Skip to content
Secure Open Solutions

Home / Secure enclaves

Explore the security architecture.

Inspect the control layers and follow the CUI workflow.

SECURITY ARCHITECTURE / INTERACTIVE

Seven controls. One coherent boundary.

Explore how identity, network, data, endpoints, detection, and cloud applications work together in a GCC High enclave. Select a numbered control to inspect its architecture.

01 / IDENTITY & ACCESS

Device trust before access

Intune manages device configuration and reports compliance signals to Microsoft Entra ID. Conditional Access uses those signals with identity, location, and sign-in risk to decide whether users may reach approved cloud resources. Policies are designed around each user and CUI workflow.

Intune device compliance, Entra Conditional Access, and protected Microsoft 365 accessUse Enlarge diagram to inspect the image, or select the diagram to discuss it ↗

GCC HIGH / AZURE GOVERNMENT ENCLAVE

Follow the CUI. Inspect the controls.

See how a virtual desktop keeps CUI processing inside the enclave, how GCC High collaboration fits alongside Azure Government, and how security telemetry supports continuous compliance.

CUI WORKSPACE / BOUNDARIES + FLOWS

See where the data goes.
See what protects it.

GCC High enclave: four data and control paths across a layered CUI boundaryAn access device and AVD broker sit outside the logical CUI processing boundary. Entra identity controls gate access. Azure Government hosts process CUI and exchange approved data with separate Microsoft 365 GCC High SaaS. Outbound host service connectivity supports the remote session. Security signals feed continuous compliance and authorization evidence. Four numbered paths use separate colors.GCC HIGH + AZURE GOVERNMENTA clear boundary. Four distinct flows.Reference design • Variant 1 • Service configuration and responsibilities must be validated.LOGICAL CUI WORKSPACE BOUNDARYSeparate service environments — not one shared network or inherited certificationIDENTITY + ACCESS POLICYEntra ID · MFA · Conditional AccessApproved identities and conditions · Intune signals for managed devicesAZURE GOVERNMENTCustomer VNet / controlled subnetAVD host poolMulti-session VMsCUI work / appsDedicated VMsEngineering / GPUIsolated sessionsSession controls: clipboard · drives · USB · printNSGs · NAT / approved outbound endpointsEncrypted disks + Azure BackupIaC baseline · configuration and change reviewMICROSOFT 365 GCC HIGHSeparate SaaS environmentSharePoint · OneDriveExchange · TeamsPurview labels · DLP · retentionSharing rules · customer responsibilitiesACCESS DEVICEWindows AppRemote display + inputOutside CUI workspaceAVD SERVICEBroker / gatewaySession establishmentRelayed reference pathLOCAL CUI EXPORTBlocked by configuredsession restrictions1223CUI / TLSApprovedworkflowsSECURITY TELEMETRY → CONTROL REVIEW → AUTHORIZATION EVIDENCEDefender / SentinelIdentity, host & SaaS signalsControl + risk reviewFindings · owners · decisionsSSP / POA&M / evidenceContinuous compliance / RMF4OPERATING FOUNDATIONVersion-controlled IaC · approved change · evidence refresh · defined customer / provider responsibilitiesREMOTE SESSIONHosts initiate outboundservice connectivity.No inbound RDP listeneris implied on the hosts.

Swipe across the map to inspect each boundary, or use the numbered steps below.

Four paths, one logical boundary.

Purple is identity policy; blue is the remote session; teal is approved CUI collaboration; amber is telemetry and evidence. The outer frame groups the CUI workspace logically. Azure Government and GCC High retain separate service boundaries.

1 / Verify identity

Entra ID, MFA and Conditional Access evaluate the user and access conditions. Managed-device compliance and untrusted-device access are separate policy decisions.

2 / Open an isolated session

Windows App reaches the AVD service. Session hosts initiate outbound service connectivity. Only display and input are intended at the access device; configured redirection restrictions protect the CUI workspace.

3 / Process and collaborate

CUI is processed on multi-session or dedicated hosts and exchanged with approved SharePoint, OneDrive, Exchange and Teams workflows. Network egress, labels, DLP and sharing policies serve different purposes.

4 / Keep evidence current

Review identity, host, application and configuration signals against controls. Validate findings, track POA&M actions and refresh SSP/authorization evidence; telemetry does not automatically establish compliance.

Moving packets illustrate flows, not live traffic.

Logical reference architecture, not a physical topology, certification or promise of control inheritance. Validate government-cloud service availability, licensing, endpoints, session controls and customer/provider responsibilities for the implementation. This view illustrates a relayed AVD session; other approved transport configurations require their own validation.

Discuss your GCC High enclave · Read the GCC High data-flow guide