1. Home
  2. Offshore compliance
  3. Technical deep dive

Technical deep dive

Sovereign desktops for offshore teams

How we let offshore staff work on Australian data without the data ever leaving Australia: the architecture, the platform choice, every control and where it is enforced, and what it costs to run.

  • For IT, security & risk leads
  • Read 12 min
  • Platforms AWS · Azure
  • Region Sydney · Melbourne
01 · The requirement

Staff overseas, data onshore

The requirement usually arrives as one line in a client contract, an audit finding or a board policy: customer data must stay in Australia. At the same time, the business depends on an offshore team that needs to work with that data every day.

The usual setup, a company laptop and a VPN, cannot meet it. The VPN brings the data to the laptop, and once it is there, nothing stops it being saved, synced, copied or photographed. You also cannot prove to an auditor where it went.

The fix is to move the work, not the data. Offshore staff sign in to a desktop that runs in an Australian cloud region, next to your systems. Only an encrypted picture of the screen travels overseas. The keyboard and mouse come back. Files never leave.

Start with the contract clause, not the design.

If an obligation bars offshore staff from even viewing the data on screen, no desktop design solves it. We ask for the actual wording in the first conversation.

02 · Architecture

How a sovereign desktop works

Desktops are pooled and non-persistent. Each one is built from a golden image when a user signs in and destroyed when they sign out. Nothing carries over between sessions, which is the strongest answer to a no-local-data requirement.

Offshore endpointmanaged laptop, thin client or BPO PC
encrypted
pixels only
ap-southeast-2 · australiaeastPooled desktopgolden image · new at sign-in
destroyed at sign-out
private
network
Your systemsLOB apps, file shares, databases, SaaS
IdentityEntra ID / Okta · MFA · Conditional Access
Egress controlallowlisted internet · no personal cloud
Loggingsign-ins, blocked events → your SIEM

Desktops go next to the data, not next to the users. Latency between the desktop and your applications is felt far more sharply than latency between the user and the desktop. So the region is chosen by where your systems run, and an existing ExpressRoute or Direct Connect circuit into one cloud is a strong argument for building there.

Patching works differently too. A pooled fleet is patched by replacing the image, not by patching running desktops. That is a real security advantage, provided someone owns the image pipeline and the maintenance window doesn’t collide with an offshore shift.

03 · Platform

Choosing a platform

All three mainstream options enforce the control set to an equivalent standard. The choice comes down to where your data already sits, what licensing you already pay for, and which cloud your team can operate. For a fuller comparison, including screen capture protection, see Azure Virtual Desktop vs Windows 365 vs Amazon WorkSpaces.

PlatformBilling modelBest whenBuild & run effort
Azure Virtual Desktop, pooledCompute by the hour; hosts deallocate off-shiftYou hold M365 E3/E5 or Business Premium, which already include desktop user rightsHeaviest: most tunable, most to build
Amazon WorkSpaces ApplicationsHourly while streaming, plus warm capacity and a per-user licenceYour systems run on AWS; clipboard, file transfer and printing are native fleet switchesModerate
Windows 365 Flex (formerly Frontline)Per concurrent user, fixed monthlyStaggered shifts where concurrency is well below headcountLightest: no host pool to run
Windows 365 EnterprisePer named user, fixed monthlySmall teams where simplicity beats tuningLightest

Amazon WorkSpaces Pools closed to new customers on 31 July 2026.

Support ends 31 December 2027. For a new AWS build the answer is WorkSpaces Applications, which runs in Sydney and accepts imported Pools images. A quote built on Pools is working from stale information.

04 · Controls

Every control, and where it is enforced

Not every control can be delivered by the desktop platform alone. Each row below is tagged with where it is enforced: in the session, in the app or on the endpoint. Pick the device your offshore staff use to see what you can actually enforce.

ControlEnforced inHowStatus
Clipboard out (session → device)sessionFleet setting on AWS; RDP property on AVDEnforced
Local drive & folder redirectionsessionDisabled redirectionEnforced
USB & removable storagesessionBlocked redirection; audio and camera can still be allowedEnforced
Printing, local and print-to-PDFsessionPrinter redirection off; approved-export path if someone needs itEnforced
Download in the session browsersessionBrowser policy in the golden imageEnforced
Upload to personal cloud or webmailsessionEgress allowlist and proxyEnforced
Watermark (user, IP, time)sessionBuilt-in watermarking on AVD / Windows 365Enforced
External email & attachmentsappMail flow rules in your tenantIn your app
Bulk export from the business appappRole permissions in the applicationIn your app
Screenshot & screen recordingendpointScreen-capture protection needs an agent on the deviceEnforced

Managed laptop (Intune or Jamf): every control can be enforced, including screen-capture protection through the device agent.

“Nobody prints” is almost never true

One legitimate exception forks the design into an approved-export path with a named approver and logging. We look for it in discovery, not during user testing.

Controls as code

Every setting in the table is written in Terraform or Intune configuration in your repository, not clicked together in a portal. That changes how compliance works day to day:

  • A control change is a pull request, with a reviewer, a reason and a record.
  • Drift is caught. A scheduled plan flags any control changed by hand, so a quiet exception can’t become permanent.
  • Evidence is a by-product. The repository history and drift reports show what each control was and when it changed, without a scramble before the audit.
host_pool.tf
resource "azurerm_virtual_desktop_host_pool" "offshore" {
  name                = "hp-offshore-syd"
  location            = "australiaeast"
  resource_group_name = azurerm_resource_group.avd.name
  type                = "Pooled"
  load_balancer_type  = "BreadthFirst"

  # Session controls: no clipboard out, no drive, printer or USB redirection
  custom_rdp_properties = join(";", [
    "redirectclipboard:i:0",
    "drivestoredirect:s:",
    "redirectprinters:i:0",
    "usbdevicestoredirect:s:",
  ])
}
05 · Identity

Identity is the real boundary

The desktop is only as strong as the sign-in in front of it. Entra ID with Conditional Access, or Okta with device and location policies, gives the gate an auditor will ask about.

  • Accounts in your own tenant give full policy control and clean offboarding.
  • Guest accounts from a BPO’s tenant mean someone else controls the password and MFA registration. We design for that explicitly when it applies.
  • Avoid a managed directory where the apps allow it. Entra ID join for AVD, or SAML federation for WorkSpaces Applications. A managed AD is often the most expensive line on a small build.
06 · State

What survives between sessions

The single biggest design question in a pooled build. Our default is that nothing persists, which only works if your applications save work server-side. We confirm that with the application owners, not just the sponsor.

StoreWhat it holdsOur default
Home foldersA per-user folder in S3, mounted into the sessionOff It gives users a place to save files, which contradicts the requirement.
App settings persistenceA per-user Windows profile (up to 5 GB) saved to S3 at sign-out, including browser sessions and recent filesOnly if needed, in a bucket in your account in ap-southeast-2, with retention, access logging and deletion wired into offboarding

Every departed contractor can leave a profile behind.

If settings persistence is on, the leaver process must delete it. Otherwise orphaned profiles pile up in S3.

07 · Network

Latency and bandwidth

A technically perfect desktop feels broken above roughly 150 ms round trip, or on a consumer link with jitter and packet loss. We measure from each offshore site before committing to a region.

FromTypical round trip to SydneyExperience
Manila110-140 msGood
Indian metros150-190 msTest first
Indicative figures to australiaeast. Always measure per site.

Budget roughly 150-400 kbps per user for standard office work, more for video. Plan internet egress from the desktops as part of the control set. A locked desktop with open internet can still upload anywhere.

08 · Cost

What it costs to run

Indicative monthly run cost for five offshore users on one shift in an Australian region, at list price.

OptionPer monthPer userBuild & run
Azure Virtual Desktop, pooled$90$18Heaviest
WorkSpaces Applications~$157~$31Moderate
WorkSpaces Personal~$200~$40Light
Windows 365 Enterprise$205$41Lightest
Windows 365 Flex$210$42Lightest
USD, list price, ex GST. 200 hours per month, light office work. Excludes build effort, support and M365 licences. A shape, not a quote.

At small scale, run cost is not the decision. The spread from cheapest to dearest is about $1,440 a year, less than two days of build effort. Choose on how simple it is to operate. Pooled AVD or WorkSpaces Applications become clearly cheaper past about thirty concurrent users, so if five is a pilot for two hundred, we build the larger architecture from day one.

Supporting services that can cost more than the desktops

ServiceApprox. per monthHow we avoid it
AWS Managed Microsoft AD~$88SAML federation instead of domain join
Microsoft Entra Domain Services~$110Entra ID join for session hosts
NAT Gateway~$43Sized egress design
Azure Firewall~$900Network security groups at small scale
09 · Pitfalls

Where sovereignty programmes actually fail

  • SaaS outside Australia. A perfectly locked desktop in front of a US-hosted SaaS tenant, backed up offshore or supported by an overseas vendor team, does not meet the requirement. We check every tenant’s region, backups and support location.
  • Internet-facing apps. Anything reachable from the internet can be opened from a personal device, outside the desktop entirely. That access has to close at go-live.
  • Licensing on throwaway machines. Software that activates against a machine ID, MAC address or hostname fails or burns licences when every desktop is new. We ask every vendor in writing.
  • Audio for contact centres. Voice routed through the session instead of optimised on the device is the most common reason offshore desktop rollouts fail on user experience.
10 · Evidence

What you can hand an auditor

Reporting is a deliverable, designed up front rather than retrofitted.

  • Architecture and data-flow diagrams showing where data is stored and processed.
  • The control matrix above, with the code that enforces each row and drift reports showing it hasn’t changed.
  • Sign-in, session and blocked-event logs streamed to your SIEM, with retention you set.
  • Joiner, mover and leaver runbooks, including profile deletion.
  • A documented exceptions register with named approvers.
11 · Delivery

How we deliver it

StageWhat happensYou get
DiscoveryA 19-question intake before the call, then a technical session on the five questions a form gets wrongPlatform recommendation, control matrix, price
PilotGolden image, identity, controls and logging for a small groupWorking desktops and measured latency per site
RolloutAutoscale or shift schedules, onboarding of the full team, old access closedEvidence pack
Hand overImage pipeline, runbooks and training for your teamEverything as code in your accounts
12 · FAQ

Common questions

Can staff use their own computers?

Yes, for most controls. Clipboard, drive, USB, print and watermark controls work regardless of the device. Blocking screenshots needs an agent on the device, which isn’t possible on personal computers. The answer there is thin clients, or a documented acceptance of that gap.

How long does a seat take to add or remove?

Minutes. A seat is an identity and a group membership. There is no hardware to ship or recover.

What happens if the offshore internet connection drops?

The session stays running in Australia for the disconnect timeout you set, then signs out and is destroyed. Work saved in your applications is kept; nothing is left on the device.

Does this work with Microsoft Teams calls?

Yes, with media optimisation on the device. We confirm the optimisation path for your calling platform and device operating system before quoting.

Next step

Send us the contract clause

We’ll tell you on a 30-minute call whether a sovereign desktop meets it, which platform fits, and roughly what it costs.