How it works
Secureframe Virtual Desktops lets your organization provision CMMC-compliant virtual desktops so your team can securely view and process Controlled Unclassified Information (CUI). It is part of Secureframe's Defense product line. Instead of bringing every employee laptop into CMMC scope, your team does CUI work inside the virtual desktops, keeping your compliance boundary small and manageable.
Connect an Azure Government account to Secureframe.
Provision secure virtual desktops from the Secureframe platform.
Users access those desktops through standard remote desktop apps.
Start with Prerequisites to setting up your Virtual Desktops, then Provisioning Virtual Desktops, then Accessing Your Virtual Desktop.
Deployment model
Virtual desktops are always deployed into an Azure Government environment that your organization owns. Secureframe handles the provisioning and configuration; the underlying infrastructure lives in your tenant.
Control: Your CUI stays inside your own Azure Government environment. Secureframe never hosts your data in a Secureframe-owned tenant.
Cost: Because the resources run in your tenant, you are responsible for the Azure infrastructure costs of the resources you provision. Those charges appear on your Azure invoice, not your Secureframe invoice. When you provision a desktop, Secureframe shows estimated Azure costs in the product before you deploy.
Supported operating system
Windows 11 is the operating system for Secureframe Virtual Desktops.
Prerequisites
Before you can provision desktops, you need:
An active Azure Government subscription that is visible to Secureframe
The required GCC High licensing
Verified custom domains in Microsoft Entra
See Prerequisites to setting up your Virtual Desktops for the full checklist, including the 15-character tenant name requirement.
Key features
Golden image
Every virtual desktop in your environment is built from a golden image: a Windows template that Secureframe builds, secures, and keeps up to date. It includes Windows 11 and Microsoft 365, with the security settings CMMC requires already in place.
This matters for CMMC in two ways:
Every desktop is secure from the start. The security settings are part of the image, so a new desktop is locked down the moment it's created. No desktop gets skipped.
Every desktop is the same. Your desktops are copies of one image, so what your assessor sees on one desktop is true for all of them.
Secureframe releases new versions of the golden image with Windows updates and security changes. Before a version is released, Secureframe starts a test desktop from it and checks that it starts up, has the right software, and has its security settings in place. New desktops are built from the newest version. A desktop you already have stays on its version until it's rebuilt.
See Golden Image for Virtual Desktops for what the image includes and how updates work.
Pooled multi-session desktops
When a user signs in, they get a ready-to-use desktop right away. Instead of paying for a dedicated virtual machine for every user (machines that sit idle whenever those users aren't working), your organization runs a smaller set of desktops that the whole team shares. Your team gets the same experience at a lower Azure cost.
Autoscaling
Autoscaling starts and stops your desktops around your team's working hours, so you pay for Azure compute when it's needed instead of around the clock. You choose those hours, called core hours, for each day when you create a pool, and you can update them anytime.
Desktops start about 30 minutes before core hours so they're ready when your team signs in, and they shut down after core hours once everyone has left. If someone is still working when core hours end, their desktop stays on until they're done. If someone needs to work outside core hours, signing in starts a desktop automatically.
Roaming profiles
Because desktops are shared and start and stop on a schedule, a user's settings and preferences belong to their profile, not to any one machine. Whichever desktop they sign in to, those follow them, so every desktop feels like their own.
The machines themselves are disposable. A desktop can be rebuilt, replaced, or upgraded without wiping profile settings. Files stored only on that desktop do not follow the profile. That includes items on the Desktop, in Downloads, and on local disks.
Shared drive
Every virtual desktop includes a shared drive (Z:) for files your team works on together. Save a file once and everyone with access to your Virtual Desktops can open it, with no copying or emailing files between people.
Shared with your whole team: Everyone with access to your Virtual Desktops can open, edit and delete files on the shared drive. Keep personal files in your own profile folders instead.
Separate from profiles: Files on the shared drive don't count against your profile storage, which keeps sign-ins fast.
Kept through rebuilds and upgrades: Files on the shared drive aren't affected when a desktop is rebuilt.
The shared drive uses its own storage account in your Azure Government environment, which appears as a separate line on your Azure bill.
Monitoring and audit records
Secureframe keeps track of two things in your Virtual Desktops: what people do in your environment, and any changes made to the setup Secureframe manages for you. Both are set up automatically, so there is nothing to turn on.
Activity logging
Secureframe keeps a record of what happens in your Virtual Desktops, such as who signed in, who connected to a desktop, which files on the shared drive were opened or changed, and what changed in your setup. Records are stored in a log workspace in your own Azure Government environment. Secureframe keeps them for a year, protects them from deletion, and emails you if logging stops. Ready-made searches answer the questions assessors ask most often. The log workspace appears as a separate line on your Azure bill.
See Activity Logging for Virtual Desktops for what is recorded and how to find your records.
Drift detection
Secureframe watches the infrastructure it manages for your Virtual Desktops and flags any change made directly in Azure, like a setting that was changed, a resource that was added, or one that was deleted. For each change, you see what changed, who made it and how much it matters, then choose to keep it or have Secureframe revert it. Every decision is recorded in the Drift log, giving you a reviewed record of changes to your CUI environment.
See Drift Detection for Virtual Desktops for how to review and manage changes.
CMMC compliance coverage
The Secureframe platform includes automated tests that make sure your virtual desktops stay CMMC compliant. As you deploy and use virtual desktops, the platform automatically checks the relevant controls and surfaces the results in your compliance dashboard.
Frequently Asked Questions (FAQ)
Does deploying a virtual desktop make me CMMC compliant?
Not by itself. Virtual Desktops gives your team a secure, controlled environment for CUI, which is one piece of CMMC compliance. Full compliance also requires policies, controls, and processes across your organization. Secureframe Defense includes all of these components, so you can build and track your entire CMMC program in one place.
Who pays for the Azure infrastructure?
You do. The resources run in your Azure Government tenant, so infrastructure charges appear on your Azure invoice. Cost estimates shown in Secureframe are not an official Azure quote or invoice.
Why do we need to verify an adsf subdomain during license setup?
Microsoft limits the NetBIOS / managed domain name length used for Azure AD Domain Services. If your tenant name is over 15 characters, see What to Do If Your Azure Government Tenant Name Is Over 15 Characters.
If I remove a user from a Virtual Desktop in Secureframe, do they lose access right away?
Yes. Removing an assigned user also revokes their Azure role assignments for that desktop. See Provisioning Virtual Desktops and Accessing Your Virtual Desktop for details.
Does Virtual Desktop / VDI Enclave setup include a CUI-compliant SharePoint?
No. Secureframe Virtual Desktops provision the Azure VDI environment used to view and process CUI. They do not create or configure a CUI-compliant SharePoint site. CUI-compliant SharePoint is part of automated Microsoft GCC High setup. See What Secureframe configures in your Microsoft GCC High tenant.
Will I lose data if my virtual desktop is rebuilt or migrated?
Yes, for files stored only on that desktop (Desktop, Downloads, local disks).
Before a rebuild or platform upgrade, move important files to OneDrive or the shared data drive (Z:).
Software installs and machine-specific configs usually cannot move to OneDrive. Plan to reinstall those after a rebuild.
Large datasets should live on the shared Z: drive, not on one desktop. See Provisioning Virtual Desktops for what the shared drive is for.
Can I install my own software on a Virtual Desktop?
Yes. Virtual Desktops are full Windows 11 machines. You can install the line-of-business apps your team needs to work with CUI (for example estimating or project tools that do not have a CMMC-ready cloud version).
Secureframe does not maintain an allowlist of approved desktop applications. You choose and install what your organization needs.
You are responsible for configuring and securing anything you install, and for keeping that software in line with your CMMC program. Secureframe hardens and monitors the desktop platform. It does not certify or manage third-party apps for you.
Software installs and machine-specific configs usually do not survive a desktop rebuild. Plan to reinstall those apps after a rebuild, or place shared data on the shared drive (Z:).
If you need a shared backend that multiple desktops can reach (for example a file, terminal, licensing, or database server for an app like HeavyBid or SolidWorks), use a service machine in the enclave. See Virtual Desktop: Engineering Workloads & Infrastructure.
Questions? Contact [email protected] or reach out to your CSM.


