Home / Details

GCC High architecture & data flow

Use the diagram to discuss the logical boundary, service dependencies and controlled work paths. The final implementation is validated against the customer’s actual requirements.

CUI WORKSPACE / BOUNDARIES + FLOWS

See where the data goes.
See what protects it.

GCC High enclave: four data and control paths across a layered CUI boundaryAn access device and AVD broker sit outside the logical CUI processing boundary. Entra identity controls gate access. Azure Government hosts process CUI and exchange approved data with separate Microsoft 365 GCC High SaaS. Outbound host service connectivity supports the remote session. Security signals feed continuous compliance and authorization evidence. Four numbered paths use separate colors.GCC HIGH + AZURE GOVERNMENTA clear boundary. Four distinct flows.Reference design • Variant 1 • Service configuration and responsibilities must be validated.LOGICAL CUI WORKSPACE BOUNDARYSeparate service environments — not one shared network or inherited certificationIDENTITY + ACCESS POLICYEntra ID · MFA · Conditional AccessApproved identities and conditions · Intune signals for managed devicesAZURE GOVERNMENTCustomer VNet / controlled subnetAVD host poolMulti-session VMsCUI work / appsDedicated VMsEngineering / GPUIsolated sessionsSession controls: clipboard · drives · USB · printNSGs · NAT / approved outbound endpointsEncrypted disks + Azure BackupIaC baseline · configuration and change reviewMICROSOFT 365 GCC HIGHSeparate SaaS environmentSharePoint · OneDriveExchange · TeamsPurview labels · DLP · retentionSharing rules · customer responsibilitiesACCESS DEVICEWindows AppRemote display + inputOutside CUI workspaceAVD SERVICEBroker / gatewaySession establishmentRelayed reference pathLOCAL CUI EXPORTBlocked by configuredsession restrictions1223CUI / TLSApprovedworkflowsSECURITY TELEMETRY → CONTROL REVIEW → AUTHORIZATION EVIDENCEDefender / SentinelIdentity, host & SaaS signalsControl + risk reviewFindings · owners · decisionsSSP / POA&M / evidenceContinuous compliance / RMF4OPERATING FOUNDATIONVersion-controlled IaC · approved change · evidence refresh · defined customer / provider responsibilitiesREMOTE SESSIONHosts initiate outboundservice connectivity.No inbound RDP listeneris implied on the hosts.

Swipe across the map to inspect each boundary, or use the numbered steps below.

Four paths, one logical boundary.

Purple is identity policy; blue is the remote session; teal is approved CUI collaboration; amber is telemetry and evidence. The outer frame groups the CUI workspace logically. Azure Government and GCC High retain separate service boundaries.

1 / Verify identity

Entra ID, MFA and Conditional Access evaluate the user and access conditions. Managed-device compliance and untrusted-device access are separate policy decisions.

2 / Open an isolated session

Windows App reaches the AVD service. Session hosts initiate outbound service connectivity. Only display and input are intended at the access device; configured redirection restrictions protect the CUI workspace.

3 / Process and collaborate

CUI is processed on multi-session or dedicated hosts and exchanged with approved SharePoint, OneDrive, Exchange and Teams workflows. Network egress, labels, DLP and sharing policies serve different purposes.

4 / Keep evidence current

Review identity, host, application and configuration signals against controls. Validate findings, track POA&M actions and refresh SSP/authorization evidence; telemetry does not automatically establish compliance.

Moving packets illustrate flows, not live traffic.

Logical reference architecture, not a physical topology, certification or promise of control inheritance. Validate government-cloud service availability, licensing, endpoints, session controls and customer/provider responsibilities for the implementation. This view illustrates a relayed AVD session; other approved transport configurations require their own validation.

Trace the workflow

  • Identify where authorized users enter the virtual workspace and where application processing occurs.
  • Separate Azure Government resources from Microsoft 365 GCC High services and identify their shared identity dependencies.
  • Map storage, collaboration, administration, monitoring and recovery paths.

Validate the design

  • Confirm service availability, licensing, workload compatibility and provider responsibilities.
  • Test access controls, session restrictions and approved transfers.
  • Record the implemented topology and customer responsibilities rather than treating a reference diagram as certification evidence.

Microsoft AVD network connectivity reference