{"id":125988,"date":"2026-03-12T15:04:00","date_gmt":"2026-03-12T22:04:00","guid":{"rendered":""},"modified":"2026-08-20T14:27:23","modified_gmt":"2026-08-20T21:27:23","slug":"itar-compliance-in-the-microsoft-cloud-navigating-gcc-azure-commercial-and-azure-government","status":"publish","type":"ms-industry","link":"https:\/\/cm-edgetun.pages.dev\/en-us\/microsoft-cloud\/blog\/us-government\/2026\/03\/12\/itar-compliance-in-the-microsoft-cloud-navigating-gcc-azure-commercial-and-azure-government\/","title":{"rendered":"ITAR Compliance in the Microsoft Cloud: Navigating GCC, Azure Commercial, and Azure Government"},"content":{"rendered":"\n<h3 class=\"wp-block-heading\" id=\"community-4501314-toc-hId--436357387\">Why ITAR Compliance Matters in the Cloud<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The International Traffic in Arms Regulations (ITAR) govern the export, temporary import, reexport, and transfer of defense articles, services, and related technical data directly related to defense articles listed on the United States Munitions List (USML) as well as furnishing defense services. Administered by the United States\u2019 Department of State&#8217;s Directorate of Defense Trade Controls (DDTC), the ITAR imposes strict requirements on manufacturers, exporters, and brokers of defense-related items &#8211; and those requirements extend to how and where ITAR-controlled data is stored, processed, and accessed in the cloud.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">For federal agencies, Defense Industrial Base (DIB) organizations, and government contractors, choosing the right Microsoft cloud environment is not just a technical decision &#8211; &nbsp;it is a compliance imperative. Getting it wrong can result in civil penalties, criminal prosecution, loss of export privileges, and the erosion of trust with federal partners. It can even cause the government to bar companies from federal contracts.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This guide walks through how ITAR compliance maps to our cloud offerings &#8211; specifically Microsoft 365 GCC, Azure Commercial, and Azure Government &#8211; drawing exclusively from official Microsoft documentation to help you make informed decisions about where your ITAR-controlled workloads belong.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"community-4501314-toc-hId-2051155446\">Understanding ITAR: Core Requirements<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Before evaluating cloud environments, it is essential to understand what the ITAR requires:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li class=\"wp-block-list-item\"><strong>Registration with DDTC:<\/strong> Organizations that manufacture, export, or broker defense articles must register with the Directorate of Defense Trade Controls.<\/li>\n\n\n\n<li class=\"wp-block-list-item\"><strong>Access Restricted to US Persons:<\/strong> ITAR-controlled technical data may only be accessed by US persons unless specific DDTC authorization has been granted.<\/li>\n\n\n\n<li class=\"wp-block-list-item\"><strong>Prohibition on Unauthorized Export<\/strong><strong>:<\/strong> ITAR-controlled technical data may not be exported &#8211; included by making it available to foreign person \u2013 without authorization from the DDTC. As described in additional detail below, the ITAR does not impose an affirmative requirement that data be stored within the Continental United States (CONUS). However, storing data within CONUS and restricting access to U.S. persons is a widely adopted mitigation strategy. <strong>End-to-End Encryption:<\/strong> The revised ITAR rules, effective March 25, 2020, introduced a carve-out stating that sending, taking, or storing unclassified technical data does not constitute an export if the data is secured using end-to-end encryption with FIPS 140 compliant cryptographic modules, the means of decryption are not provided to any person other than the intended recipient, and the data &nbsp;is not intentionally sent to or stored in a proscribed country listed under 22 CFR \u00a7 126.1. Additionally, there are specific requirements for protecting and sharing access information for ITAR data to qualify for the carve-out.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Think of ITAR requirements as a vault within a vault. It is not enough that the building is secure \u2014 the room, the safe, and the access list all have to meet the standard independently.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"community-4501314-toc-hId-243700983\">There Is No ITAR Certification<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">A critical point that often creates confusion: <strong>there is no ITAR compliance certification for cloud service providers.<\/strong> We design and operate our in-scope services to be capable of supporting your ITAR obligations and compliance program, but there is no formal ITAR certification to obtain. This means that ITAR compliance is ultimately the responsibility of the data owner \u2014 we provide the capable platform, and you are responsible for the protection, architecture, and access controls within your environment.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Reference: <a href=\"https:\/\/learn.microsoft.com\/en-us\/azure\/compliance\/offerings\/offering-itar\" target=\"_blank\" rel=\"noopener noreferrer\">International Traffic in Arms Regulations (ITAR) &#8211; Azure Compliance | Microsoft Learn<\/a><\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"community-4501314-toc-hId--1563753480\">Microsoft Cloud Environments: Where Does ITAR Fit?<\/h3>\n\n\n<figure class=\"wp-block-image size-full\"><img decoding=\"async\" src=\"https:\/\/cm-edgetun.pages.dev\/en-us\/microsoft-cloud\/blog\/wp-content\/uploads\/2026\/06\/ITAR-Right-Fit.webp\" alt=\"\" class=\"wp-image-125977 webp-format\" srcset=\"\" data-orig-src=\"https:\/\/cm-edgetun.pages.dev\/en-us\/microsoft-cloud\/blog\/wp-content\/uploads\/2026\/06\/ITAR-Right-Fit.webp\"><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"community-4501314-toc-hId--873192006\">Microsoft 365 GCC<\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">Microsoft 365 Government Community Cloud (GCC) is designed for US federal, state, local, and tribal government entities, along with contractors holding or processing data on behalf of the US Government. GCC provides compliance with FedRAMP High, DFARS, and requirements for criminal justice and federal tax information systems.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">However, GCC does not natively support ITAR or EAR-controlled data. While GCC stores data within the United States and restricts access to screened personnel, it runs on Microsoft Entra ID Commercial. Support staff may include non-US persons, and we will only agree to ITAR contract language for the GCC High environment &#8211; not standard GCC.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"community-4501314-toc-hId-1614320827\">Can Compensating Controls Make GCC Viable for ITAR? A Risk-Based Decision<\/h4>\n\n\n\n<p class=\"wp-block-paragraph\"><em>We recognize that not every organization is positioned to leverage to GCC High<\/em> &#8211; whether due to budget constraints, licensing timelines, or operational complexity. For organizations evaluating GCC, it is worth understanding the compensating controls available, the case they enable, and efforts need to reduce risk within their organization.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>The core argument for GCC viability rests on four points:<\/strong><\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li class=\"wp-block-list-item\"><strong>Data never leaves the United States.<\/strong> GCC stores all customer data within US boundaries. Unlike Azure Commercial, where data residency depends on customer configuration, GCC&#8217;s CONUS data residency is part of the environment boundary itself.<\/li>\n\n\n\n<li class=\"wp-block-list-item\"><strong>No unauthorized human access.<\/strong> When CMK and Customer Lockbox are implemented together, they eliminate the risk of unauthorized human access to ITAR-controlled data \u2014 regardless of the background check status of any individual. CMK ensures that we and our agents cannot decrypt your data without keys your organization controls. Customer Lockbox ensures that in rare instances where our support engineers need elevated access, you explicitly approve or reject every request.<\/li>\n\n\n\n<li class=\"wp-block-list-item\"><strong>Automated processing stays within the GCC boundary in CONUS.<\/strong> Automated service operations that process your data remain within the GCC environment and do not leave the United States.<\/li>\n\n\n\n<li class=\"wp-block-list-item\"><strong>Therefore, no export occurs.<\/strong> If the data never leaves the US, no&nbsp; Microsoft employee can access it in decrypted form without explicit customer approval, and all processing remains within CONUS &#8211; the conditions that would constitute an export under ITAR are not met.<\/li>\n<\/ol>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Customer Managed Keys (CMK):<\/strong> GCC supports customer-managed encryption keys through Azure Key Vault. With CMK, your organization retains exclusive control of the encryption keys that protect your data at rest. Because Azure Key Vault is designed so that we and our agents cannot see or extract your cryptographic keys, CMK is a critical component of meeting &nbsp;the ITAR end-to-end encryption carve-out requirement that the means of decryption are not provided to any third party. This is the critical control &#8211; even if a non-US person were to encounter the encrypted data, nothing is revealed because they cannot decrypt it without your keys.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Customer Lockbox:<\/strong> Customer Lockbox for Microsoft 365 provides an explicit access governance gate. In rare instances where our support engineers need elevated access to your data to resolve a service request, Customer Lockbox requires your approval before any access is granted. This gives your organization direct control over who touches your data and when \u2014 making the background check status of individual support personnel a secondary concern, because no human access occurs without your authorization.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>This is fundamentally a risk-based decision &#8211; and one that typically falls to the CISO and organizational leadership to approve and be held accountable for.<\/strong> Organizations that implement CMK and Customer Lockbox in GCC can build a defensible technical case that no export occurs, but they should ensure that decision is documented, reviewed by compliance stakeholders, and aligned with their organization&#8217;s risk tolerance. For many organizations \u2014 particularly those in the DIB handling ITAR-controlled technical data&nbsp; \u2014 GCC High will remain the appropriate path because it eliminates these considerations by design.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Bottom line:<\/strong> Ultimately, it is incumbent on the data owner to decide what tools meet their purposes. GCC is suitable for Federally Controlled Information (FCI) and certain categories of Controlled Unclassified Information (CUI). Organizations with ITAR-controlled data may prefer GCC High or DoD environments, but CMK and Customer Lockbox can serve as meaningful compensating controls for organizations managing the transition or making a documented, risk-based determination that the technical controls in GCC are sufficient for their specific use case.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Reference: <a href=\"https:\/\/learn.microsoft.com\/en-us\/office365\/servicedescriptions\/office-365-platform-service-description\/office-365-us-government\/office-365-us-government\" target=\"_blank\" rel=\"noopener noreferrer\">Office 365 US Government &#8211; Service Descriptions | Microsoft Learn<\/a><\/p>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"community-4501314-toc-hId--193133636\">Azure Commercial<\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">Azure Commercial can play a role in supporting ITAR compliance \u2014 but with an important distinction from our government cloud environments: <strong>the compliance boundary in Azure Commercial is customer-implemented rather than environment-guaranteed.<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Both Azure and Azure Government can help you meet your ITAR compliance obligations. Our Azure datacenters (except for the Hong Kong SAR region) are not located in proscribed countries or the Russian Federation. Azure services rely on FIPS 140 validated cryptographic modules and provide multiple options for encrypting data in transit and at rest, including customer-managed keys (CMK) through Azure Key Vault backed by FIPS 140 validated HSMs.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"community-4501314-toc-hId--2000588099\">Data Residency in Azure Commercial<\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">While Azure Commercial is not hard-locked to CONUS the way Azure Government is, we provide you with the tools and transparency to control where your data resides. You select the Azure region where your applications and data are deployed. Most Azure services enable you to specify the region where your customer data will be stored and processed, and we will not store or process customer data outside the selected geography. We publish a <a href=\"https:\/\/azure.microsoft.com\/en-us\/explore\/global-infrastructure\/data-residency\" target=\"_blank\" rel=\"noopener noreferrer\">data residency page<\/a> and per-service documentation that identifies which services store data at rest in-region and which have global components that may process data outside the selected geography.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">To enforce data residency in Azure Commercial, you can leverage region selection during deployment, Azure Policy to restrict resource creation to specific US regions, and service-specific residency controls documented for each service. It is your responsibility to review per-service documentation to understand which services are fully regional and which may have global processing components, and to architect your environment accordingly.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This is the fundamental difference: <strong>in Azure Government, the CONUS boundary is part of the environment. In Azure Commercial, you are building that boundary yourself through policy, encryption, access controls, and deliberate architecture choices for the available localized services.<\/strong><\/p>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"community-4501314-toc-hId-486924734\">The Encryption Carve-Out<\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">The key enabler for ITAR in Azure Commercial is the <strong>ITAR end-to-end encryption carve-out.<\/strong> The ITAR states that storing encrypted technical data does not constitute an export when the data is unclassified, encrypted end-to-end with FIPS 140 compliant modules, and not intentionally stored in a proscribed country. Also, the means of encryption must not be provided to a third party. Azure Key Vault is designed so that Microsoft and its agents cannot see or extract customers\u2019 cryptographic keys. Customer Lockbox for Azure puts you in charge of approving or rejecting any elevated access requests from our support engineers, providing an additional layer of access governance.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">However, Azure Commercial does not provide the additional contractual commitments that Azure Government offers, such as guaranteed storage within the United States and access limited exclusively to screened US persons. The compliance controls are available to you &#8211; but the responsibility for implementing, configuring, and maintaining them rests entirely with your organization.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Bottom line:<\/strong> Azure Commercial can support ITAR workloads under the encryption carve-out, but you are building and enforcing the compliance boundary yourself. Most organizations with ITAR obligations are best served by Azure Government, where the boundary is built into the environment.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Reference: <a href=\"https:\/\/learn.microsoft.com\/en-us\/azure\/compliance\/offerings\/offering-itar\" target=\"_blank\" rel=\"noopener noreferrer\">International Traffic in Arms Regulations (ITAR) &#8211; Azure Compliance | Microsoft Learn<\/a><\/p>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"community-4501314-toc-hId--1320529729\">Azure Government<\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">Azure Government is a physically and logically isolated cloud environment built specifically for US government agencies and their partners. Data transmission and processing are restricted to CONUS, and access to systems processing customer data is limited to screened US persons. Azure Government provides contractual commitments regarding data residency and personnel access that go beyond what Azure Commercial offers.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Azure Government holds FedRAMP High authorization and supports DISA SRG Impact Level 5 (IL5), ITAR, and Export Administration Regulations (EAR). For organizations that need to store and process ITAR-regulated data, Azure Government provides the strongest alignment with ITAR requirements available in our cloud ecosystem.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Key capabilities that support ITAR compliance in Azure Government include:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li class=\"wp-block-list-item\"><strong>Data location control:<\/strong> Robust tools to restrict data storage to US regions, ensuring customer data is not intentionally stored in a non-conforming location.<\/li>\n\n\n\n<li class=\"wp-block-list-item\"><strong>Access controls:<\/strong> Our technical support personnel do not have default access to customer data. Customer Lockbox for Azure enables you to approve or reject any elevated access requests.<\/li>\n\n\n\n<li class=\"wp-block-list-item\"><strong>End-to-end encryption:<\/strong> FIPS 140 validated cryptographic modules with customer-managed key options through Azure Key Vault HSMs.<\/li>\n\n\n\n<li class=\"wp-block-list-item\"><strong>Screened US citizens:<\/strong> Personnel with potential access to customer data undergo verification of US citizenship and additional background screening. This is more than what the ITAR requires, which is a US person.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Bottom line:<\/strong> Azure Government is the recommended environment for ITAR-<strong>controlled<\/strong> workloads and provides the strongest contractual and technical protections.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Reference: <a href=\"https:\/\/learn.microsoft.com\/en-us\/azure\/azure-government\/documentation-government-overview-itar\" target=\"_blank\" rel=\"noopener noreferrer\">Azure support for export controls | Microsoft Learn<\/a><\/p>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"community-4501314-toc-hId--1897113593\">Microsoft 365 GCC High and DoD<\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">For organizations that need Microsoft 365 productivity services (Exchange, SharePoint, Teams, OneDrive) alongside ITAR compliance, <strong>GCC High is the appropriate environment.<\/strong> GCC High is built on Azure Government infrastructure, stores data exclusively in US data centers, and limits access to screened US citizens. We will agree to ITAR contract language for the GCC High environment.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The Office 365 GCC High and DoD environments deliver compliance with Department of Defense Security Requirements Guidelines, DFARS, and ITAR. You must sign additional agreements notifying us of your intention to store ITAR-controlled data so that we can comply with our obligations to both you and the US government.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Reference: <a href=\"https:\/\/learn.microsoft.com\/en-us\/office365\/servicedescriptions\/office-365-platform-service-description\/office-365-us-government\/gcc-high-and-dod\" target=\"_blank\" rel=\"noopener noreferrer\">Office 365 GCC High and DoD &#8211; Service Descriptions | Microsoft Learn<\/a><\/p>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"community-4501314-toc-hId-590399240\">Comparing the Environments at a Glance<\/h4>\n\n\n\n<div class=\"wp-block-columns is-layout-flex wp-container-core-columns-is-layout-28f84493 wp-block-columns-is-layout-flex\">\n<div class=\"wp-block-column is-layout-flow wp-block-column-is-layout-flow\" style=\"flex-basis:100%\">\n<figure class=\"wp-block-table lia-background-color-16 lia-border-color-21 lia-border-style-solid is-style-regular\"><table class=\"has-fixed-layout\"><tbody><tr><td>\n<h5 id=\"community-4501314-toc-hId--1087972504\"><strong>Capability<\/strong><\/h5>\n<\/td><td>\n<h5 id=\"community-4501314-toc-hId-1399540329\"><strong>GCC<\/strong><\/h5>\n<\/td><td>\n<h5 id=\"community-4501314-toc-hId--407914134\"><strong>Azure Commercial<\/strong><\/h5>\n<\/td><td>\n<h5 id=\"community-4501314-toc-hId-2079598699\"><strong>Azure Government<\/strong><\/h5>\n<\/td><td>\n<h5 id=\"community-4501314-toc-hId-272144236\"><strong>GCC High \/ DoD<\/strong><\/h5>\n<\/td><\/tr><tr><td>\n<h5 id=\"community-4501314-toc-hId--1535310227\"><strong>ITAR Contract Language<\/strong><\/h5>\n<\/td><td>No<\/td><td>No<\/td><td>Yes<\/td><td>Yes<\/td><\/tr><tr><td>\n<h5 id=\"community-4501314-toc-hId-952202606\"><strong>Data Residency (CONUS)<\/strong><\/h5>\n<\/td><td>US only (environment boundary)<\/td><td>Customer-configured via region selection, Azure Policy, and per-service residency controls<\/td><td>US only (contractual)<\/td><td>US only (contractual)<\/td><\/tr><tr><td>\n<h5 id=\"community-4501314-toc-hId--855251857\"><strong>Compliance Boundary<\/strong><\/h5>\n<\/td><td>Environment-guaranteed<\/td><td>Customer-built through policy, encryption, and architecture<\/td><td>Environment-guaranteed<\/td><td>Environment-guaranteed<\/td><\/tr><tr><td>\n<h5 id=\"community-4501314-toc-hId--1964544379\"><strong>Personnel Screening (US Persons)<\/strong><\/h5>\n<\/td><td>Screened personnel, but support staff may include non-US persons<\/td><td>No specific commitment<\/td><td>Screened US persons<\/td><td>Screened US citizens<\/td><\/tr><tr><td>\n<h5 id=\"community-4501314-toc-hId-522968454\"><strong>Physical\/Logical Isolation<\/strong><\/h5>\n<\/td><td>Logical segregation on Azure Commercial<\/td><td>Shared commercial infrastructure<\/td><td>Physically isolated<\/td><td>Physically isolated (Azure Gov)<\/td><\/tr><tr><td>\n<h5 id=\"community-4501314-toc-hId--1284486009\"><strong>FIPS 140 Encryption<\/strong><\/h5>\n<\/td><td>Yes<\/td><td>Yes<\/td><td>Yes<\/td><td>Yes<\/td><\/tr><tr><td>\n<h5 id=\"community-4501314-toc-hId-1203026824\"><strong>Customer Managed Keys (CMK)<\/strong><\/h5>\n<\/td><td>Yes (Azure Key Vault)<\/td><td>Yes (Azure Key Vault)<\/td><td>Yes (Azure Key Vault)<\/td><td>Yes (Azure Key Vault)<\/td><\/tr><tr><td>\n<h5 id=\"community-4501314-toc-hId--604427639\"><strong>Customer Lockbox<\/strong><\/h5>\n<\/td><td>Yes<\/td><td>Yes<\/td><td>Yes<\/td><td>Yes<\/td><\/tr><tr><td>\n<h5 id=\"community-4501314-toc-hId-1883085194\"><strong>FedRAMP Authorization<\/strong><\/h5>\n<\/td><td>FedRAMP High<\/td><td>Varies by service<\/td><td>FedRAMP High<\/td><td>FedRAMP High<\/td><\/tr><tr><td>\n<h5 id=\"community-4501314-toc-hId-75630731\"><strong>ITAR-Capable<\/strong><\/h5>\n<\/td><td>Not natively; CMK + Customer Lockbox enable a defensible no-export case (risk-based decision)<\/td><td>Under encryption carve-out (customer-built boundary)<\/td><td>Yes<\/td><td>Yes<\/td><\/tr><\/tbody><\/table><\/figure>\n<\/div>\n<\/div>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"community-4501314-toc-hId--1989989170\">Shared Responsibility: Your Role in ITAR Compliance<\/h3>\n\n\n<figure class=\"wp-block-image size-full\"><img decoding=\"async\" src=\"https:\/\/cm-edgetun.pages.dev\/en-us\/microsoft-cloud\/blog\/wp-content\/uploads\/2026\/06\/ITAR-Compliance-SRM.webp\" alt=\"\" class=\"wp-image-125976 webp-format\" srcset=\"\" data-orig-src=\"https:\/\/cm-edgetun.pages.dev\/en-us\/microsoft-cloud\/blog\/wp-content\/uploads\/2026\/06\/ITAR-Compliance-SRM.webp\"><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Regardless of which cloud environment you choose, ITAR compliance is a shared responsibility. We provide the platform capabilities \u2014 encryption, data residency, access controls, and personnel screening \u2014 but your organization is responsible for:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li class=\"wp-block-list-item\"><strong>Registering with DDTC<\/strong> if you manufacture, export, or broker defense articles.<\/li>\n\n\n\n<li class=\"wp-block-list-item\"><strong>Classifying and labeling data<\/strong> to identify ITAR-controlled technical data.<\/li>\n\n\n\n<li class=\"wp-block-list-item\"><strong>Configuring access controls<\/strong> to ensure only authorized US persons can access regulated information.<\/li>\n\n\n\n<li class=\"wp-block-list-item\"><strong>Signing additional agreements<\/strong> with us to formalize your intention to store ITAR-controlled data (required for Azure Government and GCC High).<\/li>\n\n\n\n<li class=\"wp-block-list-item\"><strong>Designing application architecture<\/strong> to maintain end-to-end encryption that meets ITAR requirements. We do not inspect, approve, or monitor your applications.<\/li>\n\n\n\n<li class=\"wp-block-list-item\"><strong>Managing third-party integrations<\/strong> that may fall outside the compliance boundary.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">The Microsoft Enterprise Agreement Amendment enables us and the customer to work together in reporting ITAR violations, fulfilling the specific reporting obligations that ITAR requires.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Reference: <a href=\"https:\/\/learn.microsoft.com\/en-us\/compliance\/regulatory\/offering-itar\" target=\"_blank\" rel=\"noopener noreferrer\">International Traffic in Arms Regulations (ITAR) &#8211; Microsoft Compliance | Microsoft Learn<\/a><\/p>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"community-4501314-toc-hId-626606382\">Action Plan for Getting Started<\/h4>\n\n\n<figure class=\"wp-block-image size-full\"><img decoding=\"async\" src=\"https:\/\/cm-edgetun.pages.dev\/en-us\/microsoft-cloud\/blog\/wp-content\/uploads\/2026\/06\/ITAR-Compliance.webp\" alt=\"\" class=\"wp-image-125975 webp-format\" srcset=\"\" data-orig-src=\"https:\/\/cm-edgetun.pages.dev\/en-us\/microsoft-cloud\/blog\/wp-content\/uploads\/2026\/06\/ITAR-Compliance.webp\"><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\"><span class=\"lia-media-object lia-media-is-center lia-media-size-default\" data-image-alt=\"\"><\/span><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li class=\"wp-block-list-item\"><strong>Step 1: Assess Your Data<\/strong> Determine whether your organization handles defense articles, services, or technical data on the USML. Understand which data is ITAR-controlled and map your data flows.<strong>Step 2: Choose the Right Environment<\/strong> For ITAR-<strong>controlled<\/strong> workloads, Azure Government and Microsoft 365 GCC High provide the strongest alignment. If you are evaluating GCC with compensating controls like CMK and Customer Lockbox, or Azure Commercial under the encryption carve-out, ensure the decision is documented and approved by your CISO and compliance stakeholders \u2014 as the CISO is ultimately accountable for the risk acceptance and the defensibility of the chosen approach.<br><p><strong>Step 3: Engage Your Microsoft Account Team<\/strong> If you are seeking to host ITAR-<strong>controlled<\/strong> data, work with your Microsoft account and licensing teams to obtain proper agreements and access relevant system architecture information.<\/p><p><strong>Step 4: Develop Your Compliance Architecture<\/strong> Leverage tools like Azure Policy, Microsoft Defender for Cloud, Microsoft Purview Compliance Manager, and Customer Lockbox to enforce and monitor your compliance posture.<\/p><p><strong>Step 5: Document and Maintain<\/strong> Develop a System Security Plan (SSP) that reflects your ITAR controls, and continuously monitor and update your controls as your environment evolves.<\/p><p><strong>Resources and Further Reading<\/strong><\/p>\n<ul class=\"wp-block-list\">\n<li class=\"wp-block-list-item\"><a href=\"https:\/\/learn.microsoft.com\/en-us\/azure\/compliance\/offerings\/offering-itar\" target=\"_blank\" rel=\"noopener noreferrer\">International Traffic in Arms Regulations (ITAR) &#8211; Azure Compliance | Microsoft Learn<\/a><\/li>\n\n\n\n<li class=\"wp-block-list-item\"><a href=\"https:\/\/learn.microsoft.com\/en-us\/azure\/azure-government\/documentation-government-overview-itar\" target=\"_blank\" rel=\"noopener noreferrer\">Azure support for export controls | Microsoft Learn<\/a><\/li>\n\n\n\n<li class=\"wp-block-list-item\"><a href=\"https:\/\/learn.microsoft.com\/en-us\/compliance\/regulatory\/offering-itar\" target=\"_blank\" rel=\"noopener noreferrer\">International Traffic in Arms Regulations (ITAR) &#8211; Microsoft Compliance | Microsoft Learn<\/a><\/li>\n\n\n\n<li class=\"wp-block-list-item\"><a href=\"https:\/\/learn.microsoft.com\/en-us\/office365\/servicedescriptions\/office-365-platform-service-description\/office-365-us-government\/office-365-us-government\" target=\"_blank\" rel=\"noopener noreferrer\">Office 365 US Government &#8211; Service Descriptions | Microsoft Learn<\/a><\/li>\n\n\n\n<li class=\"wp-block-list-item\"><a href=\"https:\/\/learn.microsoft.com\/en-us\/office365\/servicedescriptions\/office-365-platform-service-description\/office-365-us-government\/gcc-high-and-dod\" target=\"_blank\" rel=\"noopener noreferrer\">Office 365 GCC High and DoD &#8211; Service Descriptions | Microsoft Learn<\/a><\/li>\n\n\n\n<li class=\"wp-block-list-item\"><a href=\"https:\/\/azure.microsoft.com\/en-us\/explore\/global-infrastructure\/data-residency\" target=\"_blank\" rel=\"noopener noreferrer\">Azure Data Residency<\/a><\/li>\n\n\n\n<li class=\"wp-block-list-item\"><a href=\"https:\/\/aka.ms\/Azure-Export-Paper\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Azure Export Controls Whitepaper<\/a><\/li>\n\n\n\n<li class=\"wp-block-list-item\"><a href=\"https:\/\/aka.ms\/MSGovCompliance\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Government Compliance Offerings<\/a><\/li>\n\n\n\n<li class=\"wp-block-list-item\"><a href=\"https:\/\/www.pmddtc.state.gov\/?id=ddtc_public_portal_itar_landing\" target=\"_blank\" rel=\"noopener nofollow noreferrer\">DDTC ITAR Landing Page<\/a><\/li>\n\n\n\n<li class=\"wp-block-list-item\"><a href=\"https:\/\/www.ecfr.gov\/current\/title-22\/chapter-I\/subchapter-M\" target=\"_blank\" rel=\"noopener nofollow noreferrer\">ITAR Title 22 CFR Part 120-130<\/a><\/li>\n<\/ul>\n<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"community-4501314-toc-hId--1309930800\">Conclusion<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">ITAR compliance in the cloud is achievable &#8211; but it requires deliberate environment selection, proper contractual agreements, and disciplined architecture. Microsoft 365 GCC does not natively support ITAR, but Customer Managed Keys and Customer Lockbox can enable a defensible technical case that no export occurs &#8211; a risk-based decision that falls to the CISO and organizational leadership to approve. Azure Commercial can support ITAR under the encryption carve-out, but the compliance boundary is customer-built rather than environment-guaranteed, which demands careful architecture and per-service residency review. Azure Government and GCC High provide the contractual commitments, data residency guarantees, and personnel screening that most closely align with ITAR requirements \u2014 with the compliance boundary built into the environment by design.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The path forward starts with understanding your data, choosing the right environment, and building your compliance architecture on our capable platform.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Why ITAR Compliance Matters in the Cloud The International Traffic in Arms Regulations (ITAR) govern the export, temporary import, reexport, and transfer of defense articles, services, and related technical data directly related to defense articles listed on the United States Munitions List (USML) as well as furnishing defense services.<\/p>\n","protected":false},"author":57,"featured_media":127974,"template":"","meta":{"ep_exclude_from_search":false,"_classifai_error":"","_classifai_text_to_speech_error":"","_innovation_original_canonical_url":"https:\/\/techcommunity.microsoft.com\/blog\/publicsectorblog\/itar-compliance-in-the-microsoft-cloud-navigating-gcc-azure-commercial-and-azure\/4501314","ms-ems-related-posts":[],"footnotes":""},"categories":[1942],"tags":[],"content-type":[118],"job-function":[],"coauthors":[1215],"class_list":["post-125988","ms-industry","type-ms-industry","status-publish","has-post-thumbnail","hentry","category-us-government","content-type-thought-leadership"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.4 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>ITAR Compliance in the Microsoft Cloud: Navigating GCC, Azure Commercial, and Azure Government | The Microsoft Cloud Blog<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/cm-edgetun.pages.dev\/en-us\/microsoft-cloud\/blog\/us-government\/2026\/03\/12\/itar-compliance-in-the-microsoft-cloud-navigating-gcc-azure-commercial-and-azure-government\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"ITAR Compliance in the Microsoft Cloud: Navigating GCC, Azure Commercial, and Azure Government | The Microsoft Cloud Blog\" \/>\n<meta property=\"og:description\" content=\"Why ITAR Compliance Matters in the Cloud The International Traffic in Arms Regulations (ITAR) govern the export, temporary import, reexport, and transfer of defense articles, services, and related technical data directly related to defense articles listed on the United States Munitions List (USML) as well as furnishing defense services.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/cm-edgetun.pages.dev\/en-us\/microsoft-cloud\/blog\/us-government\/2026\/03\/12\/itar-compliance-in-the-microsoft-cloud-navigating-gcc-azure-commercial-and-azure-government\/\" \/>\n<meta property=\"og:site_name\" content=\"The Microsoft Cloud Blog\" \/>\n<meta property=\"article:modified_time\" content=\"2026-08-20T21:27:23+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/cm-edgetun.pages.dev\/en-us\/microsoft-cloud\/blog\/wp-content\/uploads\/2026\/03\/ITAR.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"866\" \/>\n\t<meta property=\"og:image:height\" content=\"487\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:site\" content=\"@MSCloud\" \/>\n<meta name=\"twitter:label1\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data1\" content=\"14 minutes\" \/>\n\t<meta name=\"twitter:label2\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data2\" content=\"Microsoft: From Inside the Cloud\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/cm-edgetun.pages.dev\\\/en-us\\\/microsoft-cloud\\\/blog\\\/us-government\\\/2026\\\/03\\\/12\\\/itar-compliance-in-the-microsoft-cloud-navigating-gcc-azure-commercial-and-azure-government\\\/\",\"url\":\"https:\\\/\\\/cm-edgetun.pages.dev\\\/en-us\\\/microsoft-cloud\\\/blog\\\/us-government\\\/2026\\\/03\\\/12\\\/itar-compliance-in-the-microsoft-cloud-navigating-gcc-azure-commercial-and-azure-government\\\/\",\"name\":\"ITAR Compliance in the Microsoft Cloud: Navigating GCC, Azure Commercial, and Azure Government | The Microsoft Cloud Blog\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/cm-edgetun.pages.dev\\\/en-us\\\/microsoft-cloud\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/cm-edgetun.pages.dev\\\/en-us\\\/microsoft-cloud\\\/blog\\\/us-government\\\/2026\\\/03\\\/12\\\/itar-compliance-in-the-microsoft-cloud-navigating-gcc-azure-commercial-and-azure-government\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/cm-edgetun.pages.dev\\\/en-us\\\/microsoft-cloud\\\/blog\\\/us-government\\\/2026\\\/03\\\/12\\\/itar-compliance-in-the-microsoft-cloud-navigating-gcc-azure-commercial-and-azure-government\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/cm-edgetun.pages.dev\\\/en-us\\\/microsoft-cloud\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/03\\\/ITAR.jpg\",\"datePublished\":\"2026-03-12T22:04:00+00:00\",\"dateModified\":\"2026-08-20T21:27:23+00:00\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/cm-edgetun.pages.dev\\\/en-us\\\/microsoft-cloud\\\/blog\\\/us-government\\\/2026\\\/03\\\/12\\\/itar-compliance-in-the-microsoft-cloud-navigating-gcc-azure-commercial-and-azure-government\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/cm-edgetun.pages.dev\\\/en-us\\\/microsoft-cloud\\\/blog\\\/us-government\\\/2026\\\/03\\\/12\\\/itar-compliance-in-the-microsoft-cloud-navigating-gcc-azure-commercial-and-azure-government\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/cm-edgetun.pages.dev\\\/en-us\\\/microsoft-cloud\\\/blog\\\/us-government\\\/2026\\\/03\\\/12\\\/itar-compliance-in-the-microsoft-cloud-navigating-gcc-azure-commercial-and-azure-government\\\/#primaryimage\",\"url\":\"https:\\\/\\\/cm-edgetun.pages.dev\\\/en-us\\\/microsoft-cloud\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/03\\\/ITAR.jpg\",\"contentUrl\":\"https:\\\/\\\/cm-edgetun.pages.dev\\\/en-us\\\/microsoft-cloud\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/03\\\/ITAR.jpg\",\"width\":866,\"height\":487,\"caption\":\"ITAR compliance in the Microsoft Cloud.\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/cm-edgetun.pages.dev\\\/en-us\\\/microsoft-cloud\\\/blog\\\/us-government\\\/2026\\\/03\\\/12\\\/itar-compliance-in-the-microsoft-cloud-navigating-gcc-azure-commercial-and-azure-government\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/cm-edgetun.pages.dev\\\/en-us\\\/microsoft-cloud\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Industry Articles\",\"item\":\"https:\\\/\\\/cm-edgetun.pages.dev\\\/en-us\\\/microsoft-cloud\\\/blog\\\/ms-industry\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"ITAR Compliance in the Microsoft Cloud: Navigating GCC, Azure Commercial, and Azure Government\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/cm-edgetun.pages.dev\\\/en-us\\\/microsoft-cloud\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/cm-edgetun.pages.dev\\\/en-us\\\/microsoft-cloud\\\/blog\\\/\",\"name\":\"The Microsoft Cloud Blog\",\"description\":\"Build the future of your business with AI\",\"publisher\":{\"@id\":\"https:\\\/\\\/cm-edgetun.pages.dev\\\/en-us\\\/microsoft-cloud\\\/blog\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/cm-edgetun.pages.dev\\\/en-us\\\/microsoft-cloud\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/cm-edgetun.pages.dev\\\/en-us\\\/microsoft-cloud\\\/blog\\\/#organization\",\"name\":\"Microsoft Cloud Blog\",\"url\":\"https:\\\/\\\/cm-edgetun.pages.dev\\\/en-us\\\/microsoft-cloud\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/cm-edgetun.pages.dev\\\/en-us\\\/microsoft-cloud\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/cm-edgetun.pages.dev\\\/en-us\\\/microsoft-cloud\\\/blog\\\/wp-content\\\/uploads\\\/2023\\\/10\\\/microsoft_logo.webp\",\"contentUrl\":\"https:\\\/\\\/cm-edgetun.pages.dev\\\/en-us\\\/microsoft-cloud\\\/blog\\\/wp-content\\\/uploads\\\/2023\\\/10\\\/microsoft_logo.webp\",\"width\":400,\"height\":400,\"caption\":\"Microsoft Cloud Blog\"},\"image\":{\"@id\":\"https:\\\/\\\/cm-edgetun.pages.dev\\\/en-us\\\/microsoft-cloud\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/MSCloud\",\"https:\\\/\\\/www.linkedin.com\\\/showcase\\\/microsoft-cloud-platform\\\/\",\"https:\\\/\\\/www.youtube.com\\\/@MicrosoftCloud\"]}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"ITAR Compliance in the Microsoft Cloud: Navigating GCC, Azure Commercial, and Azure Government | The Microsoft Cloud Blog","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/cm-edgetun.pages.dev\/en-us\/microsoft-cloud\/blog\/us-government\/2026\/03\/12\/itar-compliance-in-the-microsoft-cloud-navigating-gcc-azure-commercial-and-azure-government\/","og_locale":"en_US","og_type":"article","og_title":"ITAR Compliance in the Microsoft Cloud: Navigating GCC, Azure Commercial, and Azure Government | The Microsoft Cloud Blog","og_description":"Why ITAR Compliance Matters in the Cloud The International Traffic in Arms Regulations (ITAR) govern the export, temporary import, reexport, and transfer of defense articles, services, and related technical data directly related to defense articles listed on the United States Munitions List (USML) as well as furnishing defense services.","og_url":"https:\/\/cm-edgetun.pages.dev\/en-us\/microsoft-cloud\/blog\/us-government\/2026\/03\/12\/itar-compliance-in-the-microsoft-cloud-navigating-gcc-azure-commercial-and-azure-government\/","og_site_name":"The Microsoft Cloud Blog","article_modified_time":"2026-08-20T21:27:23+00:00","og_image":[{"width":866,"height":487,"url":"https:\/\/cm-edgetun.pages.dev\/en-us\/microsoft-cloud\/blog\/wp-content\/uploads\/2026\/03\/ITAR.jpg","type":"image\/jpeg"}],"twitter_card":"summary_large_image","twitter_site":"@MSCloud","twitter_misc":{"Est. reading time":"14 minutes","Written by":"Microsoft: From Inside the Cloud"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/cm-edgetun.pages.dev\/en-us\/microsoft-cloud\/blog\/us-government\/2026\/03\/12\/itar-compliance-in-the-microsoft-cloud-navigating-gcc-azure-commercial-and-azure-government\/","url":"https:\/\/cm-edgetun.pages.dev\/en-us\/microsoft-cloud\/blog\/us-government\/2026\/03\/12\/itar-compliance-in-the-microsoft-cloud-navigating-gcc-azure-commercial-and-azure-government\/","name":"ITAR Compliance in the Microsoft Cloud: Navigating GCC, Azure Commercial, and Azure Government | The Microsoft Cloud Blog","isPartOf":{"@id":"https:\/\/cm-edgetun.pages.dev\/en-us\/microsoft-cloud\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/cm-edgetun.pages.dev\/en-us\/microsoft-cloud\/blog\/us-government\/2026\/03\/12\/itar-compliance-in-the-microsoft-cloud-navigating-gcc-azure-commercial-and-azure-government\/#primaryimage"},"image":{"@id":"https:\/\/cm-edgetun.pages.dev\/en-us\/microsoft-cloud\/blog\/us-government\/2026\/03\/12\/itar-compliance-in-the-microsoft-cloud-navigating-gcc-azure-commercial-and-azure-government\/#primaryimage"},"thumbnailUrl":"https:\/\/cm-edgetun.pages.dev\/en-us\/microsoft-cloud\/blog\/wp-content\/uploads\/2026\/03\/ITAR.jpg","datePublished":"2026-03-12T22:04:00+00:00","dateModified":"2026-08-20T21:27:23+00:00","breadcrumb":{"@id":"https:\/\/cm-edgetun.pages.dev\/en-us\/microsoft-cloud\/blog\/us-government\/2026\/03\/12\/itar-compliance-in-the-microsoft-cloud-navigating-gcc-azure-commercial-and-azure-government\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/cm-edgetun.pages.dev\/en-us\/microsoft-cloud\/blog\/us-government\/2026\/03\/12\/itar-compliance-in-the-microsoft-cloud-navigating-gcc-azure-commercial-and-azure-government\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/cm-edgetun.pages.dev\/en-us\/microsoft-cloud\/blog\/us-government\/2026\/03\/12\/itar-compliance-in-the-microsoft-cloud-navigating-gcc-azure-commercial-and-azure-government\/#primaryimage","url":"https:\/\/cm-edgetun.pages.dev\/en-us\/microsoft-cloud\/blog\/wp-content\/uploads\/2026\/03\/ITAR.jpg","contentUrl":"https:\/\/cm-edgetun.pages.dev\/en-us\/microsoft-cloud\/blog\/wp-content\/uploads\/2026\/03\/ITAR.jpg","width":866,"height":487,"caption":"ITAR compliance in the Microsoft Cloud."},{"@type":"BreadcrumbList","@id":"https:\/\/cm-edgetun.pages.dev\/en-us\/microsoft-cloud\/blog\/us-government\/2026\/03\/12\/itar-compliance-in-the-microsoft-cloud-navigating-gcc-azure-commercial-and-azure-government\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/cm-edgetun.pages.dev\/en-us\/microsoft-cloud\/blog\/"},{"@type":"ListItem","position":2,"name":"Industry Articles","item":"https:\/\/cm-edgetun.pages.dev\/en-us\/microsoft-cloud\/blog\/ms-industry\/"},{"@type":"ListItem","position":3,"name":"ITAR Compliance in the Microsoft Cloud: Navigating GCC, Azure Commercial, and Azure Government"}]},{"@type":"WebSite","@id":"https:\/\/cm-edgetun.pages.dev\/en-us\/microsoft-cloud\/blog\/#website","url":"https:\/\/cm-edgetun.pages.dev\/en-us\/microsoft-cloud\/blog\/","name":"The Microsoft Cloud Blog","description":"Build the future of your business with AI","publisher":{"@id":"https:\/\/cm-edgetun.pages.dev\/en-us\/microsoft-cloud\/blog\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/cm-edgetun.pages.dev\/en-us\/microsoft-cloud\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/cm-edgetun.pages.dev\/en-us\/microsoft-cloud\/blog\/#organization","name":"Microsoft Cloud Blog","url":"https:\/\/cm-edgetun.pages.dev\/en-us\/microsoft-cloud\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/cm-edgetun.pages.dev\/en-us\/microsoft-cloud\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/cm-edgetun.pages.dev\/en-us\/microsoft-cloud\/blog\/wp-content\/uploads\/2023\/10\/microsoft_logo.webp","contentUrl":"https:\/\/cm-edgetun.pages.dev\/en-us\/microsoft-cloud\/blog\/wp-content\/uploads\/2023\/10\/microsoft_logo.webp","width":400,"height":400,"caption":"Microsoft Cloud Blog"},"image":{"@id":"https:\/\/cm-edgetun.pages.dev\/en-us\/microsoft-cloud\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/MSCloud","https:\/\/www.linkedin.com\/showcase\/microsoft-cloud-platform\/","https:\/\/www.youtube.com\/@MicrosoftCloud"]}]}},"bloginabox_display_generated_audio":false,"_links":{"self":[{"href":"https:\/\/cm-edgetun.pages.dev\/en-us\/microsoft-cloud\/blog\/wp-json\/wp\/v2\/ms-industry\/125988","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cm-edgetun.pages.dev\/en-us\/microsoft-cloud\/blog\/wp-json\/wp\/v2\/ms-industry"}],"about":[{"href":"https:\/\/cm-edgetun.pages.dev\/en-us\/microsoft-cloud\/blog\/wp-json\/wp\/v2\/types\/ms-industry"}],"author":[{"embeddable":true,"href":"https:\/\/cm-edgetun.pages.dev\/en-us\/microsoft-cloud\/blog\/wp-json\/wp\/v2\/users\/57"}],"version-history":[{"count":3,"href":"https:\/\/cm-edgetun.pages.dev\/en-us\/microsoft-cloud\/blog\/wp-json\/wp\/v2\/ms-industry\/125988\/revisions"}],"predecessor-version":[{"id":127976,"href":"https:\/\/cm-edgetun.pages.dev\/en-us\/microsoft-cloud\/blog\/wp-json\/wp\/v2\/ms-industry\/125988\/revisions\/127976"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cm-edgetun.pages.dev\/en-us\/microsoft-cloud\/blog\/wp-json\/wp\/v2\/media\/127974"}],"wp:attachment":[{"href":"https:\/\/cm-edgetun.pages.dev\/en-us\/microsoft-cloud\/blog\/wp-json\/wp\/v2\/media?parent=125988"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cm-edgetun.pages.dev\/en-us\/microsoft-cloud\/blog\/wp-json\/wp\/v2\/categories?post=125988"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cm-edgetun.pages.dev\/en-us\/microsoft-cloud\/blog\/wp-json\/wp\/v2\/tags?post=125988"},{"taxonomy":"content-type","embeddable":true,"href":"https:\/\/cm-edgetun.pages.dev\/en-us\/microsoft-cloud\/blog\/wp-json\/wp\/v2\/content-type?post=125988"},{"taxonomy":"job-function","embeddable":true,"href":"https:\/\/cm-edgetun.pages.dev\/en-us\/microsoft-cloud\/blog\/wp-json\/wp\/v2\/job-function?post=125988"},{"taxonomy":"author","embeddable":true,"href":"https:\/\/cm-edgetun.pages.dev\/en-us\/microsoft-cloud\/blog\/wp-json\/wp\/v2\/coauthors?post=125988"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}