Azure Red Hat OpenShift for Azure Government moves from IL4 to IL5
The claim comes from Red Hat's own announcement, which Business Wire distributed and ExecutiveBiz reported a day later. Red Hat says that with IL5 certification, government agencies and highly-regulated industries can now use Azure Red Hat OpenShift as a platform for building, deploying and running containerized applications at scale while simultaneously addressing key security and compliance requirements for highly-sensitive workloads. The release also confirms that the IL5 certification follows Azure Red Hat OpenShift for Azure Government achieving IL4 certification in July 2024.
The certification applies to the Azure Government version of the service only. Commercial Azure Red Hat OpenShift, often shortened to ARO, is a separate offering. Microsoft's commercial product page still lists certifications for HIPAA, FedRAMP, DoD IL4, PCI-DSS, ISO, and SOC, plus joint Microsoft and Red Hat incident response, with no mention of IL5.
The wording differs slightly between sources. ExecutiveBiz says the "Department of War" certified the platform, while Red Hat's release names the Department of Defense. Both refer to the same department. ExecutiveBiz also calls Red Hat's Chris Smith vice president and general manager of North American public sector, but the September 2026 release lists him as vice president of North American Government Sales.
The release does not name the assessor, give an authorization date, or include any authorization documents. It says only that the service passed audits of critical security controls. Red Hat's statement is therefore the source for the certification, and agencies will still need the formal authorization package for their own risk decisions.
What DoD IL5 covers, and where Azure Government Secret takes over
Impact Levels come from the DoD Cloud Computing Security Requirements Guide (SRG). Red Hat's summary says IL5 protects data categorized as: Higher sensitivity Controlled Unclassified Information (CUI); Unclassified National Security Systems (NSS); and Mission-critical information. IL4 covers less sensitive CUI. The practical gain is that workloads previously kept off the service because of data classification may now be eligible.
IL5 is still an unclassified tier. Microsoft's compliance documentation separates the environments clearly: Azure Government's US Gov regions hold FedRAMP High, IL2, IL4 and IL5 authorizations, while Azure Government Secret, a separate cloud, holds the DoD IL6 authorization used for Secret-level classified data. "Mission-critical" and "national security systems" in the release should be read as unclassified. Classified work belongs in a different environment.
The service's other credentials stay the same as at launch. When the government version became generally available on February 7, 2023, Red Hat listed FedRAMP High authorization, ITAR, DFARS, IRS 1075 and CJIS, and the 2026 release repeats that list. Microsoft's own launch post said ARO on Azure Government enables compliance with strict government regulations and certifications, such as FedRAMP and CJIS. These are separate frameworks with separate obligations. A service on the list still leaves each customer to meet its own requirements under each framework.
How IL5 isolation works in Azure Government, and why ARO customers should care
Microsoft's approach to IL5 explains why a platform-level certification leaves work for the customer. Microsoft says DISA, the Defense Information Systems Agency, granted Azure Government its first IL5 Provisional Authorization in January 2017. That authorization covered the two DoD-dedicated regions, US DoD Central and US DoD East. In December 2018 it was extended to the general US Gov regions: US Gov Arizona, US Gov Texas and US Gov Virginia.
The two sets of regions reach IL5 in different ways. Microsoft says that if a service is available in the DoD regions and authorized at IL5, it is suitable for IL5 workloads by default with no extra isolation configuration, because those regions are reserved for DoD agencies and their partners. In the US Gov regions, Microsoft's audit-scope tables use a separate label, IL5WI (IL5 via Workload Isolation). Services listed under it need extra configuration to meet the SRG's compute and storage isolation requirements.
Microsoft's isolation guidance lists two requirements:
- For compute isolation, IL5 virtual machines and scale sets in the US Gov regions should run on Azure Dedicated Host or isolated VM sizes, so that a compromised neighbor on shared hardware cannot reach a DoD workload.
- For storage isolation, DISA approved separating IL5 data from other data by cryptographic means. In Azure this uses customer-managed keys held in Azure Key Vault on FIPS 140 validated hardware security modules.
- Microsoft states that customers are responsible for designing and deploying their applications to meet DoD IL5 requirements. It also warns against putting sensitive information in Azure resource names.
The version of the isolation guidance reviewed for this article has entries for Azure Kubernetes Service, Container Instances and Container Registry, but none for Azure Red Hat OpenShift. The announcement does not say which regions, cluster configurations or key-management settings the IL5 certification assumes. OpenShift teams should get that from Microsoft or Red Hat before assuming a default cluster build meets IL5.
Microsoft's compliance pages lag behind the Red Hat announcement
Microsoft's "Azure Government services by audit scope" table, which agencies use to confirm authorization boundaries, was marked last updated February 2026, seven months before Red Hat's announcement. It cannot yet show the new status reliably. As noted above, Microsoft's commercial ARO product page also still lists IL4 as its DoD credential.
Microsoft's name does appear on the announcement. Leigh Madden, Microsoft's vice president of National Security, is quoted calling the certification a significant milestone, and Red Hat describes the service as co-developed and jointly operated. The gap looks like documentation lag, and nothing suggests the certification is in dispute. For compliance teams, though, the audit-scope listing and the authorization package are what count, and a press release does not replace them.
Madden's quote also mentions Microsoft's "expanded regional availability" for the service but names no regions. Whether ARO runs in the DoD regions, where IL5 needs no extra isolation, or only in the US Gov regions under workload isolation decides how much configuration an agency takes on. That question is still open.
Where this fits in Red Hat's public-sector cloud push
The IL5 step continues a pattern that started before general availability. When Red Hat first announced the government offering, it said the service was expected to add key IT security and regulatory certifications and is intended to pass crucial compliance tests. Since the 2023 launch it has added IL4 in July 2024 and now IL5. At launch Red Hat also said the service could be bought through Microsoft using Microsoft Azure Consumption Commitment funds. That was the 2023 arrangement, and current terms should be confirmed with the account team.
ExecutiveBiz places the milestone alongside Red Hat's FedRAMP High authorizations for Red Hat OpenShift Service on AWS GovCloud and Red Hat Insights. That gives agencies a comparable managed-OpenShift option on both major government clouds, and Smith's quote focuses on letting agencies run workloads in whichever environment fits their regulatory needs.
On Azure Government, the choice that matters most is between ARO and Azure Kubernetes Service. Microsoft already lists AKS under IL5 workload isolation and documents its configuration requirement, which is encryption at rest with customer-managed keys in Key Vault. Before this announcement, a team that needed IL5 had a clear reason to pick AKS or run OpenShift itself. For teams whose applications, pipelines and operators are built on OpenShift, the managed service is now a real option at that tier.
What this means for you
If you run OpenShift workloads in Azure Government, or plan to, and your data is CUI above IL4, this is the time to reopen the platform decision. Wait for the formal paperwork before migrating anything.
- Treat Red Hat's September 24, 2026 announcement as the certification claim, and confirm Azure Red Hat OpenShift appears at IL5 in Microsoft's current Azure Government audit-scope listing before moving IL5 data onto it.
- Ask Microsoft or Red Hat which regions the IL5 status covers. IL5 in the US DoD regions needs no extra isolation for authorized services, while the US Gov regions require workload-isolation configuration.
- Plan for customer-side controls: Microsoft's IL5 model assigns the customer responsibility for compute isolation, encryption with customer-managed keys in Key Vault, and application design.
- Keep classified workloads off this service. IL5 is unclassified, and Secret-level data belongs in Azure Government Secret under IL6.
- Remember that commercial Azure Red Hat OpenShift is separate, and Microsoft's product page for it still lists DoD IL4.
With IL5 added to the IL4 it held since 2024, Azure Red Hat OpenShift for Azure Government is now eligible for the unclassified workloads that federal and defense teams most often kept on their own infrastructure. That eligibility becomes something agencies can act on when Microsoft updates its audit-scope listing and the region and isolation details are published. Once they are, agencies can document ARO as a candidate at the same tier as AKS.