FedRAMP and Microsoft 365: auditing identity for federal cloud data
Cloud services carrying U.S. federal data answer to FedRAMP, and the identity layer underneath — Entra ID and Microsoft 365 — carries a large share of the controls. Here is how to audit that tenant against the baseline that applies.
Cloud services that store or process U.S. federal data are held to FedRAMP, and the identity layer underneath them — Entra ID and Microsoft 365 — carries a large share of the controls. If your tenant supports a FedRAMP offering, or you sell to agencies through one, the configuration of that tenant is in scope. This is how to audit it against the baseline that applies.
What FedRAMP actually assesses
FedRAMP inherits its control set from NIST SP 800-53, organised into Low, Moderate and High baselines. A cloud service is authorised at one of those levels, and the higher the impact level, the more enhancements apply. For identity, the families that matter most are AC (access control), IA (identification and authentication), AU (audit and accountability) and SC (system and communications protection). Each maps directly onto tenant settings you can read today.
The identity controls, in tenant terms
- IA-2 and its enhancements — multi-factor authentication for all users and, at Moderate and High, phishing-resistant MFA for privileged access. In Entra ID this is Conditional Access plus authentication methods policy.
- AC-2 — account management: joiner-mover-leaver hygiene, disabled stale accounts, reviewed guest access.
- AC-6 — least privilege: minimal Global Administrators, role-based assignment, and just-in-time elevation through PIM.
- AC-12 — session termination: sign-in frequency and idle timeout in Conditional Access.
- AU-2 / AU-6 — logging and review: sign-in and audit logs retained and exported to a monitored system.
- SC-8 — transmission confidentiality: modern authentication only, legacy protocols blocked.
Low, Moderate, High: what changes
The same controls apply across baselines; what tightens is the enhancement. MFA at Low becomes phishing-resistant MFA at Moderate for admins and, at High, for a far wider population. Session lifetimes shorten. Log retention lengthens. A useful audit reports each control with the baseline it belongs to, so you can see at a glance which findings are blocking a Moderate authorisation versus which only bite at High. EntraGUARD carries the Low, Moderate and High tags on every control that FedRAMP covers.
Commercial vs GCC High. Many federal workloads require Microsoft 365 GCC High or a government cloud rather than the commercial tenant. The control checks are the same, but the tenant is different — audit the environment that actually holds the data, not the commercial tenant next to it.
From audit to authorisation package
A FedRAMP authorisation lives on evidence: a System Security Plan, a POA&M for open items, and continuous monitoring afterward. An automated audit does not write the SSP for you, but it produces the raw material — the current state of each control, with its 800-53 identifier and the remediation path — so the narrative you write is grounded in what the tenant actually does, not what you hope it does. Re-running the same baseline monthly is how you feed continuous monitoring without rebuilding the assessment each time.
Related: CMMC and NIST SP 800-171, and CJIS Security Policy on Microsoft 365.