FedRAMP Compliance & Feature Availability¶
Overview¶
This document outlines the availability, operational status, and functional behavior of IFS Cloud components, client-framework capabilities, and third-party integrations when operating within a FedRAMP Moderate (Hardened Level 2) environment.
To satisfy federal compliance boundaries and egress controls, certain features are modified, restricted, or disabled to prevent unauthorized outbound network traffic, secure cross-origin resources, and maintain strict runtime integrity.
1. Feature Availability Summary Matrix¶
| Component / Feature | Category | FedRAMP Moderate Status | Summary Behavior in FedRAMP |
|---|---|---|---|
| External URL Navigation | Client Framework | Blocked by Default | All external links (http, https, www) trigger an informational block dialog. |
| Microsoft Teams Integration | Integration | Supported | MSAL, Microsoft Graph, and Teams integration supported using commercial and GCC endpoints. |
| Address Control (Google/Apple Maps) | Integration | Supported (Controlled) | Supported when configured under approved FedRAMP Moderate map rules. |
| ClickLearn | Integration | Supported (Customer-Procured) | Customer-procured; third-party media embeds supported via CSP allowlisting. |
| Plugin System | Extensibility | Restricted | Framework remains enabled; plugin owners are responsible for disabling or restricting unapproved external endpoints via Marble — not an automatic client-framework-level allowlist. |
| Autodesk 3D Viewer | Integration | Disabled | Feature disabled; no outbound traffic is routed to Autodesk services. |
| FullStory Analytics | Analytics | Disabled | Excluded from the hardened Level 2 build; no telemetry sent outbound. |
| HERE Maps | Integration | Disabled | Feature gated and disabled; no waypoints or API traffic sent to HERE servers. |
| IP Address Fetch | Utility | Disabled | Public IP lookup tool hidden based on the configured ComplianceService hardening level isFedRampCompliantEnabled. |
| Help Lightning Remote Assistance | Remote Assist | Disabled | Not deployed in FedRAMP environments (interim), pending a compliant subprocessor architecture. |
| Content Security Policy (CSP) | Security | Hardening In Progress | unsafe-eval is retained with compensating mitigations and pre-execution scanning; frame-src wildcards are being replaced with validated, strict directives. |
| Branding & Custom Fonts | Platform / UI | Conditional / In Progress | Tenant-defined fonts subject to font proxying or origin allowlisting. |
| Hardware Token Handler (eSignature) | Authentication | Under Evaluation | Analysis in progress for smart-card/USB signing middleware, OCSP/CRL, and CA egress. |
| Disabled Control UI Indicators | UX / Framework | Design In Progress | Standardized visual indicators and messaging for FedRAMP-disabled controls. |
2. External URL Navigation & Runtime Enforcement¶
Default-Blocked Behavior¶
- By default, out-of-the-box navigation to external targets (
http://,https://, andwww.) is blocked across the entire application for FedRAMP-compliant customers. - Authoring vs. Runtime Execution: Users and administrators are not restricted from entering, editing, or saving external URLs within configuration screens (Page Designer, Navigator Designer, Lobby elements) and as data . However, when any user attempts to execute or click an external link at runtime, the action is intercepted.
User Experience & Informational Messaging¶
- When an external navigation attempt is blocked, the user is presented with an informational dialog explaining that external navigation has been disabled under FedRAMP compliance policies.
IFS Documentation Links & Workaround¶
- In the initial implementation, standard IFS documentation links pointing to external documentation hosts are subject to the default navigation block.
- Workaround: Users can access documentation resources directly by opening the documentation portal URL in a separate browser tab.
3. Detailed Component Guidance¶
Third-Party Integrations & Services¶
Microsoft Teams Integration¶
- Status: Supported
- Details: Integration with Microsoft Teams via MSAL and Microsoft Graph is fully supported using standard commercial and Government Community Cloud (GCC) endpoints for the FedRAMP Moderate baseline. (Note: GCC High endpoints are reserved for future FedRAMP High targets).
Address Control & Mapping Services¶
Address Control (Google / Apple Maps): Supported when configured in accordance with agreed FedRAMP Moderate map rules.
Moderate Map Rules
Google Maps and Apple Maps links are acceptable for FedRAMP Moderate deployments and must use hardcoded, controlled URLs.
Only the minimum location data required to display the map result is sent to the external service (e.g., street address or latitude/longitude coordinates).
No additional customer or user information is included in the request (e.g., first name, last name, record IDs, account details).
Desktop (configurable
ADDRESS_MAP_URL) is overridden with Google Maps in FedRAMP deployments because the application cannot control the external destination configured by the customer.
HERE Maps: Disabled. All tile fetching, waypoint routing, and API key exchanges with HERE endpoints are gated and blocked.
Autodesk 3D Viewer¶
- Status: Disabled
- Details: The current Autodesk 3D Viewer integration is not permitted within the FedRAMP Moderate boundary. The feature is disabled, and no outbound requests to Autodesk cloud endpoints are initiated.
ClickLearn Integration¶
- Status: Supported (Customer-Procured)
- Details: As an optional, customer-procured tool, ClickLearn media embeds remain functional via Content Security Policy (
media-src) allow listing without requiring core product architectural changes.
Help Lightning Remote Assistance¶
- Status: Disabled
- Details: Real-time audio/video and screen-sharing via Help Lightning are not deployed or available in FedRAMP environments until a compliant subprocessor architecture is established.
FullStory Analytics¶
- Status: Disabled
- Details: Outbound user session telemetry and analytics via FullStory are excluded from the hardened Level 2 build.
Security, Architecture & Platform Controls¶
Content Security Policy (CSP) Hardening¶
unsafe-evalremains necessary for supported client functionality and is retained, secured by compensating mitigations and pre-execution script scanning. Blanketframe-srcwildcards and other overly permissive directives are being systematically replaced with hardened, strict directive sets to prevent cross-site scripting (XSS) and unauthorized iframe embedding.
Public IP Lookup¶
- The external IP address fetch utility (previously calling
bigdatacloud.net) is hidden and disabled in FedRAMP builds according to the configured ComplianceService hardening levelisFedRampCompliantEnabled.
Branding & Custom Fonts¶
- Loading custom web fonts from arbitrary external CDNs is restricted. Custom typography must be routed through origin allowlisting or internal font proxy mechanisms.
Hardware Token Handler (eSignature)¶
- Middleware architecture for USB/smart-card digital signing, Certificate Authority (CA) validation, and OCSP/CRL network egress is currently under technical evaluation.
4. Shared Responsibility Model¶
| Responsibility Area | IFS Cloud Platform Role | Customer / Administrator Role |
|---|---|---|
| Default Baseline | Enforces out-of-the-box blocks on external URL navigations and disables unvetted third-party services. | Reviews compliance boundaries and ensures organizational awareness of restricted capabilities. |
5. User Experience & Administrator Guidance¶
- Disabled Controls UX: When a feature or command is restricted under FedRAMP, the user interface will provide clear visual indications or hide the element gracefully rather than failing silently.
- Configuration Audits: Administrators configuring custom lobbies, navigators, or plugins must ensure all configured assets and links reside within the approved FedRAMP boundary or internal tenant origins.