https://www.propublica.org/article/microsoft-cloud-fedramp-cybersecurity-government
ProPublica Journalism for the people, not for profit.
DONATE
Skip to content
Menu
Donate
Close
Donate
Search ProPublica:
[ ] Search
Topics
* Racial Justice
* Health Care
* Politics
* Criminal Justice
* more...
Browse by Place
* Midwest
* Northwest
* South
* Southwest
* Texas
Type
* Graphics & Data
* Newsletters
* Series
* Videos
* Local Reporting Network
* Electionland
Info
* About Us
* Impact
* Jobs & Fellowships
* Contact Us
Follow ProPublica
* Bluesky
* Instagram
* Facebook
* (Twitter)
* YouTube
* Threads
* LinkedIn
* RSS
Red, menacing cursors surround a U.S. flag that has the Microsoft
logo instead of a blue square with stars. The Microsoft logo is
partly open, revealing a black hole that the cursors are streaming
into. Illustration by Shoshana Gordon/ProPublica
Technology
Federal Cyber Experts Thought Microsoft's Cloud Was "a Pile of Shit."
They Approved It Anyway.
by Renee Dudley, with research by Doris Burke
March 18, 2026, 6:00 am
Share
Change Appearance Change Appearance [Auto ]
Republish
Republish This Story for Free
Creative Commons License (CC BY-NC-ND 3.0)
---------------------------------------------------------------------
Thank you for your interest in republishing this story. You are free
to republish it so long as you do the following:
* You have to credit ProPublica and any co-reporting partners. In
the byline, we prefer "Author Name, Publication(s)." At the top
of the text of your story, include a line that reads: "This story
was originally published by ProPublica." You must link the word
"ProPublica" to the original URL of the story.
* If you're republishing online, you must link to the URL of this
story on propublica.org, include all of the links from our story,
including our newsletter sign up language and link, and use our
PixelPing tag.
* If you use canonical metadata, please use the ProPublica URL. For
more information about canonical metadata, refer to this Google
SEO link.
* You can't edit our material, except to reflect relative changes
in time, location and editorial style. (For example, "yesterday"
can be changed to "last week," and "Portland, Ore." to "Portland"
or "here.")
* You cannot republish our photographs or illustrations without
specific permission. Please contact [email protected].
* It's okay to put our stories on pages with ads, but not ads
specifically sold against our stories. You can't state or imply
that donations to your organization support ProPublica's work.
* You can't sell our material separately or syndicate it. This
includes publishing or syndicating our work on platforms or apps
such as Apple News, Google News, etc.
* You can't republish our material wholesale, or automatically; you
need to select stories to be republished individually. (To
inquire about syndication or licensing opportunities, contact
[email protected].)
* You can't use our work to populate a website designed to improve
rankings on search engines or solely to gain revenue from
network-based advertisements.
* We do not generally permit translation of our stories into
another language.
* Any website our stories appear on must include a prominent and
effective way to contact you.
HTML [
Federal Cyber Ex] Copy HTML
[20240416-KAHN-Tech-Project-0189_maxWidth_]
Series: Zero Trust: Inside Microsoft's Cybersecurity Failures
More in this series
ProPublica is a nonprofit newsroom that investigates abuses of power.
Sign up to receive our biggest stories as soon as they're published.
Reporting Highlights
* "Cloud First": To move federal agencies to the cloud, the
government created a program known as FedRAMP, whose job was to
ensure the security of new technology.
* Security Breakdown: ProPublica found that FedRAMP authorized a
Microsoft product called GCC High to handle sensitive government
data, despite years of concerns about its security.
* Potential Conflict of Interest: The government relies, in part,
on third-party firms to vet cloud technology, but those firms are
hired and paid by the company being assessed.
These highlights were written by the reporters and editors who worked
on this story.
In late 2024, the federal government's cybersecurity evaluators
rendered a troubling verdict on one of Microsoft's biggest cloud
computing offerings.
The tech giant's "lack of proper detailed security documentation"
left reviewers with a "lack of confidence in assessing the system's
overall security posture," according to an internal government report
reviewed by ProPublica.
Or, as one member of the team put it: "The package is a pile of
shit."
For years, reviewers said, Microsoft had tried and failed to fully
explain how it protects sensitive information in the cloud as it hops
from server to server across the digital terrain. Given that and
other unknowns, government experts couldn't vouch for the
technology's security.
Such judgments would be damning for any company seeking to sell its
wares to the U.S. government, but it should have been particularly
devastating for Microsoft. The tech giant's products had been at the
heart of two major cybersecurity attacks against the U.S. in three
years. In one, Russian hackers exploited a weakness to steal
sensitive data from a number of federal agencies, including the
National Nuclear Security Administration. In the other, Chinese
hackers infiltrated the email accounts of a Cabinet member and other
senior government officials.
The federal government could be further exposed if it couldn't verify
the cybersecurity of Microsoft's Government Community Cloud High, a
suite of cloud-based services intended to safeguard some of the
nation's most sensitive information.
Yet, in a highly unusual move that still reverberates across
Washington, the Federal Risk and Authorization Management Program, or
FedRAMP, authorized the product anyway, bestowing what amounts to the
federal government's cybersecurity seal of approval. FedRAMP's ruling
-- which included a kind of "buyer beware" notice to any federal
agency considering GCC High -- helped Microsoft expand a government
business empire worth billions of dollars.
"BOOM SHAKA LAKA," Richard Wakeman, one of the company's chief
security architects, boasted in an online forum, celebrating the
milestone with a meme of Leonardo DiCaprio in "The Wolf of Wall
Street." Wakeman did not respond to requests for comment.
It was not the type of outcome that federal policymakers envisioned a
decade and a half ago when they embraced the cloud revolution and
created FedRAMP to help safeguard the government's cybersecurity. The
program's layers of review, which included an assessment by outside
experts, were supposed to ensure that service providers like
Microsoft could be entrusted with the government's secrets. But
ProPublica's investigation -- drawn from internal FedRAMP memos, logs,
emails, meeting minutes, and interviews with seven former and current
government employees and contractors -- found breakdowns at every
juncture of that process. It also found a remarkable deference to
Microsoft, even as the company's products and practices were central
to two of the most damaging cyberattacks ever carried out against the
government.
This is not security. This is security theater.
Tony Sager, former NSA computer scientist
FedRAMP first raised questions about GCC High's security in 2020 and
asked Microsoft to provide detailed diagrams explaining its
encryption practices. But when the company produced what FedRAMP
considered to be only partial information in fits and starts, program
officials did not reject Microsoft's application. Instead, they
repeatedly pulled punches and allowed the review to drag out for the
better part of five years. And because federal agencies were allowed
to deploy the product during the review, GCC High spread across the
government as well as the defense industry. By late 2024, FedRAMP
reviewers concluded that they had little choice but to authorize the
technology -- not because their questions had been answered or their
review was complete, but largely on the grounds that Microsoft's
product was already being used across Washington.
Today, key parts of the federal government, including the Justice and
Energy departments, and the defense sector rely on this technology to
protect highly sensitive information that, if leaked, "could be
expected to have a severe or catastrophic adverse effect" on
operations, assets and individuals, the government has said.
"This is not a happy story in terms of the security of the U.S.,"
said Tony Sager, who spent more than three decades as a computer
scientist at the National Security Agency and now is an executive at
the nonprofit Center for Internet Security.
For years, the FedRAMP process has been equated with actual security,
Sager said. ProPublica's findings, he said, shatter that facade.
"This is not security," he said. "This is security theater."
The U.S. Capitol building at night with a red light in the corner.
Despite a "lack of confidence in assessing" the security of
Microsoft's GCC High, FedRAMP authorized the product anyway. Alex
Wong/Getty Images
ProPublica is exposing the government's reservations about this
popular product for the first time. We are also revealing Microsoft's
yearslong inability to provide the encryption documentation and
evidence the federal reviewers sought.
The revelations come as the Justice Department ramps up scrutiny of
the government's technology contractors. In December, the department
announced the indictment of a former employee of Accenture who
allegedly misled federal agencies about the security of the company's
cloud platform and its compliance with FedRAMP's standards. She has
pleaded not guilty. Accenture, which was not charged with wrongdoing,
has said that it "proactively brought this matter to the government's
attention" and that it is "dedicated to operating with the highest
ethical standards."
Microsoft has also faced questions about its disclosures to the
government. As ProPublica reported last year, the company failed to
inform the Defense Department about its use of China-based engineers
to maintain the government's cloud systems, despite Pentagon rules
stipulating that "No Foreign persons may have" access to its most
sensitive data. The department is investigating the practice, which
officials say could have compromised national security.
Microsoft has defended its program as "tightly monitored and
supplemented by layers of security mitigations," but after
ProPublica's story published last July, the company announced that it
would stop using China-based engineers for Defense Department work.
In response to written questions for this story and in an interview,
Microsoft acknowledged the yearslong confrontation with FedRAMP but
also said it provided "comprehensive documentation" throughout the
review process and "remediated findings where possible."
"We stand by our products and the comprehensive steps we've taken to
ensure all FedRAMP-authorized products meet the security and
compliance requirements necessary," a spokesperson said in a
statement, adding that the company would "continue to work with
FedRAMP to continuously review and evaluate our services for
continued compliance."
But these days, ProPublica found, there aren't many people left at
FedRAMP to work with.
The program was an early target of the Trump administration's
Department of Government Efficiency, which slashed its staff and
budget. Even FedRAMP acknowledges it is operating "with an absolute
minimum of support staff" and "limited customer service." The roughly
two dozen employees who remain are "entirely focused on" delivering
authorizations at a record pace, FedRAMP's director has said. Today,
its annual budget is just $10 million, its lowest in a decade, even
as it has boasted record numbers of new authorizations for cloud
products.
The consequence of all this, people who have worked for FedRAMP told
ProPublica, is that the program now is little more than a rubber
stamp for industry. The implications of such a downsizing for federal
cybersecurity are far-reaching, especially as the administration
encourages agencies to adopt cloud-based artificial intelligence
tools, which draw upon reams of sensitive information.
The General Services Administration, which houses FedRAMP, defended
the program, saying it has undergone "significant reforms to
strengthen governance" since GCC High arrived in 2020. "FedRAMP's
role is to assess if cloud services have provided sufficient
information and materials to be adequate for agency use, and the
program today operates with strengthened oversight and accountability
mechanisms to do exactly that," a GSA spokesperson said in an emailed
statement.
The agency did not respond to written questions regarding GCC High.
A "Cloud First" World
About two decades ago, federal officials predicted that the cloud
revolution, providing on-demand access to shared computing via the
internet, would usher in an era of cheaper, more secure and more
efficient information technology.
Moving to the cloud meant shifting away from on-premises servers
owned and operated by the government to those in massive data centers
maintained by tech companies. Some agency leaders were reluctant to
relinquish control, while others couldn't wait to.
In an effort to accelerate the transition, the Obama administration
issued its "Cloud First" policy in 2011, requiring all agencies to
implement cloud-based tools "whenever a secure, reliable,
cost-effective" option existed. To facilitate adoption, the
administration created FedRAMP, whose job was to ensure the security
of those tools.
FedRAMP's "do once, use many times" system was intended to streamline
and strengthen the government procurement process. Previously, each
agency using a cloud service vetted it separately, sometimes applying
different interpretations of federal security requirements. Under the
new program, agencies would be able to skip redundant security
reviews because FedRAMP authorization indicated that the product had
already met standardized requirements. Authorized products would be
listed on a government website known as the FedRAMP Marketplace.
On paper, the program was an exercise in efficiency. But in practice,
the small FedRAMP team could not keep up with the flood of demand
from tech companies that wanted their products authorized.
The slow approval process frustrated both the tech industry, eager
for a share in the billions of federal dollars up for grabs, and
government agencies that were under pressure to migrate to the cloud.
These dynamics sometimes pitted the cloud industry and agency
officials together against FedRAMP. The backlog also prompted many
agencies to take an alternative path: performing their own reviews of
the products they wanted to adopt, using FedRAMP's standards.
It was through this "agency path" that GCC High entered the federal
bloodstream, with the Justice Department paving the way. Initially,
some Justice officials were nervous about the cloud and who might
have access to its information, which includes highly sensitive court
and law enforcement records, a Justice Department official involved
in the decision told ProPublica. The department's cybersecurity
program required it to ensure that only U.S. citizens "access or
assist in the development, operation, management, or maintenance" of
its IT systems, unless a waiver was granted. Justice's IT specialists
recommended pursuing GCC High, believing it could meet the elevated
security needs, according to the official, who spoke on condition of
anonymity because they were not authorized to discuss internal
matters.
Pursuant to FedRAMP's rules, Microsoft had GCC High evaluated by a
so-called third-party assessment organization, which is supposed to
provide an independent review of whether the product has met federal
standards. The Justice Department then performed its own evaluation
of GCC High using those standards and ruled the offering acceptable.
A smiling woman with long brown hair wearing a pink shirt and silver
necklace poses in front of a U.S. flag.Melinda Rogers, former chief
information officer for the Department of Justice U.S. Department of
Justice archives
By early 2020, Melinda Rogers, Justice's deputy chief information
officer, made the decision official and soon deployed GCC High across
the department.
It was a milestone for all involved. Rogers had ushered the Justice
Department into the cloud, and Microsoft had gained a significant
foothold in the cutthroat market for the federal government's cloud
computing business.
Moreover, Rogers' decision placed GCC High on the FedRAMP
Marketplace, the government's influential online clearinghouse of all
the cloud providers that are under review or already authorized. Its
mere mention as "in process" was a boon for Microsoft, amounting to
free advertising on a website used by organizations seeking to
purchase cloud services bearing what is widely seen as the
government's cybersecurity seal of approval.
That April, GCC High landed at FedRAMP's office for review, the final
stop on its bureaucratic journey to full authorization.
Microsoft's Missing Information
In theory, there shouldn't have been much for FedRAMP's team to do
after the third-party assessor and Justice reviewed GCC High, because
all parties were supposed to be following the same requirements.
But it was around this time that the Government Accountability
Office, which investigates federal programs, discovered breakdowns in
the process, finding that agency reviews sometimes were lacking in
quality. Despite missing details, FedRAMP went on to authorize many
of these packages. Acknowledging these shortcomings, FedRAMP began to
take a harder look at new packages, a former reviewer said.
This was the environment in which Microsoft's GCC High application
entered the pipeline. The name GCC High was an umbrella covering many
services and features within Office 365 that all needed to be
reviewed. FedRAMP reviewers quickly noticed key material was missing.
The team homed in on what it viewed as a fundamental document called
a "data flow diagram," former members told ProPublica. The
illustration is supposed to show how data travels from Point A to
Point B -- and, more importantly, how it's protected as it hops from
server to server. FedRAMP requires data to be encrypted while in
transit to ensure that sensitive materials are protected even if
they're intercepted by hackers.
But when the FedRAMP team asked Microsoft to produce the diagrams
showing how such encryption would happen for each service in GCC
High, the company balked, saying the request was too challenging. So
the reviewers suggested starting with just Exchange Online, the
popular email platform.
"This was our litmus test to say, 'This isn't the only thing that's
required, but if you're not doing this, we are not even close yet,'"
said one reviewer who spoke on condition of anonymity because they
were not authorized to discuss internal matters. Once they reached
the appropriate level of detail, they would move from Exchange to
other services within GCC High.
It was the kind of detail that other major cloud providers such as
Amazon and Google routinely provided, members of the FedRAMP team
told ProPublica. Yet Microsoft took months to respond. When it did,
the former reviewer said, it submitted a white paper that discussed
GCC High's encryption strategy but left out the details of where on
the journey data actually becomes encrypted and decrypted -- so
FedRAMP couldn't assess that it was being done properly.
A Microsoft spokesperson acknowledged that the company had
"articulated a challenge related to illustrating the volume of
information being requested in diagram form" but "found alternate
ways to share that information."
Rogers, who was hired by Microsoft in 2025, declined to be
interviewed. In response to emailed questions, the company provided a
statement saying that she "stands by the rigorous evaluation that
contributed to" her authorization of GCC High. A spokesperson said
there was "absolutely no connection" between her hiring and the
decisions in the GCC High process, and that she and the company
complied with "all rules, regulations, and ethical standards."
The Justice Department declined to respond to written questions from
ProPublica.
A Fight Over "Spaghetti Pies"
As 2020 came to a close, a national security crisis hit Washington
that underscored the consequences of cyber weakness. Russian
state-sponsored hackers had been quietly working their way through
federal computer systems for much of the year and vacuuming up
sensitive data and emails from U.S. agencies -- including the Justice
Department.
At the time, most of the blame fell on a Texas-based company called
SolarWinds, whose software provided hackers their initial opening and
whose name became synonymous with the attack. But, as ProPublica has
reported, the Russians leveraged that opening to exploit a
long-standing weakness in a Microsoft product -- one that the company
had refused to fix for years, despite repeated warnings from one of
its engineers. Microsoft has defended its decision not to address the
flaw, saying that it received "multiple reviews" and that the company
weighs a variety of factors when making security decisions.
In the aftermath, the Biden administration took steps to bolster the
nation's cybersecurity. Among them, the Justice Department announced
a cyber-fraud initiative in 2021 to crack down on companies and
individuals that "put U.S. information or systems at risk by
knowingly providing deficient cybersecurity products or services,
knowingly misrepresenting their cybersecurity practices or protocols,
or knowingly violating obligations to monitor and report
cybersecurity incidents and breaches."
Deputy Attorney General Lisa Monaco said the department would use the
False Claims Act to pursue government contractors "when they fail to
follow required cybersecurity standards -- because we know that puts
all of us at risk."
A woman with chin-length brown hair in a blue blazer looks toward the
camera. Abstract blue and red light patterns blur in the foreground
and background.Former Deputy Attorney General Lisa Monaco. After
Russian state-sponsored hackers stole sensitive data from U.S.
agencies, Monaco said the Department of Justice would hold government
contractors accountable for failing to uphold cybersecurity
standards. Stefani Reynolds/AFP via Getty Images
But if Microsoft felt any pressure from the SolarWinds attack or from
the Justice Department's announcement, it didn't manifest in the
FedRAMP talks, according to former members of the FedRAMP team.
The discourse between FedRAMP and Microsoft fell into a pattern. The
parties would meet. Months would go by. Microsoft would return with a
response that FedRAMP deemed incomplete or irrelevant. To bolster the
chances of getting the information it wanted, the FedRAMP team
provided Microsoft with a template, describing the level of detail it
expected. But the diagrams Microsoft returned never met those
expectations.
"We never got past Exchange," one former reviewer said. "We never got
that level of detail. We had no visibility inside."
In an interview with ProPublica, John Bergin, the Microsoft official
who became the government's main contact, acknowledged the prolonged
back-and-forth but blamed FedRAMP, equating its requests for diagrams
to a "rock fetching exercise."
"We were maybe incompetent in how we drew drawings because there was
no standard to draw them to," he said. "Did we not do it exactly how
they wanted? Absolutely. There was always something missing because
there was no standard."
A Microsoft spokesperson said without such a standard, "cloud
providers were left to interpret the level of abstraction and
representation on their own," creating "inconsistency and confusion,
not an unwillingness to be transparent."
But even Microsoft's own engineers had struggled over the years to
map the architecture of its products, according to two people
involved in building cloud services used by federal customers. At
issue, according to people familiar with Microsoft's technology, was
the decades-old code of its legacy software, which the company used
in building its cloud services.
One FedRAMP reviewer compared it to a "pile of spaghetti pies." The
data's path from Point A to Point B, the person said, was like
traveling from Washington to New York with detours by bus, ferry and
airplane rather than just taking a quick ride on Amtrak. And each one
of those detours represents an opportunity for a hijacking if the
data isn't properly encrypted.
Other major cloud providers such as Amazon and Google built their
systems from the ground up, said Sager, the former NSA computer
scientist, who worked with all three companies during his time in
government.
Microsoft's system is "not designed for this kind of isolation of
'secure' from 'not secure,'" Sager said.
A Microsoft spokesperson acknowledged the company faces a unique
challenge but maintained that its cloud products meet federal
security requirements.
"Unlike providers that started later with a narrower product scope,
Microsoft operates one of the broadest enterprise and government
platforms in the world, supporting continuity for millions of
customers while simultaneously modernizing at scale," the
spokesperson said in emailed responses. "That complexity is not
'spaghetti,' but it does mean the work of disentangling, isolating,
and hardening systems is continuous."
The spokesperson said that since 2023, Microsoft has made
"security-first architectural redesign, legacy risk reduction, and
stronger isolation guarantees a top, company-wide priority."
Assessors Back-Channel Cyber Concerns
The FedRAMP team was not the only party with reservations about GCC
High. Microsoft's third-party assessment organizations also expressed
concerns.
The firms are supposed to be independent but are hired and paid by
the company being assessed. Acknowledging the potential for conflicts
of interest, FedRAMP has encouraged the assessment firms to
confidentially back-channel to its reviewers any negative feedback
that they were unwilling to bring directly to their clients or
reflect in official reports.
In 2020, two third-party assessors hired by Microsoft, Coalfire and
Kratos, did just that. They told FedRAMP that they were unable to get
the full picture of GCC High, a former FedRAMP reviewer told
ProPublica.
"Coalfire and Kratos both readily admitted that it was difficult to
impossible to get the information required out of Microsoft to
properly do a sufficient assessment," the reviewer told ProPublica.
The back channel helped surface cybersecurity issues that otherwise
might never have been known to the government, people who have worked
with and for FedRAMP told ProPublica. At the same time, they
acknowledged its existence undermined the very spirit and intent of
having independent assessors.
A spokesperson for Coalfire, the firm that initially handled the GCC
High assessment, requested written questions from ProPublica, then
declined to respond.
A spokesperson for Kratos, which replaced Coalfire as the GCC High
assessor, declined an interview request. In an emailed response to
written questions, the spokesperson said the company stands by its
official assessment and recommendation of GCC High and "absolutely
refutes" that it "ever would sign off on a product we were unable to
fully vet." The company "has open and frank conversations" with all
customers, including Microsoft, which "submitted all requisite
diagrams to meet FedRAMP-defined requirements," the spokesperson
said.
Kratos said it "spent extensive time working collaboratively with
FedRAMP in their review" and does not consider such discussions to be
"backchanneling."
FedRAMP, however, was dissatisfied with Kratos' ongoing work and
believed the firm "should be pushing back" on Microsoft more, the
former reviewer said. It placed Kratos on a "corrective action plan,"
which could eventually result in loss of accreditation. The company
said it did not agree with FedRAMP's action but provided "additional
trainings for some internal assessors" in response to it.
The Microsoft spokesperson told ProPublica the company has "always
been responsive to requests" from Kratos and FedRAMP. "We are not
aware of any backchanneling, nor do we believe that backchanneling
would have been necessary given our transparency and cooperation with
auditor requests," the spokesperson said.
In response to questions from ProPublica about the process, the GSA
said in an email that FedRAMP's system "does not create an inherent
conflict of interest for professional auditors who meet ethical and
contractual performance expectations."
GSA did not respond to questions about back-channeling but said the
"correct process" is for a third-party assessor to "state these
problems formally in a finding during the security assessment so that
the cloud service provider has an opportunity to fix the issue."
FedRAMP Ends Talks
A silhouette of a person wearing a shoulder bag is surrounded by
shadow. Behind the person is a large building full of windows and a
blue sky.FedRAMP is housed under the General Services Administration
within the federal government. Al Drago/Bloomberg via Getty Images
The back-and-forth between the FedRAMP reviewers and Microsoft's team
went on for years with little progress. Then, in the summer of 2023,
the program's interim director, Brian Conrad, got a call from the
White House that would alter the course of the review.
Chinese state-sponsored hackers had infiltrated GCC, the lower-cost
version of Microsoft's government cloud, and stolen data and emails
from the commerce secretary, the U.S. ambassador to China and other
high-ranking government officials. In the aftermath, Chris DeRusha,
the White House's chief information security officer, wanted a
briefing from FedRAMP, which had authorized GCC.
The decision predated Conrad's tenure, but he told ProPublica that he
left the conversation with several takeaways. First, FedRAMP must
hold all cloud providers -- including Microsoft -- to the same
standards. Second, he had the backing of the White House in standing
firm. Finally, FedRAMP would feel the political heat if any cloud
service with a FedRAMP authorization were hacked.
DeRusha confirmed Conrad's account of the phone call but declined to
comment further.
Within months, Conrad informed Microsoft that FedRAMP was ending the
engagement on GCC High.
We can't even quantify the unknowns, which makes us very
uncomfortable.
FedRAMP reviewer of GCC High
"After three years of collaboration with the Microsoft team, we still
lack visibility into the security gaps because there are unknowns
that Microsoft has failed to address," Conrad wrote in an October
2023 email. This, he added, was not for FedRAMP's lack of trying.
Staffers had spent 480 hours of review time, had conducted 18
"technical deep dive" sessions and had numerous email exchanges with
the company over the years. Yet they still lacked the data flow
diagrams, crucial information "since visibility into the encryption
status of all data flows and stores is so important," he wrote.
If Microsoft still wanted FedRAMP authorization, Conrad wrote, it
would need to start over.
A FedRAMP reviewer, explaining the decision to the Justice
Department, said the team was "not asking for anything above and
beyond what we've asked from every other" cloud service provider,
according to meeting minutes reviewed by ProPublica. But the request
was particularly justified in Microsoft's case, the reviewer told the
Justice officials, because "each time we've actually been able to get
visibility into a black box, we've uncovered an issue."
"We can't even quantify the unknowns, which makes us very
uncomfortable," the reviewer said, according to the minutes.
Microsoft and the Justice Department Push Back
Microsoft was furious. Failing to obtain authorization and starting
the process over would signal to the market that something was wrong
with GCC High. Customers were already confused and concerned about
the drawn-out review, which had become a hot topic in an online forum
used by government and technology insiders. There, Wakeman, the
Microsoft cybersecurity architect, deflected blame, saying the
government had been "dragging their feet on it for years now."
Meanwhile, to build support for Microsoft's case, Bergin, the
company's point person for FedRAMP and a former Army official,
reached out to government leaders, including one from the Justice
Department.
The Justice official, who spoke on condition of anonymity because
they were not authorized to discuss the matter, said Bergin
complained that the delay was hampering Microsoft's ability "to get
this out into the market full sail." Bergin then pushed the Justice
Department to "throw around our weight" to help secure FedRAMP
authorization, the official said.
A man with short black hair and goatee and wearing glasses and a suit
slightly smiles in front of a U.S. flag and another flag.John Bergin
in 2019, while serving as deputy assistant secretary of the Army for
financial information management. He was later hired by Microsoft and
served as the company's liaison with FedRAMP during the GCC High
debate. Defense Visual Information Distribution Service
That December, as the parties gathered to hash things out at GSA's
Washington headquarters, Justice did just that. Rogers, who by then
had been promoted to the department's chief information officer, sat
beside Bergin -- on the opposite side of the table from Conrad, the
FedRAMP director.
Rogers and her Justice colleagues had a stake in the outcome. Since
authorizing and deploying GCC High, she had received accolades for
her work modernizing the department's IT and cybersecurity. But
without FedRAMP's stamp of approval, she would be the government
official left holding the bag if GCC High were involved in a serious
hack. At the same time, the Justice Department couldn't easily back
out of using GCC High because once a technology is widely deployed,
pulling the plug can be costly and technically challenging. And from
its perspective, the cloud was an improvement over the old
government-run data centers.
Shortly after the meeting kicked off, Bergin interrupted a FedRAMP
reviewer who had been presenting PowerPoint slides. He said the
Justice Department and third-party assessor had already reviewed GCC
High, according to meeting minutes. FedRAMP "should essentially just
accept" their findings, he said.
Then, in a shock to the FedRAMP team, Rogers backed him up and went
on to criticize FedRAMP's work, according to two attendees.
In its statement, Microsoft said Rogers maintains that FedRAMP's
approach "was misguided and improperly dismissed the extensive
evaluations performed by DOJ personnel."
Bergin did not dispute the account, telling ProPublica that he had
been trying to argue that it is the purview of third-party assessors
such as Kratos -- not FedRAMP -- to evaluate the security of cloud
products. And because FedRAMP must approve the third-party assessment
firms, the program should have taken its issues up with Kratos.
"When you are the regulatory agency who determines who the auditors
are and you refuse to accept your auditors' answers, that's not a
'me' problem," Bergin told ProPublica.
The GSA did not respond to questions about the meeting. The Justice
Department declined to comment.
Pressure Mounts on FedRAMP
If there was any doubt about the role of FedRAMP, the White House
issued a memorandum in the summer of 2024 that outlined its views.
FedRAMP, it said, "must be capable of conducting rigorous reviews"
and requiring cloud providers to "rapidly mitigate weaknesses in
their security architecture." The office should "consistently assess
and validate cloud providers' complex architectures and encryption
schemes."
But by that point, GCC High had spread to other federal agencies,
with the Justice Department's authorization serving as a signal that
the technology met federal standards.
It also spread to the defense sector, since the Pentagon required
that cloud products used by its contractors meet FedRAMP standards.
While it did not have FedRAMP authorization, Microsoft marketed GCC
High as meeting the requirements, selling it to companies such as
Boeing that research, develop and maintain military weapons systems.
But with the FedRAMP authorization up in the air, some contractors
began to worry that by using GCC High, they were out of compliance.
That could threaten their contracts, which, in turn, could impact
Defense Department operations. Pentagon officials called FedRAMP to
inquire about the authorization stalemate.
The Defense Department acknowledged but did not respond to written
questions from ProPublica.
Rogers also kept pressing FedRAMP to "get this thing over the line,"
former employees of the GSA and FedRAMP said. It was the "opinion of
the staff and the contractors that she simply was not willing to put
heat to Microsoft on this" and that the Justice Department "was too
sympathetic to Microsoft's claims," Eric Mill, then GSA's executive
director for cloud strategy, told ProPublica.
Authorization Despite a "Damning" Assessment
In the summer of 2024, FedRAMP hired a new permanent director,
government technology insider Pete Waterman. Within about a month of
taking the job, he restarted the office's review of GCC High with a
new team, which put aside the debate over data flow diagrams and
instead attempted to examine evidence from Microsoft. But these
reviewers soon arrived at the same conclusion, with the team's leader
complaining about "getting stiff-armed" by Microsoft.
"He came back and said, 'Yeah, this thing sucks,'" Mill recalled.
A smiling man with a large white beard wearing white-rimmed glasses
and a black hoodie.Pete Waterman, FedRAMP director hired in 2024
FedRAMP
While the team was able to work through only two of the many services
included in GCC High, Exchange Online and Teams, that was enough for
it to identify "issues that are fundamental" to risk management,
including "timely remediation of vulnerabilities and vulnerability
scanning," according to a summary of the team's findings reviewed by
ProPublica.
Those issues, as well as a lack of "proper detailed security
documentation" from Microsoft, limit "visibility and understanding of
the system" and "impair the ability to make informed risk decisions."
The team concluded, "There is a lack of confidence in assessing the
system's overall security posture."
A Microsoft spokesperson said in a statement that the company "never
received this feedback in any of its communications with FedRAMP."
When ProPublica read the findings to Bergin, the Microsoft liaison,
he said he was surprised.
"That's pretty damning," Bergin said, adding that it sounded like
language that "would've generally been associated with a finding of
'not worthy.' If an assessor wrote that, I would be nervous."
Despite the findings, to the FedRAMP team, turning Microsoft down
didn't seem like an option. "Not issuing an authorization would
impact multiple agencies that are already using GCC-H," the summary
document said. The team determined that it was a "better value" to
issue an authorization with conditions for continued government
oversight.
While authorizations with oversight conditions weren't unusual,
arriving at one under these circumstances was. GCC High reviewers saw
problems everywhere, both in what they were able to evaluate and what
they weren't. To them, most of the package remained a vast wilderness
of untold risk.
Nevertheless, FedRAMP and Microsoft reached an agreement, and the day
after Christmas 2024, GCC High received its FedRAMP authorization.
FedRAMP appended a cover report to the package laying out its
deficiencies and noting it carried unknown risks, according to people
familiar with the report.
It emphasized that agencies should carefully review the package and
engage directly with Microsoft on any questions.
"Unknown Unknowns" Persist
Microsoft told ProPublica that it has met the conditions of the
agreement and has "stayed within the performance metrics required by
FedRAMP" to ensure that "risks are identified, tracked, remediated,
and transparently communicated."
But under the Trump administration, there aren't many people left at
FedRAMP to check.
While the Biden-era guidance said FedRAMP "must be an expert program
that can analyze and validate the security claims" of cloud
providers, the GSA told ProPublica that the program's role is "not to
determine if a cloud service is secure enough." Rather, it is "to
ensure agencies have sufficient information to make these risk
decisions."
The problem is that agencies often lack the staff and resources to do
thorough reviews, which means the whole system is leaning on the
claims of the cloud companies and the assessments of the third-party
firms they pay to evaluate them. Under the current vision, critics
say, FedRAMP has lost the plot.
"FedRAMP's job is to watch the American people's back when it comes
to sharing their data with cloud companies," said Mill, the former
GSA official, who also co-authored the 2024 White House memo. "When
there's a security issue, the public doesn't expect FedRAMP to say
they're just a paper-pusher."
When there's a security issue, the public doesn't expect FedRAMP
to say they're just a paper-pusher.
Eric Mill, former GSA executive director for cloud strategy
Meanwhile, at the Justice Department, officials are finding out what
FedRAMP meant by the "unknown unknowns" in GCC High. Last year, for
example, they discovered that Microsoft relied on China-based
engineers to service their sensitive cloud systems despite the
department's prohibition against non-U.S. citizens assisting with IT
maintenance.
Officials learned about this arrangement -- which was also used in GCC
High -- not from FedRAMP or from Microsoft but from a ProPublica
investigation into the practice, according to the Justice employee
who spoke with us.
A Microsoft spokesperson acknowledged that the written security plan
for GCC High that the company submitted to the Justice Department did
not mention foreign engineers, though he said Microsoft did
communicate that information to Justice officials before 2020.
Nevertheless, Microsoft has since ended its use of China-based
engineers in government systems.
Former and current government officials worry about what other risks
may be lurking in GCC High and beyond.
The GSA told ProPublica that, in general, "if there is credible
evidence that a cloud service provider has made materially false
representations, that matter is then appropriately referred to
investigative authorities."
Ironically, the ultimate arbiter of whether cloud providers or their
third-party assessors are living up to their claims is the Justice
Department itself. The recent indictment of the former Accenture
employee suggests it is willing to use this power. In a court
document, the Justice Department alleges that the ex-employee made
"false and misleading representations" about the cloud platform's
security to help the company "obtain and maintain lucrative federal
contracts." She is also accused of trying to "influence and obstruct"
Accenture's third-party assessors by hiding the product's
deficiencies and telling others to conceal the "true state of the
system" during demonstrations, the department said. She has pleaded
not guilty.
There is no public indication that such a case has been brought
against Microsoft or anyone involved in the GCC High authorization.
The Justice Department declined to comment. Monaco, the deputy
attorney general who launched the department's initiative to pursue
cybersecurity fraud cases, did not respond to requests for comment.
She left her government position in January 2025. Microsoft hired her
to become its president of global affairs.
A company spokesperson said Monaco's hiring complied with "all rules,
regulations, and ethical standards" and that she "does not work on
any federal government contracts or have oversight over or
involvement with any of our dealings with the federal government."
Corrections
Filed under -- Technology
Who owns ProPublica? No one.
The story you just read was made possible by our readers. We hope it
inspires you to support ProPublica, so we can continue producing
investigations that shine a light on power, uncover the truth and
drive real change.
ProPublica is a nonprofit newsroom dedicated to nonpartisan,
evidence-based journalism that holds power accountable. Founded in
2008 to address the decline in investigative reporting, we've spent
over 15 years uncovering injustice, corruption, and abuse of power --
work that is slow, expensive and more critical than ever to our
democracy. With eight Pulitzer Prizes and reforms sparked in state
and local governments, businesses, institutions and more, our
reporting ensures that the public interest comes first.
Today, the stakes are higher than ever. From ethics in our government
offices, to reproductive health care, to the climate crisis and
beyond, ProPublica remains on the front lines of the stories that
matter most. Your gift helps us keep the powerful accountable and the
truth accessible.
Join over 90,000 supporters nationwide in standing up for
investigative journalism that informs, inspires, and creates lasting
impact. Thank you for making this work possible.
DONATE TO PROPUBLICA
Contributors
* Renee Dudley
+ X
+ Bluesky
+ LinkedIn
I am a ProPublica reporter focused on technology, cybersecurity
and business.
More Stories: Renee Dudley
Have a Tip for a Story?
I'm interested in the intersection of Big Tech and national
security. If you've worked in tech or government, or otherwise
have tips about this area, please get in touch.
[renee-dudl]
* Doris Burke
+ LinkedIn
I cover corporate wrongdoing.
More Stories: Doris Burke
Need to Get in Touch?
Please do reach out, either by email or securely on Signal.
[20190703-d]
What We're Watching
During Donald Trump's second presidency, ProPublica will focus on the
areas most in need of scrutiny. Here are some of the issues our
reporters will be watching -- and how to get in touch with them
securely.
Photo of Donald Trump at a podium seen through a crowd in the
foreground.
Learn more about our reporting team. We will continue to share our
areas of interest as the news develops.
Photo of Sharon Lerner
Sharon Lerner
I cover health and the environment and the agencies that govern them,
including the Environmental Protection Agency.
Contact me
Photo of Andy Kroll
Andy Kroll
I cover justice and the rule of law, including the Justice
Department, U.S. attorneys and the courts.
Contact me
Photo of Melissa Sanchez
Melissa Sanchez
I report on immigration and labor, and I am based in Chicago.
Contact me
Photo of Jesse Coburn
Jesse Coburn
I cover housing and transportation, including the companies working
in those fields and the regulators overseeing them.
Contact me
Photo of an truck with a large screen advertisement that reads: Are
(were) you a government worker? ProPublica journalists want to hear
from you. Signal: 917-512-0201 propublica.org/tips
If you don't have a specific tip or story in mind, we could still use
your help. Sign up to be a member of our federal worker source
network to stay in touch.
Slide 1 Slide 2 Slide 3 Slide 4 Slide 5 Slide 6
More in Technology
More in Technology
[20260129-faa-letter]
FAA Warns Airlines About Safety Risks From Rocket Launches, Urges
"Extreme Caution"
[122225-spacex-promo-final]
"We're Too Close to the Debris"
[Tech-Project-Defense-Law-Lead]
Trump Signs Defense Bill Prohibiting China-Based Engineers in
Pentagon IT Work
[Realpage-Impact-Settlement]
DOJ and RealPage Agree to Settle Rental Price-Fixing Case
[tech-project-dod-impact-FINAL]
Pentagon Bans Tech Vendors From Using China-Based Personnel After
ProPublica Investigation
[GettyImages-2220718203_maxHeight_3000_maxWidth_3000]
Pentagon Warns Microsoft: Company's Use of China-Based Engineers Was
a "Breach of Trust"
Most Read
* [20260225-Gordon-fed-ramp-tech-project-3x2_maxHeight_3000_maxWidth_3000]
Federal Cyber Experts Thought Microsoft's Cloud Was "a Pile of
Shit." They Approved It Anyway.
* [20260228-Maney-Court-Ordered-C-Sections-035]
They Didn't Want to Have C-Sections. A Judge Would Decide How
They Gave Birth.
* [Oklahoma_oil_maxHeight_3000_maxWidth_3000]
Oil Regulators Found Hundreds of Wells Violating Oklahoma Rules.
Then They Ignored Their Findings.
* [pratje_probublicanda__040_preview_maxWidth_3000_maxHeight_3000_ppi_72_embedColorProfile_true_quality_95]
The Trump Administration's "Disturbing" New Legal Strategy to
Prosecute Border Crossers Is Taxing Courts and Testing the Law
* [terror-boss-promo]
"The Intern in Charge": Meet the 22-Year-Old Trump's Team Picked
to Lead Terrorism Prevention
Stay informed with the Daily Digest.
Email Address: [ ]
Sign Up
Investigative Journalism in the Public Interest
(c) Copyright 2026 Pro Publica Inc.
Sites
* ProPublica
* Local Reporting Network
* Texas Tribune Partnership
* Electionland
Sections
* Topics
* Series
* Videos
* News Apps
* Get Involved
* The Nerd Blog
* @ProPublica
* Events
Info
* About
* Board and Advisors
* Officers and Staff
* Diversity
* Jobs and Fellowships
* Media Center
* Reports
* Impact
* Awards
* Corrections
Policies
* Code of Ethics
* Advertising Policy
* Gift Acceptance
* Privacy Policy
Follow
* Newsletters
* iOS and Android
* RSS Feed
More
* Send Us Tips
* Steal Our Stories
* Browse via Tor
* Contact Us
* Donate
* More Ways to Give
Journalism That Holds Power to Account
Sign up for ProPublica's Big Story newsletter and get our latest
stories delivered straight to your inbox.
Please enter your email address: [ ] Get the
Newsletter Subscribe