Skip to main content
Greypike's CMMC Knowledge Base

If you cannot find information about a compliance topic, please contact us for free support.

< All Topics
Print

Virtual Desktop Enclave vs Managed Laptops for CUI

A virtual desktop enclave can remove your entire laptop fleet from the assessment. Not reduce it. Remove it. That single sentence is why this comparison is worth an executive hour, and why the detail underneath it deserves more care than most vendors give it.

The regulation is precise, and the precision is the whole point. Get the configuration wrong and you keep the cost of the virtual desktop enclave while keeping every laptop in scope as well, which is the worst of both approaches. This page sits under How to Compare CMMC Compliance Options: Enclave, Full Environment, or Managed Service.

The rule, quoted, because the wording is the value

32 CFR 170.19 lists among out of scope assets the following: an endpoint hosting a virtual desktop client configured to not allow any processing, storage, or transmission of controlled information beyond the keyboard, video and mouse sent to that client.

Three things follow, and executives should understand all three.

  • Out of scope is the strongest category there is. Not a contractor risk managed asset, not a specialized asset. Out of scope means the laptop is not assessed at all.
  • It is conditional, and the condition is a configuration. Keyboard, video and mouse only. Nothing else may cross.
  • “Configured to not allow” is a control you must enforce and evidence. Intent does not qualify. A policy asking people not to copy files does not qualify. The block has to be in place and demonstrable.

What breaks the exemption

Every one of these is a channel that can move controlled information onto the endpoint, and enabling any of them puts the laptop back in scope.

RedirectionWhy it breaks the exemptionWhat people use it for
Clipboard, in either directionControlled text reaches the local clipboardCopying a part number into a quote
Local drive and USB storageControlled files written to the laptopMoving a file to a customer portal
Printer redirectionThe document is rendered on the endpointPrinting a drawing at home
Screenshots and local recordingNot addressed by the rule and a practical leakSharing a view in a meeting

Turn these off centrally rather than relying on client settings, because the more restrictive configuration wins wherever it is applied. Then document that you did, because the exemption is only worth what you can evidence.

The comparison that actually matters

Virtual desktop enclaveManaged laptops
Endpoint statusOut of scope, if properly configuredCUI Asset assessed against all 110 requirements, or at best a contractor risk managed asset
What grows with headcountA per seat subscriptionThe assessment boundary itself
Indicative costCommercial cloud desktops list from $41 per user per month at entry specification. Government equivalents are not publicly pricedNo per seat subscription, but every device needs validated encryption, endpoint detection, patching evidence and inventory
Where the saving really comes fromAssessor scope and operational labor, not hardwareNone. The saving is capital, and the cost is recurring compliance work
Biggest riskA redirection channel quietly enabled, forfeiting the exemptionA lost device becomes a potential reportable incident with a 72 hour clock

Note the honest framing, because vendors usually get this wrong. The virtual desktop seat is additive to the licence, and users still need a physical machine to run the client. You are not saving hardware. You are removing an entire class of asset from the assessment and removing the recurring labor of proving those assets are compliant. That is the return, and for a company with thirty endpoints it is substantial.

Where the virtual desktop approach breaks

Be honest about these before you commit, because they are the reasons projects fail after purchase.

Latency, and geography. Microsoft guidance treats round trip times up to about 150 milliseconds as fine, 150 to 200 as workable for text, and beyond 200 as affecting the experience. Graphics has its own budget where beyond 300 milliseconds end to end is bad. The government cloud has only three United States regions, which is fewer placement options than commercial, so a rural facility should measure before it buys.

Engineering workloads. Computer aided design is a rendering workload and lands in the graphics budget, not the text budget. It needs graphics capable session hosts from a specific supported list, and the commercial list price for a graphics tier cloud desktop is $537 per user per month. That number is what kills virtual desktop for everyone strategies in engineering firms. It does not kill it for the contracts and quoting team.

USB devices, which is the sharpest constraint. Low level USB redirection is designed for local network conditions under about 20 milliseconds, which effectively means on site. Encrypted USB storage, USB network adapters and USB displays are blocked outright, and scanner redirection has no support for the common scanning standard. Licence dongles, probes, calibration devices and programming cables are exactly what a machine shop depends on, and every redirection channel you enable to support them is a channel that threatens the out of scope status. This is the central tension of the approach and there is no way to design around it, only to decide it deliberately.

Printing. Redirected printing renders the document on the endpoint, which is the boundary the exemption depends on. Print inside the enclave to a printer inside the enclave, or do not print.

Offline work. There is no offline mode. A cloud desktop requires connectivity by construction. Field service engineers and travelling staff are the population this approach does not serve, and the workaround people reach for, syncing files locally, is precisely what forfeits the exemption.

What neither approach fixes

Shop floor equipment, which is covered further in CMMC for Machine Shops. A machine controller, a coordinate measuring machine or a test rig is a specialized asset under the rule, documented and risk managed rather than assessed against the other requirements, and that is true whichever endpoint strategy you pick. Virtual desktop does not touch it. Neither do managed laptops. Do not let a vendor imply otherwise.

One further trap on the licensing side. Cloud desktop products are sold in variants tied to different tenants, and the variant tied to the standard government community tenant sits at a lower impact level than the one tied to the high tenant. Buying the wrong variant and assuming it covers controlled information is a common and entirely avoidable error. Confirm the impact level of the specific product you are quoted, in writing.

For how this fits the wider boundary decision, see enclave vs full remediation. For where the desktops are hosted, see Azure Government vs AWS GovCloud for CUI workloads.

Frequently asked

Questions about this topic

Does a virtual desktop really take our laptops out of scope?
Yes, if configured correctly. 32 CFR 170.19 treats an endpoint hosting a virtual desktop client configured to allow nothing beyond keyboard, video and mouse as an out of scope asset. The exemption depends entirely on that configuration being enforced and evidenced, not merely intended.
What settings do we have to disable?
Clipboard redirection in both directions, local drive and USB storage redirection, and printer redirection. Enforce them centrally rather than per client, since the more restrictive setting wins, and document the configuration as evidence supporting the scoping claim.
Can engineers run CAD in a virtual desktop enclave?
Technically yes, on graphics capable session hosts, but the economics change sharply. Graphics tier cloud desktops list at $537 per user per month commercially against $41 for an entry specification seat. Many manufacturers put contracts, quoting and programme staff on virtual desktops and handle engineering differently.
What about USB dongles and measurement devices?
This is the hardest constraint. Low level USB redirection is designed for local network latency under about 20 milliseconds, and encrypted USB storage, network adapters and displays are blocked. Every channel you open to support a device is a channel that can move controlled information to the endpoint and threaten the exemption. Decide it deliberately rather than discovering it in week three.
Is it cheaper than managing compliant laptops?
Not on hardware, because users still need a physical device. It is cheaper on assessment scope and recurring compliance labor, which for a fleet of any size is the larger number. Model it as endpoints removed from scope multiplied by the per endpoint compliance effort, against the per seat subscription.
Does this help with our shop floor machines?
No. Machine controllers and test equipment are specialized assets under the rule regardless of your endpoint strategy. They are documented and risk managed rather than assessed against the other requirements, and no desktop approach changes that.

The audit is gone. The liability isn't.

Greypike runs the environment your CUI lives in and owns the compliance outcome that proves it's protected. If you are not certain your environment supports the score sitting in SPRS next to your CAGE code, that is the conversation to have.

Talk to Greypike about SPRS Attestation Assurance

Greypike Inc.

SBA-certified Veteran-Owned Small Business

Cyber AB Registered Practitioner (RP) and Registered Practitioner Advanced (RPA) on staff

CAGE 9WVS6 · UEI N6CJNGDARFM5

(703) 214-9246 info@greypike.com greypike.com

Table of Contents