Blog · 5 min read ·
ShareCopilot GCC: a setting that processes data outside FedRAMP
Since July 22, 2026 a Microsoft 365 admin center setting lets non-federal GCC customers enable Anthropic models in Copilot. It is optional and disabled by default. Microsoft states that when enabled, these models process Customer Data outside its FedRAMP-authorized U.S. Government cloud.
If you run Microsoft 365 in Government Community Cloud, a setting appeared in your admin center this summer that is worth an explicit decision rather than a default. And if you run commercial cloud with compliance obligations, there is a second setting further down the same page that matters more.
What changed in GCC, and when
Microsoft's own words:
“As of July 22, 2026, a new setting is available in the Microsoft 365 admin center that allows non-federal customers in GCC to use Anthropic models. This capability is optional and the setting is disabled by default.”
Two things about that are easy to miss. First, this is genuinely new — until July, Anthropic models were not available in government clouds at all and no toggle existed. Second, it is scoped tightly: non-federal GCC only. Microsoft is explicit that “Anthropic models aren't available for federal customers in GCC or for any customers in GCC High and Department of Defense (DoD) environments”, and that no option appears for them.
The sentence to put in front of whoever owns compliance
Microsoft flags the consequence itself, in an Important callout rather than a footnote:
“When enabled, these Anthropic AI models process Customer Data outside Microsoft's FedRAMP-authorized U.S. Government cloud. You should evaluate whether enabling this setting is consistent with your organization's data handling requirements.”
That is not a warning about a risk. It is a description of what the setting does. An organisation in GCC is usually there because of an authorisation requirement that data stays inside that boundary — which makes this a governance decision wearing the clothes of a feature toggle.
And a scoping trap worth naming. The setting supports restricting access to specific users or Entra security groups, which reads like a mitigation. It is not one. Limiting who can invoke the models limits who, not where. Data processed for those users still leaves the FedRAMP-authorized environment. If the boundary is the requirement, group scoping does not satisfy it — it only reduces the volume of the exception.
The second setting, which is the one we would look at first
Further down the same page is a distinction most summaries skip entirely, and it is the more consequential of the two. There are two different arrangements under which Anthropic models can run, and they sit on completely different legal footings.
Anthropic as a Microsoft subprocessor. The default arrangement. Microsoft states the Product Terms and Data Protection Addendum apply, use is covered under Enterprise Data Protection, and Anthropic “operates with Microsoft oversight through contractual safeguards”. Your existing agreement reaches it.
Anthropic models with Data Retention. A separate class, requiring a separate opt-in, and Microsoft is blunt about what changes:
“This means data is stored by Anthropic and not subject to your Microsoft Customer Agreement including commitments in the Product Terms and DPA. … In this scenario, Anthropic acts as an independent processor.”
Read that as a contracts person. The DPA you rely on — the document that answers the vendor questionnaire, underpins the BAA conversation, and defines what happens to your data — does not apply to that path. You are instead accepting Anthropic's own Commercial Terms of Service and Data Protection Addendum, directly.
The retention numbers, because they are specific
Microsoft publishes them rather than pointing vaguely at a partner policy:
“Anthropic (not Microsoft) stores most inputs and outputs for up to 30 days before deleting them. If Anthropic's trust and safety classifiers identify potential violations of Anthropic's Usage Policy, Anthropic may retain content (inputs and outputs) for up to two years and trust and safety classification scores for up to seven years.”
Microsoft also states that Anthropic “doesn't use retained data for model training without your express permission”, which is the reassurance most people are looking for and is not the same question as retention.
This is our read: the thirty-day figure is the one that will get quoted internally, and the two-year and seven-year figures are the ones that matter to a records-retention schedule. A classifier deciding a prompt looked like a policy violation is not an event you will know about, and it moves that content into a two-year hold at a processor your DPA does not cover.
⚠️ The safeguard is real, though: these models are off by default everywhere, including in regions where ordinary Anthropic models are on by default, and no user can reach them until an admin explicitly opts in. Nobody drifts into this. Somebody has to choose it.

Where commercial-cloud tenants stand
Outside government clouds the default runs the other way: Microsoft “enables Anthropic models on by default for most customers in commercial cloud (excluding EU/EFTA and UK)”. EU, EFTA and UK tenants have them off by default, and Anthropic-processed data is “currently excluded from the EU Data Boundary, and when applicable, in-country processing commitments”.
So the audit question differs by where you sit. In commercial cloud it is "has anyone turned this off, and did we decide to leave it on?" In GCC it is "has anyone turned it on?" Both are the same admin-center page and both take about five minutes.
What we would do this week
- Look at the page. Microsoft 365 admin center > Copilot > Settings > View all > AI providers operating as Microsoft subprocessors. You need AI Administrator or Global Administrator to change it; reading it is enough for now.
- Record the current state and the date you checked. Defaults differ by cloud and by region and they have moved twice this year. A screenshot with a date beats a memory.
- Check the Data Retention setting separately. It is a different control with different terms. Confirming it is off is a one-line answer to a question a client or auditor will eventually ask.
- If you are in GCC and someone wants this on, put the FedRAMP sentence in the change record. Quote Microsoft rather than paraphrasing. The decision may well be reasonable; what is not reasonable is making it without that sentence written down.
- Do not treat group scoping as a boundary control. It limits users, not processing location.
Sources
All quotations are from
Anthropic models in Microsoft Online Services
on Microsoft Learn (ms.date 2026-09-02), read in full on September 5, 2026.
⚠️ One note on sourcing, because it caught us. The public GitHub copy of this same article still states that Anthropic models aren't available in government clouds and that no toggle will be present — which was true before July 22, 2026 and is not true of the live page today. Several secondary write-ups repeat that older position. Check the live Learn page rather than a mirror or a summary, because this particular article has changed materially at least twice this year.
Related reading: our note on whether Microsoft Copilot is HIPAA compliant, which covers the BAA question that sits alongside this one.
If you would rather have the tenant audit, the decision record and the compliance-owner conversation handled as a bounded piece of work, scope it with us.
Questions we get asked
- What changed for GCC tenants?
- Microsoft's wording: 'As of July 22, 2026, a new setting is available in the Microsoft 365 admin center that allows non-federal customers in GCC to use Anthropic models. This capability is optional and the setting is disabled by default.' Before that date, Anthropic models were not available in government clouds at all and no toggle appeared. The toggle now exists for one specific population.
- Does enabling it keep data inside the FedRAMP boundary?
- No, and Microsoft says so directly in an Important callout: 'When enabled, these Anthropic AI models process Customer Data outside Microsoft's FedRAMP-authorized U.S. Government cloud. You should evaluate whether enabling this setting is consistent with your organization's data handling requirements.' Scoping the setting to a small group of users limits who can invoke it. It does not change where the processing happens.
- Who is excluded?
- Microsoft states: 'Anthropic models aren't available for federal customers in GCC or for any customers in GCC High and Department of Defense (DoD) environments. They're also not available in other sovereign clouds.' For those tenants no toggle appears at all, so there is no decision to make and nothing to audit.
- What are 'Anthropic models with Data Retention' and why do they matter more?
- They are a separate class with separate terms, off by default everywhere — including in regions where ordinary Anthropic models are on by default. The critical difference is legal rather than technical: Microsoft states that for these models 'data is stored by Anthropic and not subject to your Microsoft Customer Agreement including commitments in the Product Terms and DPA', and that 'Anthropic acts as an independent processor'. Enabling them requires accepting Anthropic's own Commercial Terms of Service and Data Protection Addendum.
- How long is data retained under that second setting?
- Microsoft describes it as: Anthropic 'stores most inputs and outputs for up to 30 days before deleting them. If Anthropic's trust and safety classifiers identify potential violations of Anthropic's Usage Policy, Anthropic may retain content (inputs and outputs) for up to two years and trust and safety classification scores for up to seven years.' Microsoft adds that Anthropic doesn't use retained data for model training without your express permission.
Related service
Identity, security and complianceWritten by the team at Pro IT NW · Senior-led Microsoft project consultancy · Seattle and the Pacific Northwest, delivered USA-wide.