An index of DoD & federal logistics tools · Community-vetted

Guide

The DoD Microsoft 365 Environment for Logisticians

A logistician's orientation to the Department of Defense's Microsoft 365 cloud — the Teams, SharePoint, OneDrive, Lists, and Power Platform environment that the Navy runs as Flank Speed. It explains the government cloud tiers (GCC, GCC High, and Office 365 DoD), the DoD Cloud Computing Security Requirements Guide impact levels (IL2/IL4/IL5) that govern them, what apps you actually get, and how to think about handling CUI so you can build your own supply and status tracking tools on top of it. It is operated for DoD users on Microsoft's government clouds under DISA provisional authorizations; the Navy's tenant, Flank Speed, runs at Impact Level 5.

Operator
Microsoft (cloud service provider) for the government M365 environments; the DoD component operates its own tenant — for the Navy, that tenant is Flank Speed, run under the Department of the Navy
Regulatory authority
DoD Cloud Computing Security Requirements Guide (SRG), maintained by the Defense Information Systems Agency (DISA); NIST SP 800-53 / FedRAMP; CUI governed by the National Archives (NARA) CUI program and NIST SP 800-171
Access type
cac_required
Last verified

The DoD Microsoft 365 environment is the familiar Microsoft productivity stack — Teams, SharePoint, OneDrive, Outlook/Exchange, the Office apps, Microsoft Lists, and the Power Platform — running inside Microsoft's US government clouds instead of the commercial cloud, so it can carry Controlled Unclassified Information (CUI) under the DoD Cloud Computing Security Requirements Guide (SRG). Each DoD component runs its own tenant; the Navy's tenant is Flank Speed. For a working logistician, this environment is where you already live for email and chat — and, less obviously, it is a build-your-own-tools platform: you can stand up a supply tracker, a status board, or an automated alert in the same accredited environment your unit already uses, without buying or accrediting new software. This page is the orientation: the government cloud tiers (GCC, GCC High, and Office 365 DoD), the SRG impact levels that govern them, what apps you actually get, how CUI handling works at a high level, and where to go to start building.

At a glance

  • What it is: Microsoft 365 (Teams, SharePoint, OneDrive, Exchange/Outlook, Office apps, Lists, Power Platform) hosted in Microsoft's US government clouds and accredited under the DoD SRG to carry CUI.
  • Who operates it: Microsoft is the cloud service provider; each DoD component runs its own tenant. The Navy's tenant is Flank Speed.
  • The three government tiers: GCC (entry tier, FedRAMP High), GCC High (designed to SRG Level 4 controls), and Office 365 DoD (designed to SRG Level 5 controls, exclusive to the Department of Defense).
  • Impact levels (SRG): IL2 (public/non-critical), IL4 (CUI), IL5 (CUI needing more protection than IL4, and unclassified National Security System data), IL6 (classified up to Secret, on a dedicated SIPRNet-connected enclave). Set by DISA.
  • Flank Speed's level: described as operating at Impact Level 5 (IL5) — the level Microsoft's Office 365 DoD cloud is designed to.
  • Access: CAC-authenticated; MFA with a federated identity model that supports PIV/CAC. Not a public website.
  • Build your own tools: Power Apps and Power Automate are available in the DoD cloud (see the spokes below), so you can build supply/status trackers on top of SharePoint and Lists.

What the DoD M365 environment is

At its core, this is the same Microsoft 365 apps you already know, deployed in a different, more tightly controlled place. Commercial Microsoft 365 runs in Microsoft's global public cloud. The DoD version runs in Microsoft's US government clouds, which are physically and logically segregated from the commercial infrastructure, keep customer content stored within the United States, and restrict administrative access to screened US-citizen personnel. That segregation is what lets the environment be accredited to carry government-controlled data.

It is not one single system. Microsoft operates several distinct US government environments, and DoD then runs its own tenant inside the appropriate one. A tenant is a component's private instance — its own users, mailboxes, Teams, SharePoint sites, and data. So "the DoD M365 environment" is really "Microsoft's government cloud, in which the Navy runs Flank Speed, the Army runs Army 365, and so on." Everything on this page is about that shared platform layer; the Navy-specific tenant is covered on the Flank Speed page.

For identity, the government environments authenticate with multifactor authentication using a federated identity model that supports PIV and CAC cards — which is exactly how a DoD user signs in. There is no anonymous, public front door.

The government cloud tiers: GCC, GCC High, and Office 365 DoD

Microsoft's US government Microsoft 365 comes in three tiers, and they are not interchangeable. Which one an organization is in determines what data it can hold and who it can collaborate with.

  • GCC (Government Community Cloud). The entry government tier, for US federal, state, local, and tribal governments and contractors holding or processing data on behalf of the US government. It provides compliance including FedRAMP High.
  • GCC High (Government Community Cloud – High). Designed according to Department of Defense (DoD) Security Requirements Guidelines Level 4 controls and supporting strictly regulated federal and defense information. It is used by federal agencies, the Defense Industrial Base (DIB), and government contractors — for example, contractors handling CUI or subject to ITAR. GCC High is assessed using NIST SP 800-53 controls at a FIPS 199 High categorization.
  • Office 365 DoD. Designed according to DoD Security Requirements Guidelines Level 5 controls and for the exclusive use of the US Department of Defense. Per DoD requirements, only Department of Defense entities may purchase licenses for the Office 365 DoD environment.

The practical distinction that trips people up: GCC High and Office 365 DoD are different tiers. GCC High is often used by DoD contractors (the Defense Industrial Base) and by agencies that need Level 4–aligned controls; the Office 365 DoD tier is reserved for the Department of Defense itself and is designed to the higher Level 5. For a uniformed logistician on a Navy tenant, the environment you touch is the DoD side — Flank Speed.

Impact levels and accreditation: the DoD SRG

The reason these tiers exist is the DoD Cloud Computing Security Requirements Guide (SRG). The SRG is maintained by the Defense Information Systems Agency (DISA) and defines the baseline security requirements the DoD uses to assess a cloud service provider's security posture — the assessment that supports granting a DoD Provisional Authorization (PA) to host DoD missions. It builds on the FedRAMP baseline and maps to the DoD Risk Management Framework.

The SRG sorts data into Information Impact Levels, which is the vocabulary you will hear constantly:

  • IL2 — publicly available or non-critical mission information; low confidentiality.
  • IL4Controlled Unclassified Information (CUI) and other non-national-security-system data up to moderate confidentiality/integrity.
  • IL5CUI that requires a higher level of protection than IL4, and unclassified National Security System (NSS) data. IL5 also carries additional separation requirements — for example, physical separation from non-DoD and non-federal tenants and restriction of access to US-citizen CSP employees.
  • IL6classified national security information up to the Secret level, which requires a dedicated cloud enclave connected to SIPRNet.

Mapping this back to the tiers: GCC aligns to IL2, GCC High is designed to SRG Level 4, and Office 365 DoD is designed to SRG Level 5. This is why a DoD logistician's environment can lawfully carry CUI: the underlying cloud is accredited for it. It is also why you cannot put classified material there — unclassified DoD M365 tops out at IL5; classified is IL6, a physically separate SIPRNet-connected enclave.

Where Flank Speed sits

The Navy's tenant, Flank Speed, is the Navy's transition to an improved Microsoft 365 cloud collaboration environment, and Navy and defense reporting describes it as running on the Navy's unclassified Impact Level 5 (IL5) Azure and Microsoft 365 cloud, supporting CUI. IL5 is the level Microsoft's Office 365 DoD cloud is designed to, which is consistent with Flank Speed being a DoD-tier tenant.

What's available to you

Inside a DoD Office 365 tenant, the in-scope services documented by Microsoft include Exchange Online, Microsoft Teams, SharePoint Online, OneDrive for Business, Office Online (Office for the web), Bookings, and supporting services. In plain terms, for a logistics shop that means:

  • Outlook / Exchange Online — email and calendar.
  • Microsoft Teams — chat, meetings, and the front door to shared files and apps.
  • SharePoint Online — the document libraries and sites that back your Teams and hold your shop's files.
  • OneDrive for Business — your individual file storage.
  • Office apps — Word, Excel, PowerPoint, in the browser and desktop.

Two more capabilities matter specifically because they let you build tools, not just store files:

  • Microsoft Lists — a lightweight, structured "smart list" that sits on top of SharePoint. This is the closest thing to a no-code database in the environment, and it is the natural home for a parts tracker, a status board, or an equipment log.
  • The Power Platform (Power Apps + Power Automate) — low-code app building and workflow automation, available in the government clouds (details below).

Not everything from commercial Microsoft 365 is present. Microsoft documents feature differences in GCC High and DoD — for instance, Viva Engage for enterprise is not available in the GCC High and DoD environments, and PSTN Calling and PSTN Conferencing are not available (Teams Phone System and Audio Conferencing are instead delivered via Direct Routing). Assume near-parity, but verify any specific feature against your tenant.

Access and licensing

Access is CAC-authenticated through the federated PIV/CAC model described above; there is no self-service public login. Licensing is handled by your component, not by you: the DoD tenant, its Microsoft 365 plans, and which add-ons (like Power Apps/Power Automate premium capabilities) are enabled are decisions your organization makes. The government environments are not sold with trials and go through an eligibility validation before a tenant is established, and only DoD entities can buy the Office 365 DoD tier.

For the Navy specifically, getting onto the environment — including from a personal or non-government-furnished device — is covered on the Flank Speed page and the Nautilus Virtual Desktop guide.

Data handling and CUI (high level)

The single most useful thing to internalize: the cloud being accredited for CUI is a precondition, not a permission slip. IL4 and IL5 mean the environment can hold Controlled Unclassified Information — IL5 for CUI that needs protection beyond IL4, and for unclassified National Security System data — but which CUI goes where, how it is marked, and how it is shared are still governed by DoD and component policy and the government-wide CUI program.

A few high-level guardrails:

  • Classified never goes here. The unclassified DoD M365 environment tops out at IL5. Classified information (up to Secret) is IL6, a separate SIPRNet-connected enclave. Do not place classified material in Flank Speed or any unclassified tenant.
  • External sharing is restricted. In the government clouds, sharing is constrained — for GCC High, users can share only with other organizations in GCC High, and non-GCC-High email addresses on user profiles are not supported for alerts. Cross-command and external collaboration follow your tenant's configured rules, not commercial defaults.
  • CUI still has to be marked and handled correctly. CUI categories come from the National Archives (NARA) CUI Registry, and safeguarding expectations trace to instruments like NIST SP 800-171. "It's in an approved SharePoint site" does not remove the marking, dissemination-control, and records requirements.

Bottom line for a logistician: follow your command's guidance on which Teams, SharePoint sites, and Lists are approved for which information, and when in doubt, ask your information-system security officer or security manager before you put a data set somewhere new.

Build your own tools

The reason this environment is worth understanding as a platform and not just an inbox: you can build real logistics tools on it with no new procurement and no separate accreditation, because they inherit the environment you already operate in. The two most useful building blocks each have their own guide:

  • Power Apps and Power Automate for logisticians — low-code apps and automated workflows. Build a parts/status tracker with a simple form and an app front end, or wire up automated alerts (for example, notify a section when a tracked item changes status). This spoke covers what's available in the DoD cloud, premium licensing, connector availability, and governance/DLP considerations.
  • Teams, SharePoint, and Lists for logistics — the collaboration stack. Teams is the front door, SharePoint is the backend, and Lists is the lightweight database. This spoke walks through a logistics workspace pattern — a Team with channels, a document library, and a Lists tracker — plus permissions, external sharing, and records/CUI considerations in the government cloud.

Start with whichever matches your problem: reach for Lists first when you just need a shared, structured tracker; reach for the Power Platform when you need a real app, a form, or automation on top of that data.

Last verified

This page was last reviewed on 2026-07-04. The government cloud tiers (GCC/FedRAMP High, GCC High designed to SRG Level 4, Office 365 DoD designed to SRG Level 5), the SRG impact-level definitions (IL2/IL4/IL5/IL6), the CAC/PIV federated identity model, the in-scope DoD Office 365 services, the GCC-High external-sharing restriction, the "no trials / eligibility validation / DoD-only for the DoD tier" licensing facts, and Power Apps/Power Automate US Government availability (GCC High since September 2019 at IL4; DoD since April 2021 at IL5) are all confirmed against Microsoft Learn primaries (learn.microsoft.com, including its US-Gov and DoD IL5 pages) as cited inline. The one item held at a lower confidence and flagged for human check is the precise environment-type mapping of Flank Speed: it is stated at the Impact-Level-5 level (consistent with Office 365 DoD's design target), but the supporting Navy.mil / DON CIO / Navy Reserve pages returned HTTP 403 from the verification environment, so that detail rests on the Navy.mil press-release title/URL plus official-domain search snippets rather than a fetched .mil body — confirm against an accessible DON primary before publishing the tenant-type framing as definitive. To suggest a correction, use the site's correction path.

Frequently asked questions

What is the DoD Microsoft 365 environment?
It is Microsoft 365 — Teams, SharePoint, OneDrive, Exchange/Outlook, the Office apps, Lists, and the Power Platform — running in Microsoft's US government clouds rather than the commercial cloud, so it can carry Controlled Unclassified Information (CUI) under the DoD Cloud Computing Security Requirements Guide (SRG). Each DoD component runs its own tenant. The Navy's tenant is Flank Speed. You reach it with your Common Access Card (CAC).
What is the difference between GCC, GCC High, and Office 365 DoD?
They are three separate Microsoft 365 US government environments. GCC (Government Community Cloud) is the entry tier for federal, state, local, and tribal government and their contractors, supporting FedRAMP High compliance. GCC High is designed to Department of Defense Security Requirements Guidelines Level 4 controls and serves federal agencies, the Defense Industrial Base, and contractors handling CUI or ITAR data. Office 365 DoD is designed to DoD Security Requirements Guidelines Level 5 controls and is for the exclusive use of the US Department of Defense. GCC High is assessed against NIST SP 800-53 at a FIPS 199 High categorization; both GCC High and DoD deliver DFARS/ITAR-aligned commitments.
Is Flank Speed an Impact Level 5 environment?
Flank Speed is the Navy's unclassified Microsoft 365 / Azure environment and is described in Navy and defense reporting as operating at Impact Level 5 (IL5), the DoD SRG tier used for CUI needing more protection than IL4 and for unclassified National Security System data. IL5 is the level to which Microsoft's Office 365 DoD cloud is designed. Confirm the exact accreditation status of any specific workload with your command information-system security officer before you assume it can hold a given category of data.
What is the DoD Cloud Computing SRG and who owns it?
The DoD Cloud Computing Security Requirements Guide (SRG) is the baseline the Department of Defense uses to assess a cloud service provider's security posture and decide whether to grant a DoD Provisional Authorization to host DoD missions. It is developed and maintained by the Defense Information Systems Agency (DISA). It defines the Information Impact Levels — IL2, IL4, IL5, and IL6 — that describe how sensitive the data a cloud may hold is, and it builds on the FedRAMP baseline.
Can I use Power Apps and Power Automate in the DoD M365 environment?
Yes. Microsoft offers Power Apps and Power Automate US Government in both a GCC High deployment (designed to the DISA SRG IL4 framework, available since September 2019) and a DoD deployment (designed to the DISA SRG IL5 framework, available since April 2021), each with its own DISA Provisional Authority to Operate. The DoD deployment is only available to DoD entities and integrates with Microsoft 365 DoD. Whether a specific app, connector, or premium feature is turned on in your tenant depends on your component's licensing and governance.
Where can I store CUI in this environment?
Controlled Unclassified Information can be stored in the DoD M365 environment because the underlying cloud is accredited to carry it — IL4 and IL5 both accommodate CUI, with IL5 for CUI that needs more protection than IL4. But 'the cloud is accredited for CUI' is not the same as 'anything goes anywhere.' Marking, handling, sharing, and records rules still apply per DoD and component policy and the CUI program. Follow your command's guidance on which SharePoint sites, Teams, and Lists are approved for which categories, and never place classified information in an unclassified environment.
What Microsoft tools do I actually get as a DoD user?
In a DoD Office 365 tenant the in-scope services include Exchange Online (Outlook email), Microsoft Teams, SharePoint Online, OneDrive for Business, Office Online, and Bookings, among others. Microsoft Lists (built on SharePoint) and the Power Platform (Power Apps, Power Automate) are available in the government clouds as covered above. Some commercial features are not offered in GCC High and DoD — for example, Viva Engage for enterprise is not available, and certain telephony and messaging features differ.
Does the DoD M365 environment use my CAC?
Yes. Sign-in to the GCC High and DoD environments uses multifactor authentication with a federated identity model that supports PIV and CAC cards, which is how DoD users authenticate. For the Navy, that means signing in to Flank Speed with your CAC. If you are reaching the environment from a personal or non-government device, the Navy's route is the Nautilus Virtual Desktop.
Is this the same as the commercial Microsoft 365 I use at home?
No. It is the same family of apps, but it runs in physically and logically segregated US government datacenters, staffed by screened US-citizen personnel, and accredited under the DoD SRG. Data is stored in the United States, external sharing is restricted (in GCC High you can share only with other GCC High organizations), and some commercial features are absent. Treat it as a separate, controlled environment — not your personal Microsoft 365.

Last verified by the LogTool Editorial Team.