Skip to content
CUI Trackby inDirectIT

Managed CUI enclave · Microsoft 365 GCC High

Built for the future.Ready for today.

Compliant by design.AI enabled by default.

One operated GCC High enclave for the people who handle CUI. The rest of the business stays outside the assessment.

OUT OF SCOPECorporate networkEveryday emailShop floor PCsYour MSPCUI from primes and DoDCUI TRACK · GCC HIGHTeamsCHAT · MEETINGSExchangeMAILSharePointLIBRARIESOneDriveFILESNAMED USERSJRAMKT+SSPCURRENTBOUNDARY HELD
60 days
Standard, to ready
14 days
Express, to ready
4 workloads
Teams, Exchange, SharePoint, OneDrive
CMMC L2
Operator certified, 2025

A wide network is a wide assessment.

If CUI lands in everyday mail, shared drives, and shop-floor PCs, the boundary follows it. CUI Track pulls that work into one operated environment so the corporate network can stay out of scope.

Built for the future. Ready for today.

Two defaults, set on the first day.

COMPLIANT BY DESIGN

The controls are the build, not a layer on top of it.

  • Identity, mail, files, and logging are configured for the enclave from the first station
  • The System Security Plan is written with the build and kept current after it
  • Only named people who handle CUI get access, and every change is a tracked request
  • Operated by a firm that holds CMMC Level 2 on the same Microsoft stack

AI ENABLED BY DEFAULT

AI runs inside the boundary, not beside it.

  • Purview labels and DLP are in place before any AI touches a file
  • Nothing is sent to a commercial AI endpoint outside the boundary
  • Access, prompts, and outputs are logged as evidence an assessor can test
  • GCC High native, so AI work stays in the same federal cloud as the CUI

Every enclave is built AI-ready. Three add-on tiers turn AI on, starting with flows at $0 a month in Microsoft AI cost. See the AI tiers. Microsoft licensing, including any AI licensing, is billed by Microsoft.

Inside the enclave

Microsoft 365. Not a new application.

Microsoft 365 Business Premium on GCC High, plus the Defender and Purview add-on. The work happens in the apps your people already know.

Teams

The people who handle CUI, in one place.

Exchange

Mail that stays in scope.

SharePoint

The library the boundary owns.

OneDrive

Files that do not leave.

The path

Four stations. One boundary.

  1. STATION 01

    Draw the flow

    We name where CUI is created, received, stored, and sent. If a system never sees it, it stays off the map.

    Output: a CUI flow map and the list of people who actually handle it.

  2. STATION 02

    Build the boundary

    The working environment sits on Microsoft 365 GCC High. Identity, mail, files, and logging are designed for that box, not bolted onto the corporate network.

    Output: the enclave, configured and documented as one system.

  3. STATION 03

    Name the users

    Only the people who handle CUI are onboarded. Everyone else keeps the tools they already use.

    Output: named identities with access scoped to the work.

  4. STATION 04

    Hold the evidence

    The System Security Plan and the remaining customer work stay current. The boundary does not replace policy, physical security, or your existing MSP.

    Output: ready for an assessment or a self-attestation.

The edge

A defined edge, and a clear owner on each side.

INSIDE THE BOUNDARY · OPERATED BY US

  • Microsoft 365 GCC High for the CUI workload
  • Named user identities and access
  • Encrypted mail, files, and retention for that environment
  • Logging and backup designed with the boundary, not after it

STILL YOURS

  • Systems that never see CUI
  • Your MSP or internal IT for the corporate network
  • Physical security and the policies outside the enclave
  • The decision of who is allowed to handle CUI

Enclave Console

Managed where you already see your program.

Your enclave lives in the inDirectIT client portal, next to your SSP, POA&M, and evidence: the build station and day count, named users and seats, the four workloads, and every change request.

Module in build. Status stated honestly on the tour.

portal.indirectit.com/platform/enclave

CUI Track enclave

ACME DEFENSE MFG · GCC HIGH

STANDARD · 60 DAYSDAY 38 OF 60
  1. 01

    Draw the flow

  2. 02

    Build the boundary

  3. 03

    Name the users

  4. 04

    Hold the evidence

Named users
4
3 included · 1 added
Business Premium
4
GCC High seats
Defender + Purview
4
Add-on seats
Change requests
1
Add user · open

NAMED USERS

NameRoleMFADevice
J. ReyesAuthenticatorCompliant
A. MossFIDO2 keyCompliant
K. TranAuthenticatorCompliant
L. OrtizPendingEnrolling

WORKLOADS

  • TeamsCONFIGURED
  • ExchangeCONFIGURED
  • SharePointCONFIGURED
  • OneDriveIN BUILD
Illustrative preview with sample data. The Enclave module is in build; records are kept by the inDirectIT delivery team, not collected live from the tenant. The portal holds no CUI.

The operator

Built by a firm that already holds CMMC Level 2.

inDirectIT builds and runs CUI Track. The same team runs its own Level 2 program on the Microsoft stack: GCC High, Intune, Defender, and Purview where the workload calls for them. The second engagement should look like the first.

Level 2
inDirectIT certification, 2025
GCC High
The stack we run ourselves
Operator
Not a replacement MSP
CUI Track at indirectit.com

ONE OPERATOR · ONE BOUNDARY

Price

60 days. Or 14, with express.

Ready for an assessment or a self-attestation. Everything after setup is the same on both paces. Microsoft licensing is billed by Microsoft and is not in these figures.

STANDARD

$15,000

setup, once

Ready in 60 days

EXPRESS

FASTEST

$50,000

setup, once

Ready in 14 days

THEN, ON BOTH

$1,000
each month, through 3 users
$325
each added user, each month
$6,500
compliance management, each year

We already have an MSP.

Good. CUI Track does not take over the corporate network. Your MSP keeps it.

Is this another product login?

No. It is an operated environment with a defined edge. People work in Microsoft 365.

We are not assessment-ready.

Start with the flow. The boundary comes after the map is honest.

Who sees the enclave’s status?

You do, in the inDirectIT client portal, next to your SSP, POA&M, and evidence.

Boundary review

Draw the flow first.

Thirty minutes on where CUI actually moves. We will tell you if CUI Track fits, and if it does not.