web
You’re offline. This is a read only version of the page.
close
Skip to main content

Announcements

News and Announcements icon
Community site session details

Community site session details

Session Id :
Power Platform Community / Forums / Power Apps / Is this application GC...
Power Apps
Suggested Answer

Is this application GCC High compliant and does it require ATO?

(0) ShareShare
ReportReport
Posted on by 26
We have built an enterprise application that is ultimately intended to run in a GCC High environment, but the entire solution has currently been developed and tested in a normal commercial (non-GCC) tenant. The plan is to migrate and deploy this solution into a GCC High tenant later.
 
 

Architecture Overview


  • SharePoint Online

    • Customer-specific SharePoint sites

    • SharePoint lists used as the primary data stor 

  • Power Apps (SharePoint-integrated customized forms only)

    • Forms created using Integrate → Power Apps → Customize Form

    • Only SharePoint is used as the data source

    • Built using Power Fx (low-code only)

    • No PCF controls

    • No external data sources

    • No Dataverse, SQL, or third-party service 


  • Power Automate

    • Used for automatic provisioning of:

      • SharePoint sites

      • SharePoint list 


    • Uses:


      • Standard connectors

      • Premium connectors


      •  
    • No custom connectors


    • No Azure Functions


    • Uses SharePoint and Power BI APIs


    • Very minimal expressions / low-code logic



    •  

  • Power BI

     
    • Reports embedded inside SharePoint pages


    • Data source is only SharePoint 


    •  


  •  

There are:


  • Premium connectors used


  • No custom connectors


  • No third-party integrations


  • No external Azure services

 

 

My Questions:

 

  1. From a platform compliance perspective, once this solution is deployed into a GCC High tenant, is this architecture considered GCC High compliant, given that it uses:

     

    • SharePoint Online (GCC High)


    • Power Apps (SharePoint-integrated forms)

    • Power Automate (Standard + Premium connectors)


    • Power BI (GCC High)



    •  

  2. Does the use of Premium connectors (without any custom connectors) introduce:

     

    • Any additional compliance burden in GCC High?


    • Any FedRAMP High or DoD SRG impact?



    •  

  3. Given that the solution was originally developed in a commercial (non-GCC) tenant and later migrated to GCC High:

     

    • Does this create any compliance, security, or ATO risks?


    • Does it require additional validation or security controls during authorization?



    •  

  4. Even if all services used are GCC High supported, is a formal ATO (Authority to Operate) still mandatory at the application/solution level?


  5. In real-world government implementations:

     

    • Is the ATO inherited from Microsoft’s GCC High platform, or


    • Is a separate ATO always required for each custom-built business application?



    •  

  6. Are there any known compliance risks or design limitations when combining:

     

    • Power Apps customized forms


    • Power Automate premium connectors


    • Power BI embedded in SharePoint

      within a GCC High tenant?



    •  


  7.  
 

Any authoritative guidance, real-world experience, or Microsoft documentation references would be greatly appreciated.

Screenshot 2025-12-09 112722.png
I have the same question (0)
  • Suggested answer
    Michael E. Gernaey Profile Picture
    53,958 Moderator on at
     
    Even while working at Microsoft and helping customers / partners, whatever we built needed an ATO. the services you use don't determine it so much as the requirements simply because you are building a solution in general.
     
    Everything you are using is fine in the sense that it will not cause you additional burden but yes I expect that you have to do an ATO.
     

    If these suggestions help resolve your issue, Please consider Marking the answer as such and also maybe a like.

    Thank you!
    Sincerely, Michael Gernaey

Under review

Thank you for your reply! To ensure a great experience for everyone, your content is awaiting approval by our Community Managers. Please check back later.

Helpful resources

Quick Links

Introducing the 2026 Season 1 community Super Users

Congratulations to our 2026 Super Users!

Kudos to our 2025 Community Spotlight Honorees

Congratulations to our 2025 community superstars!

Congratulations to the April Top 10 Community Leaders!

These are the community rock stars!

Leaderboard > Power Apps

#1
Vish WR Profile Picture

Vish WR 1,074

#2
Valantis Profile Picture

Valantis 639

#3
11manish Profile Picture

11manish 606

Last 30 days Overall leaderboard