Entra ID, MFA and Conditional Access evaluate the user and access conditions. Managed-device compliance and untrusted-device access are separate policy decisions.
Home / Details
GCC High architecture & data flow
Use the diagram to discuss the logical boundary, service dependencies and controlled work paths. The final implementation is validated against the customer’s actual requirements.
See where the data goes.
See what protects it.
Swipe across the map to inspect each boundary, or use the numbered steps below.
Purple is identity policy; blue is the remote session; teal is approved CUI collaboration; amber is telemetry and evidence. The outer frame groups the CUI workspace logically. Azure Government and GCC High retain separate service boundaries.
Windows App reaches the AVD service. Session hosts initiate outbound service connectivity. Only display and input are intended at the access device; configured redirection restrictions protect the CUI workspace.
CUI is processed on multi-session or dedicated hosts and exchanged with approved SharePoint, OneDrive, Exchange and Teams workflows. Network egress, labels, DLP and sharing policies serve different purposes.
Review identity, host, application and configuration signals against controls. Validate findings, track POA&M actions and refresh SSP/authorization evidence; telemetry does not automatically establish compliance.
A controlled handoff into an isolated asset boundary.
Define transfer direction, authorized operator, media protection, inspection, custody and evidence before allowing the handoff. Confirm what the asset can read. If encrypted media is incompatible, validate an appropriate protection approach for the actual workflow. The extension does not create unrestricted connectivity from AVD to equipment.
Discuss OT cybersecurity and Continuous RMFLogical reference architecture, not a physical topology, certification or promise of control inheritance. Validate government-cloud service availability, licensing, endpoints, session controls and customer/provider responsibilities for the implementation. This view illustrates a relayed AVD session; other approved transport configurations require their own validation.
Trace the workflow
- Identify where authorized users enter the virtual workspace and where application processing occurs.
- Separate Azure Government resources from Microsoft 365 GCC High services and identify their shared identity dependencies.
- Map storage, collaboration, administration, monitoring and recovery paths.
Validate the design
- Confirm service availability, licensing, workload compatibility and provider responsibilities.
- Test access controls, session restrictions and approved transfers.
- Record the implemented topology and customer responsibilities rather than treating a reference diagram as certification evidence.
