Despite a “lack of proper detailed security documentation” for Microsoft’s Government Community Cloud High, a suite of cloud-based services intended to safeguard the nation’s most sensitive information, and reviewers' “lack of confidence in assessing the system’s overall security posture,” the Federal Risk and Authorization Management Program, or FedRAMP, authorized the product anyway, bestowing what amounts to the federal government’s cybersecurity seal of approval.
https://www.propublica.org/article/microsoft-cloud-fedramp-cybersecurity-government