CMMC · Microsoft GCC High
GCC High enclave vs. full migration: which one, and who watches it?
Most guides compare license cost and assessment scope. They skip the part that decides whether you pass: how you'll monitor a GCC High tenant 24/7 when Microsoft's own SIEM connectors don't all work there yet.
Published September 30, 2026 · Cyberuptive, Honolulu
The short answer
Use an enclave when CUI is limited to a small, well-defined group of people and systems, and you can keep it out of your commercial tenant. Use a full migration when CUI is everywhere, when export-controlled data is common, or when you can't enforce a clean boundary. Either way, plan the monitoring before you sign the licensing order. In GCC High, it's the part most likely to fail an assessment.
What each option actually is
GCC High is a platform, not a compliance status. An enclave is a boundary: the set of users, devices, and services that touch or protect CUI. You can put a GCC High tenant inside that boundary, or you can move the whole company into it.
| GCC High enclave | Full GCC High migration | |
|---|---|---|
| Who moves | Only CUI users and systems | Everyone |
| Tenants to run | Two (commercial plus GCC High) | One |
| Assessment scope | Smaller, if the boundary holds | Whole organization |
| Licensing cost | Lower, fewer GCC High seats | Higher |
| Identity | Two directories, separate accounts for CUI users | One directory |
| Main risk | CUI leaking into the commercial tenant | Cost, migration effort, feature lag |
| Monitoring | Two log pipelines, correlated | One pipeline, still with GCC High gaps |
Scoping follows 32 CFR 170.19. Assets that can process CUI are in scope. Assets that can but aren't supposed to are Contractor Risk Managed Assets, which you document and manage by policy. Security tools that protect the CUI environment are Security Protection Assets and are in scope too (32 CFR 170.19). An enclave only shrinks scope if you can show the assessor that the commercial side really can't reach CUI.
Why GCC High at all
The legal hook is DFARS 252.204-7012: a cloud service that stores, processes, or transmits covered defense information must meet security requirements equivalent to the FedRAMP Moderate baseline, and must support the clause's incident reporting, malware, and forensic requirements (DFARS 252.204-7012). GCC High is popular because it also handles personnel screening. Microsoft says staff who request elevated access to GCC High customer content must first pass checks that include US citizenship verification, a seven-year employment and criminal history check, and screening against OFAC, BIS, and DDTC lists (Microsoft). That matters most if your CUI includes ITAR or EAR technical data.
One note on that same page: Microsoft says GCC High and DoD support "isn't included in the service accreditation boundary" and doesn't provide FedRAMP, DoD SRG, ITAR, IRS 1075, or CJIS data handling assurances. Don't paste CUI into a support ticket.
The monitoring problem nobody ranks for
Here's what the typical enclave guide leaves out. NIST SP 800-171 expects you to create and review audit logs and to monitor for attacks. In a GCC High tenant, the usual Microsoft tooling doesn't all work the way it does in commercial.
Microsoft's own support table for Microsoft Sentinel in GCC High and DoD shows (Microsoft Learn):
| Data in Sentinel (GCC High / DoD) | Status |
|---|---|
| Defender XDR incidents | Generally available |
| Defender for Endpoint alerts | Generally available |
| Defender XDR alerts, Defender for Office 365 alerts | Public preview |
| Defender for Endpoint raw events (process, network, file, logon) | Public preview in Sentinel |
| Defender for Identity alerts and raw events | Unsupported |
| Defender for Cloud Apps alerts and CloudAppEvents | Unsupported |
That table changes, so check it before you design. As of this writing, it means a GCC High SOC can't rely on Sentinel alone for identity-based attack detection, which is one of the most common paths into Microsoft 365. You need a plan for it: detections built in Defender XDR itself, Entra ID sign-in and audit logs sent to the SIEM, and analysts who know which alerts will never show up in the SIEM.
Enclaves add a second problem. An attacker who phishes a user in the commercial tenant and then goes after the same person's GCC High account crosses two log pipelines. If your SOC watches them separately, nobody sees the link. Correlation across both tenants, with a shared identity map, is what closes it.
Third-party MDR adds a third. Some commercial providers will monitor GCC environments but say in their terms that only their supported integrations are covered, that some Microsoft log sources may be beta, and that they don't want CUI in their platform (Arctic Wolf MDR terms). That's fine if you plan for it. It's a finding if you don't.
We run these
Get a GCC High monitoring gap review
We'll map which of your GCC High log sources reach a SIEM today, which don't, and what compensating detection covers the gap, before your assessor asks.
A decision checklist
- Map CUI first. Which people, mailboxes, sites, and devices touch it? If it is a small, stable group of people and a handful of systems, an enclave is realistic.
- Check for export-controlled data. ITAR or EAR technical data raises the stakes on who can access what, including your SOC. See whether SOC analysts need to be US persons.
- Test the boundary. Can a commercial-tenant user forward, sync, or share into the enclave? Data loss prevention and conditional access need to block it, and you need logs that prove it.
- Design the log pipeline before you migrate. List every source, where it lands, and what's unsupported. Write down compensating detections.
- Put your SOC in the SSP. Your monitoring provider is a Security Protection Asset. Get its service description and customer responsibility matrix.
- Plan incident response for both tenants. A DFARS 72-hour report needs a timeline that spans both. See our incident response retainer.
How Cyberuptive runs GCC High
We deploy and operate security controls in Microsoft GCC High for CMMC Level 2 organizations and support AWS GovCloud (US) and Azure Government workloads. All GCC High and GovCloud operations are done by US-persons analysts on our segregated US SOC. For enclaves, we monitor both tenants as one environment so a cross-tenant attack shows up as one incident, not two unrelated alerts. See Microsoft 365 and Azure security and CMMC compliance services.
Frequently asked questions
Is GCC High required for CMMC Level 2?
No. CMMC doesn't name a platform. If a cloud service stores, processes, or transmits CUI, DFARS 252.204-7012 requires it to meet security requirements equivalent to FedRAMP Moderate. GCC High is a common choice, especially when export-controlled data is involved, but it isn't the only way to meet the requirement.
What is a GCC High enclave?
A separate GCC High tenant for only the users, devices, and data that handle CUI, while the rest of the company stays on commercial Microsoft 365. It shrinks the number of GCC High licenses and the assessment scope, but you now run two identity systems, two sets of policies, and two sets of logs.
When does a full GCC High migration make more sense than an enclave?
When CUI is spread across most of your email, Teams, SharePoint, and OneDrive, when most staff touch it, or when you can't reliably keep it out of the commercial tenant. At that point the enclave's boundary becomes hard to defend in an assessment.
Does Microsoft Sentinel support all Defender data in GCC High?
Not yet. Microsoft's cloud support table for Sentinel in GCC High and DoD lists Defender for Identity and Defender for Cloud Apps alerts and raw events as unsupported, and Defender for Endpoint raw events as public preview in Sentinel. Check the current table before you design detection.
Is the SOC that monitors my GCC High tenant in CMMC scope?
Yes. Logs are Security Protection Data under 32 CFR 170.4, so a provider that collects them is assessed as a Security Protection Asset. If it can access CUI, its services are assessed as part of your assessment.