Staff overseas, data onshore
The requirement usually arrives as one line in a client contract, an audit finding or a board policy: customer data must stay in Australia. At the same time, the business depends on an offshore team that needs to work with that data every day.
The usual setup, a company laptop and a VPN, cannot meet it. The VPN brings the data to the laptop, and once it is there, nothing stops it being saved, synced, copied or photographed. You also cannot prove to an auditor where it went.
The fix is to move the work, not the data. Offshore staff sign in to a desktop that runs in an Australian cloud region, next to your systems. Only an encrypted picture of the screen travels overseas. The keyboard and mouse come back. Files never leave.
Start with the contract clause, not the design.
If an obligation bars offshore staff from even viewing the data on screen, no desktop design solves it. We ask for the actual wording in the first conversation.
How a sovereign desktop works
Desktops are pooled and non-persistent. Each one is built from a golden image when a user signs in and destroyed when they sign out. Nothing carries over between sessions, which is the strongest answer to a no-local-data requirement.
pixels only
destroyed at sign-out
network
Desktops go next to the data, not next to the users. Latency between the desktop and your applications is felt far more sharply than latency between the user and the desktop. So the region is chosen by where your systems run, and an existing ExpressRoute or Direct Connect circuit into one cloud is a strong argument for building there.
Patching works differently too. A pooled fleet is patched by replacing the image, not by patching running desktops. That is a real security advantage, provided someone owns the image pipeline and the maintenance window doesn’t collide with an offshore shift.
Choosing a platform
All three mainstream options enforce the control set to an equivalent standard. The choice comes down to where your data already sits, what licensing you already pay for, and which cloud your team can operate. For a fuller comparison, including screen capture protection, see Azure Virtual Desktop vs Windows 365 vs Amazon WorkSpaces.
| Platform | Billing model | Best when | Build & run effort |
|---|---|---|---|
| Azure Virtual Desktop, pooled | Compute by the hour; hosts deallocate off-shift | You hold M365 E3/E5 or Business Premium, which already include desktop user rights | Heaviest: most tunable, most to build |
| Amazon WorkSpaces Applications | Hourly while streaming, plus warm capacity and a per-user licence | Your systems run on AWS; clipboard, file transfer and printing are native fleet switches | Moderate |
| Windows 365 Flex (formerly Frontline) | Per concurrent user, fixed monthly | Staggered shifts where concurrency is well below headcount | Lightest: no host pool to run |
| Windows 365 Enterprise | Per named user, fixed monthly | Small teams where simplicity beats tuning | Lightest |
Amazon WorkSpaces Pools closed to new customers on 31 July 2026.
Support ends 31 December 2027. For a new AWS build the answer is WorkSpaces Applications, which runs in Sydney and accepts imported Pools images. A quote built on Pools is working from stale information.
Every control, and where it is enforced
Not every control can be delivered by the desktop platform alone. Each row below is tagged with where it is enforced: in the session, in the app or on the endpoint. Pick the device your offshore staff use to see what you can actually enforce.
| Control | Enforced in | How | Status |
|---|---|---|---|
| Clipboard out (session → device) | session | Fleet setting on AWS; RDP property on AVD | Enforced |
| Local drive & folder redirection | session | Disabled redirection | Enforced |
| USB & removable storage | session | Blocked redirection; audio and camera can still be allowed | Enforced |
| Printing, local and print-to-PDF | session | Printer redirection off; approved-export path if someone needs it | Enforced |
| Download in the session browser | session | Browser policy in the golden image | Enforced |
| Upload to personal cloud or webmail | session | Egress allowlist and proxy | Enforced |
| Watermark (user, IP, time) | session | Built-in watermarking on AVD / Windows 365 | Enforced |
| External email & attachments | app | Mail flow rules in your tenant | In your app |
| Bulk export from the business app | app | Role permissions in the application | In your app |
| Screenshot & screen recording | endpoint | Screen-capture protection needs an agent on the device | Enforced |
Managed laptop (Intune or Jamf): every control can be enforced, including screen-capture protection through the device agent.
“Nobody prints” is almost never true
One legitimate exception forks the design into an approved-export path with a named approver and logging. We look for it in discovery, not during user testing.
Controls as code
Every setting in the table is written in Terraform or Intune configuration in your repository, not clicked together in a portal. That changes how compliance works day to day:
- A control change is a pull request, with a reviewer, a reason and a record.
- Drift is caught. A scheduled plan flags any control changed by hand, so a quiet exception can’t become permanent.
- Evidence is a by-product. The repository history and drift reports show what each control was and when it changed, without a scramble before the audit.
resource "azurerm_virtual_desktop_host_pool" "offshore" { name = "hp-offshore-syd" location = "australiaeast" resource_group_name = azurerm_resource_group.avd.name type = "Pooled" load_balancer_type = "BreadthFirst" # Session controls: no clipboard out, no drive, printer or USB redirection custom_rdp_properties = join(";", [ "redirectclipboard:i:0", "drivestoredirect:s:", "redirectprinters:i:0", "usbdevicestoredirect:s:", ]) }
Identity is the real boundary
The desktop is only as strong as the sign-in in front of it. Entra ID with Conditional Access, or Okta with device and location policies, gives the gate an auditor will ask about.
- Accounts in your own tenant give full policy control and clean offboarding.
- Guest accounts from a BPO’s tenant mean someone else controls the password and MFA registration. We design for that explicitly when it applies.
- Avoid a managed directory where the apps allow it. Entra ID join for AVD, or SAML federation for WorkSpaces Applications. A managed AD is often the most expensive line on a small build.
What survives between sessions
The single biggest design question in a pooled build. Our default is that nothing persists, which only works if your applications save work server-side. We confirm that with the application owners, not just the sponsor.
| Store | What it holds | Our default |
|---|---|---|
| Home folders | A per-user folder in S3, mounted into the session | Off It gives users a place to save files, which contradicts the requirement. |
| App settings persistence | A per-user Windows profile (up to 5 GB) saved to S3 at sign-out, including browser sessions and recent files | Only if needed, in a bucket in your account in ap-southeast-2, with retention, access logging and deletion wired into offboarding |
Every departed contractor can leave a profile behind.
If settings persistence is on, the leaver process must delete it. Otherwise orphaned profiles pile up in S3.
Latency and bandwidth
A technically perfect desktop feels broken above roughly 150 ms round trip, or on a consumer link with jitter and packet loss. We measure from each offshore site before committing to a region.
| From | Typical round trip to Sydney | Experience |
|---|---|---|
| Manila | 110-140 ms | Good |
| Indian metros | 150-190 ms | Test first |
Budget roughly 150-400 kbps per user for standard office work, more for video. Plan internet egress from the desktops as part of the control set. A locked desktop with open internet can still upload anywhere.
What it costs to run
Indicative monthly run cost for five offshore users on one shift in an Australian region, at list price.
| Option | Per month | Per user | Build & run |
|---|---|---|---|
| Azure Virtual Desktop, pooled | $90 | $18 | Heaviest |
| WorkSpaces Applications | ~$157 | ~$31 | Moderate |
| WorkSpaces Personal | ~$200 | ~$40 | Light |
| Windows 365 Enterprise | $205 | $41 | Lightest |
| Windows 365 Flex | $210 | $42 | Lightest |
At small scale, run cost is not the decision. The spread from cheapest to dearest is about $1,440 a year, less than two days of build effort. Choose on how simple it is to operate. Pooled AVD or WorkSpaces Applications become clearly cheaper past about thirty concurrent users, so if five is a pilot for two hundred, we build the larger architecture from day one.
Supporting services that can cost more than the desktops
| Service | Approx. per month | How we avoid it |
|---|---|---|
| AWS Managed Microsoft AD | ~$88 | SAML federation instead of domain join |
| Microsoft Entra Domain Services | ~$110 | Entra ID join for session hosts |
| NAT Gateway | ~$43 | Sized egress design |
| Azure Firewall | ~$900 | Network security groups at small scale |
Where sovereignty programmes actually fail
- SaaS outside Australia. A perfectly locked desktop in front of a US-hosted SaaS tenant, backed up offshore or supported by an overseas vendor team, does not meet the requirement. We check every tenant’s region, backups and support location.
- Internet-facing apps. Anything reachable from the internet can be opened from a personal device, outside the desktop entirely. That access has to close at go-live.
- Licensing on throwaway machines. Software that activates against a machine ID, MAC address or hostname fails or burns licences when every desktop is new. We ask every vendor in writing.
- Audio for contact centres. Voice routed through the session instead of optimised on the device is the most common reason offshore desktop rollouts fail on user experience.
What you can hand an auditor
Reporting is a deliverable, designed up front rather than retrofitted.
- Architecture and data-flow diagrams showing where data is stored and processed.
- The control matrix above, with the code that enforces each row and drift reports showing it hasn’t changed.
- Sign-in, session and blocked-event logs streamed to your SIEM, with retention you set.
- Joiner, mover and leaver runbooks, including profile deletion.
- A documented exceptions register with named approvers.
How we deliver it
| Stage | What happens | You get |
|---|---|---|
| Discovery | A 19-question intake before the call, then a technical session on the five questions a form gets wrong | Platform recommendation, control matrix, price |
| Pilot | Golden image, identity, controls and logging for a small group | Working desktops and measured latency per site |
| Rollout | Autoscale or shift schedules, onboarding of the full team, old access closed | Evidence pack |
| Hand over | Image pipeline, runbooks and training for your team | Everything as code in your accounts |
Common questions
Can staff use their own computers?
Yes, for most controls. Clipboard, drive, USB, print and watermark controls work regardless of the device. Blocking screenshots needs an agent on the device, which isn’t possible on personal computers. The answer there is thin clients, or a documented acceptance of that gap.
How long does a seat take to add or remove?
Minutes. A seat is an identity and a group membership. There is no hardware to ship or recover.
What happens if the offshore internet connection drops?
The session stays running in Australia for the disconnect timeout you set, then signs out and is destroyed. Work saved in your applications is kept; nothing is left on the device.
Does this work with Microsoft Teams calls?
Yes, with media optimisation on the device. We confirm the optimisation path for your calling platform and device operating system before quoting.
Next step
Send us the contract clause
We’ll tell you on a 30-minute call whether a sovereign desktop meets it, which platform fits, and roughly what it costs.