Azure Government Cloud Security: A Compliance Guide for State and Local Agencies

Government cloud security is now a planning requirement for state and local agencies moving workloads to Azure Government.

The requirements that apply depend on the data involved, agency policy, and any state or federal obligations. CJIS applies to criminal justice information, while FedRAMP and NIST-based controls may shape procurement or security requirements.

A common challenge is the shared responsibility model, where Microsoft secures the platform, while the agency owns its configuration, access controls, and compliance evidence.

This guide covers the compliance frameworks that apply to Azure Government, the infrastructure decisions your agency controls, and how to maintain compliance after deployment.

Agencies evaluating their migration approach can pair this guide with the strategies outlined in Cloud Migration for Government: Strategies to Overcome Key Challenges.

What Azure Government Is and When to Use It

Azure Government is a physically separated instance of Microsoft Azure, built for U.S. federal, state, and local government agencies and their partners. It runs in dedicated datacenters operated by screened U.S. personnel and is designed to meet the security and compliance requirements that government workloads demand.

The decision to use Azure Government over commercial Azure depends on what your agency handles. The right environment depends on the workload, data type, agency requirements, and service availability.

Agencies already running Microsoft 365 can align their deployment with their existing Microsoft environment through Microsoft Consulting Services & Solutions.

Compliance Frameworks That Apply to Azure Government

FedRAMP and What It Means for State and Local Agencies

FedRAMP is the federal authorization standard for cloud service providers. Azure Government has a FedRAMP High P-ATO for in-scope services, but agencies still need to assess customer controls in their own design.

State and local agencies are not federally required to use FedRAMP-authorized services, but they may use FedRAMP evidence as part of their procurement and security review. FedRAMP requirements are evolving, so agencies should confirm current certification status and service scope before finalizing a design.

CJIS Security Policy Requirements

The CJIS Security Policy 6.0 is the FBI’s baseline for any agency accessing criminal justice information. Some CJIS Security Policy v6.0 requirements are in transition through September 30, 2027. Key requirements include:

CJIS compliance on Azure requires the agency to configure its own environment. Microsoft secures the platform, but your agency defines access rules and logging. The National Association of Counties outlines the new CJIS Security Policy 6.0 requirements that local agencies must plan for.

NIST 800-53 as the Common Thread

FedRAMP is based on NIST SP 800-53. CJIS covers many similar security areas, helping agencies map controls across both frameworks.

Understanding NIST 800-53 helps agencies avoid duplicating compliance work across multiple requirements. Agencies can reference the full NIST SP 800-53 control catalog to map their existing security posture against federal baselines.

Building a Secure Infrastructure on Azure Government

Identity, Access, and Network Controls

Infrastructure decisions in Azure Government start with identity and access management. Under the shared responsibility model, the agency defines the access rules. Key controls include:

Network security requires planning around data classification. Virtual network segmentation, network security groups, Azure Firewall, and private endpoints for sensitive data all need to match the sensitivity of the workloads they protect.

Agencies planning their Azure Government network architecture benefit from working with a partner who understands infrastructure design for regulated environments, such as Cloud Consulting Services for Businesses.

Data Protection and Monitoring

Encryption requirements depend on the data, system scope, and applicable policy, but agencies should plan for protection in transit and at rest where required. Azure Key Vault can manage keys and secrets, while Defender for Cloud and Azure Monitor can support security monitoring and audit evidence.

Continuous monitoring is central to FedRAMP and CJIS-aligned environments, with agencies responsible for reviewing findings and remediation. Agencies can align their monitoring strategy with a broader cybersecurity program covering endpoint, network, and cloud environments through Cyber Security Services for Businesses.

Planning a Compliant Migration to Azure Government

Start with assessment. Inventory current workloads, classify data by sensitivity, and map each workload to the compliance framework it falls under. Agencies with legacy on-premises systems need to determine which workloads move to Azure Government, which stay on-premises, and which require a hybrid configuration.

A phased approach is typically the right fit. Start with lower-complexity workloads that fit the selected environment and service scope. Treat email and collaboration as a separate Microsoft 365 Government decision.

Common pitfalls include:

Legacy systems can extend migration work because integration, data transfer, testing, and operational change all need to be planned. Deployment timelines vary based on workload complexity, procurement, and approval requirements.

Maintaining Compliance After Deployment

Compliance is not a one-time certification. Agencies need ongoing processes for:

Azure Policy and Microsoft Defender for Cloud can automate parts of this, but the agency still owns review and remediation.

Documentation and audit readiness matter as much as the technical controls. Maintain the documentation, evidence, and reviews required by the agency, state, or federal program. For CJIS, agencies need to address personnel screening and security awareness training in line with the policy and applicable state CJIS requirements.

Agencies managing requirements across FedRAMP, CJIS, and NIST benefit from working with IT Compliance Consultants who understand how these frameworks intersect.

Next Steps for Your Agency

Start by mapping your current workloads to the compliance frameworks that apply, then define which controls your agency owns versus what Azure Government provides. That mapping exercise clarifies the scope of work before any migration begins.

Davenport Group can help government agencies review their current environment, define compliance requirements for Azure Government, and build a migration plan that accounts for security, budget, and procurement constraints.

Learn more about IT & Cybersecurity Services for Government.

Frequently Asked Questions

What is Azure Government and how does it differ from commercial Azure?

Azure Government is a physically separated cloud instance operated by screened U.S. personnel, designed for government workloads. It can support workloads with government security and compliance requirements, subject to the services and controls in scope. Key differences include its isolated government cloud environment, screened U.S. personnel, service availability, and the compliance scope of in-scope services. Costs should be assessed by service and licensing requirements.

Is FedRAMP compliance required for state and local agencies?

FedRAMP is a federal mandate for cloud services used by federal agencies. State and local agencies are not required to use FedRAMP-authorized services, but they may use FedRAMP evidence as part of their procurement and security review. Using a FedRAMP-authorized platform like Azure Government can provide reusable security evidence, but it does not remove agency-side obligations.

How does CJIS compliance work in Azure Government?

Azure Government can support CJIS-aligned deployments through its infrastructure controls, but the agency still configures access, encryption, and audit logging. Microsoft secures the platform while the agency secures its data and user access. Personnel screening requirements depend on who has unescorted access to unencrypted CJI, encryption-key control, and applicable state CJIS rules.

What is NIST 800-53 and why does it matter for government cloud security?

NIST 800-53 is the control catalogue FedRAMP is based on. CJIS covers many similar security areas, helping agencies map controls across both frameworks. Understanding NIST 800-53 helps agencies avoid duplicating compliance work across multiple frameworks.

How long does it take to deploy Azure Government with full compliance?

Timing varies based on workload complexity, procurement, documentation, approval requirements, and required redesign work. Legacy systems and complex procurement can extend the project.

Picture of BJ Bradley

BJ Bradley

Vice President of Engineering Services BJ Bradley leads Davenport Group's engineering team with deep technical expertise and strong business acumen. Since joining in 2013, he has built the end-user computing practice, refined security market approaches, and developed managed services. BJ's leadership has been recognized with the CRN Next Generation Solution Provider Leader award in 2021, 2022, and 2023. With over 15 years in IT, his roles have included Systems Engineer, VMware Engineer, and Director of Engineering, specializing in data center and managed service solutions. View BJ's LinkedIn