How it works
Secureframe Virtual Desktops lets your organization provision CMMC-compliant virtual desktops so your team can securely view and process Controlled Unclassified Information (CUI). It is part of Secureframe's Defense product line. Instead of bringing every employee laptop into CMMC scope, your team does CUI work inside the virtual desktops, keeping your compliance boundary small and manageable.
Connect an Azure Government account to Secureframe.
Provision secure virtual desktops from the Secureframe platform.
Users access those desktops through standard remote desktop apps.
Start with Prerequisites to setting up your Virtual Desktops, then Provisioning Virtual Desktops, then Accessing Your Virtual Desktop.
Deployment model
Virtual desktops are always deployed into an Azure Government environment that your organization owns. Secureframe handles the provisioning and configuration; the underlying infrastructure lives in your tenant.
Control: Your CUI stays inside your own Azure Government environment. Secureframe never hosts your data in a Secureframe-owned tenant.
Cost: Because the resources run in your tenant, you are responsible for the Azure infrastructure costs of the resources you provision. Those charges appear on your Azure invoice, not your Secureframe invoice. When you provision a desktop, Secureframe shows estimated Azure costs in the product before you deploy.
Prerequisites
Before you can provision desktops, you need:
An active Azure Government subscription that is visible to Secureframe
The required GCC High licensing
Verified custom domains in Microsoft Entra
See Prerequisites to setting up your Virtual Desktops for the full checklist, including the 15-character tenant name requirement.
Key features
Pooled multi-session desktops
When a user signs in, they get a ready-to-use desktop right away. Instead of paying for a dedicated virtual machine for every user (machines that sit idle whenever those users aren't working), your organization runs a smaller set of desktops that the whole team shares. Your team gets the same experience at a lower Azure cost.
Roaming profiles
A user's settings and preferences belong to their profile, not to any one machine. Whichever desktop they sign in to, those follow them, so every desktop feels like their own.
The machines themselves are still disposable. A desktop can be rebuilt, replaced, or upgraded without wiping profile settings. Files stored only on that desktop do not follow the profile. That includes items on the Desktop, in Downloads, and on local disks.
Important: Before a rebuild or platform upgrade, move important files to OneDrive or the shared data drive (Z:). Software installs and machine-specific configs usually cannot move to OneDrive, so plan to reinstall those afterward. Large datasets should live on the shared Z: drive, not on one desktop. See Provisioning Virtual Desktops for what the shared drive is for.
Shared Drive
Every virtual desktop includes a shared drive (Z:) for files your team works on together. Save a file once and everyone with access to your Virtual Desktops can open it, with no copying or emailing files between people.
Shared with your whole team: Everyone with access to your Virtual Desktops can open, edit and delete files on the shared drive. Keep personal files in your own profile folders instead.
Separate from profiles: Files on the shared drive don't count against your profile storage, which keeps sign-ins fast.
Kept through rebuilds and upgrades: Files on the shared drive aren't affected when a desktop is rebuilt.
The shared drive uses its own storage account in your Azure Government environment, which appears as a separate line on your Azure bill.
Drift Detection
Secureframe watches the infrastructure it manages for your Virtual Desktops and flags any change made directly in Azure, like a setting that was changed, a resource that was added, or one that was deleted. For each change, you see what changed, who made it and how much it matters, then choose to keep it or have Secureframe revert it. Every decision is recorded in the Drift log, giving you a reviewed record of changes to your CUI environment.
See Drift Detection for Virtual Desktops for how to review and manage changes.
Supported operating system
Windows 11 is the operating system for Secureframe Virtual Desktops.
CMMC compliance coverage
The Secureframe platform includes automated tests that make sure your virtual desktops stay CMMC compliant. As you deploy and use virtual desktops, the platform automatically checks the relevant controls and surfaces the results in your compliance dashboard.
Frequently Asked Questions (FAQ)
Does deploying a virtual desktop make me CMMC compliant?
Not by itself. Virtual Desktops gives your team a secure, controlled environment for CUI, which is one piece of CMMC compliance. Full compliance also requires policies, controls, and processes across your organization. Secureframe Defense includes all of these components, so you can build and track your entire CMMC program in one place.
Who pays for the Azure infrastructure?
You do. The resources run in your Azure Government tenant, so infrastructure charges appear on your Azure invoice. Cost estimates shown in Secureframe are not an official Azure quote or invoice.
Why do we need to verify an adsf subdomain during license setup?
Microsoft limits the NetBIOS / managed domain name length used for Azure AD Domain Services. If your tenant name is over 15 characters, see What to Do If Your Azure Government Tenant Name Is Over 15 Characters.
If I remove a user from a Virtual Desktop in Secureframe, do they lose access right away?
Yes. Removing an assigned user also revokes their Azure role assignments for that desktop. See Provisioning Virtual Desktops and Accessing Your Virtual Desktop for details.
Does Virtual Desktop / VDI Enclave setup include a CUI-compliant SharePoint?
No. Secureframe Virtual Desktops provision the Azure VDI environment used to view and process CUI. They do not create or configure a CUI-compliant SharePoint site. CUI-compliant SharePoint is part of automated Microsoft GCC High setup. See What Secureframe configures in your Microsoft GCC High tenant.
Will I lose data if my virtual desktop is rebuilt or migrated?
Yes, for files stored only on that desktop (Desktop, Downloads, local disks).
Before a rebuild or platform upgrade, move important files to OneDrive or the shared data drive (Z:).
Software installs and machine-specific configs usually cannot move to OneDrive. Plan to reinstall those after a rebuild.
Large datasets should live on the shared Z: drive, not on one desktop. See Provisioning Virtual Desktops for what the shared drive is for.
Questions? Contact [email protected] or reach out to your CSM.
