Storing ITAR Controlled Information on Microsoft 365 products with Azure

Landon Luick 0 Reputation points
2024-01-15T22:15:00.2266667+00:00

LEAP is going to be constantly working with ITAR controlled information. We would like to communicate ITAR controlled information with our Office 365 products (primarily Outlook, Planner, Teams, Sharepoint, and OneDrive). However, we don't fully understand where the cloud data for our MS 365 accounts is stored and suspect we need to move over to a more secure MS Azure server in order to be in compliance.
We'd appreciate further information on how to make this possible.
Regards, Landon

Azure Storage Explorer
Azure Storage Explorer
An Azure tool that is used to manage cloud storage resources on Windows, macOS, and Linux.
231 questions
{count} votes

1 answer

Sort by: Most helpful
  1. Sumarigo-MSFT 43,801 Reputation points Microsoft Employee
    2024-01-16T06:56:23.3366667+00:00

    Hi @Landon Luick Welcome to Microsoft Q&A Forum, Thank you for posting your query here!

    You have reach Azure Storage Service Forum.

    Based on your requirement on compliance information for ITAR , Please contact your Microsoft Office 365 account support: https://support.microsoft.com/en-us/topic/contact-microsoft-office-support-fd6bb40e-75b7-6f43-d6f9-c13d10850e77 they can provide more detailed information on your scenario and it's best choice
    **
    However let me share some insights on your query:** If you are working with ITAR controlled information, you need to ensure that your data is stored in a compliant manner. Microsoft offers a range of compliance certifications, including ITAR compliance, for its cloud services.

    To ensure that your data is stored in a compliant manner, you can use Microsoft Azure Government, which is a cloud platform designed specifically for US government agencies and their partners. Azure Government is a physically isolated instance of Microsoft Azure that employs strict security and compliance controls to meet the requirements of US government agencies. To communicate ITAR controlled information with your Office 365 products, you can use Office 365 Government, which is a version of Office 365 that is designed specifically for US government agencies and their partners. Office 365 Government includes the same features and functionality as Office 365, but with additional security and compliance controls to meet the requirements of US government agencies. To move your data to Azure Government and Office 365 Government, you can work with a Microsoft partner or a Microsoft sales representative to help you migrate your data to the new platform. They can help you assess your current environment, plan your migration, and execute the migration process. It is important to note that ITAR compliance is a shared responsibility between you and Microsoft. While Microsoft provides a compliant platform, you are responsible for ensuring that your use of the platform is compliant with ITAR regulations. You should work with your legal and compliance teams to ensure that your use of Azure Government and Office 365 Government is compliant with ITAR regulations.

    According to Microsoft, customers who want to host ITAR-regulated data should work with their Microsoft account and licensing teams. Customers can also use Microsoft's GCC High to meet ITAR requirements.  To be ITAR compliant, companies must: 

    • Register with the Directorate of Defense Trade Controls (DDTC)
    • Know what is required of their organization to comply with ITAR
    • Self-certify that they possess this knowledge

    To control ITAR-regulated information in Microsoft 365 or SharePoint on-premises, archTIS' NC Protect provides ABAC-based controls to secure CUI and other ITAR data. 

    To move cloud data for MS 365 accounts to a more secure MS Azure server, users can: Copy or move data to Azure Storage by using AzCopy v10 Choose an Azure solution for data transfer | Microsoft Learn

    • Use AzCopy, a command-line utility that can copy data to, from, or between storage accounts

    Use Storage Mover for migration scenarios such as lift-and-shift, and for cloud migrations that are repeated occasionally

    Azure and ITAR: https://learn.microsoft.com/en-us/azure/compliance/offerings/offering-itar

    ---Please do not forget to "Accept the answer” and “up-vote” wherever the information provided helps you, this can be beneficial to other community members.

    0 comments No comments