How it works
Secureframe Virtual Desktops lets your organization provision CMMC-compliant virtual desktops so your team can securely view and process Controlled Unclassified Information (CUI). It is part of Secureframe's Defense product line. Instead of bringing every employee laptop into CMMC scope, your team does CUI work inside the virtual desktops, keeping your compliance boundary small and manageable.
Connect an Azure Government account to Secureframe.
Provision secure virtual desktops from the Secureframe platform.
Users access those desktops through standard remote desktop apps.
Start with Prerequisites to setting up your Virtual Desktops, then Provisioning Virtual Desktops, then Accessing Your Virtual Desktop.
Deployment model
Virtual desktops are always deployed into an Azure Government environment that your organization owns. Secureframe handles the provisioning and configuration; the underlying infrastructure lives in your tenant.
Control: Your CUI stays inside your own Azure Government environment. Secureframe never hosts your data in a Secureframe-owned tenant.
Cost: Because the resources run in your tenant, you are responsible for the Azure infrastructure costs of the resources you provision. Those charges appear on your Azure invoice, not your Secureframe invoice. When you provision a desktop, Secureframe shows estimated Azure costs in the product before you deploy.
Prerequisites
Before you can provision desktops, you need:
An active Azure Government subscription that is visible to Secureframe
The required GCC High licensing
Verified custom domains in Microsoft Entra
See Prerequisites to setting up your Virtual Desktops for the full checklist, including the 15-character tenant name requirement.
Key features
Pooled multi-session desktops
When a user signs in, they get a ready-to-use desktop right away. Instead of paying for a dedicated virtual machine for every user (machines that sit idle whenever those users aren't working), your organization runs a smaller set of desktops that the whole team shares. Your team gets the same experience at a lower Azure cost.
Roaming profiles
A user's files, settings, and preferences belong to their profile, not to any one machine. Whichever desktop they sign in to, everything is where they left it, so every desktop feels like their own.
Because profiles are stored separately from the desktops themselves, the machines are disposable: a desktop can be rebuilt, replaced, or upgraded at any time with no risk to user data. Users simply sign in to the new desktop and pick up where they left off.
Supported operating system
Windows 11 is the operating system for Secureframe Virtual Desktops.
CMMC compliance coverage
The Secureframe platform includes automated tests that make sure your virtual desktops stay CMMC compliant. As you deploy and use virtual desktops, the platform automatically checks the relevant controls and surfaces the results in your compliance dashboard.
Frequently Asked Questions (FAQ)
Does deploying a virtual desktop make me CMMC compliant?
Not by itself. Virtual Desktops gives your team a secure, controlled environment for CUI, which is one piece of CMMC compliance. Full compliance also requires policies, controls, and processes across your organization. Secureframe Defense includes all of these components, so you can build and track your entire CMMC program in one place.
Who pays for the Azure infrastructure?
You do. The resources run in your Azure Government tenant, so infrastructure charges appear on your Azure invoice. Cost estimates shown in Secureframe are not an official Azure quote or invoice.
Why do we need to verify an adsf subdomain during license setup?
Microsoft limits the NetBIOS / managed domain name length used for Azure AD Domain Services. If your tenant name is over 15 characters, see What to Do If Your Azure Government Tenant Name Is Over 15 Characters.
If I remove a user from a Virtual Desktop in Secureframe, do they lose access right away?
Yes. Removing an assigned user also revokes their Azure role assignments for that desktop. See Provisioning Virtual Desktops and Accessing Your Virtual Desktop for details.
Does Virtual Desktop / VDI Enclave setup include a CUI-compliant SharePoint?
No. Secureframe Virtual Desktops provision the Azure VDI environment used to view and process CUI. They do not create or configure a CUI-compliant SharePoint site. CUI-compliant SharePoint is part of automated Microsoft GCC High setup. See What Secureframe configures in your Microsoft GCC High tenant.
Questions? Contact [email protected] or reach out to your CSM.
