Blog > Keeping Government Project Data Inside Microsoft 365

Keeping Government Project Data Inside Microsoft 365

August 4, 2026 9 min read

Government project data security requires exact details, not broad promises. At BrightWork, we use the phrase “inside Microsoft 365” carefully because agencies need to know the exact cloud, tenant, Power Platform environment, and storage service holding their project records.

The same standard should apply to every product built on Microsoft Power Platform. A product might keep core project records in an agency-controlled Dataverse environment. That fact helps the security review.

It does not automatically confirm product support for GCC, GCC High, or DoD. It also does not grant the product a Microsoft authorization or guarantee agency compliance.

Here is what you need to verify before approval:

  • How to define the boundary around government project records.

  • Why the exact Microsoft cloud and service matter.

  • Which identity, permission, and administrator checks to run.

  • How reports, connectors, exports, and AI create extra access paths.

  • What evidence to request from a project software vendor.

Define the Government Project Record Boundary

Project portfolios track planned investments, budgets, vendor activity, and delivery risks. A summary report often combines sensitive details from multiple projects. This exposes patterns no single project record shows.

The security review must cover more than the main project database. Map each record type to its specific service:

  • Project requests, project fields, risks, issues, and status

  • Documents and attachments

  • Teams messages and meeting material

  • Approval emails and notifications

  • Power BI models, reports, subscriptions, and exports

  • Power Automate flows and connector payloads

  • Audit logs and diagnostic data

  • Support cases and temporary support access

  • Backup and recovery copies

  • AI prompts, retrieved records, output, and logs

For each item, record the owner, storage service, environment, region, access groups, retention treatment, export paths, and external processors. The result becomes a working data map for PMO, IT, security, records, and procurement teams.

Start With the Exact Microsoft Cloud and Service

“Microsoft 365 Government” covers several distinct offerings. An agency might use commercial Microsoft 365, Government Community Cloud (GCC), GCC High, or DoD services. Eligibility, identity setups, endpoints, commitments, and feature coverage differ across these options.

Microsoft’s Office 365 Government service description distinguishes GCC, GCC High, and DoD commitments. It tells customers to read the government description alongside the description for each specific service in scope.

That service-by-service method matters heavily for project software. A solution might depend on:

  • Power Apps

  • Dataverse

  • Power Automate

  • Power BI

  • SharePoint Online

  • Teams

  • Outlook

  • Microsoft Entra ID

  • Standard or custom connectors

Confirm Every Required Component in the Intended Cloud

The agency must confirm that every required component and feature is available in the intended cloud. Availability in a commercial Power Platform environment does not guarantee availability in a Government cloud.

Microsoft’s Power Apps US Government documentation describes customer-content location, personnel access, eligibility, identity differences, third-party services, and feature exceptions for the named Power Apps Government offerings. Those statements apply to the Microsoft service itself. They do not automatically apply to an application installed on top of it.

Treat Data Location as a Service-Specific Claim

Government buyers need concrete proof of data residency or sovereignty. The documented wording should identify:

  • The exact data category.

  • The Microsoft service.

  • The named cloud.

  • The storage state, such as data at rest.

  • The geographic commitment.

  • Replication or recovery conditions.

  • Connected services outside the boundary.

Microsoft states Power Apps US Government customer content at rest stays in US datacenters. It sits physically segregated from commercial Power Apps customer content. The same documentation warns about third-party applications. Services reached through connectors can store, transmit, or process data outside the Power Apps US Government infrastructure.

Separate Microsoft Service Boundaries From Connected Services

That distinction belongs in the project data review. A Dataverse project record, a SharePoint file, a Power BI export, an email, and a third-party connector payload can all have different service boundaries.

Do not convert a statement about one specific service into a blanket promise that “all project data remains in the United States.” Ask the vendor to identify every service and transfer path before writing the final data-location statement.

Map Identity, Permissions, and Administrative Access

Identity answers who the person is. Permission design answers what that person can see or change. Administrative access answers who can alter the environment, application, records, flows, connections, and reports.

A thorough government review should map:

  • Microsoft Entra tenant administrators

  • Power Platform administrators

  • Environment administrators

  • Application installers and makers

  • Dataverse security assignments

  • Project, program, and portfolio access groups

  • Power BI workspace and report permissions

  • SharePoint site and library permissions

  • Flow owners and connector credentials

  • Vendor support access

  • Emergency access and approval workflows

These layers must follow least-privilege principles and an agency-approved separation of duties. A tenant administrator might control the platform without receiving automatic access to every Dataverse record. An application maker might have rights that differ entirely from an ordinary project user.

Test Effective Access, Not Group Names

The review should test actual access with real groups. Check who can read, edit, delete, export, share, publish, reshare, create a flow, change a connection, or grant another person access.

Group names alone give weak evidence. Capture the assigned permissions, approval owner, review date, and test result.

Follow Project Data Through Reports, Connectors, and Exports

The main application might have sound permissions while a connected workflow or report widens access. Review each path separately.

Power BI Reporting Access

Power BI workspaces, apps, shared links, model permissions, and export settings all affect report access. Microsoft’s Power BI sharing documentation describes sharing options and permissions such as reshare and build. Reliable Power BI portfolio reporting for government PMOs also depends on standardized project data, defined access paths, and controlled export settings.

For a government portfolio, confirm:

  • Who publishes the report?

  • Who can view each level of detail?

  • Who can reshare it?

  • Who can build another report from the model?

  • Who can export summarized or underlying data?

  • Does row-level security apply to the user’s specific access path?

  • Which Government cloud and license plan support the required functions?

An executive summary can reveal sensitive portfolio patterns even if the report hides detailed project pages.

Connectors and Flows

Power Platform connectors can pass information to Microsoft services or an external provider. Agency policies can group, permit, or block connector combinations. Effective Power Platform governance should cover data policies, connector oversight, tenant isolation, maker controls, and regular administrative reviews.

Microsoft states new connectors are disabled by default in GCC High and DoD until an administrator reviews them. The connector review control for GCC High and DoD does not cover every cloud or every custom connector.

Record every standard and custom connector, its owner, credential, destination, transmitted fields, and approved business purpose. Recheck this inventory after any product or flow changes.

Files, Messages, and Exports

Attachments often move to SharePoint Online. Approvals trigger emails. Teams posts repeat status information. An Excel or PDF export creates a separate file governed entirely outside the original report’s permission settings.

The agency must decide which transfers are approved, how labels or records rules apply, and where users can store copies. Product documentation should describe the data path rather than leaving reviewers to guess.

AI Functions

An AI review should cover prompts, retrieved project records, model provider, processing region, retention policies, logs, output, support access, and model-training terms. Treat each AI feature as its own separate data flow.

The main application’s tenant deployment does not answer those questions. Request a current feature-specific statement and contract terms.

Configure Audit and Records Controls for the Actual Tables

Audit capability and audit configuration are two different things. Microsoft documents Dataverse auditing at environment, table, and column levels. Depending on the exact configuration, logs can record data changes, user access, sharing updates, and security adjustments.

The agency must identify:

  • Which project tables and columns need audit history.

  • Which events need review.

  • Who can view or delete logs.

  • How long logs remain available.

  • Which license or service condition applies.

  • How audit records support investigations and records management.

  • Which actions require a separate activity log.

Records policies need this exact same service map. A policy for SharePoint documents does not automatically prove coverage for Dataverse rows, Teams messages, Power BI exports, email, or a third-party connector.

Ask the records and legal teams to approve the mapping for each workload. Confirm current Microsoft Government availability for every feature before relying on it.

Request Written Deployment Evidence

Use the following questions when you evaluate BrightWork 365 or any other project and portfolio management product. We should be able to answer them in clear deployment terms, supported by current Microsoft and BrightWork documentation.

Product and Cloud Fit

  • Which product release supports the agency’s exact cloud?

  • Does the vendor support GCC, GCC High, or DoD in writing?

  • Which required functions differ from the commercial release?

  • Which licenses and capacities are required?

Data and Access

  • Which records sit in Dataverse, SharePoint Online, Teams, Power BI, Outlook, or another service?

  • Which environment and region contain the core records?

  • Which administrators and support staff can gain access?

  • How do administrators approve and log temporary access and emergency changes?

Connections and Reporting

  • Which connectors and flows ship with the product?

  • Which external services can receive data?

  • Which report sharing, build, export, and subscription paths are enabled?

  • Which settings can the agency disable?

Operations and Assurance

  • How does the vendor handle backups, recovery, telemetry, and support cases?

  • Which logs record data and configuration changes?

  • How do upgrades affect permissions, connectors, and Government cloud availability?

  • Which Microsoft statements and vendor documents support each answer?

Record each response, source, version, date, reviewer, and remaining condition. Do not close a security item until the supporting evidence matches the proposed deployment.

How BrightWork 365 Fits Into a Government Data Review

BrightWork 365 is our project and portfolio management solution for Microsoft 365. For agencies evaluating government project management software in Microsoft 365, BrightWork 365 brings together centralized project information, templates, workflows, reporting, Teams, SharePoint Online, and Power Automate. Deployment follows the BrightWork 365 licensing and installation requirements, including a Power Platform tenant with a Dataverse-enabled environment.

Make the Evidence Match the Deployment

Government project data can receive strong Microsoft controls when the agency chooses the right cloud, configures the environment, limits access, reviews connections, and maintains strict audit settings. The review must always match the exact product release and data flow.

Teams evaluating BrightWork government project management solutions should ask our team to confirm deployment fit, Government cloud support, data paths, permissions, connectors, and support access for their agency.

Categories
Billy Guinan​​
BrightWork Demand Generation Manager

Billy has nearly 15 years of experience in B2B SaaS project portfolio management, specializing in Microsoft 365, Teams, the Power Platform, and SharePoint. He focuses on collaborative and template-driven project management. Outside work, he enjoys reading, golf, and walking his pug, Nova.

Ready to Centralize Your PMO? See BrightWork 365 in Action