Skip to main content

Managing users in your secureframe provisioned Azure GCC High account

Adding, deleting, and managing user roles to maintain CMMC compliance

S
Written by Secureframe Engineering

How to add users with access to Controlled Unclassified Information (CUI)

In order to maintain CMMC compliance you should never directly assign roles to users, instead you should add users to the correct user group.

  1. Log into your azure government tenant: https://portal.azure.us/auth/login/

  2. Navigate to Microsoft Entra ID by searching on the top bar

  3. On the left pane click manage > Groups:

  4. Find the "CUI Users" group by searching

  5. On the left pane click Manage > Members > Add members to add a user with access to CUI.

How to add IT admin users (and super admin users) - these cannot have access to CUI

In order to maintain CMMC compliance IT admin users (and super admin users) should not have access to CUI.

  1. Log into your azure government tenant: https://portal.azure.us/auth/login/

  2. Navigate to Microsoft Entra ID by searching on the top bar

  3. On the left pane click manage > Groups:

  4. Find the "IT Admins" or "Super Admins" group by searching

  5. On the left pane click Manage > Members > Add members to add an IT admin/ Super Admin user. If this user is also in the CUI users group then secureframe tests will start to fail as this configuration is not CMMC compliant.

Did this answer your question?