How to add users with access to Controlled Unclassified Information (CUI)
To maintain CMMC compliance, do not assign roles to users directly. Add users to the correct user group instead.
Log into your Azure Government tenant: https://portal.azure.us/auth/login/
Navigate to Microsoft Entra ID by searching on the top bar.
On the left pane, click Manage > Groups:
Find the CUI Users group by searching:
On the left pane, click Manage > Members > Add members to add a user with access to CUI.
How to add IT admin and Super Admin users
IT Admins and Super Admins should not have access to CUI. Keep those accounts out of the CUI Users group.
Log into your Azure Government tenant: https://portal.azure.us/auth/login/
Navigate to Microsoft Entra ID by searching on the top bar.
On the left pane, click Manage > Groups:
Find the IT Admins or Super Admins group by searching.
On the left pane, click Manage > Members > Add members to add the IT Admin or Super Admin user.
Note: Whenever you add a user to any of these groups, also add them to the Defense Trust Boundary administrative unit: in Microsoft Entra ID, go to Manage > Admin units > Defense Trust Boundary > Users > Add member. IT Admins' user-management roles are scoped to this administrative unit, so users outside it cannot be managed by your IT Admins.
Important: If an IT Admin or Super Admin is also in the CUI Users group, Secureframe tests will fail because that configuration is not CMMC compliant.



