Microsoft will give them whatever they request. When you spend that much money you can just ask for a custom build. I would imagine that NSA TAO and other such parts of the USG are provided access to much of the Windows source already.
Microsoft and US intelligence and the US armed forces are practically vertically integrated at this point, they are the Lockheed of software.
The Windows 11 STIG says use the Windows 10 STIG.
The Windows 10 STIG says basically fix this stuff before using. So it seems they have a high tolerance for shenanigans. But what will they do about the online part?