Microsoft 365 Commercial to GCC High Migration
There is no upgrade button from commercial Microsoft 365 to GCC High. Microsoft provisions a new tenant after validating your eligibility, and everything — identity, mail, files, Teams — moves as a full tenant-to-tenant migration with a CUI boundary designed on purpose, not inherited by accident. IT Partner plans and executes that move for defense contractors: eligibility submission support, GCC High tenant standup, migration of Entra identity, Exchange, SharePoint, OneDrive, and Teams, coexistence and cutover, and the evidence artifacts your SSP and POA&M need afterward. From $25,000, scoped by tenant size and CUI boundary; a typical engagement runs about 12 weeks. Two things we are honest about up front: eligibility is granted by Microsoft, not by us, and GCC High licensing itself is purchased through Microsoft's AOS-G partner or Enterprise Agreement channels — we coordinate with that partner, we are not it.
What this engagement is
Defense contractors handling Controlled Unclassified Information or ITAR-controlled technical data keep arriving at the same conclusion: the commercial cloud, however well hardened, cannot make the contractual assurances their obligations require, and GCC High can — US data residency and support restricted to screened US persons, in an environment built for DFARS 252.204-7012 flowdowns. What surprises most of them is what the move actually is. Microsoft does not convert a commercial tenant to GCC High. Your organization submits to Microsoft's US Government cloud eligibility validation, licensing is purchased through an AOS-G partner (for most sub-500-seat contractors) or an Enterprise Agreement, Microsoft provisions a brand-new tenant — and then every mailbox, site, file, team, and identity has to cross by tenant-to-tenant migration. That second part is the muscle IT Partner has been exercising for years across email, SharePoint, OneDrive, and Teams. What this engagement adds is the reason you are moving: the CUI boundary. Before anything migrates, we design where CUI will live and who will touch it — whether the whole company moves into GCC High or an enclave carries the defense workload while the commercial tenant keeps the rest of the business. That decision drives licensing cost, user experience, and the scope of every control you will be assessed on later, so it is made deliberately, on paper, before cutover dates exist. Delivery follows the discipline our tenant-to-tenant work always follows: discovery and inventory, a coexistence design that respects the fact that your domain can only live in one tenant at a time, staged pre-migration of content, a planned cutover window, and validation against the inventory. Because this migration is usually a compliance event and not just an IT event, we also hand over evidence artifacts — the boundary design, migration records, and configuration documentation written to slot into your System Security Plan and POA&M rather than into a drawer. We hold a CAGE code ourselves (8BZ81, on SAM.gov) — we operate in this world as a registered supplier, not a tourist. What we do not do is make promises that are not ours to make: Microsoft controls eligibility validation and tenant provisioning timelines, assessors control assessment outcomes, and our quote and plan say so plainly.
Success criteria
What you receive
How the work unfolds
Prepare and submit the eligibility validation with your documentation; coordinate license selection and purchase through the AOS-G partner or EA channel. Microsoft controls validation and tenant provisioning timelines — this track starts first because it gates everything and its duration is not ours to promise.
Inventory the commercial tenant, map where CUI and export-controlled data actually live and flow, and produce the boundary design — full move or enclave — with licensing cost and collaboration impact modeled for each option. Client sign-off on the design closes this phase.
Stand up the provisioned tenant to the security baseline: identity configuration, Conditional Access, collaboration and sharing settings, and the domain strategy for coexistence. Configuration is documented as built — this is where the evidence package starts.
Configure migration tooling, execute a pilot group end to end — mailbox, files, Teams, device sign-in — and pre-stage bulk content with delta synchronization. Pilot findings adjust the runbook before the organization follows.
Execute the cutover runbook in agreed waves or a single window: final deltas, mail routing switch, domain move sequencing, DNS, and user communications. The published plan states per-workload what users will notice and for how long.
Reconcile migrated content against the inventory, resolve exceptions, deliver the validation report and compliance evidence package, and run the knowledge-transfer session on operating GCC High day to day.
Prerequisites
Who does what
IT Partner
- Prepare the eligibility submission and track it to Microsoft's decision.
- Design the CUI boundary and model both boundary options with costs and impacts.
- Build the GCC High tenant to the agreed baseline and document it as built.
- Plan and execute the migration of identity, mail, files, and Teams within the agreed scope.
- Publish and execute the coexistence and cutover runbook.
- Deliver the validation report and the SSP/POA&M-ready evidence package.
- State every Microsoft-controlled dependency and every parity limitation in writing before it can surprise anyone.
Your team
- Provide eligibility documentation and own the accuracy of contract and export-control representations made to Microsoft.
- Purchase GCC High licensing through the AOS-G partner or EA channel, on the sequence the plan requires.
- Make the CUI boundary decision and sign off the design before migration begins.
- Provide tenant access, inventory inputs, and line-of-business application owners for authentication re-pointing.
- Communicate with staff using the provided cutover pack, and staff the client-side cutover coordination.
- Own ITAR/export-control legal determinations and all assessment outcomes.
- Operate the GCC High tenant after handover, including its licensing renewals and support relationships.
What's not included
Limitations & technical notes
Frequently asked questions
Why can't we just upgrade our existing tenant to GCC High?
Because GCC High is a separate cloud environment with its own infrastructure, its own licensing channel, and a gated door. Microsoft does not convert commercial tenants; it validates your eligibility, provisions a new tenant in the US Government cloud, and leaves the moving to you. That makes this a full tenant-to-tenant migration — which is exactly the work this service exists to run.
Who is eligible for GCC High, and who decides?
Microsoft decides, through its US Government cloud eligibility validation. Typical qualifying evidence is a CAGE code and SAM.gov registration plus contracts carrying CUI, ITAR/EAR, or DFARS obligations. We assemble and submit the package and track it to a decision — but we do not grant eligibility, and we will tell you plainly if your documentation looks thin before you spend money on the attempt.
Do we actually need GCC High, or would GCC or commercial be enough?
It depends on your contracts and your data — ITAR technical data and certain DFARS flowdowns push firmly toward GCC High, while plenty of CUI scenarios are served by GCC or even a properly hardened commercial tenant with an enclave strategy. We wrote a detailed decision guide comparing the three, and our CMMC and NIST 800-171 readiness assessment makes the call from your actual boundary rather than from vendor marketing. We would rather talk you out of an unnecessary GCC High migration than sell you one.
What is an AOS-G partner and why do we need one?
GCC High licensing is not sold through the commercial CSP channel most SMBs buy from. Organizations with under roughly 500 seats purchase through a small set of Microsoft-authorized AOS-G (Agreement for Online Services for Government) partners; larger organizations typically use an Enterprise Agreement. IT Partner is your migration engineer in this engagement, not your GCC High license reseller — we map your current licenses to their GCC High equivalents, coordinate the purchase sequence with the AOS-G partner you select, and stay in our lane about it.
How does the CMMC timeline affect this decision?
Less than the headlines suggest, in both directions. DoD suspended the CMMC phased rollout's Level 2 third-party assessment expansion in mid-2026 pending a program review, so dates you may have seen are in motion. But the obligations that actually drive GCC High decisions — DFARS 252.204-7012, NIST SP 800-171 safeguarding, ITAR data handling — are in contracts today and never paused. Our advice: plan from the clauses in your contracts, use the readiness assessments for the compliance program, and treat migration lead time as the scarce resource, because a tenant move cannot be compressed into the weeks before a deadline.
What is a CUI enclave, and should we move everyone or just some users?
An enclave puts only the users, projects, and data touching CUI into GCC High while the rest of the business stays commercial — smaller licensing bill, smaller assessment scope, but a permanent two-tenant operating model with real collaboration friction at the seam. A full move is simpler to operate and to assess but prices every user at GCC High rates. This is the central design decision of the engagement, and we model both options with actual costs and workflow impacts before you choose.
What actually gets migrated?
The core estate: Entra identities and groups, Exchange mailboxes, OneDrive content, SharePoint sites, and Teams with their standard channels and files — staged in advance with delta passes so the cutover window moves the minimum. Known hard cases are dispositioned explicitly in the inventory: Teams private chat history, in-place archives, Planner, Forms, Stream, and Power Platform content either migrate through separately scoped work or are consciously archived, and you sign off that list before cutover.
Will our users lose access during the migration?
Most of the migration happens invisibly, while users keep working in the commercial tenant. The cutover window itself — mail routing switch, domain move, device re-sign-in — is planned, communicated, and scheduled for minimum disruption, and the runbook states per workload what users will notice. What we do not promise is 'zero downtime': a domain can only live in one tenant at a time, and honest sequencing beats a slogan.
What happens to our custom domain and email addresses?
Your domain moves — it cannot be attached to both tenants simultaneously, so the runbook sequences its removal from the commercial tenant and attachment to GCC High inside the cutover window, with mail routing managed so messages are not lost in the transition. Users keep their addresses; what changes is the tenant answering for them.
What are the evidence artifacts for the SSP and POA&M?
Three things assessors and your compliance lead actually use: the CUI boundary design (what is in scope and why), the migration records (what moved, when, reconciled against inventory), and the as-built configuration documentation of the GCC High tenant's identity, access, and collaboration settings. They are written to drop into your System Security Plan's environment description and to close or open POA&M items with dates and evidence — not as a binder of screenshots.
Is GCC High more expensive to license than commercial Microsoft 365?
Yes, materially — government cloud SKUs carry a premium over their commercial equivalents, and pricing moves over time, so we deliberately do not print license prices here. The licensing model we build in the boundary design phase shows your actual delta, per option, using current AOS-G or EA pricing from the licensing partner — which is one more reason the enclave-versus-full-move decision deserves modeling rather than instinct.
Why does the price start at $25,000 when your other tenant-to-tenant migrations cost less?
Because this is several migrations plus a compliance design wrapped in one program: eligibility and licensing coordination, a new tenant built to a security baseline, the CUI boundary design, four workload migrations, coexistence, cutover, and an evidence package — across roughly 12 weeks. The floor covers a small, single-boundary move; tenant size and enclave complexity scope it up from there, and you get the fixed quote in writing before committing to anything.
What happens after cutover?
You operate the GCC High tenant, with our knowledge-transfer session covering the differences that matter day to day — restricted external collaboration, service parity, support channels. The natural next step for most clients is the compliance program itself: readiness assessment, SSP depth, and self-assessment support through our CMMC services. Ongoing management of the tenant is available but deliberately not bundled — the migration stands on its own, and you decide who runs the environment afterward.