Independent DIB implementation resource — not affiliated with or endorsed by the U.S. Department of WarView the official DoW campaign ↗
BRILLIANT AT THE BASICS · CLOUD SETUPAzure Government
GOV CLOUD

Security Setup Checklist

70 steps across the ten Brilliant at the Basics requirements. Check each box as you complete it. Confirm every step against Azure Government’s own documentation before you rely on it.

Where you work
Azure Government portal (portal.azure.us)
Content reviewed
2026-07-21
Prepared for
________________________________
Date started
________________________________
Controlled-data note

Azure Government, paired with GCC High identity, is a purpose-built home for CUI: FedRAMP High and DoD Impact Level 4/5, with data kept in the U.S. and screened U.S.-person operations.

01

Phishing-Resistant Multi-Factor Authentication

IT-013.5.3IA.L2-3.5.3

Evidence to keep: Screenshot of the Conditional Access policy showing Phishing-resistant MFA strength · Authentication methods registration report · Sign-in logs showing MFA method used

02

Least-Privilege Access Control

3.1.5AC.L2-3.1.5

Evidence to keep: Export of role assignments per subscription · PIM eligible-assignment and activation history report · List of custom role definitions

03

Asset & Account Inventory

IT-023.4.1CM.L2-3.4.1

Evidence to keep: Dated Azure Resource Graph export of all resources · Defender for Cloud inventory export · Entra All devices and All users lists

04

Logging, Monitoring & Audit

3.3.1AU.L2-3.3.1

Evidence to keep: Diagnostic settings configuration for key resources · Sentinel data-connector and analytics-rule list · Log retention setting screenshot

05

Network Segmentation & Boundary Protection

IT-053.13.5SC.L2-3.13.5

Evidence to keep: Network diagram of hub-spoke VNets · Exported NSG and Azure Firewall rule sets · List of private endpoints protecting data services

06

Vulnerability & Patch Management

IT-063.11.2RA.L2-3.11.2

Evidence to keep: Defender for Cloud vulnerability assessment report · Azure Update Manager compliance/patch history · Record of remediation timelines

07

Data Protection & Encryption

3.13.11SC.L2-3.13.11

Evidence to keep: Key Vault configuration showing purge protection and rotation policy · Storage/disk settings showing customer-managed key encryption · Proof TLS 1.2+ is enforced

08

Backup & Recovery

IT-093.8.9MP.L2-3.8.9

Evidence to keep: Backup policy showing frequency and retention · Recovery Services vault redundancy and immutability settings · Successful test-restore report

09

Secure Configuration Baseline

3.4.2CM.L2-3.4.2

Evidence to keep: Defender for Cloud secure score over time · Regulatory compliance dashboard export for NIST 800-171 / CMMC · Azure Policy assignments and compliance results

10

Secure AI Adoption & Data Loss Prevention

IT-083.1.3AC.L2-3.1.3

Evidence to keep: Azure OpenAI deployment showing US Gov region and private networking · Purview DLP policy definitions and match reports · DSPM for AI activity showing sensitive-data interactions

This checklist is independent education from the Brilliant at the Basics Resource Center, published by inDirectIT. It does not by itself establish compliance, satisfy a contract clause, or confer CMMC certification. Cloud consoles change often — verify each step against the provider’s documentation. The official DoW campaign remains authoritative: https://dowcio.war.gov/BrilliantBasics/

Back to the guide