Connecting your Azure Government environment
Provisioning happens in two parts. You connect your Azure Government environment once, guided by the CUI Enclave Setup module in the Defense Navigator, and then provision desktops whenever you need them from the Virtual Desktops module.
This is the one-time step, and the recommended place to do it is the CUI Enclave Setup module in Navigator, where it happens in the right order within your CMMC setup. If you go straight to the Virtual Desktops page instead, you will be prompted to set up your virtual desktop infrastructure first. It is the same connection either way, and both paths walk you through it.
Secureframe connects to your environment through an App Registration that you create, which means Secureframe only ever has access to the infrastructure needed for virtual desktops, nothing else in your tenant.
Follow the on-screen instructions to create the App Registration and enter the required IDs and secrets. Each step is laid out exactly.
Sign in with an account that has the Owner role on the subscription (or Contributor plus User Access Administrator), including permission to assign roles, and select your subscription when prompted.
Secureframe then builds the foundation your desktops run on, including an isolated virtual network with security rules that block inbound internet traffic and a NAT gateway for controlled outbound access. You will land on a confirmation page when your environment is connected, and the person who started the deployment gets an email when the infrastructure finishes deploying. These core resources incur Azure costs even before any desktops exist. Costs depend on the number of users and your workflow type.
Note: Complete Prerequisites to setting up your Virtual Desktops before you start. Missing subscription visibility or Owner access is the most common cause of stalled setup.
Provisioning a desktop
Desktops are provisioned from the Virtual Desktops page under Defense.
Click Provision new desktop.
Configure the desktop: Name, Image (Windows 11), Region (US Gov Virginia), Instance type (Lite: 2 vCPUs / 8 GB RAM, Medium: 4 vCPUs / 16 GB RAM, Heavy: 8 vCPUs / 32 GB RAM, or Power GPU-enabled for engineering work), Disk size (128 GB to 2 TB), and User access (each user needs an active GCC High license).
Review and confirm. Secureframe shows estimated Azure costs in the product before you deploy. Confirm to start provisioning.
If your subscription is out of quota for the selected instance type, Secureframe falls back to an alternative where possible. Otherwise the deployment error tells you what to fix, and you may need to request a quota increase from Azure.
Your CSM can help you choose the right setup for your team.
What every desktop includes
You are not provisioning a bare virtual machine. Every desktop deploys from a CMMC-compliant configuration:
Windows 11, joined to your Entra ID, with multi-factor authentication required to sign in
Microsoft Defender endpoint protection and automatic patching
Automatic screen lock after inactivity
Clipboard, drive, USB, and printer redirection blocked, so CUI stays inside the desktop
Encryption at rest on FIPS-validated Azure Government hardware
Network isolation, with desktops unable to reach each other and no inbound access from the internet
This configuration is what Secureframe's automated CMMC tests validate continuously after deployment.
Managing your desktops
Every desktop you provision appears in your desktop list, showing its size, region, image, assigned users, and two statuses:
Deployment status: Tracks the build, showing Complete once Azure finishes creating the desktop.
System status: Shows whether the desktop is currently Running or Stopped.
If a deployment fails, the error message describes the issue (for example, quota or SKU availability) so you know what to fix.
From each desktop's menu you can Start, Stop, or Restart the desktop, or Delete it when it is no longer needed. Azure charges accrue for resources while they exist, so delete desktops you no longer use.
Managing user access
Assign users to a desktop from the same menu. Each assigned user needs an active GCC High license, and the desktop appears in their remote desktop app automatically. See Accessing Your Virtual Desktop for what your users do next.
Removing a user takes effect right away. Their sign-in access and their remote desktop feed access are both revoked. If a removed user still sees the desktop listed, have them refresh or remove and re-add the workspace in their app.
Frequently Asked Questions (FAQ)
What Azure resources are created during initial setup, before any desktops?
Core resources needed to securely enable desktop deployment, such as a virtual network, subnets, and a NAT gateway.
What Azure resources are created for each desktop?
The virtual machine along with its storage disk, network interface, and security configurations (network security groups, identity assignments, and monitoring agents).
Can I provision into an existing subscription or VDI environment?
No. Desktops are always provisioned fresh into a dedicated subscription that you own. See Prerequisites to setting up your Virtual Desktops for why.
Questions? Contact [email protected] or reach out to your CSM.
