Independent DIB implementation resource — not affiliated with or endorsed by the U.S. Department of WarView the official DoW campaign ↗
GOV CLOUDPLAIN-LANGUAGE GUIDE

Azure Government setup guide

A separate, sovereign Azure cloud built for U.S. government data. Work through the ten requirements below — each has a diagram and a checklist you can follow click by click.

Print checklist ↧
Built for controlled data

Azure Government, paired with GCC High identity, is a purpose-built home for CUI: FedRAMP High and DoD Impact Level 4/5, with data kept in the U.S. and screened U.S.-person operations.

REQUIREMENT 01 OF 10

Phishing-Resistant Multi-Factor Authentication

IT-013.5.3IA.L2-3.5.3
IN PLAIN WORDS

Multi-factor authentication (MFA) means you prove who you are with more than just a password. Phishing-resistant MFA uses a special key or badge that a fake website simply cannot copy, like a house key that only turns in your own front door and no other. In Azure Government you turn this on with Entra ID (the identity system) using tools like FIDO2 security keys and government smart cards (CAC/PIV).

WHY IT MATTERS

Passwords get stolen or tricked out of people every day, and if an attacker signs in as you they can reach the controlled unclassified information (CUI) you are trusted to protect.

TOOLS YOU WILL USE
Microsoft Entra ID for GovernmentConditional AccessFIDO2 security keysEntra Certificate-Based Authentication (CAC/PIV)
HOW THE SETUP FLOWS
  1. 1Enable methods
  2. 2Register keys/CAC
  3. 3Create CA policy
  4. 4Require phish-resistant
  5. 5Report-only test
  6. 6Turn on
STEP-BY-STEP CHECKLIST
Pro tip

Always exclude at least one emergency break-glass account from the policy so a misconfiguration never locks every admin out.

Government cloud & CUI

Entra ID for Government runs in the FedRAMP High / DoD IL4-IL5 boundary, and Entra certificate-based authentication is how CAC/PIV smart cards meet the phishing-resistant MFA required by federal memo M-22-09 and NIST 800-171.

EVIDENCE TO KEEP
Screenshot of the Conditional Access policy showing Phishing-resistant MFA strengthAuthentication methods registration reportSign-in logs showing MFA method used
See the full IT-01 practice guide →
FAQ

Frequently asked questions

What does the Azure Government setup guide cover?

It walks through ten security requirements — including phishing-resistant multi-factor authentication, least-privilege access control, asset & account inventory, and more — mapped to the DoW Brilliant at the Basics IT Top 10 and to NIST SP 800-171 / CMMC Level 2. Each requirement has a plain-language explanation, a process-flow diagram, and a click-by-click checklist.

Where do I perform these Azure Gov steps?

In the Azure Government portal (portal.azure.us). Every step names the exact portal or console path to follow.

Is my checklist progress saved anywhere?

Your step checklist progress is saved only in your own browser (local storage). Nothing is sent to the site, and you can reset it at any time.

Why choose Azure Government for CUI?

Azure Government, paired with GCC High identity, provides FedRAMP High and DoD Impact Level 4/5, keeps data in US regions, and uses screened US-person operations — a purpose-built home for CUI and ITAR.

Does Azure Government use FIPS-validated encryption?

Yes. Azure Government offers FIPS 140-validated cryptographic modules, and Azure Key Vault Managed HSM provides FIPS 140-3 Level 3 validated hardware — required for encrypting CUI.