
Export-Controlled Technical Data Handling in Microsoft 365
Export controls change how you select and configure Microsoft 365, and Microsoft states the customer remains the exporter who must assess cloud use.

Export controls change how you select and configure Microsoft 365, and Microsoft states the customer remains the exporter who must assess cloud use.

CMMC Level 2 expects you to create and retain audit logs long enough to support investigations, and Microsoft 365 can meet that need when you configure Purview Audit retention to match your policy, scope, and licensing.

Microsoft Purview Compliance Manager offers NIST SP 800-171 and CMMC-aligned assessment templates that organize actions and evidence in Microsoft 365, useful for gap analysis and documentation across a CUI environment.

CMMC Level 2 logging outcomes rest on control coverage, data residency, and operational maturity; choose native M365, Microsoft Sentinel, or a third-party SIEM based on evidence and scope, not brand names.

Defense contractors can use Microsoft Defender for Endpoint device control, Intune, BitLocker, and Endpoint DLP to run allow-by-exception USB policies on CUI workstations, protect CUI on removable media with FIPS-validated encryption, and produce evidence aligned to NIST 800-171 and CMMC assessment expectations.

Contractors can protect CUI in email with S/MIME or with Microsoft Purview encryption through sensitivity labels or OME, but the design must meet NIST SP 800-171 cryptographic and flow-control requirements and work for external recipients.