The short answer
Microsoft AI governance for a CMMC manufacturer runs on controls the plant already owns. Microsoft Entra ID decides who an agent acts for, Microsoft Purview decides what it can read and what gets logged, Microsoft Defender for Cloud scores the environment against the CMMC Level 2 v2.0 standard, and the cloud environment you sit in sets the outer boundary for controlled unclassified information. Microsoft publishes more than 100 compliance offerings across its global and U.S. government clouds, including FedRAMP High authorized services (Microsoft Learn, accessed 2026-09-01).
An assessor doesn't ask whether Copilot is secure. The question is which control kept a CUI traveler out of a prompt, and where that decision was written down. Defense subcontractors running Plex or Epicor on the shop floor already carry that burden for the ERP. AI puts a new surface in front of the same paperwork.
For a CIO or VP of IT at an AS9100 shop with DoD work in the mix, the pressure runs both directions at once. The plant wants Copilot summarizing shift reports and drafting work order notes. Contracts wants proof that nothing under DFARS ever reached a model. Those are the same decision taken twice, once in the identity layer and once in the data layer. Neither one is a new purchase. CMMC practices map onto controls a Microsoft tenant already licenses, and Microsoft publishes the mapping itself.
Microsoft controls and the CMMC practice families they support
Microsoft does the per-practice mapping in two artifacts: the Product Placemat for CMMC, a dashboard laid out like a periodic table of practice families, and the Technical Reference Guide for CMMC, which carries implementation statements per service (Microsoft Learn, accessed 2026-09-01). Below is the short version, scoped to what changes once AI is in the tenant.
| Microsoft control | What it does once AI is in scope | CMMC practice families it supports |
|---|---|---|
| Entra ID (Conditional Access, MFA, PIM, access reviews) | Copilot honors Conditional Access and MFA; grounding stays scoped to the signed-in user | Access Control; Identification and Authentication |
| Purview sensitivity labels and encryption | Labeled content requires the EXTRACT usage right alongside VIEW before an AI app returns it | Access Control; Media Protection |
| Purview DSPM for AI | Discovers AI apps and agents; runs oversharing risk assessments | Risk Assessment; Security Assessment |
| Purview Audit and Activity explorer | Captures prompts and responses in the unified audit log | Audit and Accountability |
| Purview DLP for the Copilot location | Stops labeled items from being summarized by Copilot and agents | Media Protection; System and Communications Protection |
| Purview Compliance Manager | Assessment templates, owned improvement actions, exportable evidence | Security Assessment |
| Defender for Cloud | Carries CMMC Level 2 v2.0 as an assignable standard, assessed per control | Security Assessment; Configuration Management; System and Information Integrity |
| Sentinel CMMC 2.0 solution | Workbook, analytics rules over Defender mappings, playbooks | Audit and Accountability; Incident Response |
| Azure Policy NIST SP 800-171 initiatives | Enforces and reports configuration state across both Azure clouds | Configuration Management |
| Microsoft 365 GCC High and Azure Government | Set the isolation boundary for CUI and ITAR regulated data | System and Communications Protection |
| Microsoft Foundry in Azure Government | Agent identity through Entra, private networking, RBAC, content safety | Access Control; System and Communications Protection |
Coverage is shared on most of these. The placemat separates practices inherited from the platform from practices where your own configuration finishes the job.
What does CMMC ask of an AI tool?
CMMC asks nothing about AI by name. It assesses how a contractor implements practices drawn from NIST SP 800-171 across families like Access Control and Audit and Accountability. An AI tool lands in scope because it reads and returns the same controlled unclassified information those practices already govern (Microsoft Learn, accessed 2026-09-01).
CMMC is a Department of Defense unified standard with three certification levels, assessed through formal third-party audits run by CMMC third-party assessor organizations accredited by the Cyber AB. It expands DFARS 252.204-7012 by adding that audit and certification requirement, and it draws its practices from NIST SP 800-171, the guidance for protecting CUI in nonfederal systems. Prime contractors validate subcontractor compliance before award, which is why a second-tier machining shop feels the same pressure a prime does.
One structural point matters for anyone evaluating a cloud AI tool. CMMC does not certify cloud platforms. A contractor delivering a cloud-based solution has to confirm the underlying platform holds at least FedRAMP Moderate authorization. Azure and Azure Government both hold a FedRAMP High provisional authorization to operate issued by the FedRAMP Joint Authorization Board, and an accredited third-party assessment organization has attested that both meet the applicable requirements of DFARS 252.204-7012. Microsoft's documentation states plainly that CMMC requirements are subject to change while the framework is finalized, so treat any level mapping as a point-in-time read and re-check it at contract renewal.
The practical consequence for an AI rollout is that scope follows the data, never the product name. A Copilot deployment that only touches marketing collateral sits outside the CUI boundary. Point that same deployment at a SharePoint library of drawings marked under DFARS and it lands inside. Deciding which one you're building is the first governance act.
Where can CUI flow once Copilot is turned on?
Copilot returns only what the signed-in user already has rights to see. Microsoft Entra authorizes the request, the semantic index honors the same identity-based access boundary during grounding, and Purview adds a second gate: when a sensitivity label applies encryption, the user needs the EXTRACT usage right alongside VIEW before an AI app returns that content.
The exposure most manufacturers underestimate is the permission state that already exists, because Copilot inherits it. A SharePoint site with no valid owner, a drawing library shared broadly during a launch, an inherited folder of supplier quality records: none of that changes when Copilot arrives, but all of it becomes reachable through natural language instead of a search box. Purview's data risk assessments in DSPM for AI exist for this, running a default weekly assessment that identifies and helps fix oversharing before it shows up in a response.
Logging closes the loop. Prompts and responses are captured in the unified audit log, including references to the files accessed and the sensitivity labels applied to them, and they surface in Activity explorer under the AI activities tab. Data loss prevention for the Copilot location prevents labeled items from being summarized by Copilot and agents, and Insider Risk Management carries a Risky AI usage policy template for detecting risky prompts and responses. Worth noting for regulated tenants: Insider Risk Management isn't currently available in GCC High (Microsoft Learn, accessed 2026-09-01).
Sensitivity labels have to be enabled for SharePoint and OneDrive for any of this to hold at rest. Without that, the encrypted files Copilot and agents can honor are limited to data in use inside Office apps on Windows, which is a much narrower guarantee than most compliance teams assume they are getting.
Does an ITAR manufacturer need GCC High for Copilot?
Microsoft's guidance routes ITAR and DFARS regulated CUI to GCC High. GCC suits organizations needing U.S. data residency that don't handle ITAR, DFARS regulated CUI or DoD mission data. Microsoft 365 GCC High supports CMMC Level 2 and Level 3 requirements when configured appropriately, plus FedRAMP High, DFARS, DISA Impact Level 4 and ITAR.
Eligibility is a gate before it's an architecture. A commercial entity holding ITAR data, CUI or DoD Impact Level data qualifies for the Microsoft Government Cloud through a validation process, and proof of membership is required before access. That validation timeline belongs on the project plan next to tenant design, because it gates everything downstream.
Copilot itself is available across all three U.S. government environments, and prompts, responses and generated content remain inside the customer's government cloud tenant. Feature parity is where the planning happens. Web grounding isn't enabled by default in government clouds. GCC High currently supports declarative agents created with Agent Builder and those published through admin controls. Microsoft 365 Copilot connectors, including external and partner connections, aren't enabled by default for government clouds. Release timing generally trails commercial.
On the infrastructure side, Azure Government supports FedRAMP High, DFARS 7012, DoD CC SRG Impact Level 4 and 5, ITAR and EAR. It adds contractual commitments on U.S. data storage, plus limits on access to systems processing customer data to screened U.S. persons (Microsoft Learn, accessed 2026-09-01). For an exporter under ITAR, that screening commitment is often the clause that settles the environment debate, because it speaks to the deemed-export question a commercial tenant leaves open.
How do you keep a Foundry agent inside the boundary?
Microsoft Foundry runs in Azure Government from US Gov Virginia and US Gov Arizona. Agent identity through Microsoft Entra, private networking with virtual network integration, role-based access control, Network Security Perimeter and content safety guardrails are all listed as available in that environment (Microsoft Learn, accessed 2026-09-01).
Network isolation is where a custom agent stops being a governance question and becomes a build spec. You disable public access on the Foundry resource, add an inbound private endpoint on the virtual network, then set virtual network injection against a subnet delegated to Microsoft.App/environments sized /27 or larger. Private endpoints for Azure Storage, Azure AI Search and Azure Cosmos DB aren't created automatically, so each one is a separate deliberate step. Egress runs through a firewall, commonly in a hub-and-spoke topology with a shared firewall virtual network peered to the Foundry spoke.
Tool selection carries its own boundary decision. Code Interpreter and Function Calling keep traffic on Microsoft's backbone network with no extra configuration. Bing, Websearch and SharePoint tools communicate over public endpoints, and Microsoft documents blocking them with Azure policies where that's unacceptable. Purview covers Foundry as well, so prompts and responses from applications built on Foundry can be captured for regulatory compliance. That combination is what lets a plant-floor agent read a work order queue without widening the CUI boundary. Two operational notes save rework later. Hosted agents run in a fixed set of regions, so the virtual network, container registry and Foundry account belong in or peered to one of them. And private DNS resolution is the most common failure mode, worth verifying end to end before anyone blames role assignments.
What will a C3PAO assessor ask about AI?
An assessment evaluates technical security controls, documentation, policies and processes. For an AI tool that resolves to four things: the access decision, the label state of the data it reads, the audit record of prompts and responses, and the configuration standard the environment is continuously scored against.
Defender for Cloud gives you the last of those directly. Cybersecurity Maturity Model Certification (CMMC) Level 2 v2.0 is an assignable regulatory compliance standard across Azure, AWS and GCP. Once assigned, the regulatory compliance dashboard shows each control with its assessments, splits work into Your Actions and Microsoft Actions, supports manual attestation with linked evidence for controls that can't be assessed automatically, and produces downloadable audit reports. Assessments run roughly every 12 hours.
That data doesn't stay siloed. Compliance data from Defender for Cloud surfaces automatically in Microsoft Purview Compliance Manager for the same standard. Compliance Manager provides over 360 regulatory templates, assigns improvement actions to named owners for implementation and testing, stores evidence against each action, and exports an assessment snapshot to Excel for external auditors and regulators. The platform generates that artifact.
Between assessments, the Microsoft Sentinel CMMC 2.0 solution watches drift with a workbook over Azure Policy, Azure Resource Graph and Azure Monitor Log Analytics, analytics rules built on Defender compliance mappings, and playbooks that notify teams by email and Teams chat. The default rule alerts when policy compliance falls below 70 percent within one week. Underneath it, Azure Policy ships NIST SP 800-171 built-in initiatives for both Azure and Azure Government, though Microsoft is clear that policy compliance is a partial view of overall status (Microsoft Learn, accessed 2026-09-01).
The governance baseline, in build order
ArchitectNow puts a governance baseline in before any agent touches production data, and the order matters more than the tooling. First the boundary decision: commercial, GCC or GCC High, taken against Microsoft's published criteria and the actual contract language, with eligibility validation started early. Second the permission state, fixing oversharing with a Purview data risk assessment while the tenant is still quiet. Third labeling, published and enabled for SharePoint and OneDrive. Fourth the audit path, capturing prompts and responses before the first pilot user signs in. Fifth the standard, assigning CMMC Level 2 v2.0 in Defender for Cloud and opening the matching Compliance Manager assessment. Sixth, and only then, the agent, with its own Entra identity, scoped RBAC, private networking and a written statement of which data it reads.
Each step produces the evidence the next one depends on, and an assessor can walk it in that order.
ArchitectNow designs and delivers AI, data, and cloud solutions on the Microsoft stack. The AI Readiness Assessment scores this baseline as part of its Foundation layer (platform, data, governance) and names the right next step.
Sources and references
- Microsoft and the Cybersecurity Maturity Model Certification (CMMC), Microsoft Learn, accessed 2026-09-01. https://learn.microsoft.com/compliance/us-government/gov-cmmc
- CMMC, Azure compliance offerings, accessed 2026-09-01. https://learn.microsoft.com/azure/compliance/offerings/offering-cmmc
- U.S. government cloud environments for Microsoft 365 and Copilot, accessed 2026-09-01. https://learn.microsoft.com/microsoft-365/copilot/gov-overview
- Microsoft Copilot service description, accessed 2026-09-01. https://learn.microsoft.com/office365/servicedescriptions/office-365-platform-service-description/microsoft-365-copilot
- Microsoft 365 Government, how to buy, accessed 2026-09-01. https://learn.microsoft.com/office365/servicedescriptions/office-365-platform-service-description/office-365-us-government/microsoft-365-government-how-to-buy
- International Traffic in Arms Regulations (ITAR), accessed 2026-09-01. https://learn.microsoft.com/compliance/regulatory/offering-itar
- Purview data security for Microsoft 365 Copilot, accessed 2026-09-01. https://learn.microsoft.com/purview/ai-m365-copilot
- Data Security Posture Management for AI, accessed 2026-09-01. https://learn.microsoft.com/purview/dspm-for-ai
- Purview data security for Microsoft Foundry, accessed 2026-09-01. https://learn.microsoft.com/purview/ai-azure-foundry
- Data, Privacy, and Security for Microsoft Copilot, accessed 2026-09-01. https://learn.microsoft.com/microsoft-365/copilot/microsoft-365-copilot-privacy
- Microsoft Copilot architecture and how it works, accessed 2026-09-01. https://learn.microsoft.com/microsoft-365/copilot/microsoft-365-copilot-architecture
- Require device compliance with Conditional Access, accessed 2026-09-01. https://learn.microsoft.com/entra/identity/conditional-access/policy-all-users-device-compliance
- Apply principles of Zero Trust to Microsoft 365 Copilot, accessed 2026-09-01. https://learn.microsoft.com/security/zero-trust/copilots/zero-trust-microsoft-365-copilot
- Regulatory compliance standards in Defender for Cloud, accessed 2026-09-01. https://learn.microsoft.com/azure/defender-for-cloud/concept-regulatory-compliance-standards
- Improve regulatory compliance, Defender for Cloud, accessed 2026-09-01. https://learn.microsoft.com/azure/defender-for-cloud/regulatory-compliance-dashboard
- Microsoft Purview Compliance Manager, accessed 2026-09-01. https://learn.microsoft.com/purview/compliance-manager
- Microsoft Foundry in Azure Government, accessed 2026-09-01. https://learn.microsoft.com/azure/foundry/concepts/foundry-azure-government
- How to configure network isolation for Microsoft Foundry, accessed 2026-09-01. https://learn.microsoft.com/azure/foundry/how-to/configure-private-link