Federal News
FedRAMP Approves Microsoft GCC High Amid Security Concerns
March 20, 2026
Federal Risk and Authorization Management Program (FedRAMP) granted High authorization to Microsoft's Government Community Cloud High (GCC High) in December 2024 despite significant unresolved security deficiencies and incomplete documentation. Federal cybersecurity experts repeatedly raised concerns about the platform's security posture, citing legacy code issues, lack of encryption detail, and limited system visibility. The approval process was influenced by pressure from the Department of Justice and Microsoft, highlighting systemic challenges in federal cloud security vetting, including conflicts of interest among third-party assessors and resource constraints within FedRAMP. This decision impacts the security assurance of sensitive government data hosted on GCC High and underscores the need for procurement professionals to carefully evaluate cloud service authorizations and vendor transparency in future contracts.
- Why this matters: Procurement officials should recognize potential risks in cloud service authorizations where security documentation and assessments may be incomplete or influenced by external pressures.
- The involvement of third-party assessors with limited access to critical information signals challenges in verifying cloud security claims, affecting contract risk management.
- Agencies relying on GCC High must consider supplemental security controls or alternative solutions to mitigate identified vulnerabilities.
- Contractors and vendors should anticipate increased scrutiny and demand for transparency in cloud security documentation and FedRAMP compliance processes moving forward.
Microsoft’s Government Community Cloud High everything from a 'pile of shit' to a 'pile of spaghetti pies' while simultaneously green-lighting it for the nation’s most sensitive data.
— Federal cybersecurity reviewers
Coalfire and Kratos both readily admitted that it was difficult to impossible to get the information required out of Microsoft to properly do a sufficient assessment.
— Former FedRAMP reviewer
When there’s a security issue, the public doesn’t expect FedRAMP to say they’re just a paper-pusher.
— Eric Mill, former GSA executive director for cloud strategy
Agencies
Department of Justice, FedRAMP, General Services Administration, National Security Agency, White House
Vendors
Microsoft, Coalfire, Kratos, Accenture
Contracts
Locations
Sources
- Federal Cyber Experts Called Microsoft's Cloud "S**t" - Approved It Anyway - Gadget Review · Gadget Review · Mar 18
- Federal Cyber Experts Thought Microsoft’s Cloud Was Garbage. They Approved It Anyway. · Gizmodo · Mar 18
- Federal cyber experts hated Microsoft's cloud - approved it anyway · MSN · Mar 20
- Federal cyber experts had condemned Microsoft's cloud as a 'pile of shit,' but were pressured into approving it. - GIGAZINE · GIGAZINE · Mar 19
- Microsoft GCC High: FedRAMP's Security Failure - Technology Org · Technology Org · Mar 19