Industries / State and local government
Microsoft security for the agencies that fund IT out of a general appropriation.
State and local government IT teams run Microsoft 365 while answering to multiple overlapping regulators: the state CJIS Systems Agency for law enforcement, IRS 1075 for revenue and tax offices, StateRAMP for cloud service adoption, and (in some cases) HIPAA for public health. Identra configures the tenant so the same underlying Entra and Purview settings satisfy every overlay, and produces the per-regulator evidence pack in the format each auditor expects.
- Regulations
- CJIS, IRS 1075, StateRAMP, HIPAA (as applicable)
- Vertical scope
- State agencies, counties, cities, special districts
- License footprint
- M365 GCC or commercial cloud (GCC common)
- Delivery
- Fixed scope, fixed price
01 / What we configure
Four patterns for multi-overlay government IT.
- 01
Unified baseline configuration
Single Entra tenant baseline covers CJIS, IRS 1075, and StateRAMP controls in one configuration. Conditional Access enforces MFA on all privileged access. Legacy authentication disabled tenant-wide. Access reviews scheduled quarterly.
Entra baselineCA policiesAccess reviews - 02
Per-workload segmentation
Law enforcement, revenue, health, and general administration workloads segmented via information barriers or separate tenant regions. Sensitivity labels and DLP rules tuned per workload without duplicating identity configuration.
Information barriersSensitivity labelsPer-workload DLP - 03
Vendor and interagency access
Third-party service providers reach the tenant via B2B with restrictive Conditional Access, MFA, and time-boxed access. Interagency data-sharing configured via Purview Communication Compliance and Sensitivity Labels rather than ad-hoc email.
B2BGSAInteragency labels - 04
Per-regulator evidence pack
One Sentinel workspace produces filtered evidence exports per regulator: CJIS pack for the CSA, IRS 1075 SCSEM for the tax office, StateRAMP evidence for the CIO office. No hand-drafted spreadsheets, no per-audit reworks.
SentinelCJIS packSCSEM
02 / What it looks like
Three state and local government engagements.
Different agency structures, same overlapping regulator surface.
CIO at a mid-size state department
Situation. Combined tenant serves the department central office plus 12 field offices. Some field offices handle CJI (state investigators), some handle IRS federal tax information (revenue enforcement). Two different auditors asking different questions of the same tenant.
Outcome. Information barriers segmented CJI and FTI workloads inside the shared tenant. Single Entra baseline satisfied CJIS §5.6.2.1 and IRS 1075 §9.3.5 MFA requirements. Auditors from CSA and IRS SafeGuards accepted the unified evidence pack.
IT Director at a county with 3,000 employees
Situation. Sheriff department (CJIS), county attorney (attorney-client privileged), and health department (HIPAA) all in the same tenant. County board asked for a StateRAMP-aligned cloud services baseline before approving further SaaS adoption.
Outcome. StateRAMP Moderate baseline applied at tenant level. Per-department information barriers and DLP tuned to the workload sensitivity. Board approved subsequent SaaS adoption citing the unified baseline as the risk-reduction control.
CISO at a large city
Situation. Multiple SaaS acquisitions over the past three years left the tenant with 40+ enterprise applications, most without a documented access-review owner. State Auditor asked for evidence of periodic access review on all enterprise applications.
Outcome. Entitlement management access packages defined per business application. Quarterly access reviews assigned to the application business owner (not IT). State Auditor accepted the entitlement package review evidence as satisfying the audit control.
03 / Frequently asked
What buyers ask first.
- Do we need Microsoft 365 GCC?
- Most state and local government workloads can run in GCC. GCC provides US-based data residency, background-checked support staff, and coverage of CJIS platform controls. Some smaller local government tenants run in commercial cloud without a compliance issue, but if you handle CJIS, IRS FTI, or plan a StateRAMP authorization, GCC is the default recommendation. GCC High is only needed for defense-adjacent or ITAR workloads.
- What is StateRAMP?
- The State Risk and Authorization Management Program provides a common baseline for state and local government cloud service authorization, modelled on FedRAMP but with state and local sponsorship. State agencies use the StateRAMP authorized product list to speed cloud procurement. If your agency is standing up a StateRAMP-authorized service offering, or if you require vendors to be StateRAMP authorized, Identra can map your tenant configuration against the StateRAMP Moderate baseline.
- How does IRS Publication 1075 apply to Microsoft 365?
- IRS Publication 1075 sets the safeguarding requirements for Federal Tax Information (FTI) held by state, local, and territorial governments (typically revenue and child support offices). Publication 1075 requires MFA on all FTI access, encrypted transmission, restricted access, and an annual Safeguards Computer Security Evaluation Matrix (SCSEM) audit. The Microsoft 365 controls satisfying CJIS §5.6.2.1 also satisfy IRS 1075 §9.3.5. Identra covers the SCSEM Microsoft 365 lines.
- What about the CIS Microsoft 365 benchmark?
- The Center for Internet Security publishes the CIS Microsoft 365 Foundations Benchmark, which is a common reference standard for state and local government IT auditors. The CIS benchmark is not itself a regulator obligation but is often used as the baseline the auditor compares your tenant against. Identra engagements deliver a tenant baseline that meets or exceeds the CIS Microsoft 365 benchmark by default.
- How long does a state or local government engagement take?
- Typical engagement runs 12 to 20 weeks depending on the number of workloads and the number of regulators in scope. Weeks 1 to 4 map workloads and regulators. Weeks 5 to 14 configure the unified baseline plus per-workload information barriers and DLP. Weeks 15 to 20 produce the per-regulator evidence pack and train the internal IT and audit teams.
04 / Related
Where this fits.
Law enforcement
CJIS compliance
FBI CJIS Security Policy for law enforcement and state agency tenants.
Federal
FedRAMP and GCC High consulting
Government-cloud tenant configuration for federal and StateRAMP-aligned workloads.
Framework
NIST 800-53 Rev 5 mapping
Control-by-control mapping of tenant settings to NIST 800-53 for state and local baselines.