PreVeil VDI Administrator Onboarding Guide for IT Administrators

PreVeil VDI Administrator Onboarding Guide for IT Administrators

Licensed PreVeil product: The VDI is a licensed PreVeil product. Contact sales@preveil.com for questions on pricing and enrollment.

Table of Contents

Video Walkthroughs

1. Welcome and What to Expect

1. Welcome and What to Expect.mov

2. Claiming Your Okta Account

2. Claiming Your Okta Account.mov

3. Setting Up Your Okta Password and MFA

3. Setting Up Your Okta Password and MFA.mov

4. Accessing Your Virtual Desktop

4. Accessing Your Virtual Desktop.mov

5. Creating Your PreVeil Account

5. Creating Your PreVeil Account.mov

6. Managing Users in the Okta Admin Console

6. Managing Users in the Okta Console.mov

7. Assigning Administrator Roles in Okta

7. Assigning Admin Roles.mov

8. Creating Your PreVeil Organization

8. Creating Your PreVeil Organization.mov

9. ThreatLocker Administrator Console Walkthrough

ThreatLocker Administrator Console Overview.mp4

Audience

This article is intended for IT administrators responsible for standing up and managing the PreVeil VDI environment.

Administrator-only content: End users should use the separate end user guide, not this article.

VDI Administrator Onboarding Guide

Welcome to PreVeil VDI. Your organization has been provisioned with a secure, isolated virtual desktop environment hosted in FedRAMP-authorized infrastructure on AWS GovCloud. Your Controlled Unclassified Information (CUI) lives inside the virtual machine, so processing, storage, and transmission all happen there. This keeps physical devices outside your CMMC compliance boundary.

This guide walks IT administrators through initial onboarding. You will be the first person onboarded, and once complete you will be able to invite and manage the rest of your team.

If you have questions about compliance requirements or account structure, contact compliance@preveil.com.

How the Deployment Works

Stage

What Happens

Stage

What Happens

PreVeil builds

PreVeil engineering provisions AWS GovCloud infrastructure, Workspace endpoints, Okta tenant and Active Directory, Email Relay if purchased, ThreatLocker, and PreVeil, then completes smoke testing.

PreVeil onboards you

PreVeil Tech Support provisions your administrator accounts and runs the onboarding session covered in this guide.

You accept

You confirm the environment is working correctly and sign off on the change ticket as formal delivery acknowledgment.

PreVeil hardens

After sign-off, PreVeil removes Tech Support accounts and applies final security hardening. From that point, the environment is treated as live and containing CUI.

Timing: The onboarding session is scheduled the week after the build is completed, never the same week.

What PreVeil Collected Before the Build

  • Legal business name for Okta tenant naming

  • Full user list with email addresses, first and last name

  • Email Relay purchase status and DNS prerequisites if applicable

Okta usernames cannot include special characters such as +, and two users cannot share the same username prefix across different domains.

Your Okta Accounts

CMMC Level 2 requires separation between administrative functions and CUI handling. Depending on your role, you will receive either two or three Okta accounts.

Standard IT Admin

Account

Okta Admin

Workspace Access

Purpose

Account

Okta Admin

Workspace Access

Purpose

Regular account

No

Yes

Day-to-day management VDI for IT administration, inviting users, and managing the PreVeil organization.

Okta admin account

Yes

No

Used only to manage Okta identities from within the VDI.

Dual-Role IT Admin

Account

Okta Admin

Workspace Access

Purpose

Account

Okta Admin

Workspace Access

Purpose

Regular account

No

Yes

Administrative VDI for user and organization management.

Okta admin account

Yes

No

Identity administration only, accessed from within the VDI.

CUI account

No

Yes

Only account permitted to view or process CUI.

Compliance requirement: CUI must only be accessed from the CUI account on the CUI VDI. Using any other account or device is a compliance violation.

Onboarding Steps

  1. Claim your Okta accounts
    Activate the regular account first, then the Okta admin account, then the CUI account if applicable. Set a password, enroll Okta Verify, and confirm expected access.

    image-20260722-012639.png
  2. Launch your Workspace
    Use the Workspaces tile in Okta My Apps to open the AWS WorkSpaces desktop application. The browser client is not supported.

    image-20260722-011942.png
    Click on the Okta WorkSpaces app

     

    image-20260722-012005.png
    Open the Amazon WorkSpaces app

     

    image-20260722-012115.png
    Click Continue to sign in to Workspaces



    image-20260722-012228.png
    Log in with your Okta password

     

  3. Claim your ThreatLocker account
    Activate the ThreatLocker invitation and log in at portal.threatlocker.com from within the VDI only.

  4. Set up PreVeil
    New customers complete activation during onboarding. Existing users copy their account to the VDI using the device transfer flow at 127.0.0.1:4003/get-started.

  5. Acceptance and sign-off
    Confirm access to Okta, Workspace, PreVeil, ThreatLocker, and the Okta Admin Console, then sign off on the delivery ticket.

  6. Invite your team
    Use the PreVeil Admin Console to add users and manage roles.

Your virtual machine is provisioned after your regular account is activated and typically takes about one hour.

ThreatLocker Responsibilities

  • Monitor the 21-day learning mode and prevent unauthorized installs during that period

  • Review and approve valid blocked-application requests

  • Review denied-item reports with ThreatLocker’s Cyber Hero team

  • Adjust web-control categories as needed

PreVeil Setup Paths

New customers

Your PreVeil account is created during onboarding, and Tech Support walks you through initial usage.

Existing customers

Transfer your existing account to the VDI from 127.0.0.1:4003/get-started, then remove the old device after confirmation.

Dual-role setup

Complete setup on the regular admin VDI first, then add the CUI VDI using the supported Copy from Device flow.

Ongoing Responsibilities

Cadence

Responsibilities

Cadence

Responsibilities

Weekly

Review PreVeil weekly activity logs, baseline security reports, and ThreatLocker and Okta activity reports.

Ongoing

Manage ThreatLocker policy tuning, monitor Okta inactivity, enforce CUI separation, and coordinate allowlist changes with PreVeil Tech Support.

PreVeil Tech Support does not provide ongoing IT support or VDI maintenance after final handoff.

Need Help?

Contact PreVeil Tech Support for issues with the VDI environment, PreVeil, Okta, or ThreatLocker. For compliance and account-structure questions, contact compliance@preveil.com.