First page of Microsoft's 100,000-partner directory, sorted by responsiveness Microsoft Solutions Partner — Security, Modern Work, Infrastructure, App Innovation Microsoft partner since 2006 1,100+ organizations under management
Home/Services/Microsoft 365 Commercial to GCC High Migration
MigrationCompliance

Microsoft 365 Commercial to GCC High Migration

There is no upgrade button from commercial Microsoft 365 to GCC High. Microsoft provisions a new tenant after validating your eligibility, and everything — identity, mail, files, Teams — moves as a full tenant-to-tenant migration with a CUI boundary designed on purpose, not inherited by accident. IT Partner plans and executes that move for defense contractors: eligibility submission support, GCC High tenant standup, migration of Entra identity, Exchange, SharePoint, OneDrive, and Teams, coexistence and cutover, and the evidence artifacts your SSP and POA&M need afterward. From $25,000, scoped by tenant size and CUI boundary; a typical engagement runs about 12 weeks. Two things we are honest about up front: eligibility is granted by Microsoft, not by us, and GCC High licensing itself is purchased through Microsoft's AOS-G partner or Enterprise Agreement channels — we coordinate with that partner, we are not it.

Timeline 12 weeksService owner Roman SotnikMicrosoft 365 GCC HighMicrosoft Entra IDMicrosoft Teams

What this engagement is

Defense contractors handling Controlled Unclassified Information or ITAR-controlled technical data keep arriving at the same conclusion: the commercial cloud, however well hardened, cannot make the contractual assurances their obligations require, and GCC High can — US data residency and support restricted to screened US persons, in an environment built for DFARS 252.204-7012 flowdowns. What surprises most of them is what the move actually is. Microsoft does not convert a commercial tenant to GCC High. Your organization submits to Microsoft's US Government cloud eligibility validation, licensing is purchased through an AOS-G partner (for most sub-500-seat contractors) or an Enterprise Agreement, Microsoft provisions a brand-new tenant — and then every mailbox, site, file, team, and identity has to cross by tenant-to-tenant migration. That second part is the muscle IT Partner has been exercising for years across email, SharePoint, OneDrive, and Teams. What this engagement adds is the reason you are moving: the CUI boundary. Before anything migrates, we design where CUI will live and who will touch it — whether the whole company moves into GCC High or an enclave carries the defense workload while the commercial tenant keeps the rest of the business. That decision drives licensing cost, user experience, and the scope of every control you will be assessed on later, so it is made deliberately, on paper, before cutover dates exist. Delivery follows the discipline our tenant-to-tenant work always follows: discovery and inventory, a coexistence design that respects the fact that your domain can only live in one tenant at a time, staged pre-migration of content, a planned cutover window, and validation against the inventory. Because this migration is usually a compliance event and not just an IT event, we also hand over evidence artifacts — the boundary design, migration records, and configuration documentation written to slot into your System Security Plan and POA&M rather than into a drawer. We hold a CAGE code ourselves (8BZ81, on SAM.gov) — we operate in this world as a registered supplier, not a tourist. What we do not do is make promises that are not ours to make: Microsoft controls eligibility validation and tenant provisioning timelines, assessors control assessment outcomes, and our quote and plan say so plainly.

Success criteria

01Eligibility submission is prepared and lodged with Microsoft with the client's supporting documentation, and its status is tracked to a decision.
02The CUI boundary design — full move or enclave — is documented and signed off by the client before migration begins.
03The GCC High tenant is stood up with an agreed security baseline: identity, Conditional Access, and collaboration settings configured to the boundary design.
04Mail, OneDrive, SharePoint, and Teams content defined as in-scope reaches the GCC High tenant and reconciles against the migration inventory.
05Users authenticate and work in the GCC High tenant after cutover, with mail flow, file access, and Teams collaboration verified.
06Coexistence and cutover execute to the published runbook, with the client informed of exactly what happens to each workload and when.
07The client receives the evidence package — boundary design, migration records, tenant configuration documentation — usable directly in SSP and POA&M updates.
08Known parity and content-type limitations are documented and acknowledged before cutover, not discovered after it.

What you receive

Eligibility submission support: assembly of the validation request to Microsoft with your CAGE code, SAM registration, and contract documentation evidencing CUI or export-controlled data handling.
Licensing coordination with your chosen AOS-G partner or Enterprise Agreement channel — mapping current commercial licenses to their GCC High equivalents and sequencing purchase against provisioning.
CUI boundary design document: full-tenant move versus enclave, data flows, user populations, and the collaboration model between GCC High and any remaining commercial footprint.
GCC High tenant standup: Entra ID configuration, domain strategy, security baseline, Conditional Access, and collaboration settings aligned to the boundary design.
Migration inventory: mailboxes, OneDrive accounts, SharePoint sites, Teams, shared mailboxes, and groups, with owners, sizes, and disposition (migrate, archive, leave).
Identity transition plan and execution: accounts, groups, and device re-registration approach for the new tenant.
Migration execution for Exchange mailboxes, OneDrive, SharePoint, and Teams standard channels, staged with delta passes ahead of cutover.
Coexistence and cutover runbook: mail routing through the transition, domain move sequencing, DNS changes, and a user-facing cutover communication pack.
Post-cutover validation report reconciling migrated content against the inventory, with every exception listed and dispositioned.
Compliance evidence package: boundary design, migration records, and tenant configuration documentation formatted for SSP and POA&M use.
Knowledge-transfer session with your IT team on operating the GCC High tenant's differences — external collaboration, service parity, and support channels.

How the work unfolds

1. Eligibility and licensing track (weeks 1-3, Microsoft-dependent)

Prepare and submit the eligibility validation with your documentation; coordinate license selection and purchase through the AOS-G partner or EA channel. Microsoft controls validation and tenant provisioning timelines — this track starts first because it gates everything and its duration is not ours to promise.

2. Discovery and CUI boundary design (weeks 1-4)

Inventory the commercial tenant, map where CUI and export-controlled data actually live and flow, and produce the boundary design — full move or enclave — with licensing cost and collaboration impact modeled for each option. Client sign-off on the design closes this phase.

3. GCC High tenant build (weeks 4-6)

Stand up the provisioned tenant to the security baseline: identity configuration, Conditional Access, collaboration and sharing settings, and the domain strategy for coexistence. Configuration is documented as built — this is where the evidence package starts.

4. Migration staging and pilot (weeks 6-9)

Configure migration tooling, execute a pilot group end to end — mailbox, files, Teams, device sign-in — and pre-stage bulk content with delta synchronization. Pilot findings adjust the runbook before the organization follows.

5. Coexistence and cutover (weeks 9-11)

Execute the cutover runbook in agreed waves or a single window: final deltas, mail routing switch, domain move sequencing, DNS, and user communications. The published plan states per-workload what users will notice and for how long.

6. Validation, evidence, and handover (weeks 11-12)

Reconcile migrated content against the inventory, resolve exceptions, deliver the validation report and compliance evidence package, and run the knowledge-transfer session on operating GCC High day to day.

Prerequisites

Eligibility documentation: a CAGE code and SAM.gov registration, or contract documentation evidencing CUI, ITAR/EAR, or other qualifying government data obligations — Microsoft validates eligibility, and without a plausible basis the engagement should not start.
A licensing path: engagement with an AOS-G partner (typical under roughly 500 seats) or an Enterprise Agreement channel for GCC High licenses; we coordinate with them, and license costs are the client's.
An executive owner for the CUI boundary decision — full move versus enclave is a business decision with cost and workflow consequences, and it needs a named decision-maker.
Global administrator access to the commercial tenant and, once provisioned, the GCC High tenant.
An inventory starting point: user list, mailbox and site estate, third-party integrations, and line-of-business applications that authenticate against the current tenant.
Awareness that ITAR/export-control determinations about your data are your counsel's call — we design and migrate to the boundary you determine, and flag questions we see along the way.
User communication channels and a client-side coordinator for cutover logistics.
Device estate information for the identity transition: management state, join type, and count of Windows endpoints that will re-register against the new tenant.

Who does what

IT Partner

  • Prepare the eligibility submission and track it to Microsoft's decision.
  • Design the CUI boundary and model both boundary options with costs and impacts.
  • Build the GCC High tenant to the agreed baseline and document it as built.
  • Plan and execute the migration of identity, mail, files, and Teams within the agreed scope.
  • Publish and execute the coexistence and cutover runbook.
  • Deliver the validation report and the SSP/POA&M-ready evidence package.
  • State every Microsoft-controlled dependency and every parity limitation in writing before it can surprise anyone.

Your team

  • Provide eligibility documentation and own the accuracy of contract and export-control representations made to Microsoft.
  • Purchase GCC High licensing through the AOS-G partner or EA channel, on the sequence the plan requires.
  • Make the CUI boundary decision and sign off the design before migration begins.
  • Provide tenant access, inventory inputs, and line-of-business application owners for authentication re-pointing.
  • Communicate with staff using the provided cutover pack, and staff the client-side cutover coordination.
  • Own ITAR/export-control legal determinations and all assessment outcomes.
  • Operate the GCC High tenant after handover, including its licensing renewals and support relationships.

What's not included

Granting or guaranteeing eligibility — Microsoft validates and decides, and no consultant can promise the outcome or its timing.
GCC High licensing costs, or acting as your licensing reseller for GCC High — licenses flow through Microsoft's authorized AOS-G partners or Enterprise Agreement channels, and we coordinate with that partner rather than replacing it.
CMMC certification preparation, assessment, or remediation programs — that is its own discipline: see the CMMC and NIST 800-171 Compliance Readiness Assessment, CMMC and FedRAMP Readiness Assessment, and CMMC Self-Assessment Assistance.
C3PAO engagement, assessor fees, or any guarantee of assessment or certification outcomes.
Legal determinations that data is or is not CUI, ITAR-controlled, or export-controlled — counsel's work, informed by our boundary analysis.
Migration of workloads outside the stated scope — Teams private chat history, in-place archives, shared mailboxes at volume, Power Platform solutions, and third-party SaaS data are scoped and priced separately where needed, several through our existing tenant-to-tenant services.
On-premises infrastructure work: Active Directory restructuring, GCC High-adjacent Azure Government subscriptions, or physical network changes, unless separately scoped.
Endpoint refresh or at-scale device reimaging — device re-registration is planned in the identity transition; hardware work is separate.
Rewriting or re-integrating line-of-business applications whose vendors do not support GCC High endpoints.
Ongoing managed services, monitoring, or help desk for the GCC High tenant after handover — available separately if wanted.

Limitations & technical notes

!Timeline honesty: eligibility validation and tenant provisioning are Microsoft-controlled steps measured in weeks, and the 12-week figure is a typical engagement, not a commitment. We sequence around Microsoft's gates; we cannot compress them, and we will not pretend to.
!GCC High is not feature-identical to commercial Microsoft 365. Some services and features arrive later, behave differently, or are absent, and external collaboration is deliberately more restricted. The boundary design and knowledge transfer cover the differences that affect you specifically.
!Some content does not migrate cleanly with standard tenant-to-tenant tooling — Teams private chat history is the classic example, alongside Planner, Forms, Stream, and per-app settings. The inventory dispositions each of these explicitly before cutover.
!A custom domain can be attached to only one tenant at a time. The coexistence design sequences the domain move honestly, including the transition states users will notice.
!Third-party and line-of-business applications must support GCC High endpoints; some vendors do not. Discovery flags them, but vendor roadmaps are outside our control.
!The regulatory timeline moves: the CMMC program's phased rollout has already shifted under DoD review in 2026. Contractual obligations under DFARS 252.204-7012 and NIST SP 800-171 — and ITAR data-handling requirements — exist today regardless of assessment phasing, which is why boundary decisions should be driven by contracts in hand rather than program headlines.
!The 'from $25,000' floor covers a small, single-boundary migration; tenant size, enclave complexity, workload count, and coexistence duration move the price, and the fixed quote precedes any commitment.
!Migration moves and configures data and services; it does not by itself make you compliant with anything. Compliance is the posture and evidence you maintain in the new tenant — we hand over the starting documentation, and the readiness services take it from there.

Frequently asked questions

Why can't we just upgrade our existing tenant to GCC High?

Because GCC High is a separate cloud environment with its own infrastructure, its own licensing channel, and a gated door. Microsoft does not convert commercial tenants; it validates your eligibility, provisions a new tenant in the US Government cloud, and leaves the moving to you. That makes this a full tenant-to-tenant migration — which is exactly the work this service exists to run.

Who is eligible for GCC High, and who decides?

Microsoft decides, through its US Government cloud eligibility validation. Typical qualifying evidence is a CAGE code and SAM.gov registration plus contracts carrying CUI, ITAR/EAR, or DFARS obligations. We assemble and submit the package and track it to a decision — but we do not grant eligibility, and we will tell you plainly if your documentation looks thin before you spend money on the attempt.

Do we actually need GCC High, or would GCC or commercial be enough?

It depends on your contracts and your data — ITAR technical data and certain DFARS flowdowns push firmly toward GCC High, while plenty of CUI scenarios are served by GCC or even a properly hardened commercial tenant with an enclave strategy. We wrote a detailed decision guide comparing the three, and our CMMC and NIST 800-171 readiness assessment makes the call from your actual boundary rather than from vendor marketing. We would rather talk you out of an unnecessary GCC High migration than sell you one.

What is an AOS-G partner and why do we need one?

GCC High licensing is not sold through the commercial CSP channel most SMBs buy from. Organizations with under roughly 500 seats purchase through a small set of Microsoft-authorized AOS-G (Agreement for Online Services for Government) partners; larger organizations typically use an Enterprise Agreement. IT Partner is your migration engineer in this engagement, not your GCC High license reseller — we map your current licenses to their GCC High equivalents, coordinate the purchase sequence with the AOS-G partner you select, and stay in our lane about it.

How does the CMMC timeline affect this decision?

Less than the headlines suggest, in both directions. DoD suspended the CMMC phased rollout's Level 2 third-party assessment expansion in mid-2026 pending a program review, so dates you may have seen are in motion. But the obligations that actually drive GCC High decisions — DFARS 252.204-7012, NIST SP 800-171 safeguarding, ITAR data handling — are in contracts today and never paused. Our advice: plan from the clauses in your contracts, use the readiness assessments for the compliance program, and treat migration lead time as the scarce resource, because a tenant move cannot be compressed into the weeks before a deadline.

What is a CUI enclave, and should we move everyone or just some users?

An enclave puts only the users, projects, and data touching CUI into GCC High while the rest of the business stays commercial — smaller licensing bill, smaller assessment scope, but a permanent two-tenant operating model with real collaboration friction at the seam. A full move is simpler to operate and to assess but prices every user at GCC High rates. This is the central design decision of the engagement, and we model both options with actual costs and workflow impacts before you choose.

What actually gets migrated?

The core estate: Entra identities and groups, Exchange mailboxes, OneDrive content, SharePoint sites, and Teams with their standard channels and files — staged in advance with delta passes so the cutover window moves the minimum. Known hard cases are dispositioned explicitly in the inventory: Teams private chat history, in-place archives, Planner, Forms, Stream, and Power Platform content either migrate through separately scoped work or are consciously archived, and you sign off that list before cutover.

Will our users lose access during the migration?

Most of the migration happens invisibly, while users keep working in the commercial tenant. The cutover window itself — mail routing switch, domain move, device re-sign-in — is planned, communicated, and scheduled for minimum disruption, and the runbook states per workload what users will notice. What we do not promise is 'zero downtime': a domain can only live in one tenant at a time, and honest sequencing beats a slogan.

What happens to our custom domain and email addresses?

Your domain moves — it cannot be attached to both tenants simultaneously, so the runbook sequences its removal from the commercial tenant and attachment to GCC High inside the cutover window, with mail routing managed so messages are not lost in the transition. Users keep their addresses; what changes is the tenant answering for them.

What are the evidence artifacts for the SSP and POA&M?

Three things assessors and your compliance lead actually use: the CUI boundary design (what is in scope and why), the migration records (what moved, when, reconciled against inventory), and the as-built configuration documentation of the GCC High tenant's identity, access, and collaboration settings. They are written to drop into your System Security Plan's environment description and to close or open POA&M items with dates and evidence — not as a binder of screenshots.

Is GCC High more expensive to license than commercial Microsoft 365?

Yes, materially — government cloud SKUs carry a premium over their commercial equivalents, and pricing moves over time, so we deliberately do not print license prices here. The licensing model we build in the boundary design phase shows your actual delta, per option, using current AOS-G or EA pricing from the licensing partner — which is one more reason the enclave-versus-full-move decision deserves modeling rather than instinct.

Why does the price start at $25,000 when your other tenant-to-tenant migrations cost less?

Because this is several migrations plus a compliance design wrapped in one program: eligibility and licensing coordination, a new tenant built to a security baseline, the CUI boundary design, four workload migrations, coexistence, cutover, and an evidence package — across roughly 12 weeks. The floor covers a small, single-boundary move; tenant size and enclave complexity scope it up from there, and you get the fixed quote in writing before committing to anything.

What happens after cutover?

You operate the GCC High tenant, with our knowledge-transfer session covering the differences that matter day to day — restricted external collaboration, service parity, support channels. The natural next step for most clients is the compliance program itself: readiness assessment, SSP depth, and self-assessment support through our CMMC services. Ongoing management of the tenant is available but deliberately not bundled — the migration stands on its own, and you decide who runs the environment afterward.

Didn’t find your question?

Ask it here. A real engineer answers by email within one business day — and if it’s a good one, it becomes part of this page so the next person finds it.

Answered by a person, one time, to your inbox. Nothing you type here is published without a human reviewing and anonymizing it first.

Often combined with

From $25,000 (scoped by tenant and CUI boundary)
12 weeks
Book a GCC High scoping call