How does GCC High Teams calling handle call metadata and logs, and where is that data stored and who can access it?
All call metadata and logs generated within GCC High Teams calling are stored in FedRAMP High-compliant data centers located exclusively within the United States. Access to this data is restricted to screened U.S. personnel who have passed enhanced background checks, including U.S. citizenship verification and FBI fingerprint screening.
Signaling data is encrypted using Transport Layer Security (TLS), and media streams are encrypted using Secure Real-time Transport Protocol (SRTP) with AES encryption. Microsoft support personnel do not have standing access to GCC High production environments. Any staff requesting temporary access must pass the full background screening process, which includes seven-year employment and criminal history verification, Social Security Number validation, and checks against the Office of Foreign Assets Control (OFAC), Bureau of Industry and Security (BIS), and Defense Trade Controls debarred persons lists. Audit logs and tracking are available for ITAR-related communications, and organizations can configure retention policies within the GCC High boundary. The key distinction from commercial Teams is that no call data, metadata, or logs leave the U.S. sovereignty boundary, and no unscreened personnel can access the data at any point.