Skip to content
Secure Open Solutions

Home / Details

Variant 2 — Managed endpoint extension

Extend the virtual enclave to approved, managed devices when authorized work requires local applications or peripherals. The device becomes part of the control environment instead of a simple display endpoint.

Variant 2 — Managed endpoint extension reference diagram
Reference illustration. Select the image to send an inquiry or schedule an appointment. Service configuration and control responsibilities are validated for the actual deployment.
Managed device authentication
Managed device authentication. The customer workflow and implemented controls determine the final configuration.

Who this fits

Teams with a documented business need for local processing, approved printing, or device-specific engineering tools.

What belongs in the boundary

The virtual enclave plus authorized endpoints, local storage and applications, device administration, permitted peripherals, recovery, and the locations in which CUI is handled.

Implementation work

  • Identify the users, devices, files, and tasks permitted outside the virtual desktop.
  • Enroll and harden devices, define access conditions, and establish encryption, patching, endpoint protection, and recovery.
  • Configure labeling, sharing and transfer policies, peripheral approvals, and separation of administrative accounts.
  • Verify local storage, access, lost-device response, logging, and evidence collection.

Evidence and operating responsibilities

  • Boundary and data-flow records; asset and authorized-user inventories.
  • Configuration baselines, control narratives, owner assignments and operating procedures.
  • Validation results, access reviews, monitoring records and recovery tests.

Decisions to resolve before deployment

Local CUI handling expands the boundary. Physical safeguards, device custody, authorized use, and evidence of ongoing maintenance need explicit owners.