors serving them. Content is stored at rest in the continental U.S., and it aligns to FedRAMP High, Criminal Justice Information Services (CJIS) policy, IRS Publication 1075, and DoD Impact Level 2 (IL2). For a state agency or civilian federal contractor, GCC is often the right home.

For DoW CUI, it stops short in three specific ways:

DFARS Commitments

DFARS 252.204-7012 requires a cloud service provider (CSP) handling covered defense information to meet the FedRAMP Moderate baseline or equivalent and comply with the incident reporting and forensic requirements in paragraphs (c) through (g). Microsoft extends those commitments through GCC High and its DoW environments, not GCC—a distinction that is contractual and the one most often missed.

Export Controlled Data

International Traffic in Arms Regulations (ITAR) and Export Administration Regulations (EAR) technical data must be stored in the U.S. and accessed only by screened U.S. persons. GCC is logically segregated inside Microsoft’s public cloud rather than physically separate, and its support model does not restrict access to U.S. persons. GCC High is separate on both counts and validated for export-controlled CUI.

DoD Impact Levels

GCC is accredited to IL2, not IL4 nor IL5. If a contract invokes either, GCC is not an option regardless of how the tenant is configured.

Microsoft 365 GCC High: The Collaboration Boundary

GCC High carries FedRAMP High authorization supports DoD IL4 and IL5 alignment and is validated for ITAR and export controlled CUI. It is where Microsoft points defense contractors.

The tradeoffs are substantial. There is a licensing premium. Feature parity lags, so the newest Copilot, Teams, and Purview capabilities arrive later. Fewer third-party providers certify for the government cloud and identity is deliberately rigid: guest access and cross-tenant collaboration are constrained by design.

There is also no upgrade button. Moving from GCC to GCC High is a tenant-to-tenant migration, not a license change—mailboxes, files, Teams, and identities all rebuilt in the new tenant. Starting in GCC shortens that path less than most people expect.

Azure Government: The Compute Boundary

Here is what most companies underestimate: GCC has no compute counterpart. GCC is a Microsoft 365 offering. There is no “Azure GCC.” A firm that moved collaboration into GCC and considered the CUI question settled still has every compute workload outside a government cloud—and compute is usually where CUI lives.

The identity split makes this concrete. Microsoft 365 GCC is paired with the commercial Microsoft Entra ID instance: users sign in at login.microsoftonline.com and reach Azure at portal.azure.com. GCC High and DoW are paired with the Entra ID instance inside Azure Government, using login.microsoftonline.us and portal.azure.us. That means a GCC customer who adds an Azure Government subscription runs two directories and two identity lifecycles. A GCC High customer can put collaboration and compute behind one sovereign tenant.

Azure Government is a separate, isolated cloud instance in dedicated U.S. regions (e.g., US Gov Virginia, US Gov Arizona, US Gov Texas) and specific DoW regions (e.g., US DoD East, US DoD Central). It was the first hyperscale platform to earn a DoD IL5 Provisional Authorization from the Defense Information Systems Agency (DISA), hold FedRAMP High authorization, and is accredited across IL2, IL4, and IL5. Like GCC High, it is run by screened U.S. persons from U.S. soil.

Five things shape how you build in it:

  • Region choice drives your isolation work: The US DoW regions are reserved for DoW agencies and their partners, so physical separation from non-DoW tenants comes by design and most IL5 services don’t need extra configuration. In a US Gov region, tenant separation is your job.
  • IL5 compute isolation is architecture, not a checkbox: Section 5.2.2.3 of the Cloud Computing Security Requirements Guide (CC SRG) governs separation during processing. In the US Gov regions, IL5 virtual machines must land on Azure Dedicated Host—a physical server dedicated to one subscription. Scale sets are not supported on Dedicated Host, so those workloads need isolated VM SKUs that consume an entire host instead. Plan for churn: as hardware generations retire, isolated SKUs must be scaled up or migrated to stay on dedicated hardware.
  • IL5 storage isolation runs on your keys: DISA allows the logical separation of IL5 data by cryptographic means—in practice, customer-managed keys (CMK) in Azure Key Vault backed by FIPS 140 validated hardware security modules. That pattern extends across Azure Storage, SQL Database transparent data encryption, Cosmos DB, AKS managed disks, Container Registry, Service Bus, Event Hubs, and the Log Analytics workspaces feeding Defender for Cloud or Microsoft Sentinel. Remember: enable CMK before you load data because anything written beforehand stays under Microsoft managed keys.
  • Structure the tenant around contracts, not the org chart: One Azure Government tenant can hold many subscriptions. A management group hierarchy with subscriptions segregated by contract or program keeps CUI workloads apart and gives you one clean place to enforce policy. Azure Government ships a built-in Azure Policy regulatory compliance initiative mapped to NIST SP 800-171 R2—assign it at the management group holding your CUI landing zones. Pair it with hub and spoke networking and private endpoints rather than public service endpoints, and ExpressRoute for the on-premises leg.
  • Budget for the gaps: Azure Government does not carry the full commercial catalog, the marketplace is smaller, and endpoints differ—storage resolves to core.usgovcloudapi.net, resource management to management.usgovcloudapi.net, and Graph to graph.microsoft.us. SDKs, infrastructure as code (IaC), and CI/CD pipelines all need rework. Government regions also price at a premium. It’s important to confirm service availability before it reaches a design document and price the engineering effort into proposals rather than afterwards.

How The Two Fit Together

To put it briefly, GCC High holds the CUI your people create and share, while Azure Government holds the CUI your systems process and store. Most DIB companies need both. Microsoft supports connectivity between them, but they are still separate environments with distinct administrative planes.

Your CMMC scope boundary should follow the CUI. Wherever CUI is stored, processed, or transmitted is in scope (e.g., a Teams channel in GCC High or a database on an Azure Government virtual machine) and everything connected to it inherits requirements. Drawing that boundary deliberately is what keeps assessments manageable.

A Note On the Evolving CMMC Landscape

The DFARS CMMC final rule took effect on November 10, 2025, launching Phase 1 self-assessment requirements. On July 13, 2026, USD (A&S) Memorandum 26-P-1023 suspended the Phase 2 transition scheduled for November 2026, so third-party Level 2 certification is not currently a condition of award. Consider that as a pause on the verification mechanism, but not your obligation: DFARS 252.204-7012 and the NIST SP 800-171 controls remain in force, and self-attestation carries False Claims Act exposure.

Final Thoughts

Draw an honest boundary around your CUI and commit to it early. GCC is a legitimate government cloud, but for DoW work it stops short of DFARS commitments, export control assurances, and Impact Levels the mission requires—and it offers nothing for compute.

GCC High helps secure how your people collaborate. Azure Government helps secure how your systems compute. The premiums, feature gaps, and migration efforts are all real, but so is the cost of discovering, mid-assessment, that your CUI has been living somewhere it never should have been.

Aprio advisors work with defense contractors on both halves of this problem: the collaboration boundary in GCC High and the compute boundary in Azure Government. If you want to know where your CUI sits today and what that means for your scope, talk to us about our CMMC assessment services.

This article is informational and reflects the regulatory landscape as of August 2026. It is not legal or compliance advice. Cloud environment and CMMC scoping decisions should be reviewed by qualified compliance and legal professionals against your specific contracts and data before implementation.

How we can help

Aprio advisors work with defense contractors to scope the CUI boundary across GCC High and Azure Government and validate the controls inside it. Explore our CMMC assessment services today. Connect with us

Close-up of advanced data center equipment with energy storage and cooling technology. Represents cloud computing, AI infrastructure, power efficiency, and digital transformation.