What Is Azure Government Cloud? A Compliance Overview

Written by: 
Team Knox
Published on: 
August 3, 2026

Microsoft's Azure Government holds a Federal Risk and Authorization Management Program (FedRAMP) High authorization and carries Provisional Authorizations from the Defense Information Systems Agency (DISA) for Department of Defense (DoD) Impact Levels (IL) 2, 4, and 5.

That authorization stack makes it a common Microsoft option for regulated federal workloads, but its boundaries are easy to misread. Azure Government, Government Community Cloud (GCC), and GCC High have distinct infrastructure and identity models, and hosting inside an authorized cloud does not make a vendor's own service compliant.

Those misunderstandings can affect procurement and assessments: the wrong environment can raise data-handling issues, and the hosting assumption tends to surface late, usually during an assessment.

Key Takeaways

  • Azure Government Isolation. It is a US-only Microsoft cloud with a separate network and identity model. Microsoft also contractually limits data residency to the US and support access to screened US persons.  
  • GCC Tier Differences. GCC runs on commercial Azure infrastructure at FedRAMP Moderate and IL-2; GCC High runs on Azure Government and supports Controlled Unclassified Information (CUI), International Traffic in Arms Regulations (ITAR), and Defense Federal Acquisition Regulation Supplement (DFARS)-driven workloads.  
  • Impact Level Coverage. Azure Government's US Gov regions carry IL-2, IL-4, and IL-5 Provisional Authorizations, while IL-6 classified workloads run only in Azure Government Secret.  
  • Hosting Limits. Platform authorization is only one layer for FedRAMP, Cybersecurity Maturity Model Certification (CMMC), Criminal Justice Information Services (CJIS), and related assessments; your own service still needs configuration work and assessment evidence.

Azure Government Cloud Is Microsoft's Isolated Environment for Regulated Workloads

Azure Government is a US government community cloud serving federal, state, local, and tribal entities, plus commercial organizations subject to regulations such as CJIS and ITAR. It is physically separated from commercial Azure, deployed on an isolated network with its own identity model: sign-in runs through login.microsoftonline.us rather than login.microsoftonline.com.

It is available only to US-based registered entities and spans five regions: US Gov Arizona, US Gov Texas, US Gov Virginia, and two US DoD regions reserved for exclusive DoD use. Within the environment, each Microsoft Entra tenant is logically isolated to keep customer data and identity information from comingling.

Both commercial Azure and Azure Government hold FedRAMP High provisional Authority to Operate (P-ATO), but Azure Government adds contractual commitments that customer data stays in the United States and that access to systems processing it is limited to screened US persons.

Azure Government Cloud Underpins Several Related Microsoft Environments

GCC, GCC High, and Azure Government are frequently used interchangeably, and the confusion has real consequences because they don't share infrastructure. GCC runs on commercial Azure with logical separation. GCC High runs on Azure Government's dedicated US datacenters and uses the same .onmicrosoft.us identity endpoints.

GCC Aligns to FedRAMP Moderate

GCC carries a FedRAMP Moderate baseline and DoD IL-2 alignment. It suits Federal Contract Information (FCI), general federal workloads, and CMMC Level 1 obligations, and it handles CJIS and Internal Revenue Service (IRS) Federal Tax Information.

Microsoft's guidance is explicit: CUI specified categories such as ITAR or nuclear data require the US sovereignty model that only GCC High offers. Because GCC inherits shared services from commercial Azure, it does not provide the same sovereignty model as GCC High.

GCC High Aligns to Higher DoD Impact Levels

GCC High carries a FedRAMP High baseline and is IL-4-equivalent. DoD has not formally granted IL-4 to GCC High, since DoD mission owners are directed to the DoD cloud services instead.

GCC High supports CUI and Covered Defense Information, including ITAR and Export Administration Regulations (EAR) data, and Microsoft prescribes it for National Institute of Standards and Technology (NIST) SP 800-171 Rev2, and DFARS covered defense requirements compliance and encourages it for CMMC 2.0.

The required threshold under DFARS 7012 is FedRAMP Moderate or equivalent. GCC High is sold through Volume Licensing only, requires eligibility validation before provisioning, and offers no trials.

Azure Government Cloud Supports Multiple DoD Impact Levels

DISA's Provisional Authorizations for Azure Government map to four ILs defined in the DoD Cloud Computing Security Requirements Guide (SRG) V1R6 (December 2025).

  1. IL-2 authorizes non-sensitive DoD workloads. This covers non-controlled unclassified information and is the baseline Provisional Authorization; commercial Azure holds it too, and no restriction applies to cloud provider personnel nationality.  
  2. IL-4 authorizes CUI. This includes export-controlled data, protected health information, and designations such as For Official Use Only and Law Enforcement Sensitive. Provider personnel with access must be US citizens, nationals, or persons.  
  3. IL-5 authorizes higher-protection CUI and unclassified National Security Systems. In the US DoD regions, dedicated exclusively to DoD, an IL-5-authorized service needs no extra isolation configuration. In the US Gov regions, some services require additional isolation. DISA approved logical separation via cryptographic means with customer-managed keys held in Azure Key Vault hardware security modules.  
  4. IL-6 authorizes classified information up to SECRET. IL-6 workloads run only in Azure Government Secret, a closed environment connected to Secret Internet Protocol Router Network (SIPRNet), operated by cleared US citizens, and restricted to authorized government customers. Standard Azure Government regions top out at IL-5.

Which impact level applies flows from the data type, contract language, and regulatory framework driving the workload in the first place. That upstream logic is what shapes the sequence organizations follow to land in the right environment.

Organizations Adopt Azure Government Cloud Through a Defined Path

Adopting Azure Government follows a defined sequence that moves from compliance driver to authorized workload. Each step narrows the environment options, eligibility requirements, and assessment scope that will apply to a given workload.

1. Identify the Compliance Driver

DFARS cloud provider requirements require cloud providers handling covered defense information to meet FedRAMP Moderate-equivalent security with 72-hour cyber incident reporting. ITAR data requires US sovereignty that Microsoft contractually supports only in GCC High and Azure Government, while CMMC 2.0 level determines whether GCC suffices or GCC High is needed.

2. Select the Environment Tier

GCC fits FCI and general federal workloads, while workloads involving CUI, ITAR, or DFARS requirements usually point to GCC High or Azure Government. US DoD regions fit IL-5 workloads needing DoD-dedicated physical separation.

3. Validate Eligibility

Microsoft requires proof of eligibility, such as a government contract or evidence of handling regulated workloads, with revalidation at contract renewal. ITAR validation may require State Department registration.

4. Configure Identity and Data Residency

GCC High and Azure Government use Microsoft Entra Government with .us endpoints, and CMMC Level 2 tenants must be architected as CUI and documented in a System Security Plan (SSP).

5. Complete the Required Assessment

A CMMC Level 2 assessment requires a Certified Third-Party Assessment Organization (C3PAO) assessment, with conditional status permitting an open Plan of Action and Milestones (POA\&M) and closeout within 180 days.

Completing these steps positions a workload inside an authorized environment, but the personnel controls governing who can operate that environment are what separate Azure Government from commercial Azure at higher impact levels.

Azure Government Cloud Restricts Access to Screened US Persons

The DoD Cloud Computing SRG V1R6 requires that cloud provider personnel with access to IL-4 or IL-5 systems or the data they hold be US citizens, US nationals, or US persons; no foreign persons may have such access. Commercial Azure makes no such commitment, so the US-persons requirement is the structural reason IL-4 and IL-5 workloads land on Azure Government.

Personnel Restrictions Apply at Higher Impact Levels

Microsoft screens all Azure Government operators through several checks:

  • Tier 3 Investigation as defined in the SRG  
  • US citizenship verification  
  • Seven-year employment and criminal history checks  
  • Fingerprint checks against Federal Bureau of Investigation (FBI) databases  
  • Cloud screens repeated every two years

This screening model supports the IL-4 and IL-5 access restrictions that distinguish Azure Government from commercial Azure. Support staff holds no standing access to customer content, and elevated access to IL-5 service capacities additionally requires DoD IT-2 adjudication.

The restriction tightens with the data: IL-2 permits foreign persons, while IL-6 requires US citizens only. For ITAR-regulated companies, this addresses export-control concerns directly, since Azure Government is operated by screened US persons.

Data Residency Stays Within US Government Regions

Azure Government's datacenters and networks are located only in the US, and Microsoft commits contractually to storing customer data at rest in the United States. Geo-redundant storage replicates within the US Government geography through region pairing (Arizona pairs with Texas; Virginia pairs with Texas). Replication strategy still belongs to the customer: organizations that want data confined to a single region choose locally redundant or zone-redundant storage instead.

Azure Government Cloud Leaves CMMC and CJIS Obligations with the Customer

FedRAMP Rev5 agency authorization treats platform authorization as one layer, and each cloud service boundary still has to document what it inherits, shares, or implements itself. Microsoft's CMMC guidance says GCC and GCC High users still must properly implement and document the required controls.

The Customer Responsibility Matrix (CRM) draws the actual boundary, identifying which controls are inherited from Microsoft, which are shared, and which sit entirely with the customer. Data classification and access control always remain customer obligations, along with endpoint protection and account management. A CMMC Level 2 assessment tests the required objectives against what you have implemented and can prove, and assessment evidence still has to show implemented controls and connect current architecture diagrams to controls and evidence.

CJIS follows the same pattern: Microsoft signs the CJIS Security Addendum covering its own operational scope, and the agency remains responsible for determining whether each vendor complies with the FBI CJIS Security Policy.

Software as a Service Vendors Face a Build-Versus-Inherit Decision on Government Cloud Infrastructure

Because customer-owned controls sit above Microsoft's platform, Azure Government answers the environment question only. Software as a Service (SaaS) vendors still have to decide who builds and owns the compliance boundary on top of it. A SaaS vendor standing up its own boundary migrates workloads, reconfigures identity against .us endpoints, implements FedRAMP Moderate's 323 controls or FedRAMP High's 410 controls, then carries the assessment and monitoring load indefinitely.

A traditional build concentrates work in several categories:

  • Readiness and gap analysis  
  • Engineering and remediation  
  • Documentation and package build  
  • Third-party assessment  
  • Tooling and managed services

Authorization doesn't end the work. Continuous monitoring, the FedRAMP Post-ATO requirements every authorized service carries, adds recurring operational obligations after authorization. An inherited boundary can remove much of that work when it has already been built, assessed, and authorized.

Choosing the Right Government Cloud Environment Starts the Compliance Work

Every framework in this article draws the same line: the platform is one layer, and the layers above it belong to you. That line is also a lever: if the platform layer can be inherited, so can most of the boundary around your application, sparing a vendor the migration, control implementation, and infrastructure line items that dominate a traditional build.

Knox Systems is a FedRAMP-as-a-Service platform that enables SaaS companies to achieve federal authorization in approximately 90 days at roughly 90% less cost than traditional methods, with automated continuous monitoring after authorization. Knox currently supports FedRAMP Moderate, FedRAMP High, and DISA IL-4, with IL-5 authorization in process and expected to complete in December 2026.

If your federal pipeline depends on authorization status, book a meeting.

FAQs about Azure Government Cloud

Who Is Eligible to Purchase Azure Government?

US federal, state, local, tribal, and territorial government entities, plus non-government organizations handling regulated workloads such as ITAR data, CUI, or DoD IL data. Only select accredited partners are authorized to sell US Government licenses, and Microsoft revalidates eligibility at contract renewal.

How Much of a FedRAMP Baseline Can a SaaS Provider Inherit from Azure Government?

It depends on stack depth and the Customer Responsibility Matrix. Inherited, shared, and customer-owned controls vary by service, while access control still requires customer configuration: Azure provides the capability, but you configure it. Building on platform services inherits substantially more than building on raw infrastructure.

Do State and Local Agencies Need Azure Government for CJIS Workloads?

CJIS Security Policy v5.9.1 (October 2022) allows agencies to run criminal justice information on commercial Azure if they encrypt it in transit, at rest, and in use while keeping sole control of the encryption keys. Azure Government remains the lower-burden path, backed by CJIS Management Agreements with state CJIS Systems Agencies dating to 2014.