Can you correlate Microsoft Sentinel data across Government and Commercial clouds?

Reviewed by ContraForce team ยท Updated 2026-09-04

> Azure Lighthouse does not support delegation of subscriptions across a national cloud and the Azure public cloud, or across two national clouds, so the cross-tenant mechanism Sentinel correlation depends on does not span that boundary. Microsoft also states it is not possible to move data or a workspace from Azure to Azure Government.

Last verified: 2026-09-04. Sources linked at the foot of the page.

Where exactly is the boundary?

Azure Lighthouse is the mechanism that lets a provider query customer Sentinel workspaces from its own tenant, and Microsoft lists cross-cloud delegation among the Lighthouse features not available in Azure Government. The unsupported case is stated as delegation of subscriptions across a national cloud and the Azure public cloud, or across two national clouds.

That single constraint decides the question. Without delegation across the boundary, there is no path for a query in one cloud to reach a workspace in the other.

Microsoft separately states that it is not possible to move data or a workspace from Azure to Azure Government, which closes the other obvious workaround of consolidating everything into one cloud after the fact.

What does work across clouds?

Multitenant management itself is available on both sides. Microsoft documents Defender multitenant management, including for US Government clouds, as available to GCC, GCC High, DoD, and Commercial customers.

So a provider can operate a multi-tenant practice inside Government and a multi-tenant practice inside Commercial. What it cannot do is treat them as one estate.

CapabilityWithin one cloudAcross Government and Commercial
Azure Lighthouse delegationSupportedNot supported
Cross-tenant Sentinel querySupportedNo delegation path
Move a workspace or its datan/aNot possible
Defender multitenant managementAvailable in GCC, GCC High, DoD, CommercialTwo separate practices
Microsoft also documents a related failure worth knowing: a cross-cloud tenant removed from cross-cloud visibility becomes unavailable, and describes this as a recognised limitation of cross-cloud tenant management that is currently under review. That is Microsoft's own characterisation, not an inference.

What does a provider serving both actually run?

Two of everything, and the duplication is structural rather than a configuration choice. Separate delegated access, separate hunting, separate content distribution, separate reporting. An analyst covering both works two consoles, and a question asked of the whole book of business has to be asked twice and reconciled by hand.

For a provider whose government work is a minority of its customers, the practical effect is that the government segment carries a disproportionate share of operational overhead relative to its revenue.

How do you report across a boundary the platform will not cross?

Nothing removes the delegation constraint, which is a property of the clouds rather than of any tool sitting on top of them. What can change is where the reconciliation happens.

ContraForce holds the incident records, verdicts, and evidence its agents produce in its own regional deployment, separately from where the customer's logs live. Cross-customer reporting therefore reads the platform's own records rather than requiring a federated query that crosses a boundary no query can cross. The underlying access into each customer environment still respects whichever cloud that customer is in.

Sources

Verified on the date shown. Microsoft describes at least one of these constraints as under review, so confirm before treating any of it as permanent.

Continue the evaluation

Sources and review method

Product capabilities were reviewed against the page-specific primary sources below on 2026-09-04. Performance claims require the population and limitations stated in the linked methodology.

Related microsoft resources