Praesidium • Case Study

Makwa Global: Two-Week Compliant Virtualization in GCC High

How a tribal enterprise federal contractor deployed a CMMC Level 3 and NIST 800-171 aligned Azure virtualization environment in just two weeks — enabling secure, sovereign remote access without the cost or delay of traditional infrastructure.

Client Makwa Global
Industry Tribal Enterprise / DIB
Environment Azure Government in GCC High
Timeline 2 Weeks to Deployment
Platform Praesidium
At a Glance

Headline Outcomes

Four measurable results that defined the engagement — from deployment speed to compliance posture.

2 Weeks From Kickoff to Deployment

Fully compliant Azure virtualization environment provisioned and operational in two weeks.

CMMC L3 Aligned Out of the Gate

Virtual desktops configured to meet CMMC Level 3 and NIST 800-171 control expectations.

Sovereign U.S. Data Residency

Deployed inside Azure Government / GCC High for CUI-safe handling and access.

No Hardware Capital Avoided

Eliminated the cost, delay, and risk of building traditional remote-access infrastructure.

The Situation

A Growing Tribal Enterprise Federal Contractor Needed Secure Remote Access — Fast

Makwa Global, a tribal enterprise federal contractor operating in the Defense Industrial Base, had already established a sovereign Microsoft 365 GCC High enclave to support its federal work. As the team grew and projects expanded, leadership needed a way to provide their distributed workforce with secure access to a controlled desktop environment — one that could handle Controlled Unclassified Information (CUI) without forcing CUI onto endpoints that weren’t designed to hold it.

The traditional answer would have been physical infrastructure: a fleet of GFE laptops, VPN concentrators, hardened on-premises servers, and a sustained refresh cycle to support it all. For a small but rapidly growing federal contractor, that path meant capital expense, deployment delay, and ongoing operational burden — none of which aligned with how Makwa wanted to scale.

What Makwa needed was a virtualization layer that lived inside their existing sovereign environment — one that could be stood up quickly, aligned to the same NIST 800-171 and CMMC Level 3 controls as the rest of their enclave, and operated as part of their Microsoft 365 GCC High footprint rather than as a parallel system to manage.

The Impact

Why Traditional Infrastructure Wasn’t a Viable Path

For a federal contractor handling CUI, the wrong remote-access architecture isn’t just expensive — it’s a compliance and operational risk. Without a sovereign, compliant virtualization layer, Makwa faced four concrete consequences:

💰

Capital and Lifecycle Cost

A hardware-based remote-access model would have required device procurement, VPN infrastructure, and a sustained refresh cycle that didn’t fit a growing small business cost structure.

⏱️

Deployment Delay

Standing up traditional infrastructure would have taken months — time the business didn’t have while expanding contract work and onboarding new federal teammates.

🔓

CUI Drift Onto Endpoints

Without a controlled desktop layer, CUI risked landing on personal or improperly configured endpoints — creating audit findings, regulatory exposure, and breach potential.

🧩

Parallel Systems to Maintain

Any third-party VDI or remote-access platform outside the GCC High boundary would mean two compliance perimeters, two audit scopes, and two operational teams — exactly the opposite of where Makwa wanted to go.

The Resolution

A Praesidium-Aligned Azure Virtualization Layer Inside GCC High

Jadex Strategic Group delivered the engagement through the Praesidium platform — extending Makwa’s existing sovereign GCC High enclave with a compliant virtualization layer built on Azure Government. The approach was phased, evidence-backed, and structured to be operational in two weeks without compromising compliance posture.

01

Design Inside the Existing Sovereign Boundary

Architected the virtualization environment to live inside the existing Microsoft 365 GCC High enclave and Azure Government tenant — extending Makwa’s compliance perimeter rather than creating a parallel one.

02

Image, Identity, and Access Hardening

Built and hardened the virtual desktop image, integrated identity through Entra ID, and enforced Conditional Access policies aligned to the same controls applied across Makwa’s M365 GCC High environment.

03

CMMC L3 and NIST 800-171 Control Alignment

Mapped configuration choices to specific CMMC Level 3 and NIST 800-171 controls — covering access management, audit logging, system integrity, and protection of CUI at rest and in use.

04

Endpoint Protection and Monitoring

Deployed Defender for Endpoint across the virtual estate, layered in anti-malware enforcement, and integrated monitoring with the same operational posture used across the rest of the enclave.

05

Rollout, Documentation, and Handoff

Rolled the environment out to Makwa’s federal workforce inside the two-week window, documented every configuration choice for audit-readiness, and transitioned operational ownership to Makwa’s internal team and partners.

The Outcomes

A Sovereign, Compliant Remote-Access Layer — Live in Two Weeks

The Praesidium-aligned virtualization deployment gave Makwa Global a compliant, scalable, sovereign remote-access layer without expanding hardware footprint or introducing a parallel compliance perimeter.

Two-Week Deployment Window

From engagement kickoff to operational handoff in two weeks — far faster than a traditional infrastructure path and without compromising the rigor required for federal compliance.

Sovereign CUI Handling

Virtual desktops sit inside Azure Government and the GCC High boundary, ensuring CUI is processed in a sovereign environment with screened U.S. personnel and U.S. data residency.

Aligned to CMMC L3 and NIST 800-171

Every configuration was mapped to specific control families — making the environment audit-defensible rather than self-attested, and consistent with the rest of Makwa’s GCC High enclave.

No Hardware Capital Required

By replacing traditional remote-access infrastructure with cloud-native virtualization, Makwa avoided device procurement, VPN concentrators, and the lifecycle costs that come with them.

One Compliance Perimeter, Not Two

The virtualization layer extended Makwa’s existing compliance perimeter rather than creating a parallel one — collapsing audit scope, simplifying operations, and reducing risk of policy drift.

Scales With the Business

Adding new federal teammates is now a licensing and image-assignment action — not a hardware procurement cycle. Makwa can grow contract work without growing infrastructure complexity.

We needed compliant remote access without the cost or delay of building traditional infrastructure — and we needed it inside the sovereign environment we already had. Jadex extended our GCC High footprint with a virtualization layer that was operational in two weeks, not two quarters.
Makwa Global Leadership Tribal Enterprise • Defense Industrial Base
Need Sovereign Remote Access — Fast?

Extend Your Compliance Perimeter, Not Your Hardware Footprint.

Like Makwa, your federal workforce can operate inside a sovereign, CMMC-aligned virtualization layer that lives inside your existing GCC High enclave — deployed in weeks, not quarters, through the Praesidium platform.