Federal reviewers approved Microsoft GCC High for handling sensitive government data despite internal findings that the company’s security documentation was inadequate and that evaluators lacked confidence in the service’s overall security posture. ProPublica reported that a late-2024 internal government review described Microsoft’s submission in scathing terms and raised concerns that officials could not fully verify how sensitive data was protected as it moved through the cloud environment. The reporting also highlighted a structural FedRAMP weakness: third-party assessors that help validate cloud services are selected and paid by the vendors they evaluate, creating concerns about independence and rigor.
Additional reporting said the consequences are now surfacing across government, including at the Justice Department, where officials learned that Microsoft had used China-based engineers to help service sensitive cloud systems despite restrictions on non-U.S. citizens assisting with certain IT maintenance. According to the reports, that arrangement was not disclosed in the written security plan submitted for GCC High, and officials said they learned of it through investigative reporting rather than from Microsoft or FedRAMP. Microsoft said it had communicated the information to Justice officials before 2020 and has since ended the use of China-based engineers in government systems, but the episode intensified concerns that other risks in GCC High and the broader FedRAMP authorization process may have gone undetected.

See affected versions and whether adversaries are exploiting it.
5 events from the most recent confirmed update back to the earliest known activity.
ProPublica published an investigation detailing how FedRAMP approved GCC High despite longstanding internal concerns, structural weaknesses in the authorization process, and Microsoft's prior security controversies involving government systems.
The Justice Department recently stepped up scrutiny of cybersecurity misrepresentations by federal contractors, a broader development highlighted in connection with concerns around Microsoft's government cloud representations. The references do not provide a more specific date for this shift.
In December 2024, FedRAMP approved Microsoft Government Community Cloud High even though internal reviewers said Microsoft had not provided sufficient detailed security documentation and evaluators lacked confidence in judging the product's overall security posture.
While the FedRAMP review remained unresolved, GCC High continued to be adopted across federal agencies and the defense sector. Its growing deployment increased pressure to approve the service because it was already widely in use.
FedRAMP reviewers began flagging problems with Microsoft Government Community Cloud High as early as 2020, including missing documentation on data flows and encryption. Repeated exchanges with Microsoft, third-party assessors, and the Justice Department did not fully resolve the issues.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
6 references tracked. Mallory keeps watching after this page renders.
schneier.com
Open sourcepropublica.org
Open sourcetechdirt.com
Open sourceboingboing.net
Open sourcearstechnica.com
Open sourcepropublica.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.