Quick answer. As of September 2026, whichever directory authenticates the users who reach CUI provides a security function to the CMMC Level 2 assessment scope, so keeping on-premises Active Directory as the identity authority brings its domain controllers and the Microsoft Entra Connect server, which Microsoft’s Prerequisites for Microsoft Entra Connect says must be treated as a Tier 0 component, into that scope, while a cloud-only Microsoft Entra ID in the CUI tenant can keep the corporate forest out at the cost of a second identity and its own lifecycle. According to 32 CFR part 170, the security requirements in CMMC Level 2 are identical to those in NIST SP 800-171 R2, and NIST SP 800-171 Revision 2 applies to components that provide security protection for CUI components and requires multifactor authentication for local and network access to privileged accounts and for network access to non-privileged accounts (3.5.3). Where the CUI tenant is GCC High, Microsoft’s Topologies for Microsoft Entra Connect page says verifying the same custom domain in two tenants is not supported, Microsoft’s Protect Microsoft 365 from on-premises attacks recommends cloud-only accounts for privileged roles; the final scope is the contractor’s to document and the C3PAO’s to assess.
The readiness meeting has drawn the CUI boundary around a Microsoft 365 tenant, often a new GCC High tenant, and someone asks the question the diagram does not answer: where do the users’ passwords actually live? If the people who handle CUI sign in with accounts synchronized from the corporate forest, you suspect the assessment will follow that trust back into a forest that grew over many years and was never built to be assessed. If they sign in with cloud-only accounts in the CUI tenant, you inherit a second identity for every one of them and a joiner and leaver process that has to keep both in step. Go wrong one way and remediating a forest no one fully inventoried becomes the critical path to the certification the business needs to win work. Go wrong the other way and the access-control evidence fails anyway, because the second identity drifted from HR. This guide works through the decision from the rule’s own definitions and Microsoft’s own constraints, and it leaves the final scope where the rule puts it: with the contractor who documents it and the C3PAO who assesses it.
Why the identity choice decides how much of the estate gets assessed
When the boundary diagram is drawn, the question is not whether identity gets assessed but how much of the estate comes into the assessment with it. The rule starts from the scope itself. 32 CFR part 170 states: “CMMC Assessment Scope means the set of all assets in the OSA’s environment that will be assessed against CMMC security requirements.” The same part defines the category that matters here: “Security Protection Assets (SPA) means assets providing security functions or capabilities for the OSA’s CMMC Assessment Scope.”
The rule’s Level 2 asset table, in 32 CFR part 170, says what a contractor does with those assets. It documents them in the asset inventory, records their treatment in the system security plan, shows them on the network diagram of the CMMC Assessment Scope, and prepares them to be assessed against the Level 2 security requirements that are relevant to the capabilities they provide. The same part keeps them from being argued away: its definition of out-of-scope assets carries the exception “except for assets that provide security protection for a CUI asset”, and its definition of Security Protection Data includes “passwords that grant access to the in-scope environment”.
NIST reaches the same place from the requirements side. NIST SP 800-171 Revision 2 states: “The security requirements apply to the components of nonfederal systems that process, store, or transmit CUI, or that provide security protection for such components.” It also names the lever a contractor has: “If nonfederal organizations designate specific system components for the processing, storage, or transmission of CUI, those organizations may limit the scope of the security requirements by isolating the designated system components in a separate CUI security domain.”
The contractor’s own reasoning from those definitions, which is a planning reading and not words the rule uses, runs like this. A directory that authenticates the people who reach CUI is providing a security function to the assessment scope, and the passwords it holds grant access to the in-scope environment. So the identity authority is documented and assessed with the boundary whichever directory it is, and where it lives decides what else comes in with it. The contractor writes that reasoning into its own scoping documentation, and the C3PAO decides whether it holds.
If your question is broader than the CUI boundary, and is really which identity platform fits a hybrid enterprise, start with Which IAM Platforms Fit a Complex Hybrid Enterprise: How to Decide.
What the identity authority must carry, whichever you choose
Whichever directory you make authoritative will be asked to show the same identity requirements, and the failure mode is choosing a shape before checking which directory can produce the evidence. According to 32 CFR part 170, the security requirements in CMMC Level 2 are identical to the requirements in NIST SP 800-171 R2. NIST SP 800-171 Revision 2 sets out the requirements an identity authority carries most directly:
- 3.1.1: “Limit system access to authorized users, processes acting on behalf of authorized users, and devices (including other systems).”
- 3.5.1: “Identify system users, processes acting on behalf of users, and devices.”
- 3.5.2: “Authenticate (or verify) the identities of users, processes, or devices, as a prerequisite to allowing access to organizational systems.”
- 3.5.3: “Use multifactor authentication for local and network access to privileged accounts and for network access to non-privileged accounts.”
- 3.5.7: “Enforce a minimum password complexity and change of characters when new passwords are created.”
- 3.5.8: “Prohibit password reuse for a specified number of generations.”
For a hybrid design, Microsoft documents how on-premises password policy reaches the cloud. Microsoft’s Configure CMMC Level 2 Identification and Authentication (IA) controls page states: “For customers that require strict password character change, password reuse and complexity requirements use hybrid accounts configured with Password-Hash-Sync.” The same page says the passwords synchronized to Microsoft Entra ID then inherit the restrictions configured in Active Directory password policies. That page predates the final rule, and this guide uses it for that configuration fact only.
List, for each candidate directory, which of these requirements it enforces and where the evidence for each is produced. The full control-family mapping for Microsoft 365 lives on Microsoft 365 CMMC Compliance Consulting: Product Scope and Audit Evidence, and this guide does not repeat it.
Shape A: keep on-premises Active Directory authoritative
If the CUI users keep signing in with accounts synchronized from the corporate forest, the forest comes with them, and the question becomes whether that forest can stand being assessed. The synchronization server is the first thing Microsoft names. Microsoft’s Prerequisites for Microsoft Entra Connect page states: “The Microsoft Entra Connect server must be treated as a Tier 0 component as documented in the Active Directory administrative tier model.”
Microsoft also describes the path an attacker takes through that trust. Microsoft’s Protect Microsoft 365 from on-premises attacks page states: “The two primary threat vectors are federation trust relationships and account synchronization.” The same page adds: “If threat actors compromise the on-premises environment, these trust relationships become opportunities for them to also compromise your Microsoft 365 environment.”
Read with the definitions above, the contractor’s planning reading for Shape A is that the domain controllers authenticate the CUI users and hold the passwords that grant access to the in-scope environment, and the Microsoft Entra Connect server carries those identities into the CUI tenant, so all of them are documented and assessed with the boundary. Shape A fits when the forest is already small, inventoried and hardened, or when the CUI users cannot practically carry a second identity. What it costs is the forest itself, its domain controllers and the sync server, documented and assessed as part of the scope. How those users authenticate is a separate decision, and this guide does not compare the authentication models.
Shape B: a cloud-only Microsoft Entra ID in the CUI tenant, and the GCC High case
If the forest is too large or too old to put in front of an assessor, the alternative is an identity the forest does not feed, and it has its own price. Microsoft’s own guidance points this way for the accounts that matter most. Microsoft’s Protect Microsoft 365 from on-premises attacks page states: “Use cloud-only accounts for Microsoft Entra ID and Microsoft 365 privileged roles.”
A separate CUI tenant is a deliberate departure from Microsoft’s default. Microsoft’s Topologies for Microsoft Entra Connect page states: “We recommend having a single tenant in Microsoft Entra ID for an organization.” The same page sets the constraint that shapes every naming plan: “It’s not supported to add and verify the same custom domain name in more than one Microsoft Entra tenant, even if these tenants are in different Azure environments.” A commercial tenant and a separate CUI tenant, a GCC High tenant included, cannot both verify the corporate domain, so the CUI users need a domain of their own.
The contractor’s planning reading for Shape B follows from the rule’s out-of-scope definition in 32 CFR part 170 and the separate security domain that NIST SP 800-171 Revision 2 allows: when nothing in the corporate forest authenticates CUI users or otherwise protects a CUI asset, the contractor can document the forest outside the boundary, and the C3PAO assesses that reasoning. What it costs is a second identity for every CUI user, a joiner, mover and leaver process that keeps that identity in step with the first, because 3.1.1 still asks the contractor to limit system access to authorized users, and a domain of its own in the CUI tenant. If the CUI tenant is fed by a synchronization engine rather than managed cloud-only, which engine to use is a separate decision this guide does not make.
Whether the CUI tenant should be GCC or GCC High is its own question, answered on Does CMMC Require GCC High? What the Rule Actually Requires for Defense Contractors; this guide takes the tenant as given. Moving identity and data into a new GCC High tenant is planned on Microsoft 365 GCC High Migration Checklist: Best Practices for Defense Contractors.
Shape C: a separate forest or domain for CUI, and when it is worth it
Some CUI work cannot leave on-premises authentication behind, because it runs on domain-joined servers or on-premises applications, and a cloud-only identity does not remove the need for a directory there. For that case the option is a separate forest or domain for CUI, synchronized into the CUI tenant, and Microsoft’s rules still apply to it. Microsoft’s Topologies for Microsoft Entra Connect page says a Microsoft Entra Connect server is deployed for every tenant to be synchronized, because “one Microsoft Entra Connect server can’t synchronize to more than one Microsoft Entra tenant”, and it states: “It’s supported to configure Password Hash Sync from Active Directory to multiple Microsoft Entra tenants for the same user object.”
A dedicated forest is still synchronized by a Microsoft Entra Connect server that Microsoft’s Prerequisites for Microsoft Entra Connect page places at Tier 0, so the smaller forest and its sync server come into scope in place of the larger one. Where the CUI tenant sits in the Azure Government cloud, Microsoft’s Hybrid identity considerations for the Azure Government cloud page states: “To integrate a Microsoft Active Directory environment (either on-premises or hosted in an IaaS that is part of the same cloud instance) with the Azure Government cloud, you need to upgrade to the latest release of Microsoft Entra Connect.” This guide names Shape C as an option and does not describe the design of the forest itself.
Device join and management follow the identity choice, and the device side is covered on Is Microsoft Intune CMMC Compliant? What It Covers, and What It Does Not.
The version and the clock
If a team is mapping controls against the newest NIST revision because it is the newest, it is mapping against the wrong text. According to 32 CFR 170.14(c)(3), “The security requirements in CMMC Level 2 are identical to the requirements in NIST SP 800-171 R2.” NIST’s own NIST SP 800-171 Rev. 2 page marks that revision withdrawn on May 14, 2024 and superseded by SP 800-171 Rev. 3. Both facts stand at once: the requirement numbers on this page are Rev 2’s because the rule names Rev 2. For the current phase-in clock, see i3solutions’ Which CMMC Level Applies to You, and When Does It Start?.
When this framing is wrong
A decision guide that fits every contractor fits none of them, so test yours against the cases where this framing breaks, using 32 CFR part 170 and NIST SP 800-171 Revision 2:
- The corporate forest is already small, current and hardened: Shape B’s second identity can cost more in joiner and leaver errors against 3.1.1 than it saves in scope.
- CUI work depends on domain-joined servers or on-premises applications: a cloud-only identity does not remove the directory there, and Shape C or Shape A is the honest answer.
- The contract calls for Level 2 (Self) rather than Level 2 (C3PAO): the rule describes a Level 2 self-assessment as the contractor evaluating its own information system, and the scoping reasoning still has to be written down.
- The real question is GCC versus GCC High, a non-Microsoft identity provider or which sync engine to run: this is the wrong guide for it.
No design removes the assessment. Microsoft’s Configure Microsoft Entra ID for CMMC compliance page states: “To be compliant with requirements in CMMC, it’s the responsibility of companies performing work with, and on behalf of, the US Dept. of Defense (DoD) to complete other configurations or processes.”
What to ask of whoever helps you decide, and how i3solutions answers
A scoping decision you cannot show on paper is one the assessment will reopen, so hold whoever helps you decide to criteria drawn from 32 CFR part 170, NIST SP 800-171 Revision 2 and Microsoft’s Topologies for Microsoft Entra Connect:
- Show every directory, sync server and trust that touches a CUI user, with the asset category proposed for each and why.
- Show which of 3.1.1, 3.5.1, 3.5.2, 3.5.3, 3.5.7 and 3.5.8 each directory enforces, and the evidence each produces.
- Show the domain and account plan if the CUI tenant is GCC High, given that one custom domain cannot be verified in two tenants.
- Show how joiners, movers and leavers reach the CUI identity, and how fast.
- Show that privileged roles in the CUI tenant are cloud-only, or say why not.
- Show what is left for your own team to run and to evidence after the work ends.
i3solutions has deep experience implementing identity governance for enterprises in aerospace and defense manufacturing, financial services, and healthcare, including environments with CMMC and ITAR obligations. The work described in this guide is delivered as a project, with specialists embedded in your team where it needs them: designing which directory is authoritative for the CUI boundary and how the forest, the sync server and the tenant are placed, configuring Microsoft Entra ID, Conditional Access and Privileged Identity Management, moving identity into a GCC High tenant where that is the boundary, and documenting the design for your system security plan and your own assessment. We manage GCC High migrations end-to-end: from eligibility validation and licensing coordination with your AOS-G supplier through identity architecture, data migration, security baseline configuration, and post-migration governance. i3Solutions plans and runs these migrations for regulated defense organizations, structuring each phase around the compliance evidence assessors expect. i3solutions governs identity and access for regulated Microsoft estates with senior, U.S.-based engineers and leaves an audit-defensible record.
The i3solutions Federal Compliance Assessment evaluates a client tenant against NIST SP 800-53 and CMMC using automated tenant configuration scripts and a 42-point security checklist. An i3solutions engagement does not produce managed-service ownership, a replacement for the internal team, open-ended scope expansion, or vendor lock-in. For how this fits a wider identity program, see Establish Identity as a Governed Enterprise Capability.
Key Takeaways
Drawn from 32 CFR part 170, NIST SP 800-171 Revision 2 and Microsoft’s Topologies for Microsoft Entra Connect:
- The identity authority for CUI users is assessed with the boundary whichever directory it is; the choice decides what comes in with it.
- Keeping on-premises Active Directory authoritative brings the domain controllers and the Microsoft Entra Connect server, which Microsoft places at Tier 0, into the contractor’s scoping.
- A cloud-only Microsoft Entra ID in the CUI tenant can keep the corporate forest out, at the cost of a second identity, its own lifecycle and a domain of its own.
- Microsoft does not support verifying the same custom domain in two tenants, and recommends cloud-only accounts for privileged roles.
- CMMC Level 2 is pegged to NIST SP 800-171 R2, which NIST has withdrawn.
- The scope is the contractor’s to document and the C3PAO’s to assess.
Frequently Asked Questions
Is on-premises Active Directory in scope for CMMC Level 2 if users sync to Entra ID?
It depends on the contractor’s documented scoping, which the C3PAO assesses. According to 32 CFR part 170, Security Protection Assets are assets providing security functions or capabilities for the CMMC Assessment Scope, and according to NIST SP 800-171 Revision 2, its requirements apply to components that provide security protection for CUI components. According to Microsoft Learn, the Microsoft Entra Connect server must be treated as a Tier 0 component, so a contractor whose CUI users sync from on-premises Active Directory has to account for the forest, its domain controllers and the sync server in its scoping reasoning.
Can we use the same domain name in our commercial tenant and a GCC High tenant?
No. According to Microsoft Learn, it is not supported to add and verify the same custom domain name in more than one Microsoft Entra tenant, even if these tenants are in different Azure environments, so a GCC High tenant alongside a commercial tenant needs a domain of its own.
Does CMMC Level 2 use NIST SP 800-171 Rev 2 or Rev 3?
Rev 2. According to 32 CFR part 170, the security requirements in CMMC Level 2 are identical to the requirements in NIST SP 800-171 R2. According to NIST, Rev 2 was withdrawn on May 14, 2024 and superseded by Rev 3, but the rule still names R2, so the requirement numbers a Level 2 assessment uses are Rev 2’s.
Should privileged admin accounts in the CUI tenant be synchronized from Active Directory?
According to Microsoft Learn, Microsoft recommends cloud-only accounts for Microsoft Entra ID and Microsoft 365 privileged roles, and names account synchronization, beside federation trust relationships, as a primary threat vector by which a compromised on-premises environment reaches Microsoft 365.
Planning the Decision
If the boundary diagram is drawn and the identity question is still open, start by listing every directory, sync server and trust that touches a CUI user, decide which shape the forest can honestly support, settle the domain and privileged-account plan for the CUI tenant, and write the reasoning into the system security plan before CMMC Phase 2 reaches your contracts (a Defense Department CIO memo of July 13, 2026 suspended its November 2026 start).
