PreVeil VDI Administrator Onboarding Guide for IT Administrators
Licensed PreVeil product: The VDI is a licensed PreVeil product. Contact sales@preveil.com for questions on pricing and enrollment.
Table of Contents
- 1 Table of Contents
- 2 Video Walkthroughs
- 2.1 1. Welcome and What to Expect
- 2.2 2. Claiming Your Okta Account
- 2.3 3. Setting Up Your Okta Password and MFA
- 2.4 4. Accessing Your Virtual Desktop
- 2.5 5. Creating Your PreVeil Account
- 2.6 6. Managing Users in the Okta Admin Console
- 2.7 7. Assigning Administrator Roles in Okta
- 2.8 8. Creating Your PreVeil Organization
- 2.9 9. ThreatLocker Administrator Console Walkthrough
- 3 Audience
- 4 VDI Administrator Onboarding Guide
- 5 How the Deployment Works
- 6 What PreVeil Collected Before the Build
- 7 Your Okta Accounts
- 8 Onboarding Steps
- 9 ThreatLocker Responsibilities
- 10 PreVeil Setup Paths
- 10.1 New customers
- 10.2 Existing customers
- 10.3 Dual-role setup
- 11 Ongoing Responsibilities
- 12 Need Help?
Video Walkthroughs
1. Welcome and What to Expect
2. Claiming Your Okta Account
3. Setting Up Your Okta Password and MFA
4. Accessing Your Virtual Desktop
5. Creating Your PreVeil Account
6. Managing Users in the Okta Admin Console
7. Assigning Administrator Roles in Okta
8. Creating Your PreVeil Organization
9. ThreatLocker Administrator Console Walkthrough
Audience
This article is intended for IT administrators responsible for standing up and managing the PreVeil VDI environment.
Administrator-only content: End users should use the separate end user guide, not this article.
VDI Administrator Onboarding Guide
Welcome to PreVeil VDI. Your organization has been provisioned with a secure, isolated virtual desktop environment hosted in FedRAMP-authorized infrastructure on AWS GovCloud. Your Controlled Unclassified Information (CUI) lives inside the virtual machine, so processing, storage, and transmission all happen there. This keeps physical devices outside your CMMC compliance boundary.
This guide walks IT administrators through initial onboarding. You will be the first person onboarded, and once complete you will be able to invite and manage the rest of your team.
If you have questions about compliance requirements or account structure, contact compliance@preveil.com.
How the Deployment Works
Stage | What Happens |
|---|---|
PreVeil builds | PreVeil engineering provisions AWS GovCloud infrastructure, Workspace endpoints, Okta tenant and Active Directory, Email Relay if purchased, ThreatLocker, and PreVeil, then completes smoke testing. |
PreVeil onboards you | PreVeil Tech Support provisions your administrator accounts and runs the onboarding session covered in this guide. |
You accept | You confirm the environment is working correctly and sign off on the change ticket as formal delivery acknowledgment. |
PreVeil hardens | After sign-off, PreVeil removes Tech Support accounts and applies final security hardening. From that point, the environment is treated as live and containing CUI. |
Timing: The onboarding session is scheduled the week after the build is completed, never the same week.
What PreVeil Collected Before the Build
Legal business name for Okta tenant naming
Full user list with email addresses, first and last name
Email Relay purchase status and DNS prerequisites if applicable
Okta usernames cannot include special characters such as +, and two users cannot share the same username prefix across different domains.
Your Okta Accounts
CMMC Level 2 requires separation between administrative functions and CUI handling. Depending on your role, you will receive either two or three Okta accounts.
Standard IT Admin
Account | Okta Admin | Workspace Access | Purpose |
|---|---|---|---|
Regular account | No | Yes | Day-to-day management VDI for IT administration, inviting users, and managing the PreVeil organization. |
Okta admin account | Yes | No | Used only to manage Okta identities from within the VDI. |
Dual-Role IT Admin
Account | Okta Admin | Workspace Access | Purpose |
|---|---|---|---|
Regular account | No | Yes | Administrative VDI for user and organization management. |
Okta admin account | Yes | No | Identity administration only, accessed from within the VDI. |
CUI account | No | Yes | Only account permitted to view or process CUI. |
Compliance requirement: CUI must only be accessed from the CUI account on the CUI VDI. Using any other account or device is a compliance violation.
Onboarding Steps
Claim your Okta accounts
Activate the regular account first, then the Okta admin account, then the CUI account if applicable. Set a password, enroll Okta Verify, and confirm expected access.Launch your Workspace
Use the Workspaces tile in Okta My Apps to open the AWS WorkSpaces desktop application. The browser client is not supported.Click on the Okta WorkSpaces appOpen the Amazon WorkSpaces appClick Continue to sign in to WorkspacesLog in with your Okta passwordClaim your ThreatLocker account
Activate the ThreatLocker invitation and log in at portal.threatlocker.com from within the VDI only.Set up PreVeil
New customers complete activation during onboarding. Existing users copy their account to the VDI using the device transfer flow at127.0.0.1:4003/get-started.Acceptance and sign-off
Confirm access to Okta, Workspace, PreVeil, ThreatLocker, and the Okta Admin Console, then sign off on the delivery ticket.Invite your team
Use the PreVeil Admin Console to add users and manage roles.
Your virtual machine is provisioned after your regular account is activated and typically takes about one hour.
ThreatLocker Responsibilities
Monitor the 21-day learning mode and prevent unauthorized installs during that period
Review and approve valid blocked-application requests
Review denied-item reports with ThreatLocker’s Cyber Hero team
Adjust web-control categories as needed
PreVeil Setup Paths
New customers
Your PreVeil account is created during onboarding, and Tech Support walks you through initial usage.
Existing customers
Transfer your existing account to the VDI from 127.0.0.1:4003/get-started, then remove the old device after confirmation.
Dual-role setup
Complete setup on the regular admin VDI first, then add the CUI VDI using the supported Copy from Device flow.
Ongoing Responsibilities
Cadence | Responsibilities |
|---|---|
Weekly | Review PreVeil weekly activity logs, baseline security reports, and ThreatLocker and Okta activity reports. |
Ongoing | Manage ThreatLocker policy tuning, monitor Okta inactivity, enforce CUI separation, and coordinate allowlist changes with PreVeil Tech Support. |
PreVeil Tech Support does not provide ongoing IT support or VDI maintenance after final handoff.
Need Help?
Contact PreVeil Tech Support for issues with the VDI environment, PreVeil, Okta, or ThreatLocker. For compliance and account-structure questions, contact compliance@preveil.com.