Organizations running Microsoft 365 in Government Community Cloud (GCC) High have made a deliberate trade-off. They've accepted the cost and operational overhead of a sovereign, high-security cloud because their mission (including defense contracts and other federal regulatory requirements) demands it.
That's a serious commitment that deserves a recovery story that matches the responsibility government IT owes the citizenry.
Today, Rubrik Security Cloud - Government (RSC-G) expands that story. RSC-G now supports Microsoft 365 GCC High workloads (specifically SharePoint, OneDrive, and Exchange) where a customer’s data is classified as Moderate impact or lower, along with Identity Recovery for Entra ID GCC High. Rubrik is also announcing Autonomous Business Recovery (ABR) for Microsoft 365, a new approach to recovering at scale when native tools alone can't keep pace.
Why Compliant Isn't the Same as Resilient
GCC High was purpose-built for federal agencies and defense contractors handling Controlled Unclassified Information (CUI) and other federal data subject to heightened compliance requirements. The platform restricts data storage and administrative access to screened U.S. personnel, keeps the environment isolated from commercial Microsoft infrastructure, and meets a higher federal authorization standard than commercial or standard GCC tenants.
But that isolation addresses a different problem than recovery does.
Microsoft's Shared Responsibility Model draws the line clearly: Microsoft secures the infrastructure, while your organization owns the data inside it. In practice, native retention tools in GCC High are built for governance and compliance, not cyber recovery. Exchange Online keeps deleted items for 30 days. OneDrive and SharePoint hold 93 days. Deleted accounts are gone for good after 30 days. Microsoft's best-effort restoration for enterprise outages reaches back only 14 days, with no guaranteed recovery time objective.
Modern attacks routinely outlast those windows. Identity remains the most heavily targeted layer of Microsoft's ecosystem: Microsoft has reported more than 600 million identity attacks against its infrastructure every single day, the large majority of them password-based. By the time an incident is discovered, the clean restore point an organization needs may already have rolled off the retention window entirely.
GCC High environments require a backup copy that's isolated from the production environment and immutable, with flexible retention and point-in-time recovery. That way, the recovery data can't be altered, encrypted, or deleted once written, even if an attacker gains administrative access to the live tenant. It's the difference between an incident you manage and one that jeopardizes your mission or business.
Identity is the Keystone (and the Hardest Thing to Rebuild)
For any M365 environment, Entra ID controls who can access what. Every user, every group, every role assignment, every conditional access policy and application permission lives there. When Entra ID is compromised or corrupted, the damage cascades across everything downstream and rebuilding it without purpose-built tooling is slow. Restoring even a modest number of users through native, manual methods can take days—and a more complex corruption that touches conditional access policies, app registrations, and group-based access controls can stretch recovery into weeks.
In a GCC High environment, that timeline isn't just an operational headache. It's a continuity risk for the mission-critical work the environment was built to support. An extended identity outage doesn't pause contract deliverables or operational commitments while you recover.
This is why Rubrik's Identity Recovery now extends natively to Entra ID GCC High, restoring the full identity context, not just user objects: users, groups, roles, conditional access policies, and application integrations. In hybrid environments, it also automatically re-stitches the relationship mapping between on-premises Active Directory and Entra ID, so services and applications come back aligned instead of requiring manual reconfiguration.
Solving the Scale Problem: Autonomous Business Recovery
Even with a clean backup, restoring an entire M365 tenant one user at a time is slow. Native, sequential restoration doesn't scale, and recovery times balloon as the number of affected users grows.
Autonomous Business Recovery (ABR) is built for that scale problem. Rather than restoring users in an arbitrary or sequential order, ABR identifies the users and data that make up your minimum viable business—a critical subset your organization needs to stay operational—and prioritizes their restoration first. Critical users are back online in minutes, while full restoration continues in the background. It's a shift from "restore everything and hope it's fast enough" to "restore what matters most first, by design."
Together with threat monitoring that flags anomalous behavior and indicators of compromise inside backup data, ABR helps ensure that when you do recover, you're recovering from a known good state, not reintroducing the very foothold you're trying to eliminate.
Why This Update Matters (and What it Doesn't Mean)
It's worth being precise about what's changing and why, because platform authorization and data impact level are easy to conflate. RSC-G is authorized at FedRAMP Moderate. Microsoft's GCC High is authorized at FedRAMP High. Previously, that gap led to guidance discouraging customers from connecting RSC-G to M365 GCC High at all.
The updated position: RSC-G now supports protecting M365 GCC High workloads (SharePoint, OneDrive, and Exchange) where the customer's data itself is categorized at Moderate impact or lower, per the FIPS 199 standard for classifying information sensitivity.
For many federal organizations, GCC High is a business requirement. Their workloads live in a high-authorization environment because their mission, contracts, or agency standards demand it, not because their data is classified at High impact. RSC-G now supports those customers on their terms. Previously, those customers were blocked from using RSC-G simply because of the platform they sat on, regardless of their actual data sensitivity. This update removes that blocker and aligns Microsoft 365 GCC High with how Rubrik has long treated other high-security clouds, like AWS GovCloud and Azure Government.
The distinction that makes this work is between the underlying infrastructure and the service layer. GCC High is a platform authorization; it describes the security level of Microsoft's infrastructure, not the impact level of a customer's data. RSC-G runs on that high-authorization infrastructure, but the RSC-G service itself is authorized at FedRAMP Moderate.
Running on a FedRAMP High platform doesn't change that. As with any RSC-G deployment, customers remain responsible for ensuring the data they protect through the service is properly classified at Moderate impact or lower.
For organizations whose data must be categorized as High impact, or whose compliance obligations require FedRAMP High protection across the entire data lifecycle, Rubrik Security Cloud – Private (RSC-P) remains the recommended path, giving customers full control over data residency within their own accredited environment.
Bringing it Together
The decision to operate in GCC High reflects a genuine commitment to security and compliance. That same commitment is exactly why the consequences of extended downtime or data loss are more severe there than almost anywhere else. Native retention windows and best-effort restoration weren't built to answer that risk. Increasingly, neither are the audits and assessments these organizations face. Federal organizations are expected to demonstrate more than the existence of backups; they need to show a tested, credible recovery posture with defined recovery time objectives.
With RSC-G now supporting M365 GCC High, Identity Recovery extended to Entra ID GCC High, and Autonomous Business Recovery addressing recovery at scale, Rubrik is closing the gap between a compliant environment and a resilient one, natively, within the boundary these organizations have already committed to.
Learn more about https://www.rubrik.com/solutions/microsoft-365