Once upon a time, Windows 365 was shiny and new and Azure Virtual Desktop was still going by “Windows Virtual Desktop.” I used to talk about how virtual desktops were great for like… “control your data when you’ve got contractors using their own computers but working in your systems” and now JUST KIDDING it’s all about CMMC. (also the other thing with the contractors)
Why a virtual desktop at all? One word: SCOPE.
Virtual desktops (VDI, DaaS, Cloud PCs, whatever we’re calling them right now) have always had a solid pitch: give people a full Windows desktop that lives in the cloud, centrally managed, accessible from anywhere, with nothing sensitive sitting on the laptop in their bag. Fast onboarding, easy offboarding, BYOD without the heartburn. All good things!
But for defense contractors there is a MUCH bigger reason, and it’s spelled C-M-M-C.
CMMC assessments are scoped around where CUI lives. Every asset that processes, stores, or transmits CUI is in scope. Every in-scope asset is something you have to secure, document, and defend in front of an assessor. Which brings us to a line in the CMMC Level 2 Scoping Guide that should make every IT director sit up straight:
“An endpoint hosting a VDI client configured to not allow any processing, storage, or transmission of CUI beyond the Keyboard/Video/Mouse sent to the VDI client is considered an Out-of-Scope Asset.”
This was a question we were all asking before 32 CFR Part 170 (the CMMC program bit of the Code of Federal Regulations), and then the question was ANSWERED when that rule got published. If your users only ever touch CUI inside a virtual desktop, and the local device is configured so nothing but keyboard, video, and mouse crosses the wire, then the physical device is OUT OF SCOPE. Colloquially, we say “your jump box is out of scope”.
And here’s the part that’s easy to forget: it’s not just the jump box. If CUI never touches your local environment, your local NETWORK falls out of scope too. The only thing traveling across your office network (or your employee’s home Wi-Fi, or the coffee shop’s questionable router) is an encrypted remote-session stream, and what’s inside it is keyboard, video, and mouse. No CUI transmission means no CUI assets, which means your switches, your access points, and yes, your firewall are not part of the assessment. You know what that means? You do not have to figure out how to run your firewall in FIPS mode. I need you to understand how much pain that one sentence just saved you.
That’s the whole logic of the enclave model: build a boundary in GCC High and Azure Government, put ALL of your CUI (and the people who need it) inside that boundary, and let the laptops, desktops, home machines, and network gear between them become windows into the environment instead of part of it. Your assessment boundary shrinks from “every device and cable we own” to “the enclave.” Smaller boundary means a smaller System Security Plan, fewer assets to inventory and harden, less evidence to produce, and a WAY less painful assessment, whether that’s a self-assessment or a C3PAO engagement.
Two caveats before you get too excited.
Caveat one: “configured to not allow” is doing a LOT of work in that sentence. Clipboard redirection, drive mapping, printing, screen capture, local file transfer… all of it has to be locked down and provable, because an assessor will absolutely check. DoW’s own technical implementation guidance says exactly that: if the endpoint isn’t truly restricted to keyboard/video/mouse, it gets reclassified as a CUI asset and yanked into scope. A VDI client with copy/paste to the local machine enabled is just a CUI asset with extra steps.
Caveat two: the enclave itself is 100% in scope. The session hosts or Cloud PCs, the identity platform, the storage, the security tooling protecting all of it. VDI does not make CMMC go away. It puts a fence around the part you have to defend. (Same goes for the rest of your boundary: if CUI also lives in your GCC High email and SharePoint, those are in scope and you gotta set up your DLP policies and make sure you know exactly how CUI is moving around those services. The enclave story works because the CUI stays IN the enclave.)
The two contenders
Microsoft gives you two ways to run virtual Windows desktops in its government clouds, and they share DNA in that they are both virtual environments and the end-user experience can be pretty similar, but the backends are wildly different. Let’s go.
Windows 365 Government
This is the SaaS take: a dedicated Cloud PC for each user, at a fixed size, for a fixed monthly price, with Microsoft managing the underlying infrastructure. Windows 365 Government for GCC High runs in Azure Government: physically isolated, US-based, operated by screened US persons, and built for the DFARS 7012 / ITAR / CMMC crowd (Microsoft’s service description spells out the compliance lineup). Per that same service description, each user needs Windows 11 or Windows 10 Enterprise, Intune, and Entra ID P1. Then you pick a Cloud PC size (vCPU, RAM, storage), assign the license, and manage the machine through Intune like any other endpoint. There’s also a GCC edition, plus a pooled offering called Flex (formerly Frontline) for part-time and occasional-access users.
Azure Virtual Desktop in Azure Government
This is the build-it-yourself take: you run session hosts in your own Azure Government subscription, generally available across the US Gov regions, and you manage the VMs, images, networking, scaling, and profiles yourself. In exchange you get flexibility Windows 365 can’t touch: pooled multi-session hosts that let a bunch of users share one VM, custom images, GPU-class machines for the engineering folks, and granular control over every single layer.
Same control plane, different philosophies
| Windows 365 Government | AVD in Azure Government | |
| Who runs it | Microsoft manages the infrastructure; you manage the Cloud PC through Intune | You manage the session hosts, images, networking, scaling, and updates |
| Cost model | Fixed per-user, per-month license | Azure consumption billed to your Azure Government subscription |
| Assignment | Dedicated 1:1 Cloud PC per user | Personal (1:1) or pooled multi-session |
| Identity | Managed through your GCC High tenant’s Entra ID and Intune | Entra joined, Entra hybrid joined, or AD DS domain joined (your call) |
| Networking | Microsoft-hosted network, or connect to your own Azure virtual network | Your Azure Government virtual network, your routing, your rules |
| User profiles | Profile lives on the Cloud PC (single user) | FSLogix profile containers (required for pooled) |
| Flexibility | Fixed sizes (vCPU/RAM/storage combos), broad enough for most office work | Any supported VM series, custom images, GPU-class machines |
How pricing works (without the price tags)
The original version of this post had a pricing table. Those prices have changed approximately nine hundred times since 2021, so instead of numbers (which would be stale before you finished reading), here’s how to actually compute your costs. Teach a person to fish, etc.
Windows 365 Government math is EASY, and that is most of its charm: number of users times the monthly license for the Cloud PC size each user needs. That’s it. That’s the math. Sizes are defined by vCPU/RAM/storage combinations, and the fee is flat whether a user logs in for two hours or two hundred. Users need the prerequisite licensing (Windows Enterprise, Intune, and Entra ID P1, which most GCC High shops already own through their Microsoft 365 licensing), and GCC High Cloud PC licenses come through an AOS-G partner like Agile IT (hi!). Budget forecasting is a multiplication problem. DONE.
AVD math has more variables, and that’s the point. There’s no separate per-user AVD fee if your users already carry eligible licenses (Microsoft 365 G5/G3/F3/Business Premium). What you pay for is Azure Government consumption: session host compute by the hour, OS disks, FSLogix profile storage, and networking. The back-of-napkin model: peak concurrent users divided by users-per-session-host gives you your host count, then hosts times hours powered on times the VM rate, plus storage. And that formula is exactly where the savings hide. Pack more users onto multi-session hosts. Autoscale hosts OFF overnight and on weekends (why are you paying for empty desktops at 2am?). Cover the always-on core with reserved instances or a savings plan.
Rule of thumb: predictable, full-time, one-desktop-per-person workforce? Windows 365’s flat fee and near-zero infrastructure management are hard to beat. Shift workers, part-timers, surge capacity, or a big population of occasional users? AVD’s pooled model usually wins, and usually by a lot, IF you have (or hire) the expertise to run it well.
So which one?
For a lot of contractors building CMMC enclaves, the real answer is “both,” and I’m not being wishy-washy. Windows 365 Government for the steady, full-time CUI users who need a persistent desktop that’s always theirs. AVD for pooled access, specialized workloads, and everyone who touches CUI occasionally. They hang off the same control plane and the same management stack, so mixing them isn’t exotic. It’s common. And either way, the scoping benefit is identical, because the local device is only ever sending keyboard, video, and mouse.
FAQ
Does a virtual desktop really take my laptops out of CMMC scope?
Yes, with conditions. The endpoint has to be configured so that no CUI is processed, stored, or transmitted locally. Nothing beyond keyboard, video, and mouse goes to the VDI client. That means clipboard, drive, and printer redirection are disabled (or tightly controlled) and you can PROVE it. Assessors verify the configuration, and an endpoint that fails the test gets reclassified as a CUI asset. Configuration is the whole ballgame here.
What about my network gear? Do I need FIPS mode on my firewall?
If CUI never traverses your local network, your local network is not transmitting CUI, and equipment that can’t touch CUI is out of scope. The remote session stream is encrypted by the service, and what’s inside it (per the scoping guide) is keyboard, video, and mouse. So no: in a clean enclave model, you do not need to run your office firewall in FIPS mode or drag your switches into your SSP. HOWEVER, and this is a big however, that only holds if CUI truly never touches the local environment. Print a CUI drawing to the office printer or sync a CUI file to a local share and you have just changed your own answer.
Is the virtual desktop environment itself in scope?
Completely. 100%. The Cloud PCs or session hosts, identity, storage, networking, and every security tool protecting them are all inside your assessment boundary and must meet the applicable NIST SP 800-171 requirements. The enclave is the thing you defend. The win is that it’s the ONLY thing you defend.
Do I have to use GCC High and Azure Government for this?
If your CUI includes export-controlled data (think ITAR), or your contracts flow down DFARS 252.204-7012, which requires your cloud provider to meet FedRAMP baselines and support paragraphs (c) through (g) on incident reporting, the government clouds are where you want to be. Microsoft’s service description lists GCC High’s compliance lineup directly: FedRAMP High, ITAR, DFARS. Richard Wakeman’s compliance comparison is the best walkthrough of commercial vs. GCC vs. GCC High out there, and most defense contractors handling CUI land on GCC High plus Azure Government.
Isn’t CMMC paused right now? Why bother?
Ok. Yes, the Department of War suspended CMMC Phase II requirements in July 2026 while a reform task force reviews the program. The underlying obligations didn’t go ANYWHERE. DFARS 252.204-7012 is still in your contracts. NIST SP 800-171 compliance has been required since December 31, 2017 (that is not a typo, 2017). And 32 CFR Part 170, the rule establishing the CMMC program, remains in effect. The pause changes the assessment timeline, not the requirements. An enclave you build now is compliance you already owe, plus a head start for when third-party assessments come roaring back. And they will.
Is Windows 365 or Azure Virtual Desktop cheaper for your business?
It depends on your usage pattern (see the pricing section above). Flat per-user pricing wins for full-time dedicated desktops. Pooled multi-session usually wins for part-time and shift-based users. And do not forget the operational side of the ledger: AVD needs ongoing care and feeding (image management, scaling, patching, FSLogix tuning), and that is a real cost whether it lands on your team or a partner.
Can people work from personal or BYOD devices?
Yes, and for many organizations that is THE biggest draw. Because a properly configured endpoint is out of scope, employees can reach the enclave from devices you don’t own or manage, without dragging those devices into your assessment. Pair it with strong conditional access (require MFA, block downloads, restrict redirection at the host) and the enclave stays sealed no matter what’s connecting to it.
My engineers need serious horsepower for CAD, rendering, and simulation. Which one?
AVD, no contest. Because the session hosts are VMs in your own subscription, you can deploy GPU-class machine series (where available in your Azure Government region) and size them however the workload demands. Windows 365’s fixed sizes cover most office and line-of-business work just fine, but heavy engineering workloads are AVD territory.
Agile IT has spent YEARS moving defense contractors into GCC High and Azure Government and building CMMC enclaves that hold up under assessment. We legit know this stuff. If you’re weighing Windows 365 against AVD, or you just really want your laptops and firewalls out of scope, schedule a call and let’s figure out the right architecture for your environment, your contracts, and your budget. LFG.





