· Microsoft GCC High  · 7 min read

ADFS Retirement in GCC High: Migration Paths to Entra ID

GCC High tenants reduce risk and operational drag when they retire AD FS and consolidate identity in Microsoft Entra ID, and the move intersects directly with NIST 800-171 and CMMC Level 2 evidence expectations for access control and identification and authentication.

GCC High tenants reduce risk and operational drag when they retire AD FS and consolidate identity in Microsoft Entra ID, and the move intersects directly with NIST 800-171 and CMMC Level 2 evidence expectations for access control and identification and authentication.

GCC High tenants reduce risk and operational drag when they retire AD FS and consolidate identity in Microsoft Entra ID. Microsoft directs customers to treat Entra ID as the strategic identity platform. GCC High runs on separate infrastructure from commercial, and Microsoft designs it for government data handling and U.S. persons-only administration. Identity consolidation fits that model and removes legacy complexity that slows control implementation.

Drivers for ADFS retirement in GCC High

AD FS farms carry patching, certificates, proxies, and high availability as a local burden. Each piece adds failure modes and audit scope. Entra ID absorbs those layers into a cloud identity service operated by Microsoft, which aligns with how Microsoft 365 GCC High and Azure Government deliver services. Teams that centralize sign-in gain direct policy control in Entra ID and cut the time they spend tending federation infrastructure.

Identity modernization also removes protocol drift. Many applications already support SAML or modern protocols like OpenID Connect. Entra ID supports those protocols across enterprise applications, which reduces custom token rules and brittle transformations common in long-lived AD FS trusts.

Entra ID architecture options in GCC High

Teams pick a managed sign-in method that their tenant supports. Two common choices appear in Microsoft guidance.

  • Password hash synchronization. Administrators sync credential hashes for sign-in at the cloud edge and keep Active Directory as the authority of record.

  • Pass-through authentication. Administrators run lightweight agents to validate passwords against Active Directory without AD FS.

Each method removes the dependency on AD FS for identity federation. Both work with Entra ID Conditional Access and modern authentication flows. The right choice depends on application mix, security posture, and operational model in Azure Government.

Stepwise migration of AD FS applications and domains

Microsoft provides a structured path to move applications and cut over domains. The process starts with an inventory. Administrators connect the AD FS application migration tool to the farm, discover relying party trusts, and review compatibility. The tool produces a list with protocol type, claim rules, and readiness flags.

Engineers then configure equivalent enterprise applications in Microsoft Entra ID. They stand up SAML integrations first or use OpenID Connect where supported by the app. They validate attributes, name identifiers, and claim mappings. They test user sign-in for each application before any production traffic change. This model reduces risk because each application moves on its own schedule with clear rollback.

After application migrations reach a safe threshold, administrators change tenant sign-in to managed authentication. They run the Entra Connect change user sign-in task and flip the domain from Federated to Managed. Some teams script the change with Microsoft Graph PowerShell to coordinate timing with communication and support plans. This step removes live dependency on AD FS for user sign-in and prepares the environment for decommissioning work.

Safe decommissioning of AD FS for CUI

CUI environments need a clean, documented exit from AD FS. Administrators start with a full backup of the AD FS farm and configuration. They confirm that all production domains in Entra ID show a Managed authentication state and that critical applications sign in through Entra ID without federation.

Engineers then remove federation plumbing that can attract stale dependencies. They delete public and internal DNS records that point clients to the AD FS service or Web Application Proxy. They remove load balancer entries that route traffic to the proxies. They revoke or delete AD FS service certificates and token signing certificates to prevent unplanned reuse.

Platform teams remove the AD FS and Web Application Proxy roles from servers and clean up the back-end database, whether Windows Internal Database or SQL Server. They delete the AD FS service account and the certificate-sharing container in Active Directory. They update monitoring, identity runbooks, and incident response playbooks to reference Entra ID as the identity provider.

A simple rollback plan helps during cutover windows. Keep a known-good AD FS snapshot and a plan to restore DNS and load balancer entries for a short period, then finalize removal after a calm run of production traffic.

CMMC and NIST 800-171 identity requirements

Identity architecture sits at the center of Level 2. NIST SP 800-171 Rev. 2 drives the design. AC.L2-3.1.1 requires you to limit system access to authorized users, processes acting on behalf of users, and devices. IA.L2-3.5.1 requires you to identify and authenticate users and devices before authorizing access. IA.L2-3.5.3 requires multifactor authentication for local and network access to privileged accounts and for network access to non-privileged accounts.

Entra ID policies help you implement these outcomes after AD FS retirement. Conditional Access enforces MFA for privileged roles and for standard user sign-in. Sign-in session controls address AC.L2-3.1.12 session lock expectations and support AC.L2-3.1.13 by shortening or ending sessions under defined conditions. Entra ID device-based conditions bring authorized device signals into access decisions, which supports AC.L2-3.1.1 in a way that AD FS alone could not.

Assessment mechanics matter. The DoD Level 2 Assessment Guide and the Cyber AB CAP v2.0 direct assessors to examine technical configuration, interview operators, and test performance over time. You need implementation evidence, not a product list. Document Conditional Access policies, MFA enrollment windows, emergency access accounts, and sign-in risk responses. Retain change records and screenshots that match tenant state during the assessment period.

CUI scoping also changes as you move identity. The identity provider resides inside the CUI boundary when it brokers access to systems that store or process CUI. A move from AD FS to Entra ID shifts authentication services from on-premises to Azure Government. Update your boundary narrative and interconnection descriptions. Our post on CMMC scoping and the CUI boundary gives a structure for that update.

Practical migration plan for GCC High tenants

Strong outcomes follow a repeatable plan that treats identity as a program, not a ticket queue.

  • Scope the identity portfolio. Catalog AD FS trusts, target state in Entra ID, and risk by business impact. Align the cutover plan to production maintenance windows.

  • Pilot and iterate. Move a low-risk app, verify attribute mappings, enroll users in MFA, and tune Conditional Access. Capture operator checklists and support scripts.

Production waves come next. Group applications by protocol and business owner. Move SAML applications first. Use OpenID Connect where the vendor supports it. Avoid broad-bang cutovers without a tested rollback because AD FS exits most cleanly after application waves have cleared.

Harden Entra ID before you change the domain to Managed. Enforce MFA for administrators and users, align sign-in sessions to your policy, and confirm break-glass accounts. Confirm audit log retention and export to your SIEM. The Microsoft Product Placemat for CMMC maps Entra ID capabilities to Level 2 practices as an informational guide, and it states that the mapping does not guarantee any assessment outcome.

Domain cutover closes the loop. Run the Entra Connect change user sign-in task in a scheduled window. Validate sign-in for pilot users and monitor sign-in logs for errors. Communicate the deprecation of AD FS sign-in pages to reduce help desk noise after the switch.

Decommission AD FS after a quiet period. Remove DNS and load balancer entries, remove roles, and clean up certificates and service accounts. Update configuration management databases and disaster recovery plans to point to Entra ID. Close POA&Ms that tracked federation retirement steps. Update your System Security Plan with the new identity design and evidence. Our guide on the System Security Plan for NIST 800-171 details the sections that change most during identity modernization.

GCC High context and data protection

GCC High and DoD tenants run on Azure Government with controls that differ from commercial and GCC. Microsoft provides those services from separate infrastructure with personnel and data residency controls suited to federal and defense needs. Identity design should respect those boundaries and the interconnects between Entra ID, Microsoft 365 GCC High, and workloads that handle CUI.

CUI includes unclassified information that requires safeguarding or dissemination controls under law or policy. Identity controls sit at the front door of those systems. Entra ID Conditional Access and Identity Protection help you gate access based on user and sign-in risk and device posture. Pair those controls with least privilege in Microsoft 365 roles and application roles. Our post on Conditional Access and DFARS 7012 explains common policy patterns that support controlled data handling.

Sources

AD FS application migration to Microsoft Entra ID (Microsoft)

Understanding compliance between Commercial, Government, DoD, and Secret offerings (Microsoft)

Microsoft Product Placemat for CMMC 2.0, Preview Sept 2024 (Microsoft)

NIST SP 800-171 Rev. 2 (NIST)

CMMC Level 2 Assessment Guide v2 (DoD CIO)

CMMC Assessment Process v2.0 (Cyber AB)

CUI Registry category list (National Archives)

Want a structured starting point?

Our 27-question CMMC technical readiness self-survey covers tenant, identity, endpoint, data protection, audit logging, documentation, and the 72-hour DFARS reporting plan. The score is produced in your browser from your answers alone. Nothing is verified or stored.

Back to Blog

Related Posts

View All Posts »