What Is Microsoft GCC High? Government Cloud Explained
Microsoft will agree to International Traffic in Arms Regulations (ITAR) contract language in only one Microsoft 365 environment available to contractors: Government Community Cloud High (GCC High). For companies in the Defense Industrial Base (DIB), that single contractual fact often decides where Controlled Unclassified Information (CUI) and export-controlled data can live.
Early tenant selection aligns signed contract clauses with migration schedules and gives contractors time to plan a complex tenant migration around existing deadlines.
Key Takeaways
- Physical isolation. GCC High runs on Azure Government data centers located only in the U.S., operated by screened U.S. persons, and is separate from Microsoft's commercial cloud.
- Export-control requirements. Contractors handling only standard CUI can often use GCC; ITAR- or export-controlled data effectively requires GCC High.
- Tenant rebuild. Moving to GCC High requires validation, a separately provisioned government environment, licensing through government purchasing channels, and migration work. Migration duration varies substantially by tenant size and complexity.
- Infrastructure and authorization. SaaS products hosted in GCC High still require Federal Risk and Authorization Management Program (FedRAMP) authorization; the vendor is responsible for its own assessment and for obtaining an Authority to Operate (ATO).
GCC High Is a Physically Isolated Government Cloud for Regulated Workloads
Microsoft 365 GCC High is a Microsoft 365 environment built on Azure Government rather than Microsoft's commercial infrastructure. Microsoft offers it to the Department of Defense (DoD) and to contractors that hold or process DoD CUI or are subject to ITAR.
Azure Government uses physically isolated datacenters and networks located only in the U.S., and customer content at rest stays in U.S. datacenters. Baseline per-tenant isolation controls separate GCC High customers from one another. Operations personnel are screened U.S. persons. Support staff receives production access only through temporary elevation. Anyone requesting it must first pass U.S. citizenship verification as well as employment and criminal record checks. They must also pass Office of Foreign Assets Control (OFAC) list validation.
The core workloads covered by subscriptions include Exchange Online, SharePoint, OneDrive for Business, and Microsoft Teams. Microsoft 365 Copilot for US Government became generally available in GCC High and runs inside the customer's government tenant. Those architectural and personnel controls establish the boundary; the government tiers differ in how far their contractual and impact-level commitments extend.
GCC High Sits Between Standard GCC and the DoD-Only Environment
Microsoft operates three U.S. government tiers: Microsoft 365 GCC, Microsoft 365 GCC High, and Microsoft 365 DoD. The tiers map to impact levels defined in the DoD Cloud Computing Security Requirements Guide (SRG) V1R6 (December 2025). Each tier serves a different customer population under different contractual commitments.
GCC High Adds Isolation and Export-Control Commitments
GCC is a data enclave of Microsoft's commercial cloud, running in Azure Commercial U.S. regions. It supports Criminal Justice Information Services (CJIS) and DoD SRG Impact Level 2 (IL-2).
Under the Defense Federal Acquisition Regulation Supplement (DFARS), DFARS 252.204-7012 requires an external cloud service provider that holds covered defense information to meet security requirements equivalent to the FedRAMP Moderate baseline. GCC also screens personnel as U.S. citizens under CJIS background screening. GCC is unsuitable for export-controlled data because it permits access by personnel outside the U.S. Microsoft limits ITAR contract language to GCC High.
GCC High moves the entire stack onto Azure Government with full infrastructure isolation, adds FedRAMP High and DoD SRG Impact Level 4 (IL-4) alignment, and restricts operations to U.S. persons who clear additional checks. The additional screening requires fingerprinting against Federal Bureau of Investigation (FBI) databases. It also includes Bureau of Industry and Security (BIS) and Directorate of Defense Trade Controls (DDTC) list validation. Microsoft's contract terms commit to U.S. data residency and U.S.-person access. These terms make data sovereignty both architectural and contractual.
Microsoft 365 DoD Is Reserved for DoD Organizations
Microsoft 365 DoD is designed according to DoD SRG Impact Level 5 (IL-5) controls and is reserved for exclusive use by the DoD. Only the DoD can purchase it.
An IL-5 provisional authorization requires additional controls and control enhancements beyond the FedRAMP High baseline. The SRG also requires physical separation from non-DoD, non-federal tenants within dedicated government data centers. GCC High is the highest tier available to the DIB; non-DoD entities in GCC High can demonstrate equivalency to IL-4 or the control inheritance needed for Cybersecurity Maturity Model Certification (CMMC).
GCC High Satisfies a Specific Set of Federal and Defense Requirements
Four framework commitments define what a GCC High tenant buys from a contractor:
1. FedRAMP High authorization
Microsoft 365 GCC High is listed in the FedRAMP Marketplace and is assessed against the National Institute of Standards and Technology (NIST) SP 800-53 Rev5 (September 2020) controls at a Federal Information Processing Standards (FIPS) 199 High categorization.
2. DoD SRG IL-4, with IL-5 infrastructure beneath
Office 365 GCC High is designed to meet DoD SRG Level 4 controls, and non-DoD purchasers can demonstrate IL-4 equivalency or the control inheritance required for CMMC. The Azure Government infrastructure underneath holds Defense Information Systems Agency (DISA) IL-4 and IL-5 provisional authorizations.
3. ITAR and Export Administration Regulations (EAR) data
Cloud providers are outside the scope of ITAR compliance certification. Microsoft designs GCC High to support a customer's own ITAR compliance program through U.S.-person access restrictions and contractual sovereignty commitments. The contractor's State Department registration and export-control obligations remain the contractor's.
4. CMMC 2.0 Level 2 and DFARS 252.204-7012
DFARS 252.204-7012 requires cloud services holding covered defense information to meet security requirements equivalent to the FedRAMP Moderate baseline. Microsoft demonstrates that equivalency for GCC High with a Body of Evidence available under a nondisclosure agreement (NDA).
When configured appropriately, GCC High supports CMMC Level 2 and Level 3. CMMC Level 2 currently assesses against NIST SP 800-171 Rev2, the revision the CMMC Program Rule references and that a May 2024 DoD class deviation requires under DFARS 252.204-7012. NIST published Rev3 in May 2024, but it does not apply to CMMC until the DoD completes separate rulemaking.
Contractors can inherit controls covered by these commitments. The contractor remains responsible for its complete configuration and authorization work.
Migrating to GCC High Requires a Multi-Phase Tenant Project
Microsoft excludes government-cloud users from its native Cross-Tenant OneDrive migration. GCC High uses Azure Government and a separate Microsoft Entra ID environment, so migration requires a separately provisioned environment:
Eligibility validation and licensing
Organizations submit proof of eligibility before Microsoft will allow a purchase. Microsoft validates eligibility based on the organization and the government data it handles. Licenses come through government purchasing channels. Agreement for Online Services Government (AOS-G) partners offer a single purchasing option.
Tenant provisioning and identity configuration
Provisioning and environment preparation must be completed before migration. The destination tenant requires planning and configuration for:
- Identity;
- the custom domain;
- Domain Name System (DNS) and mail routing;
- authentication; and
- security policies.
Pilot migration
A small user group tests identity and third-party application compatibility in the new tenant. It also tests workflows before full migration.
Full data migration and user transition
Exchange Online mailboxes and OneDrive files can move through cross-tenant migration processes. Teams chats can also move through those processes. That process excludes SharePoint sites. Teams structures, Power Apps, and Power Automate workflows must be rebuilt by hand. Migration duration varies substantially with tenant size and complexity.
Completing the tenant move addresses where regulated workloads run. Products operating within that environment are subject to separate authorization requirements.
GCC High Provides Infrastructure While SaaS Products Require Authorization
For a defense contractor, a properly configured GCC High tenant can meet the infrastructure requirements of regulated workloads. For a SaaS vendor selling into the federal or defense market, GCC High supplies the authorized infrastructure layer. The SaaS product requires separate FedRAMP authorization, and components outside the authorized service boundary require their own authorizations, which translates into engineering and security needs.
The authorized infrastructure layer provides control inheritance for physical, environmental, and platform controls. The vendor must prove the controls above that layer. The authorization path then proceeds through a defined sequence:
- Secure agency sponsorship. Agency sponsorship is currently required for High-baseline authorizations.
- Prepare the System Security Plan. The vendor writes a System Security Plan that documents how each NIST 800-53 control is implemented or inherited.
- Complete the independent assessment. An independent Third-Party Assessment Organization (3PAO) produces a Security Assessment Report.
- Complete FedRAMP review. The FedRAMP authorization process includes review of the authorization package.
- Receive the Marketplace designation. After review, the Marketplace designation changes to FedRAMP Authorized. A FedRAMP Authorized Marketplace designation records completion of FedRAMP review. Each agency customer then issues its own ATO.
Initial FedRAMP High authorization requires substantial documentation and assessment. It also requires review and ongoing monitoring. A preexisting authorization layer can reduce the work a vendor must complete.
Compliant Infrastructure Supports the Federal Sales Process
Contractors adopt GCC High because their contracts demand it, and that adoption then constrains every vendor who wants to sell to them. GCC High's Teams environment supports incoming webhooks as its third-party app option, and integrations must be compatible with government cloud endpoints.
Federal buyers may require authorization before adopting a product. Delaying authorization can therefore delay adoption while vendors prepare deployment and integration support for the environment where their buyers already work.
Knox Systems is a FedRAMP-as-a-Service platform that enables vendors to inherit up to 80% of the required controls from its pre-authorized FedRAMP boundary, rather than building them. Knox currently supports FedRAMP Moderate and FedRAMP High. It also supports DISA IL-4, with IL-5 in process and estimated for December 2026. The advisory and assessment tracks are contractually separate.
To scope an authorization path against your federal pipeline, book a meeting.
FAQs about Microsoft GCC High
Do I Need GCC High?
GCC High is effectively required when signed contract clauses cover ITAR or other export-controlled data. Contractors handling only standard CUI can often use GCC, subject to their contract requirements and data classification.
What Is the Difference Between GCC and GCC High?
GCC is an enclave within Microsoft's commercial cloud that supports IL-2 and permits access by personnel outside the U.S. GCC High runs on isolated Azure Government infrastructure, aligns with FedRAMP High and IL-4, and limits operations to screened U.S. persons.
What Impact Level Is GCC High?
Microsoft 365 GCC High is designed in accordance with DoD SRG IL-4 controls. Its underlying Azure Government infrastructure holds DISA IL-4 and IL-5 provisional authorizations, while Microsoft 365 DoD is the DoD-only environment designed for IL-5 controls.
How Much Does Microsoft GCC High Cost?
GCC High does not have a single fixed price; organizations must request pricing through authorized government purchasing channels. The final quote depends on the selected licenses, seat count, and agreement route, including AOS-G partners, Large Solution Providers (LSPs), or Enterprise Agreements.
Does GCC High Satisfy CMMC Requirements?
GCC High supports CMMC Level 2 and Level 3 when configured appropriately, but the tenant does not independently satisfy CMMC. The contractor remains responsible for configuration, logging, device compliance, data protection, evidence, and the remaining authorization work.