GCC High Federal Tenant Administration

Complete
Global System Administrator December 2023 — March 2024

Overview

Stood up and administered the GCC High environment supporting Infoblox federal operations — a physically and logically separate Microsoft tenant with its own compliance obligations, its own identity boundary, and no shortcuts borrowed from the commercial side. Covered roughly 60+ federal users across both Windows and macOS.

Problem

Federal work cannot run in the commercial tenant. GCC High exists because DoD and ITAR-adjacent requirements demand data residency, personnel screening, and controls that a standard Microsoft 365 tenant does not provide. That means a parallel environment: separate identities, separate device management, separate imaging, separate everything — and the operational cost of running two of each without letting them drift into each other.

The practical problem was that federal users still needed working laptops on day one, in both platforms, without any commercial-tenant tooling touching the process.

Approach

Built custom Windows ISO images and deployed install USBs sized for federal endpoints, so provisioning did not depend on a commercial-tenant deployment path. On the Mac side, brought devices in through Jamf Connect bound to the GCC High tenant rather than the commercial one, keeping the identity boundary intact from first boot.

Held administrator responsibility inside both federal tenants — the GCC High Intune tenant for Windows and the Jamf Connect GCC High configuration for macOS — including account resets and lifecycle actions that could not be delegated to standard helpdesk tooling.

Also evaluated the federal mobile path: tested Edison Mail for GCC High Android users, and concluded managed iOS was the better primary solution rather than forcing an Android workaround.

Architecture

Two parallel management planes. Windows federal endpoints provision from custom ISO media and enroll into the GCC High Intune tenant. macOS federal endpoints enroll through Jamf with Jamf Connect pointed at the GCC High identity tenant, so a federal Mac authenticates against federal identity and never against the commercial directory.

Administration stayed deliberately separate — the same person operating both, but never a shared credential, shared policy object, or shared enrollment path between commercial and federal.

Outcome

Federal operations ran on a compliant, fully separated environment across both platforms. The environment maintained adherence to DoD compliance requirements and cleared two consecutive audit review cycles with zero findings.

Lessons Learned

Running a federal tenant is less about knowing a different console and more about refusing convenience. Every time the fast path was to reuse something from the commercial side — an image, a policy, a login — reusing it would have been the compliance failure. The discipline is procedural, not technical.