sha3:e02bf31ff32581c8ee5a916a752d948b18ecc51eff6e65b18afaa72c8f034300IntactAzure Policy / Defender for Cloud / Entra ID / GCC High
Azure-native. Commercial through GCC High.
PolicyCortex was built Azure-first and runs inside your subscriptions in commercial Azure, Azure Government, and GCC High. It reads Azure Policy, Defender for Cloud, Entra ID, and Resource Graph, records what the estate was, what changed it, and what machines were allowed to do, and every remediation handler ships with matched captureState and restoreState so rollback is a contract.
dc50cced62487ec6acb373477f61c8059bbaeb8ca057115eb26927ca27809d78prev:14ac4ab0f4d5What an Azure estate must prove
Azure Policy reports compliance for now; Defender for Cloud recommends for now; the activity log records that something changed. The assessor's questions are about then: what was this storage account's encryption setting, this Key Vault's network rule, this Conditional Access policy, as of the date they name, who or what changed it and under what authority, and what was any automated fix permitted to do before it ran.
Government tenants add a boundary question: which subscriptions under which management group sit inside the CUI enclave, and whether what is outside it was unobserved or simply not connected.
- azure.scope
- Management group through subscription to resource, scoped with Resource Graph (KQL). The declared boundary is a field on every record.
- azure.clouds
- Commercial Azure, Azure Government, GCC, and GCC High. GCC High is a first-class deployment target.
- azure.sources
- Azure Policy initiatives and compliance results, Defender for Cloud recommendations, Entra ID and PIM, Resource Graph. Reader at management-group scope for read-only onboarding.
- azure.frameworks
- CMMC Level 2, NIST 800-171, NIST 800-53, FedRAMP. Azure boundaries are supported for ATO packaging.
69b378b4d34ca766e804369749e9316d718b64591d4c71aefb8b2b4ea8587a9dprev:dc50cced6248The evidence produced from your subscriptions
Azure Policy is the execution layer. The record is what Azure Policy does not ship: state as of any date, the authority behind each change, and the envelope around each action. Where each proof files:
- Azure Policy · Defender
- Proof of state: compliance results and recommendations captured as point-in-time records with the raw ARM response attached, content hashed, regenerable to any date.
- Activity log · Entra ID
- Proof of change: who or what altered a resource, under what authority, with before and after hashes and a rollback identifier. PIM elevation is part of the authority on the record.
- ARM remediation
- Proof of agency: every remediation runs through native ARM operations, no agent required, inside an envelope and in the trust mode you set; GATED, a named human approving each action, is the default. Matched captureState and restoreState pairs make rollback a contract.
- Conditional Access · PIM
- Identity posture as evidence: which policies bound which principals as of a date, with MFA and PIM state carried on the record.
- Frameworks
- One control mapping per record: a storage encryption setting evidences NIST 800-171 3.13.16, 800-53 SC-28, and CMMC SC.L2-3.13.16 at once, written down, not implied.
ce3ba82c4d022890186119148360107e02236bbf88dd7172a5b592766a4f8d42prev:69b378b4d34cHow the record is verified across management groups
Across a management group the recomputation covers every connected subscription as one chain, and PIM elevation on a change is part of what the digest commits to, so authority cannot be revised after the fact.
Every record PolicyCortex writes for this obligation is content hashed with SHA3-256 and carries the digest of the record before it, so each line commits to the entire history above it. The log is append only: a correction is a new record, never an edit. Verification is a recomputation, not an assertion. Run the chain from the first record forward and it returns one of two answers: intact, or the sequence number of the first record that breaks.
A second party can do that recomputation without our help. The records, the digests, and the chain rule are everything required: no PolicyCortex account, no API of ours in the loop. When a collector was down or a scope was unobserved, the chain carries a declared gap with the interval and the reason, never silently fewer rows. Absence is declared, not inferred.
19c0df903bf0969fca5d92c936337c896810c100f841ed7bea646c60fe25db05prev:ce3ba82c4d02Access and onboarding in an Azure tenant
After access is reviewed and scope is agreed, read-only onboarding uses a service principal holding Reader at management-group scope. Azure Policy results, Defender recommendations, Entra ID, and Resource Graph are read, nothing is written, and Contributor is not needed for this read-only mode.
Request access so we can review your environment, evidence needs, and onboarding scope. After access is approved, read-only onboarding uses SHADOW mode inside your own tenant. Nothing executes. Policy evaluation, evidence collection, and action gating run where your data already is; there is no telemetry pipeline to PolicyCortex servers and no egress of evidence. You hold the records and can recompute the chain yourself.
- eval.mode
- SHADOW. Watch only; nothing executes.
- eval.onboarding
- Access is reviewed. Scope and onboarding are agreed with your team.
- eval.location
- Your tenant. Azure, AWS, and GCP are observed clouds, including AWS GovCloud, Azure Government, and GCC High.
- eval.egress
- None. No telemetry pipeline to PolicyCortex servers; no evidence leaves the tenant.
- eval.after
- You keep the records. Licensing is annual and the tenant owns the evidence; a delivery engagement is optional.
8ef29e0a939d82ff619248b9ff2a403326b93f9ee336ba73d81a0bb490238299prev:19c0df903bf0Delivery, if you want the record stood up for you
Licensing does not depend on it, but a fixed-scope delivery engagement is available: thirty days, one agreed primary cloud environment, an evidence package built and defended through assessor review. The independent assessor makes the certification decision. No certification is guaranteed.
The standard engagement scope is a CMMC Level 2 package in one primary environment; Azure Government and GCC High are in scope.
- engagement.scope
- Thirty days. One agreed primary cloud environment.
- engagement.outcome
- An evidence package built and defended through assessor review.
- engagement.limit
- The independent assessor decides. No certification is guaranteed.
e02bf31ff32581c8ee5a916a752d948b18ecc51eff6e65b18afaa72c8f034300prev:8ef29e0a939dQuestions assessors and buyers ask
Is GCC High supported?
Yes. PolicyCortex deploys in commercial Azure, Azure Government, GCC, and GCC High. The platform is Azure-first, so GCC High is a first-class deployment target.
Does this replace Azure Policy?
No. Azure Policy is the execution layer. PolicyCortex authors initiatives, deploys them at scope, and records the compliance results, then adds what Azure Policy does not ship: cross-framework mapping, gated remediation with a rollback contract, and a hash-chained record of state as of any date.
How does Defender for Cloud fit?
Defender recommendations are consumed and recorded. A high-severity recommendation gets a remediation proposed with a published confidence figure, gated for a named human's approval by default, applied through ARM with a rollback identifier armed first, and verified against the pinned target state.
What service principal permissions are needed?
Reader at the management-group scope for read-only onboarding. Contributor at the resource scope only where remediation is enabled. PIM-aware: just-in-time elevation is supported and is recorded as part of the authority behind each change.
Where does the data live?
In your own tenant. There is no telemetry pipeline to PolicyCortex servers and no egress of evidence.
What happens when a collector is down?
The chain carries a declared gap: the stream, the interval, the reason, and when it was declared. Evidence never silently has fewer rows.
Request access to review your Azure scope and onboarding needs.