Identra

Solutions / FedRAMP + GCC High

FedRAMP and GCC High tenant work, without the platform re-explaining.

Microsoft 365 GCC and GCC High tenants already carry FedRAMP High authorisation at the platform layer. What the third-party assessor asks about is the customer-responsibility matrix: the AC, AU, IA, and CM controls that the customer has to configure inside their own tenant. Identra configures those controls, produces the SSP-ready evidence pack, and helps the customer answer the 3PAO interview questions on Entra and Purview posture.

Authorisation framework
FedRAMP Moderate / High, DoD IL4 / IL5
Tenant type
GCC or GCC High (Microsoft 365)
Baseline
NIST 800-53 Rev 5 + FedRAMP overlays
Delivery
Fixed scope, fixed price

01 / What we configure

Four workstreams for the customer-responsibility side of the matrix.

  • 01

    AC and IA control configuration

    Conditional Access with FIPS 140-2 validated authenticators. FIDO2 keys or Windows Hello for Business on every account with elevated access. Legacy authentication disabled. Account management workflow tied to the customer HR system.

    FIPS 140-2FIDO2Lifecycle
  • 02

    AU control configuration

    Purview audit retention set to the FedRAMP baseline (1 year online for Moderate, 3 years for High). Sentinel workspace configured in the government cloud region matching the tenant. Log forwarding to the customer SIEM if applicable.

    Purview AuditSentinel GovSIEM export
  • 03

    SSP-ready evidence pack

    Per-control evidence document showing which tenant setting satisfies each customer-responsibility control, with screenshots and Sentinel query references. Formatted to align with the customer System Security Plan and the FedRAMP Rev 5 template.

    SSPEvidence pack3PAO-ready
  • 04

    3PAO interview preparation

    Trial-run interviews with the tenant admin ahead of the 3PAO visit. Common assessor questions on Entra, Defender, and Purview posture, with the settings and evidence to answer each. Reduces the assessment-cycle back-and-forth and cuts the risk of a finding.

    3PAOInterview prepAssessment cycle

02 / What it looks like

Three engagements, same customer-responsibility footprint.

Different agency customers, same tenant type, same 3PAO expectations.

CISO at a SaaS vendor selling to federal agencies

Situation. Product runs on Azure Gov. Federal customer procurement stalled because the vendor could not produce evidence for 30 customer-responsibility controls in the M365 GCC tenant used for corporate operations.

Outcome. Identra 3-week sprint configured the 30 controls in the corporate GCC tenant and generated the evidence pack. Federal customer procurement completed. Same evidence reused for the next two agency onboardings.

Compliance Manager at a defense-adjacent research organisation

Situation. Operating in GCC High for a DoD IL4 workload. Annual FedRAMP High re-assessment produced 12 customer-responsibility findings that required control-owner sign-off before the ATO renewal.

Outcome. Findings clustered into three tenant-configuration workstreams (AC, AU, IA). Identra closed all 12 in a 6-week engagement. ATO renewed on time without an extension letter.

IT Director at a state government IT services organisation

Situation. StateRAMP Moderate target. Existing GCC tenant configuration had inconsistent audit retention across business units. Multiple SIEM export paths configured, half not working.

Outcome. Unified Purview audit configuration deployed via tenant baseline. Single Sentinel workspace in the government region replaced three disparate SIEM export paths. StateRAMP authorisation package accepted.

03 / Frequently asked

What buyers ask first.

What is the difference between GCC and GCC High?
Both are US-sovereign-cloud Microsoft 365 tenants with US-based data residency and background-checked support staff. GCC serves federal, state, local, and tribal government plus commercial customers with regulated data (CJIS, IRS 1075, ITAR-adjacent). GCC High serves DoD, defense industrial base, ITAR-regulated commercial, and DFARS 7012 customers, at higher cost and with more restricted feature availability. Choose based on the data classification and customer contract requirements.
Do we need GCC High if we handle CUI?
Not always. CUI can be handled in commercial cloud, GCC, or GCC High depending on the marking, the disseminating agency, and the contract clause. DFARS 7012 clauses that flow down from DoD contracts typically require GCC High or equivalent. Non-DoD CUI can often run in GCC. The contract clause is the deciding factor, not the CUI marking alone.
What is the customer-responsibility matrix?
Microsoft publishes a per-control document (the CRM) that identifies which NIST 800-53 controls Microsoft satisfies at the platform layer and which controls the customer must configure or supplement inside their own tenant. FedRAMP assessments hold customers accountable for the customer-responsibility controls. Identra engagements are scoped against the CRM for the specific tenant type (GCC or GCC High) and baseline (Moderate or High).
What is a 3PAO?
A Third-Party Assessment Organisation, accredited by the American Association for Laboratory Accreditation (A2LA) under the FedRAMP program, that performs the independent assessment of a cloud service offering against the FedRAMP baseline. The 3PAO produces the Security Assessment Report the customer submits to the FedRAMP PMO or JAB for authorisation. Identra prepares customers for the 3PAO interview and evidence review, but does not perform the assessment itself.
How long does a FedRAMP or GCC High engagement take?
A first-time customer-responsibility configuration typically runs 12 to 16 weeks for Moderate and 16 to 24 weeks for High. Annual re-assessment prep runs 4 to 8 weeks. If the tenant is new to GCC or GCC High and the licensing move is still in progress, add 4 to 8 weeks for the platform migration workstream on top.

Next step

Book a FedRAMP or GCC High scoping call.

Thirty minutes on your tenant type, target baseline, and the customer-responsibility controls the 3PAO will ask about. Written scoping note within two business days.