Connect from Windows
Your virtual desktop is a full Windows 11 machine that you reach through a remote desktop app. Here is how to connect for the first time and what to expect.
Open the Windows Remote Desktop client.
Click the + (Add) icon and select Add Workspace.
Enter the Azure Government workspace URL:
https://rdweb.wvd.azure.us/api/arm/feeddiscoveryLog in with your Azure Government credentials.
Your assigned desktops appear in the app. Double-click a desktop to launch it.
Connect from Mac
Confirm you are on macOS 14 or later.
Install the latest Windows App from the Mac App Store: Windows App.
Add the same workspace URL and sign in with your Azure Government credentials.
If a Mac connection fails after adding the workspace, make sure the Windows App is up to date. If issues continue, reach out to your CSM for assistance.
Your first sign-in
First-time access often requires a password change. Watch for the "change your Azure password to access your virtual desktop" email and complete the change before signing in.
The first launch can take a few minutes while the desktop loads. Later sign-ins are faster.
You may see more than one sign-in prompt: one for the Windows App or Remote Desktop client, and another when the desktop session starts. Automatic single sign-in after the app is not expected on the current platform.
Your files and profile
Your settings and preferences live in your profile, not on any single machine. Whichever desktop you sign in to, those follow you.
Files stored only on that desktop do not. That includes items on the Desktop, in Downloads, and on local disks. Before a rebuild or platform upgrade, move important files to OneDrive or the shared data drive (Z:). Large working datasets should live on Z:, not on one desktop. See Provisioning Virtual Desktops for what the shared drive is for.
Important: Software installs and machine-specific configs usually cannot move to OneDrive. Plan to reinstall those after a rebuild.
What's blocked, and why
Your virtual desktop is a controlled CUI environment, so some familiar actions are intentionally disabled:
Copying and pasting between the virtual desktop and your local computer
Transferring files to your local drives
Redirecting USB devices into the desktop
Printing to local printers
These restrictions are what generally keep the computer you connect from out of CMMC scope. CUI stays inside the desktop. The desktop also locks automatically after inactivity, and multi-factor authentication protects sign-in.
Troubleshooting
Can't connect, or error 0x5000057 in the Windows App: this usually means the app does not see an available virtual desktop for your account yet. Check four things: your GCC High license is active, you are listed under User access for the desktop, the desktop's provisioning has completed, and you entered the correct Azure Government workspace URL (
https://rdweb.wvd.azure.us/api/arm/feeddiscovery).Can't sign in: check for the password-change email and complete it first. If the email never arrived, contact [email protected] and include the user email and desktop name.
Desktop not listed: refresh the workspace in your app, or remove and re-add it.
Slow first load: first sign-in takes the longest. Give it a few minutes before retrying.
More than one sign-in prompt: Supported Virtual Desktops use a managed domain join, not Entra join. One prompt is for the Windows App or Remote Desktop client, and another can appear when the desktop session starts. Automatic single sign-in after the app is not expected on the current platform.
OneDrive asks for a passkey or fails to sync: Sign out of the desktop, refresh the Windows App, and reconnect, then try OneDrive again. If your tenant limits SharePoint OneDrive sync to domain-joined PCs, allow syncing beyond that restriction or add your Entra Domain Services domain GUID so Virtual Desktops can sync. If passkey prompts from a phone still fail after reconnect, contact [email protected] or your CSM. Some tenants need a Secureframe-side change.
Frequently Asked Questions (FAQ)
Why do I get more than one sign-in prompt now?
Supported Virtual Desktops use a managed domain join, not Entra join. That can mean one prompt for the Windows App or Remote Desktop client, and another when the desktop session starts. Automatic single sign-in after the app is not expected on the current platform.
OneDrive asks for a passkey or fails to sync on the virtual desktop. What should we check?
Confirm OneDrive sign-in works after you sign out of the desktop, refresh the Windows App, and reconnect.
If SharePoint OneDrive sync is limited to domain-joined PCs, either allow syncing beyond that restriction, or add your Entra Domain Services domain GUID so sync is allowed on Virtual Desktops.
Contact [email protected] or your CSM if passkey prompts from a phone still fail after reconnect. Some tenants need a Secureframe-side change.
Will I lose data if my virtual desktop is rebuilt or migrated?
Yes, for files stored only on that desktop (Desktop, Downloads, local disks). Move important files to OneDrive or the shared Z: drive before a rebuild. See Secureframe Virtual Desktops and Provisioning Virtual Desktops.
Questions? Contact [email protected] or reach out to your CSM.
