Skip to main content

Golden Image for Virtual Desktops

M
Written by Mike Castro

What a golden image is

A golden image is a master copy of a computer's operating system, with the software, settings, and security configuration already in place. Instead of setting up each computer one at a time, IT teams build one golden image and create every new computer as a copy of it. Every computer starts out the same, and none of them has to be configured by hand.


Secureframe's golden image

Secureframe builds and maintains a golden image for your Virtual Desktops, and every desktop in your environment is created from it. It's a Windows 11 desktop with Microsoft 365 apps preinstalled, so your team can open a desktop and start working right away. Before any desktop is created, Secureframe hardens the image. Hardening means locking the system down to a strict security standard: turning on the protections CMMC requires, and turning off anything that could put CUI at risk. The image is configured to Microsoft and U.S. Department of Defense security guidance and mapped to CMMC Level 2.

The goal is a desktop that is secure without getting in your team's way. The protections are built in, so people work in a familiar Windows and Microsoft 365 setup while the desktop keeps CUI inside your environment, records who did what, and blocks software that isn't approved.

  1. Secureframe builds a Windows 11 image with Microsoft 365 apps preinstalled.

  2. Secureframe hardens the image with a security configuration mapped to CMMC Level 2.

  3. Secureframe tests each new version before it's released. A version that fails is never released.

  4. The approved image is added to your Azure Government environment, and your desktops are built from it.


How each version is tested

Every version of the golden image is tested before it reaches you. Secureframe starts a test desktop from the new version and checks that it works as expected. Only a version that passes is released. If a version fails its test, it's never released, and your desktops keep using the last approved version. A broken or incomplete image can't reach your environment.


Where your image is kept

Once a version passes testing, Secureframe adds it to an image gallery in your own Azure Government environment, next to your desktops. Your desktops are built from that copy.


Why it matters for CMMC

CMMC requires a documented security baseline, applied the same way on every system that handles CUI. Assessors check that the baseline is in place and that your systems match each other. When every desktop is a copy of the same golden image, the baseline is the image itself. A setting can't be applied to some desktops and missed on others, and a new desktop is never running before it's locked down. A desktop built next month matches one built today. That makes your evidence simpler. Your assessor can look at one desktop and know the others were built the same way.


What the golden image includes

The golden image includes dozens of security settings, each mapped to a CMMC requirement. Here are some of the main ones, grouped by what they protect:

  • Sign-in is controlled: Only the right people get in, a notice appears before sign-in, and idle sessions lock and end on their own (AC.L2-3.1.x).

  • Credentials are protected: Sign-in attempts and passwords follow strict rules, stored credentials are protected, and smart cards like CAC are supported (IA.L2-3.5.x).

  • Admin rights are limited: Everyday work runs without admin rights, and Windows asks for approval before anything runs with them (AC.L2-3.1.5, AC.L2-3.1.7).

  • Only approved software runs: Software that hasn't been approved is blocked for regular users, and features the desktop doesn't need are removed (CM.L2-3.4.x).

  • CUI stays inside: Nothing moves between the desktop and the computer you connect from, and files can't be copied to removable media (AC.L2-3.1.3, MP.L2-3.8.7).

  • Activity is recorded: Windows records enough detail to tell who did what, including PowerShell activity (AU.L2-3.3.x). See Activity Logging for Virtual Desktops for where those records go.

  • Connections are protected: Outdated network protocols are turned off, network traffic is signed and encrypted, and the firewall blocks unwanted incoming connections (SC.L2-3.13.x).

  • Malicious code is blocked: Unsafe downloads, Office macros, and programs that launch automatically from drives are blocked (SI.L1-3.14.2).

For the full list of settings and their CMMC mappings, reach out to your CSM.


What your team will notice

Most of this is invisible. These are the parts people actually feel.

  • Desktops lock on their own: A desktop locks after 15 minutes without activity, and an idle session ends after 15 minutes. If someone disconnects, the session ends after a minute, so reconnecting means signing in again.

  • Nothing moves between the desktop and your own computer: Copy and paste, drive and file transfer, printing, and screenshots are all turned off between the two. This is how CUI stays inside the environment instead of ending up on a personal laptop.

  • Most people can't install software: Regular users can run the software already on the desktop, but not something they downloaded. Someone with administrator access on the desktop can install software.

  • Sign-in rules are strict: Accounts lock after repeated failed attempts, and passwords have to be long.

  • A notice appears before you sign in: Everyone sees an authorized-use notice before they sign in, as required for a system that handles CUI.


How the golden image is updated

Secureframe releases new versions of the golden image, including Windows updates and security changes. New desktops are built from the newest approved version. A desktop you already have kept the version it was built from until it's rebuilt.

Note: Your profile and files on the shared drive (Z:) are kept separate from the golden image, so they're not affected when a desktop is rebuilt. Files saved only on a desktop, such as on the Desktop, in Downloads, or on local disks, are not kept. Save shared work on the shared drive (Z:).


Frequently Asked Questions (FAQ)

Do I need to do anything to use the golden image?

  • No. Secureframe builds, tests, and copies the golden image for you. Your desktops are built from it automatically.

Can my team install software?

  • Someone with administrator access on the desktop can. Everyone else is limited to the software already there.

Why was my installer blocked?

  • You're most likely signed in as a regular user rather than an administrator. Regular users can run the software already installed, but can't run something they downloaded themselves.

Are the desktops encrypted?

  • Yes. Azure encrypts each desktop's disks at the platform level, which covers the whole machine.

Which Azure regions is the golden image available in?

  • US Gov Virginia, US Gov Arizona, and US Gov Texas.

Questions? Contact [email protected] or reach out to your CSM.

Did this answer your question?