<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>Government AMA topics</title>
    <link>https://techcommunity.microsoft.com/t5/government-ama/bd-p/GovernmentAMA</link>
    <description>Government AMA topics</description>
    <pubDate>Wed, 29 Apr 2026 03:36:09 GMT</pubDate>
    <dc:creator>GovernmentAMA</dc:creator>
    <dc:date>2026-04-29T03:36:09Z</dc:date>
    <item>
      <title>That's a wrap: Microsoft CMMC AMA</title>
      <link>https://techcommunity.microsoft.com/t5/government-ama/that-s-a-wrap-microsoft-cmmc-ama/m-p/1611445#M350</link>
      <description>&lt;P&gt;Thank you for joining us and voicing your questions and feedback during this fun and action-packed hour.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;*Please note that you won't be able to ask new questions in this space until our next live event.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;We will be disabling posting and further comments in this AMA space but encourage you to post any new questions or follow up in our&amp;nbsp;&lt;A href="https://techcommunity.microsoft.com/t5/public-sector-local-state/bd-p/PublicSector" target="_blank"&gt;Public Sector, Local/State Government Space&lt;/A&gt;.&amp;nbsp;&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We will put together a summary document of what was covered during and share it in this group as well as a follow up blog post. See you next time!&lt;/P&gt;</description>
      <pubDate>Tue, 25 Aug 2020 17:00:11 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/government-ama/that-s-a-wrap-microsoft-cmmc-ama/m-p/1611445#M350</guid>
      <dc:creator>Sarah_Gilbert</dc:creator>
      <dc:date>2020-08-25T17:00:11Z</dc:date>
    </item>
    <item>
      <title>Azure Gov AIP Unified label client support for MacOS</title>
      <link>https://techcommunity.microsoft.com/t5/government-ama/azure-gov-aip-unified-label-client-support-for-macos/m-p/1611378#M337</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm currently setting up AIP for our tenant and it doesn't appear that the Unifield Labling client for MacOS is available.&amp;nbsp; Does that mean Office Apps for Mac can't label their documents until this is available?&amp;nbsp; Would they have to use the web versions?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Mike&lt;/P&gt;</description>
      <pubDate>Tue, 25 Aug 2020 16:46:00 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/government-ama/azure-gov-aip-unified-label-client-support-for-macos/m-p/1611378#M337</guid>
      <dc:creator>BerlinerVice</dc:creator>
      <dc:date>2020-08-25T16:46:00Z</dc:date>
    </item>
    <item>
      <title>Bitlocker Encryption Compliance</title>
      <link>https://techcommunity.microsoft.com/t5/government-ama/bitlocker-encryption-compliance/m-p/1611365#M333</link>
      <description>&lt;P&gt;Could you detail the settings that are required for Bitlocker full-disk encryption to be compliant with CMMC (FIPS-validated encryption)? I've seen a "FIPS-mode" setting, but heard there was more than one step to being compliant.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What Operating Systems is this available on? Win7, Win10, Server 2008, Server 2012, Server 2016?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Tue, 25 Aug 2020 16:44:54 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/government-ama/bitlocker-encryption-compliance/m-p/1611365#M333</guid>
      <dc:creator>Anon414</dc:creator>
      <dc:date>2020-08-25T16:44:54Z</dc:date>
    </item>
    <item>
      <title>Securely Transferring Data from Company O365/M365 to Customers/Partners</title>
      <link>https://techcommunity.microsoft.com/t5/government-ama/securely-transferring-data-from-company-o365-m365-to-customers/m-p/1611340#M325</link>
      <description>&lt;P&gt;What options are available to securely transfer data/documents from company-managed Office 365 (commercial, GCC, or GCC High) environments and customer/partner ones?&amp;nbsp; I realize the data could always stay in one environment to avoid this problem, but what Microsoft options exist to 'deliver' CUI to customers securely?&lt;/P&gt;</description>
      <pubDate>Tue, 25 Aug 2020 16:39:36 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/government-ama/securely-transferring-data-from-company-o365-m365-to-customers/m-p/1611340#M325</guid>
      <dc:creator>MichaelKing</dc:creator>
      <dc:date>2020-08-25T16:39:36Z</dc:date>
    </item>
    <item>
      <title>ITAR Compliance</title>
      <link>https://techcommunity.microsoft.com/t5/government-ama/itar-compliance/m-p/1611333#M323</link>
      <description>&lt;P&gt;If an organization is using ITAR data with Microsoft solutions, is GCC high required for the storage or processing of this data?&lt;/P&gt;</description>
      <pubDate>Tue, 25 Aug 2020 16:38:56 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/government-ama/itar-compliance/m-p/1611333#M323</guid>
      <dc:creator>Anon414</dc:creator>
      <dc:date>2020-08-25T16:38:56Z</dc:date>
    </item>
    <item>
      <title>Protection of CUI in OneDrive</title>
      <link>https://techcommunity.microsoft.com/t5/government-ama/protection-of-cui-in-onedrive/m-p/1611305#M319</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Is there a secure and compliant way to store and process data in OneDrive (FIPS validated cryptography, configuration settings, etc)? Does this require a GCC or GCC high license for this function?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Are there specific settings that are required?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 25 Aug 2020 16:35:53 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/government-ama/protection-of-cui-in-onedrive/m-p/1611305#M319</guid>
      <dc:creator>Anon414</dc:creator>
      <dc:date>2020-08-25T16:35:53Z</dc:date>
    </item>
    <item>
      <title>Re: Welcome to the Microsoft CMMC AMA!</title>
      <link>https://techcommunity.microsoft.com/t5/government-ama/re-welcome-to-the-microsoft-cmmc-ama/m-p/1611270#M317</link>
      <description>&lt;P&gt;&lt;a href="javascript:void(0)" data-lia-user-mentions="" data-lia-user-uid="321630" data-lia-user-login="Sarah_Gilbert" class="lia-mention lia-mention-user"&gt;Sarah_Gilbert&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hi there, I was wondering if MS believes customers that require CMMC level 3 would be able to leverage M365 services such as EMS to become compliant or if moving to GCC high is a must?&lt;/P&gt;</description>
      <pubDate>Tue, 25 Aug 2020 16:31:09 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/government-ama/re-welcome-to-the-microsoft-cmmc-ama/m-p/1611270#M317</guid>
      <dc:creator>GOsorio</dc:creator>
      <dc:date>2020-08-25T16:31:09Z</dc:date>
    </item>
    <item>
      <title>Protection of CUI in SharePoint</title>
      <link>https://techcommunity.microsoft.com/t5/government-ama/protection-of-cui-in-sharepoint/m-p/1611294#M316</link>
      <description>&lt;DIV class="lia-message-subject-wrapper lia-component-subject lia-component-message-view-widget-subject-with-options"&gt;&lt;SPAN&gt;Is there a secure and compliant way to store and process data in SharePoint (FIPS validated cryptography, access controls, etc)? Does this require a GCC or GCC high license for this function?&lt;/SPAN&gt;&lt;/DIV&gt;</description>
      <pubDate>Tue, 25 Aug 2020 16:33:51 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/government-ama/protection-of-cui-in-sharepoint/m-p/1611294#M316</guid>
      <dc:creator>Anon414</dc:creator>
      <dc:date>2020-08-25T16:33:51Z</dc:date>
    </item>
    <item>
      <title>CMMC - does it require MFA at network login?</title>
      <link>https://techcommunity.microsoft.com/t5/government-ama/cmmc-does-it-require-mfa-at-network-login/m-p/1611269#M310</link>
      <description>&lt;P&gt;"NIST 800-171 3.5.3 Use multifactor authentication for local and network access to privileged accounts and for network access to non-privileged accounts"&amp;nbsp; Some debate inside my company about whether MFA is required at network login vs MFA being required only when accessing CUI systems (not all systems on our network have CUI).&amp;nbsp; So, can we place MFA at entry to CUI system and not MFA all employees at time of network login?&amp;nbsp; And does CMMC require anything different that NIST 800-171 3.5.2?&lt;/P&gt;</description>
      <pubDate>Tue, 25 Aug 2020 16:31:06 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/government-ama/cmmc-does-it-require-mfa-at-network-login/m-p/1611269#M310</guid>
      <dc:creator>bkaufman</dc:creator>
      <dc:date>2020-08-25T16:31:06Z</dc:date>
    </item>
    <item>
      <title>What are the recommendation and procedures for flagging data as CUI and managing it?</title>
      <link>https://techcommunity.microsoft.com/t5/government-ama/what-are-the-recommendation-and-procedures-for-flagging-data-as/m-p/1611244#M305</link>
      <description>&lt;P&gt;In preparing for our CMMC Certification, as a company that is heavily uses SharePoint and Teams in the Office365 cloud environment -- what are the recommendations and procedures for flagging data as CUI and managing it?&lt;/P&gt;</description>
      <pubDate>Tue, 25 Aug 2020 16:25:19 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/government-ama/what-are-the-recommendation-and-procedures-for-flagging-data-as/m-p/1611244#M305</guid>
      <dc:creator>Kalonji_ICS</dc:creator>
      <dc:date>2020-08-25T16:25:19Z</dc:date>
    </item>
    <item>
      <title>Microsoft's Perspective on FCI</title>
      <link>https://techcommunity.microsoft.com/t5/government-ama/microsoft-s-perspective-on-fci/m-p/1611227#M301</link>
      <description>&lt;P&gt;What is Microsoft's perspective on the definition of FCI that was used to assess controls implemented for Azure and O365 against CMMC practices that call out FCI?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 25 Aug 2020 16:22:37 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/government-ama/microsoft-s-perspective-on-fci/m-p/1611227#M301</guid>
      <dc:creator>HaranStark</dc:creator>
      <dc:date>2020-08-25T16:22:37Z</dc:date>
    </item>
    <item>
      <title>Protection of CUI via email</title>
      <link>https://techcommunity.microsoft.com/t5/government-ama/protection-of-cui-via-email/m-p/1611226#M300</link>
      <description>&lt;P&gt;Is there a secure and compliant way to transfer CUI using Outlook (SC.3.177 requires FIPS validated cryptography)? Does this require a GCC or GCC high license if you are only using this function?&lt;/P&gt;</description>
      <pubDate>Tue, 25 Aug 2020 16:22:24 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/government-ama/protection-of-cui-via-email/m-p/1611226#M300</guid>
      <dc:creator>Anon414</dc:creator>
      <dc:date>2020-08-25T16:22:24Z</dc:date>
    </item>
    <item>
      <title>MS 365 and CMMC Level 1</title>
      <link>https://techcommunity.microsoft.com/t5/government-ama/ms-365-and-cmmc-level-1/m-p/1611215#M296</link>
      <description>&lt;P&gt;CMMC Level 1 has 17 requirements. Does MS 365 address any of these requirements.&amp;nbsp; NOT MS 365 + Azure but only MS 365. If so, please address each of the Level 1 requirements.&amp;nbsp; If this is not the correct forum, please do a white paper.&lt;BR /&gt;Thank you.&lt;BR /&gt;Demps1787&lt;/P&gt;</description>
      <pubDate>Tue, 25 Aug 2020 16:21:39 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/government-ama/ms-365-and-cmmc-level-1/m-p/1611215#M296</guid>
      <dc:creator>Demps1787</dc:creator>
      <dc:date>2020-08-25T16:21:39Z</dc:date>
    </item>
    <item>
      <title>CMMC secure score recommendations</title>
      <link>https://techcommunity.microsoft.com/t5/government-ama/cmmc-secure-score-recommendations/m-p/1611190#M291</link>
      <description>&lt;P&gt;I know that Azure has secure score recommendations for other common compliance standards, ie HIPAA. Will Microsoft be creating ones that can apply for CMMC compliance?&lt;/P&gt;</description>
      <pubDate>Tue, 25 Aug 2020 16:18:38 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/government-ama/cmmc-secure-score-recommendations/m-p/1611190#M291</guid>
      <dc:creator>bduszkie1980</dc:creator>
      <dc:date>2020-08-25T16:18:38Z</dc:date>
    </item>
    <item>
      <title>Azure VM CMMC compliance</title>
      <link>https://techcommunity.microsoft.com/t5/government-ama/azure-vm-cmmc-compliance/m-p/1611181#M288</link>
      <description>&lt;P&gt;How is Microsoft working to make Azure VMs CMMC compliant? What can we do to pass audits with these systems? My guess would be to start by reading the 10 blog series from&amp;nbsp;&lt;SPAN&gt;TJ Banasik.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://devblogs.microsoft.com/azuregov/cmmc-with-microsoft-azure-access-control-1-of-10/" target="_blank"&gt;https://devblogs.microsoft.com/azuregov/cmmc-with-microsoft-azure-access-control-1-of-10/&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 25 Aug 2020 16:17:11 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/government-ama/azure-vm-cmmc-compliance/m-p/1611181#M288</guid>
      <dc:creator>Brian Sondreal</dc:creator>
      <dc:date>2020-08-25T16:17:11Z</dc:date>
    </item>
    <item>
      <title>Azure lighthouse and CMMC Compliance</title>
      <link>https://techcommunity.microsoft.com/t5/government-ama/azure-lighthouse-and-cmmc-compliance/m-p/1611155#M283</link>
      <description>&lt;P&gt;I work for a consulting business which uses Azure Lighthouse to manage clients Azure instances. Can we keep managing GCC or GCC high tenants in lighthouse? How do we ensure compliance with CMMC if using azure Lighthouse ( issues surrounding data locations and movement)?&lt;/P&gt;</description>
      <pubDate>Tue, 25 Aug 2020 16:14:42 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/government-ama/azure-lighthouse-and-cmmc-compliance/m-p/1611155#M283</guid>
      <dc:creator>bduszkie1980</dc:creator>
      <dc:date>2020-08-25T16:14:42Z</dc:date>
    </item>
    <item>
      <title>Office 365 GCC High and AU compliance</title>
      <link>https://techcommunity.microsoft.com/t5/government-ama/office-365-gcc-high-and-au-compliance/m-p/1611128#M280</link>
      <description>&lt;P&gt;Do you have a direct mapping of how GCC High meets AU compliance?&amp;nbsp; Most importantly from a logging prospective?&lt;/P&gt;</description>
      <pubDate>Tue, 25 Aug 2020 16:13:33 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/government-ama/office-365-gcc-high-and-au-compliance/m-p/1611128#M280</guid>
      <dc:creator>twernet</dc:creator>
      <dc:date>2020-08-25T16:13:33Z</dc:date>
    </item>
    <item>
      <title>Roadmap for collaboration tools</title>
      <link>https://techcommunity.microsoft.com/t5/government-ama/roadmap-for-collaboration-tools/m-p/1611090#M278</link>
      <description>&lt;P&gt;Aloha Richard,&lt;BR /&gt;Is there a roadmap for collaboration tools Teams/Yammer above moderate assurance level 4 in FEDRamp?&lt;/P&gt;</description>
      <pubDate>Tue, 25 Aug 2020 16:13:43 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/government-ama/roadmap-for-collaboration-tools/m-p/1611090#M278</guid>
      <dc:creator>allHawaii</dc:creator>
      <dc:date>2020-08-25T16:13:43Z</dc:date>
    </item>
    <item>
      <title>When can we use Archive Tier for blob storage on GCC-High?</title>
      <link>https://techcommunity.microsoft.com/t5/government-ama/when-can-we-use-archive-tier-for-blob-storage-on-gcc-high/m-p/1611114#M277</link>
      <description>&lt;P&gt;We need a secure blob storage target for long term retention data. (7 year and 30 year)&lt;/P&gt;&lt;P&gt;I would only put this data in to our Azure tenant at the Archive tier but I'm told that it's not available for GCC-High yet.&lt;/P&gt;</description>
      <pubDate>Tue, 25 Aug 2020 16:12:59 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/government-ama/when-can-we-use-archive-tier-for-blob-storage-on-gcc-high/m-p/1611114#M277</guid>
      <dc:creator>A9G-Data-Droid</dc:creator>
      <dc:date>2020-08-25T16:12:59Z</dc:date>
    </item>
    <item>
      <title>CMMC compliance of existing contracts</title>
      <link>https://techcommunity.microsoft.com/t5/government-ama/cmmc-compliance-of-existing-contracts/m-p/1611113#M276</link>
      <description>&lt;P&gt;Hello All,&lt;/P&gt;&lt;P&gt;How do you address CMMC compliance for existing CUI-based contracts which are not based on CMMC (could be based on ITAR/NIST SP 800-171, for instance)? The contract terms were already agreed between federal and contractors, but are still under the current "self-attestation". Or must the current contracts and environments built around the CUI protection for those systems continue with their existing terms, and are not subject to CMMC? Would they just need to complete their contract life in their original compliance terms? Meaning, CMMC only applies to new contracts with the DoD.&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Mark&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 25 Aug 2020 16:36:56 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/government-ama/cmmc-compliance-of-existing-contracts/m-p/1611113#M276</guid>
      <dc:creator>MarkPelea</dc:creator>
      <dc:date>2020-08-25T16:36:56Z</dc:date>
    </item>
  </channel>
</rss>

