Prerequisites checklist
Secureframe Virtual Desktops run in Azure Government. People who use them need GCC High licenses. Before Secureframe can provision desktops, you need an Azure Government account, GCC High licenses, an active Azure Government subscription, and verified custom domains in Microsoft Entra. No prior Azure experience is required to complete these steps.
Confirm all of the following before provisioning:
Azure Government account: you have credentials for an Azure Government (not commercial Azure) account.
GCC High licenses: every user who will access a virtual desktop has their own GCC High license.
Active Azure Government subscription: a subscription exists in your Azure Government tenant and is visible to the account you will use to authorize Secureframe. Licenses alone do not create a subscription.
Dedicated subscription available: you are prepared for Secureframe to provision desktops into a dedicated Azure subscription that you own (not a shared or existing one).
Verified custom domain in Microsoft Entra: your apex domain (for example, yourcompany.com) is added and verified.
If any of these are missing, work through the sections below in order. Your CSM can help at any point.
Azure Government account
Azure Government is a separate cloud from commercial Azure, restricted to U.S. government entities and their contractors. If your organization does not have an Azure Government account yet:
Submit Microsoft's U.S. Government Cloud intake form at https://usgovintake.embark.microsoft.com/. Provide your company details and confirm that you handle CUI (Controlled Unclassified Information) or ITAR data to explain your need for Azure Government or GCC High. You can also follow Microsoft GCC High Tenant Eligibility for CMMC.
Wait for Microsoft's eligibility approval, which typically takes 1 to 2 business days. When approved, you receive an Eligibility ID by email.
Share that email with your Secureframe CSM and purchase GCC High licenses through Secureframe.
After your license purchase is complete, you receive your Azure Government account credentials.
Important: Your tenant name must be 15 characters or fewer. When your Azure Government tenant is created, its .onmicrosoft.us name is permanent and can never be changed. Microsoft puts a 15 character limit on the managed domain name behind your desktops, so a longer tenant name will block desktop provisioning and force extra domain workarounds later. Whether Secureframe creates your tenant or you do, the name before .onmicrosoft.us must be 15 characters or fewer (for example, acmedefense.onmicrosoft.us works; acmedefensesystems.onmicrosoft.us does not).
Already created an Azure Government tenant with a longer name? The tenant name cannot be changed, so this needs to be resolved before desktops can be provisioned. See What to Do If Your Azure Government Tenant Name Is Over 15 Characters.
GCC High licensing
GCC High (Government Community Cloud High) licenses are required for everyone who uses a virtual desktop.
Who needs a license: every user who accesses a virtual desktop needs their own GCC High license, even if that user does not use GCC High for email or file storage. There is no shared or concurrent licensing for desktop access; licensing is per user.
How to purchase: GCC High licenses can be purchased through Secureframe with help from your CSM.
How many: count every person who will log into a virtual desktop, including administrators and occasional users.
Azure Government subscription
This is the step customers most often miss, and the most common cause of failed or stalled deployments.
Important: Purchasing and applying GCC High licenses does not create an Azure subscription. Licenses give your users access to Microsoft 365 GCC High services. An Azure Government subscription is a separate, required setup step. It is the billing and resource location where your virtual desktops are actually deployed.
Use the subscription activated through Secureframe. Your tenant may also offer a default pay-as-you-go subscription that you can activate yourself with a credit card. Do not use it for your enclave. It is billed by Microsoft directly rather than through your Secureframe agreement, and desktops cannot easily be moved to a different subscription later.
Before provisioning can proceed, all of the following must be true:
The subscription exists. An active Azure Government subscription has been created in your tenant.
The subscription is visible to the authorizing account. During setup, Secureframe asks you to sign in with an Azure account and select a subscription. That selection step only lists subscriptions the signed-in account can see in Azure. If the account cannot view any subscription, setup stalls at this step.
The authorizing account has Owner access on the subscription, including permission to assign roles. This is what allows Secureframe's deployment identity to get the access it needs to create desktops.
To check:
Sign in to the Azure Government portal (portal.azure.us) with the account you plan to use for setup.
Open Subscriptions.
Confirm an active subscription is listed. If you do not see one, Secureframe will not see one either.
Note: Seeing your GCC High licenses in the Microsoft 365 admin center does not mean you have an Azure subscription. They are separate systems. If licenses are visible but no subscription appears in the Azure portal, the subscription step still needs to be completed.
Reseller purchases
Many defense contractors purchase Azure Government and GCC High through a reseller such as Carahsoft. If that is you, plan for additional lead time:
Azure Government enrollment and billing activation happens through the reseller, not directly in your tenant. This process can take days to weeks.
The subscription will not appear in your tenant until Azure Government is activated, the billing agreement is set up, and an account owner has been added to the enrollment.
This is true even after your GCC High licenses are applied and visible in the Microsoft 365 admin center. Licenses arriving first is normal. It does not mean the subscription is ready.
If your licenses are active but no subscription has appeared after your reseller's expected activation window, contact your reseller to check enrollment status. Your CSM can also help you confirm what is outstanding.
Dedicated subscription requirement
Secureframe always provisions virtual desktops into a dedicated Azure subscription that you own, never into a shared or existing subscription. This is by design:
Clear security and compliance boundaries. A dedicated subscription creates a clean boundary around your CUI enclave that auditors can verify.
Reliable operation. Isolation means your desktops cannot affect, and cannot be affected by, other workloads running in your Azure environment.
Transparent billing and cost tracking. All virtual desktop costs land in one subscription, so you can see exactly what your desktops cost on your Azure invoice.
Provisioning into an existing VDI environment or a shared subscription is not supported.
Custom domain verification
Before enclave provisioning, add and verify a custom domain name in Microsoft Entra:
Your apex domain (for example, yourcompany.com).
If your tenant's .onmicrosoft.us prefix is longer than 15 characters, a second domain will be necessary (for example, adsf.yourcompany.com) due to a Microsoft naming limit. If this applies to your setup, see What to Do If Your Azure Government Tenant Name Is Over 15 Characters for complete instructions.
Verifying a domain involves adding a DNS record with your domain registrar.
Note: DNS changes can take time to propagate. Complete domain verification ahead of your planned provisioning date so it is not a last-minute blocker.
Once your prerequisites are met
Once everything on this checklist is confirmed, go to the Defense Navigator. The CUI Enclave Setup module walks you through connecting your Azure Government environment as part of your guided CMMC setup. Once connected, you can provision your first desktops. See Provisioning Virtual Desktops for what happens next.
Frequently Asked Questions (FAQ)
Why can't Secureframe deploy into a subscription I already have?
Three reasons: a dedicated subscription gives you a compliance boundary auditors can clearly verify; it guarantees Secureframe cannot accidentally impact anything else running in your environment; and it makes virtual desktop costs obvious on your bill instead of mixed in with other workloads.
Can Secureframe use or integrate with my existing VDI setup?
No. Secureframe cannot use or integrate with an existing VDI deployment. Secureframe-managed desktops are always provisioned fresh into a dedicated subscription.
I already run my own virtual desktops in Azure. What happens to them?
Secureframe's automated tests run against all resources in your connected Azure environment, regardless of who provisioned them, so your self-deployed desktops are still covered by compliance testing. However, they appear only in Asset Inventory; they will not show up as virtual desktops in the Secureframe app. Secureframe-managed desktops can be deployed alongside your existing environment, in a new, separate subscription on an isolated network.
We're an MSP (or manage multiple subscriptions). How does billing work?
Adding a dedicated subscription does not fragment your billing. You keep central, account-level billing across all your subscriptions, and you gain the ability to track virtual desktop costs independently.
Does a separate subscription mean separate access management?
No. You can still manage access centrally across subscriptions using Azure's identity and access management. A dedicated subscription isolates resources and costs, not administration.
My GCC High licenses show up in Microsoft 365, but Secureframe setup can't find a subscription. Why?
Licenses and subscriptions are separate. Applying GCC High licenses does not create an Azure subscription. If you purchased through a reseller, the subscription will not appear until Azure Government enrollment and billing activation are complete. See Reseller purchases above.
If you have questions about any of these prerequisites, contact your CSM or reach out to [email protected].
