
Export-Controlled Technical Data Handling in Microsoft 365
Export controls change how you select and configure Microsoft 365, and Microsoft states the customer remains the exporter who must assess cloud use.

Export controls change how you select and configure Microsoft 365, and Microsoft states the customer remains the exporter who must assess cloud use.

You reduce CUI exposure and assessment scope by segmenting the enclave and enforcing a clear, monitored boundary that you can prove to an assessor.

Contractors can protect CUI in email with S/MIME or with Microsoft Purview encryption through sensitivity labels or OME, but the design must meet NIST SP 800-171 cryptographic and flow-control requirements and work for external recipients.

CMMC Level 2 assessors expect complete audit coverage across your CUI boundary, so identify, collect, protect, retain, and review logs from identity, endpoints, networks, applications, cloud services, and security tools in line with NIST SP 800-171 AU controls.

Conditional Access policy design in Entra ID for DFARS 252.204-7012 compliance.

For DIB contractors handling CUI, the cloud decision is GCC or GCC High, not commercial. Choosing right the first time avoids a costly second migration.