Quest Software’s Identity Defense and Identity Recovery for Entra ID are now available in a FedRAMP High environment, clearing a real procurement and deployment barrier for federal identity teams running hybrid Active Directory and Microsoft Entra ID. But the primary FedRAMP record shows the authorization belongs to Project Hosts’ GSS One Azure service, which includes Quest’s applications inside its authorization boundary; it is not a standalone Quest listing in the FedRAMP Marketplace. Quest announced the availability on July 8, 2026, while the supplied August 5 report appears to be a later republication of that announcement. The distinction is more than calendar trivia: the marketplace says GSS One Azure became FedRAMP Certified at the High baseline on March 16, 2026, meaning the underlying government cloud service was authorized months before Quest publicly framed the two identity products as available through it.
For Windows administrators and security teams, the practical news is that Quest’s protection and recovery tooling can now be considered for government environments that need to keep Microsoft identity data and operational workflows inside a High-authorized SaaS boundary. The less glamorous reality is that prospective buyers need to validate their planned architecture against the specific GSS One deployment, rather than assume every Quest tenant, feature, integration, agent, or existing commercial subscription automatically carries the same status.

A cybersecurity operations center visualizes cloud security, blockchain, servers, data, and global network monitoring.The FedRAMP record identifies Project Hosts, not Quest​

FedRAMP’s marketplace lists “GSS One - Azure” under Project Hosts Inc., package ID F1403283529A. It is an Agency-path FedRAMP Rev. 5 Class D, or High, cloud service offering in ongoing certification, with six recorded authority-to-operate or authority-to-use letters. The official service description explicitly names the Quest Security Management Platform as an application included in the GSS One authorization boundary.
That description then identifies the two relevant Quest components: Identity Recovery for Entra ID and Identity Defense. It says Identity Recovery is a SaaS service for backing up and restoring Entra ID and Microsoft 365 objects, including users, groups, attributes, and memberships, while Identity Defense assesses Active Directory and Entra ID for privileged-object risk, configuration drift, suspicious directory changes, and threats to Tier Zero assets.
This confirms the central claim in Quest’s announcement: the products are available through a High-authorized offering in Azure Government. It also supplies the architectural detail Quest’s release leaves vague. The authorization is delivered through Project Hosts’ GSS One Azure platform, where Quest’s software operates as an included application, rather than as a separately listed cloud service whose marketplace provider is Quest.
That affects how federal buyers should read sales language around “FedRAMP High authorized SaaS.” FedRAMP certification is tied to a documented cloud service offering and its boundary, controls, operational processes, assessment evidence, and continuous-monitoring obligations. It is not a blanket certification that automatically attaches to every edition of a product bearing the same name.
FedRAMP’s current rules require an agency-path Class D provider to complete a formal agency Authorization to Operate process and submit the signed ATO through official channels. The marketplace classification therefore reflects a government authorization of the GSS One service offering at the High level. It does not, by itself, establish that a customer can deploy any Quest-hosted environment in any Microsoft cloud and call it FedRAMP High.

Two products reached the government offering; the earlier roadmap named three​

Quest’s December 2025 roadmap had named Security Guardian, Security Guardian Audit, and On Demand Recovery as products planned for FedRAMP High authorization in Azure Government in early 2026. The July announcement uses newer branding and names only Quest Identity Defense and Quest Identity Recovery for Entra ID.
The marketplace record tracks that narrower scope. It describes Identity Defense and Identity Recovery for Entra ID, but it does not separately list Security Guardian Audit. Quest’s announcement does not explain whether Identity Defense is a renamed or repackaged successor to Security Guardian, whether auditing functions are included in the authorized configuration, or whether any capabilities from the earlier three-product roadmap were deferred.
That omission matters for security operations teams because identity tooling lives or dies on integration details. A product may detect risky directory changes, but teams still need to know whether the authorized deployment includes the collectors, agents, API permissions, alert-routing options, Microsoft 365 coverage, log-retention choices, and recovery workflows required by their incident-response plan.
Quest says Identity Defense can identify identity exposure, prioritize Tier Zero risk, contain threats, and protect critical assets. It says Identity Recovery provides a tested restoration path after ransomware, destructive changes, or administrative compromise. Those capabilities are relevant to Windows estates because Active Directory remains the authentication and policy backbone for many government and defense organizations even as Entra ID takes on more cloud access and device-management roles.
The useful operational combination is clear: detect and contain a compromise in hybrid identity infrastructure, then restore a trusted directory state when prevention fails. Recovery should be treated as a separate discipline from backup. Restoring a deleted group or user is routine; restoring authentication, privileged access, synchronization dependencies, application registrations, Conditional Access, and policy state after a destructive identity incident is a much more demanding task.
Quest’s own recovery material says its Entra ID service can perform point-in-time comparison and granular restoration of cloud identity objects. The GSS One description adds that the service supports hybrid recovery through integration with on-premises Quest Recovery Manager for Active Directory. But neither Quest nor the FedRAMP listing publicly defines which on-premises elements are inside the High-authorized architecture, which remain agency-managed, or which Recovery Manager edition and configuration are required.

“High” changes the procurement conversation, not the threat model​

FedRAMP High is a meaningful threshold for cloud services handling more sensitive federal workloads. Under the current FedRAMP Rev. 5 framework, Class D services must satisfy the High control baseline and complete a fresh independent assessment before initial certification; agency-path providers must also hold a signed agency ATO. The controls cover issues such as account management, privileged access, auditing, encryption, monitoring, incident response, configuration management, and supply-chain assurance.
That is valuable evidence for agencies that need to use SaaS without creating a separate authorization package from scratch. Project Hosts’ six listed authorizations also indicate that the GSS One service has moved beyond a one-off initial authorization and has authorization reuse experience.
It does not mean an identity recovery product has solved the agency’s identity recovery problem. An agency still has to decide what it will back up, how often it will capture Entra ID and Microsoft 365 state, who can approve a restore, which break-glass accounts survive a tenant-wide incident, and how restoration will be tested without making a live compromise worse.
The most important work is often outside the product console. Active Directory administrators need a current inventory of Tier Zero systems and groups. Entra administrators need to document privileged roles, administrative units, application identities, certificates, service principals, Conditional Access dependencies, Intune policy relationships, and the account paths used when normal authentication fails. Security teams need to establish who can activate containment controls and who has authority to roll them back.
The FedRAMP availability makes Quest easier to evaluate for those environments; it does not remove those operational requirements. In fact, a government-grade hosting model makes it more important to establish them before deployment, because data flows, support access, incident escalation, and change control need to conform to the authorized design.

What agencies should verify before treating it as deployable​

Quest’s release supplies no public pricing, availability region, onboarding timeline, participating-agency list, migration path for existing commercial Quest tenants, or feature matrix separating the GSS One version from commercial offerings. No independent outlet located during reporting has published those deployment terms.
Teams considering the service should therefore ask for written answers on the exact boundary rather than relying on product-family names:
  • Confirm that the proposed tenant is provisioned in the Project Hosts GSS One Azure environment and that the desired Quest modules are explicitly included in the authorized configuration.
  • Confirm what data leaves Active Directory, Entra ID, Microsoft 365, and any connected Windows management systems; identify where backups, telemetry, audit records, and encryption keys reside.
  • Establish whether collectors or recovery components installed in the agency environment fall inside the authorization documentation or remain customer-managed components subject to local controls.
  • Request the supported-object list for recovery, particularly privileged roles, group memberships, application registrations, service principals, Conditional Access policies, Intune configurations, and Microsoft Teams or Microsoft 365 data.
  • Run a recovery exercise that begins with an unavailable or compromised administrator account, rather than a simple deletion test performed by a healthy global administrator.
Quest also claims it is the only purpose-built hybrid Active Directory and Entra ID ITDR provider with a FedRAMP High-authorized SaaS offering. The official marketplace confirms that its two products are included in the Project Hosts High service, but it does not assess competitors or substantiate exclusivity claims. That is vendor positioning, not a conclusion established by the FedRAMP record.

The immediate consequence is a shorter path to evaluation​

The story here is not that FedRAMP High magically turns identity defense into a solved category. It is that a federal customer can now evaluate Quest’s hybrid AD and Entra ID detection-and-recovery stack through an already certified High cloud service rather than waiting for Quest to appear as a separate provider on the marketplace.
For organizations with legacy Windows authentication infrastructure and a growing Entra footprint, that can reduce one of the hardest blockers to adopting SaaS identity recovery: keeping the recovery platform itself in an environment their authorization process can accept. The next procurement milestone is not another Quest press release. It is a customer-specific architecture review showing exactly which Quest capabilities, connected systems, support processes, and recovery data are covered by the GSS One FedRAMP High boundary.

References​

  1. Primary source: Portal ERP
    Published: 2026-08-05T20:31:21+00:00
  2. Related coverage: quest.com
  3. Related coverage: quest.com
  4. Related coverage: blog.quest.com
  5. Related coverage: support.quest.com
  6. Related coverage: blog.quest.com
  7. Related coverage: support-public.cfm.quest.com
  8. Related coverage: fedramp.gov
  9. Related coverage: marketplace.fedramp.gov
  10. Related coverage: fedramp.gov
  11. Related coverage: learn.microsoft.com
  12. Related coverage: security.cms.gov
  13. Related coverage: marketplace.microsoft.com
  14. Related coverage: demo.fedramp.gov
  15. Related coverage: automate.fedramp.gov