Independent DIB implementation resource — not affiliated with or endorsed by the U.S. Department of WarView the official DoW campaign ↗
BRILLIANT AT THE BASICS · CLOUD SETUPAzure Government
GOV CLOUD

Key Settings One-Pager

The essential goal, the features that carry it, the mistake to avoid, and the proof to keep — for each of the ten Brilliant at the Basics requirements. A quick reference to pin up, not a substitute for the full step-by-step guide. Confirm every setting against Azure Government’s own documentation.

Where you work
Azure Government portal (portal.azure.us)
Content reviewed
2026-07-21
Controlled-data note

Azure Government, paired with GCC High identity, is a purpose-built home for CUI: FedRAMP High and DoD Impact Level 4/5, with data kept in the U.S. and screened U.S.-person operations.

01

Phishing-Resistant Multi-Factor Authentication

IT-013.5.3IA.L2-3.5.3

Make a stolen password useless on its own.

Configure in
Microsoft Entra ID for GovernmentConditional AccessFIDO2 security keysEntra Certificate-Based Authentication (CAC/PIV)
Don’t miss

Always exclude at least one emergency break-glass account from the policy so a misconfiguration never locks every admin out.

Evidence to keep

Screenshot of the Conditional Access policy showing Phishing-resistant MFA strength · Authentication methods registration report · Sign-in logs showing MFA method used

02

Least-Privilege Access Control

3.1.5AC.L2-3.1.5

Give each person only the access their job needs — and no more.

Configure in
Azure RBACMicrosoft Entra Privileged Identity Management (PIM)Entra ID for GovernmentCustom roles
Don’t miss

Avoid assigning roles to individual people; assign to Entra groups instead so access is easy to review and revoke.

Evidence to keep

Export of role assignments per subscription · PIM eligible-assignment and activation history report · List of custom role definitions

03

Asset & Account Inventory

IT-023.4.1CM.L2-3.4.1

Keep a live list of every device, identity, and app you defend.

Configure in
Azure Resource GraphMicrosoft Defender for CloudMicrosoft Entra ID DevicesAzure Resource Manager
Don’t miss

Tag every resource with an owner and data type when you create it, so your inventory stays meaningful instead of a wall of names.

Evidence to keep

Dated Azure Resource Graph export of all resources · Defender for Cloud inventory export · Entra All devices and All users lists

04

Logging, Monitoring & Audit

3.3.1AU.L2-3.3.1

Record important events and watch for trouble.

Configure in
Azure MonitorLog Analytics workspaceMicrosoft SentinelDiagnostic settings
Don’t miss

Do not forget to log the identity system itself; Entra ID sign-in and audit logs are the most valuable trail an investigator will ask for.

Evidence to keep

Diagnostic settings configuration for key resources · Sentinel data-connector and analytics-rule list · Log retention setting screenshot

05

Network Segmentation & Boundary Protection

IT-053.13.5SC.L2-3.13.5

Keep one compromised thing from reaching everything else.

Configure in
Azure Virtual Network (VNet)Network Security Groups (NSG)Azure FirewallAzure Private LinkHub-spoke topology
Don’t miss

Start every NSG from a deny-all mindset and open only what you can justify, rather than allowing broad ranges you plan to tighten later.

Evidence to keep

Network diagram of hub-spoke VNets · Exported NSG and Azure Firewall rule sets · List of private endpoints protecting data services

06

Vulnerability & Patch Management

IT-063.11.2RA.L2-3.11.2

Find weak spots and fix the risky ones first.

Configure in
Microsoft Defender for CloudDefender vulnerability assessmentAzure Update ManagerAzure Arc (for hybrid servers)
Don’t miss

Do not just patch Azure virtual machines; connect on-premises servers with Azure Arc so Update Manager and Defender cover them too.

Evidence to keep

Defender for Cloud vulnerability assessment report · Azure Update Manager compliance/patch history · Record of remediation timelines

07

Data Protection & Encryption

3.13.11SC.L2-3.13.11

Scramble sensitive data so only the right people can read it.

Configure in
Azure Key Vault (or Managed HSM)Customer-managed keys (CMK)Azure Storage / Disk encryptionTLS 1.2+
Don’t miss

Turn on soft-delete and purge protection for Key Vault first; losing a key with no recovery can lock you out of your own encrypted data forever.

Evidence to keep

Key Vault configuration showing purge protection and rotation policy · Storage/disk settings showing customer-managed key encryption · Proof TLS 1.2+ is enforced

08

Backup & Recovery

IT-093.8.9MP.L2-3.8.9

Be able to restore your data after an attack or outage.

Configure in
Azure BackupRecovery Services vaultGeo-redundant storage (GRS)Azure Business Continuity Center
Don’t miss

A backup you have never restored is only a hope; schedule regular restore tests so you know recovery truly works before a real emergency.

Evidence to keep

Backup policy showing frequency and retention · Recovery Services vault redundancy and immutability settings · Successful test-restore report

09

Secure Configuration Baseline

3.4.2CM.L2-3.4.2

Start every service from a known-good, hardened setting.

Configure in
Microsoft Defender for Cloud (Secure Score)Azure PolicyRegulatory compliance dashboardAzure Blueprints / built-in initiatives
Don’t miss

Use Deny policies for your most critical rules, not just Audit, so risky resources are blocked at creation instead of found later.

Evidence to keep

Defender for Cloud secure score over time · Regulatory compliance dashboard export for NIST 800-171 / CMMC · Azure Policy assignments and compliance results

10

Secure AI Adoption & Data Loss Prevention

IT-083.1.3AC.L2-3.1.3

Use AI and share files without leaking sensitive information.

Configure in
Azure OpenAI in Azure Government (Microsoft Foundry)Microsoft Purview Data Loss PreventionMicrosoft Purview sensitivity labelsMicrosoft Purview DSPM for AI
Don’t miss

Turn off or approve-only the abuse-monitoring human review for Azure OpenAI when handling CUI, and never let staff use commercial public AI chatbots for controlled data.

Evidence to keep

Azure OpenAI deployment showing US Gov region and private networking · Purview DLP policy definitions and match reports · DSPM for AI activity showing sensitive-data interactions

This one-pager is independent education from the Brilliant at the Basics Resource Center, published by inDirectIT. It is a condensed reference — the full guide has the click-by-click steps. It does not by itself establish compliance, satisfy a contract clause, or confer CMMC certification. Cloud consoles change often — verify each setting against the provider’s documentation. The official DoW campaign remains authoritative: https://dowcio.war.gov/BrilliantBasics/