Skip to main content

FAQs: GCC High troubleshooting

S
Written by Secureframe Engineering

File access and sharing

After Secureframe sets up and configures your Microsoft GCC High tenant, some changes can affect how users sign in, share files, or send mail. This guide covers the most common questions and where to check.

Why can't CUI users access the CUI Shared Drive or OneDrive right after setup?

  • Microsoft provisions the SharePoint document library in the background after the site is created. On GCC High this can take anywhere from about 15 minutes to 48 hours, with no guaranteed time, so the drive may look empty or missing at first. Check back later. If it still is not accessible, confirm the affected person is a member of the CUI Users group, since access to the CUI Shared Drive follows that group's membership.

Users can no longer share files externally, or external links stopped working. Why?

  • Secureframe locks down external sharing on CUI SharePoint site(s), not as a blanket tenant-wide sharing change.

  • External sharing is restricted to existing guests only, sharing links default to specific people with view-only access, allowed domains are locked down, external links expire after 30 days, and downloads/sync from unmanaged devices are blocked.

  • Re-share within those limits, or add the recipient as a guest first. If non-CUI sites behave differently than you expect, check the site-level sharing settings for your CUI site(s).


Conditional Access and MFA

Most Conditional Access policies start in report-only mode so you can validate impact before enforcing them.

I enabled the Require Compliant Device policy and now CUI users are locked out. Why?

  • That policy requires each device to be marked compliant by a mobile device management (MDM) solution such as Microsoft Intune. Until your MDM is enrolled and reporting device compliance, turning this policy on will block CUI users. Set up device compliance first, confirm devices are reporting as compliant, and then enable the policy.

MFA and the other security policies don't seem to be enforced. Is that expected?

  • Yes. Conditional Access policies are created in report-only mode so no one is locked out during rollout. They log what would happen without actually enforcing it. Review the report-only results in the Microsoft Entra admin center, then switch each policy to On when you are ready.

How do I check whether a Conditional Access policy is safe to turn on?

  • In the Microsoft Entra admin center, go to IdentityMonitoringSign-in logs, filter by Conditional Access and the policy name, and review the report-only results. Once the results look clean for your tenant, switch the policy to On.

Why aren't our Super Admins prompted for MFA or subject to the policies?

  • This is by design. Super Admins are excluded from the Conditional Access policies so these break-glass accounts remain accessible if your sign-in infrastructure is ever degraded. Keep Super Admin accounts few in number and tightly controlled.


Email and clients

Email and mailbox settings are tightened to keep CUI inside your boundary and block weak protocols.

Older email clients or devices stopped connecting. What changed?

  • Once enabled, the Block Legacy Authentication policy blocks legacy protocols such as Exchange ActiveSync and SMTP AUTH that cannot satisfy modern MFA. We also disable POP and IMAP on the default mailbox plan and disable SMTP client authentication tenant-wide. Move affected clients to modern authentication, and if a specific service account genuinely needs SMTP AUTH, re-enable it only for that account.

Auto-forwarding or mailbox forwarding to external addresses stopped working. Why?

  • This is intentional. To protect CUI, we add mail-flow rules that block external auto-forwarding and external mailbox forwarding, and we disable auto-forwarding on the default remote domain. If a specific business case requires external forwarding, handle it through a reviewed exception rather than re-enabling forwarding broadly.

Legitimate email is landing in quarantine. What should we do?

  • Our anti-spam, anti-phishing, and anti-malware policies are intentionally strict (high-confidence spam is quarantined, about 50 executable/script attachment types are blocked, and zero-hour auto-purge is on). An admin can review and release messages from the Microsoft Defender portal and, where appropriate, refine the policies.


Admins and permissions

Admin roles are assigned through groups scoped to the Defense Trust Boundary.

Setup reported a licensing issue, or some policies didn't apply. What now?

  • The risk-based Identity Protection policies require Microsoft Entra ID P2 (Entra ID P1 is not sufficient). Add Entra ID P2 to your tenant and contact your Customer Success Manager to re-run setup.

My IT Admins can't perform some user-management actions. Why?

  • IT Admins are granted the custom GCC High IT Admin role plus User Administrator, scoped to the Defense Trust Boundary. If an admin sees a permissions error, confirm they are a member of the IT Admins group. The roles are assigned to the group, not to individuals.

Why did the AC-85-10 (break-glass / Super Admin) test start failing when we didn't change anything?

  • Secureframe now fails AC-85-10 when a Global Administrator exists outside the Super Admins group. The check used to look only at members inside that group.

  • Global Administrator should be held through the Super Admins group (break-glass), not as a standing role on individual users.

  • The Secureframe-maintained setup account (for example secureframe@... or secureframe-setup@..., including .onmicrosoft.us variants) is excepted and should not cause a fail by itself.

  • To remediate: in Microsoft Entra ID (Azure Government), review users with the Global Administrator role. Move customer break-glass admins into the Super Admins group, and remove direct Global Administrator assignments from anyone who should not hold standing privilege. Then sync the connection again in Secureframe.


Defender and security portal

If Microsoft Defender for Endpoint is not provisioned in your GCC High tenant, Secureframe may flag the portal as not set up. Use the steps below to finish provisioning, then sync again.

Microsoft Defender / security.microsoft.us isn't set up, or Secureframe says the Defender portal isn't provisioned. What should we do?

  • Sign in to https://security.microsoft.us with an eligible Microsoft admin account and wait for the portal to finish loading.

  • In Microsoft Defender, go to Endpoints > Configuration Management.

  • If you see Dashboard, open it, select View all devices, and wait for the setup screen to complete. If you see Devices, open it instead. Setup can take several minutes on a new tenant.

  • Return to Secureframe and sync the Microsoft Entra ID connection again.

  • On some unprovisioned tenants, you may only see Dashboard and Endpoint security policies under Configuration Management. In that case, use Dashboard > View all devices.


Teams and apps

Teams meeting and app policies limit unmanaged collaboration paths.

Teams meeting attendees are stuck in the lobby, or external guests can't join. Why?

  • The Teams meeting policy auto-admits only people in your organization, prevents anonymous users from starting or joining, and prevents PSTN callers from bypassing the lobby. Organizers can admit waiting participants from the lobby. Cloud recording is also turned off by policy.

Users can't install Teams apps, create SharePoint sites, or use certain integrations. Why?

  • To limit unmanaged data paths, Teams apps are restricted to an approved list with sideloading disabled, third-party file services (Dropbox, Box, Google Drive, ShareFile, Egnyte) and email-into-channel are blocked, and self-service SharePoint site creation is disabled tenant-wide. Have an admin provision sites or approve apps as needed.


Tests and results

Some GCC High tests change behavior over time. Results can move after a Secureframe update even when you did not change anything in Microsoft.

Why did some GCC High test results change when we didn't change anything in Microsoft?

  • Secureframe updated several GCC High tests and remediation steps so they better match what the checks evaluate today.

  • AC-85-4 and AC-85-6 now have clearer remediation guidance. If a test still fails, open it, follow the current steps, then sync.

  • For AC-85-6 on configure-only connections, the test can auto-pass after configuration runs.

  • IA-02-1 now accepts the device-join method used by v2 / AADDS enclave customers, so those environments can pass after the next evaluation.

  • AC-85-7 now checks idle session timeout only. A result shift here can follow that scope change, not a config change on your side.

  • AU-03-2 is now an automated, license-aware test instead of an upload. If you previously uploaded evidence for this test, expect the automated result to replace that path.

  • AC-85-23 (max session enforcement) is a new test and may appear as a new open item.

  • User Identifier Management no longer false-fails on Secureframe enclave service accounts. If that test was failing only for those accounts, it should clear after the next sync.

  • Sync the Microsoft / GCC High connection again after reviewing. If a result still looks unexpected, contact support with the test key and a screenshot.

Did this answer your question?