Solutions / CJIS compliance
CJIS Security Policy on Microsoft 365, without new platforms.
Law enforcement and state or local government agencies with access to Criminal Justice Information have to satisfy the FBI CJIS Security Policy. Most of the technical controls are already in Microsoft 365 E3 and E5. Identra configures Advanced Authentication (§5.6.2.1) via FIDO2 or Windows Hello for Business, audit logging (§5.4) via Purview and Sentinel, and personnel security screening (§5.12) via Entra access reviews tied to the customer HR system.
- Regulation
- FBI CJIS Security Policy v5.9.5
- Applies to
- Law enforcement, courts, state/local agencies
- License footprint
- M365 E3 or E5 + Entra P2 recommended
- Delivery
- Fixed scope, fixed price
01 / What we configure
Four CJIS policy areas mapped to Microsoft 365 controls.
- 01
Advanced Authentication §5.6.2.1
FIDO2 security keys or Windows Hello for Business enforced through Conditional Access on every account that reaches a CJI system. SMS and voice-call MFA phased out for privileged users first, then all users. Legacy authentication disabled tenant-wide.
FIDO2Windows HelloAdvanced Auth - 02
Auditing and Accountability §5.4
Purview audit log retention set to the CJIS 365-day minimum with escalation to Sentinel for longer retention. Alerts on privileged role changes, CJI system access outside normal hours, and unusual export patterns. Weekly review workflow assigned to the LASO.
Purview AuditSentinelLASO workflow - 03
Access Control §5.5
Least-privilege enforced through Entra role assignments and PIM for administrator activation. CJI-holding SharePoint sites and Teams isolated by sensitivity label and information barrier segments. Guest access to CJI systems blocked by policy.
PIMSensitivity labelsInformation barriers - 04
Personnel Security §5.12
Access reviews on every group that reaches a CJI system, tied to the customer HR system so terminations remove access within one business day. Fingerprint-based background check status recorded in the joiner/mover/leaver workflow. Sanction and appropriate use policy acceptance tracked per user.
Access reviewsLifecycle WorkflowsHR integration
02 / What it looks like
Three engagements, same CJIS policy.
Different agency types, same starting state: Microsoft 365 licensed, CJIS defaults not applied.
Chief Information Security Officer at a mid-size sheriff department
Situation. Deputies use department-issued mobile devices to reach case records via Teams and SharePoint. SMS MFA in place. State CJIS auditor flagged the SMS control as not meeting Advanced Authentication.
Outcome. FIDO2 keys rolled out to sworn personnel first, WHfB to civilian staff. Conditional Access blocks SMS fallback on CJI-tagged apps. Audit trail exportable to the state CJIS Systems Agency (CSA) on request.
IT Director at a state department of criminal justice
Situation. Multiple business units run their own Microsoft 365 tenants. CJIS audit demonstrated inconsistent audit retention across tenants. Consolidation stalled because each unit has different licence footprints.
Outcome. Unified CJIS baseline policy deployed via Entra tenant configuration. Sentinel workspace consolidates audit logs from every tenant into a single CJIS-scoped workbook. Per-tenant delta reports show which units are outside baseline for the LASO monthly review.
Deputy Chief at a metropolitan police department
Situation. Recent internal audit found former officers still had access to case management SharePoint sites 30 to 90 days after separation. Manual offboarding process breaks under staff turnover.
Outcome. Entra Lifecycle Workflows tied to the HR system remove all CJI access within one business day of the separation date being posted. Weekly reconciliation report to the LASO catches manual exceptions. Historical access exposure documented for the closeout audit.
03 / Frequently asked
What buyers ask first.
- Does Microsoft 365 GCC meet CJIS Advanced Authentication out of the box?
- GCC provides the platform certifications (US Gov-hosted, background-checked personnel) that CJIS §5.10 asks for. Advanced Authentication under §5.6.2.1 still has to be enforced through Conditional Access and MFA method configuration. The tenant configuration is the customer responsibility even in GCC.
- Do we need GCC High for CJIS?
- GCC (not GCC High) is the more common CJIS deployment. GCC High is required when the CJI data also carries ITAR or DFARS 7012 obligations, or when the CSA explicitly requires it. Most state and local law enforcement can run CJI in commercial-cloud GCC provided the CJIS-specific controls are configured.
- What is the CSA and LASO?
- The CSA (CJIS Systems Agency) is the state-level authority that administers CJIS access for the state. The LASO (Local Agency Security Officer) is the person at each user agency responsible for CJIS security implementation. Every CJIS-covered agency needs a named LASO who owns the annual security awareness training, incident reporting, and audit-response duties. Identra engagements typically deliver the LASO an annual evidence pack.
- How does the fingerprint-based background check fit into Microsoft 365?
- CJIS §5.12 requires fingerprint-based background checks for every person with unescorted access to a physical CJIS area or logical CJI system. Microsoft 365 does not carry out the check; the tenant records whether each user has a passing check status in the joiner/mover/leaver workflow. Identra configures the workflow so that a user without a current passing check cannot be granted access to CJI-tagged Groups, Teams, or SharePoint sites.
- How long does a CJIS engagement take?
- Typical engagement runs 10 to 14 weeks. Weeks 1 to 3 assess the current tenant against the CJIS Security Policy areas. Weeks 4 to 10 configure and stage-enforce controls, with Advanced Authentication rollout usually the longest single workstream. Weeks 11 to 14 build the LASO evidence pack, train the internal security officer, and hand over the runbook.
04 / Related
Where this fits.
Identity
Microsoft Entra consulting
Conditional Access, PIM, ID Protection turned on to enforcement, with a documented handover.
Federal
FedRAMP and GCC High consulting
Government-cloud tenant configuration for federal, defense, and CJIS-adjacent workloads.
Industry
State and local government
Microsoft 365 configuration patterns for municipal, county, and state agency IT.