Overview of Secure Desktops

The Oracle Cloud Infrastructure Secure Desktops service allows an administrator to create a set of identically configured virtual desktops, which individual users can then securely access.

Secure Desktops is ideal for organizations that need to provide employees with controlled access to a preconfigured desktop environment. An administrator can create pools of desktops in their tenancy, based on existing compute shapes or custom images. All configuration for the desktop and Oracle Cloud Infrastructure is completed by the administrator, making it possible for non-technical users to securely access and use a virtual desktop for their day-to-day work. Secure Desktops controls all access to the virtual desktops, protecting Oracle Cloud Infrastructure resources and customer data from malicious client activity.

The Secure Desktops service provides:

  • A way to create and maintain a large number of identical desktops.
  • Controlled access to a virtual desktop for potentially non-technical users.
  • Data security by storing data on Oracle Cloud Infrastructure resources and not on an individual client device.

A virtual desktop provides:

  • Access to applications on a different operating system than your client device. For instance, you may have a Linux device, but need to access software that only runs on Windows.
  • Access to more powerful resources, such as more CPUs and memory, storage, and so on.
  • Increased data security in the event your client device is lost or crashes.
  • Desktop mobility as the desktop is available wherever you can connect to the internet.

Resource Usage

Each desktop consists of underlying Oracle Cloud Infrastructure resources (such as a compute instance and block volume). Use of these resources counts towards Oracle Cloud Infrastructure usage for cost and billing.

The state of desktops within the pool affects resource usage. Desktops in the ACTIVE state mean the underlying compute instance is running and using resources. To manage resource usage and reduce costs, you can modify the pool's schedule, manually stop desktops, or manually delete desktops. Always use the Secure Desktops service to stop and delete desktops. Do not delete the underlying compute instance directly.

Note

Shutting down the OS manually within the desktop does not stop the underlying compute instance. A desktop with a shutdown OS continues to run in the ACTIVE state and therefore continues to incur costs.

Additionally, users should not manually shut down their desktops as they will lose access and require desktop administrator intervention. See Error message after shutting down the desktop.

Availability

Secure Desktops is available in the following Oracle Cloud Infrastructure commercial regions:

Region Name Region Identifier
Australia East (Sydney) ap-sydney-1
Australia Southeast (Melbourne) ap-melbourne-1
Brazil East (Sao Paulo) sa-saopaulo-1
Brazil Southeast (Vinhedo) sa-vinhedo-1
Canada Southeast (Montreal) ca-montreal-1
Canada Southeast (Toronto) ca-toronto-1
Chile Central (Santiago) sa-santiago-1
Chile West (Valparaiso) sa-valparaiso-1
Columbia Central (Bogota) sa-bogota-1
France Central (Paris) eu-paris-1
France South (Marseille) eu-marseille-1
Germany Central (Frankfurt) eu-frankfurt-1
India South (Hyderabad) ap-hyderabad-1
India West (Mumbai) ap-mumbai-1
Israel Central (Jerusalem) il-jerusalem-1
Italy Northwest (Milan) eu-milan-1
Japan East (Tokyo) ap-tokyo-1
Mexico Central (Queretaro) mx-queretaro-1
Mexico Northeast (Monterrey) mx-monterrey-1
Netherlands Northwest (Amsterdam) eu-amsterdam-1
Saudi Arabia West (Jeddah) me-jeddah-1
Singapore (Singapore) ap-singapore-1
South Africa Central (Johannesburg) af-johannesburg-1
South Korea Central (Seoul) ap-seoul-1
South Korea North (Chuncheon) ap-chuncheon-1
Spain Central (Madrid) eu-madrid-1
Sweden Central (Stockholm) eu-stockholm-1
Switzerland North (Zurich) eu-zurich-1
UAE Central (Abu Dhabi) me-abudhabi-1
UAE East (Dubai) me-dubai-1
UK South (London) uk-london-1
UK West (Newport) uk-cardiff-1
US East (Ashburn) us-ashburn-1
US Midwest (Chicago) us-chicago-1
US West (Phoenix) us-phoenix-1
US West (San Jose) us-sanjose-1

For a complete list of Oracle Cloud Infrastructure commercial regions, including associated locations, region identifiers, region keys, and availability domains, see About Regions and Availability Domains.

Additionally, Secure Desktops is available in the following Oracle Cloud Infrastructure United Kingdom Government Cloud regions:

Region Name Region Identifier
UK Gov South (London) uk-gov-london-1
UK Gov West (Newport) uk-gov-cardiff-1

For more information, see Oracle Cloud Infrastructure Government Cloud.

Resource Identifiers

Most types of Oracle Cloud Infrastructure resources have a unique, Oracle-assigned identifier called an Oracle Cloud ID (OCID). For information about the OCID format and additional ways to identify your resources, see Resource Identifiers.

Authorization and Authentication

Each service in Oracle Cloud Infrastructure integrates with IAM for authentication and authorization, for all interfaces (the Console, SDK or CLI, and REST API).

An administrator in your organization must set up groups, compartments, and policies that control user access to specific services, resources, and functions. For example, the policies control who can create new users, create and manage the cloud network, launch instances, create buckets, download objects, etc. For more information, see Getting Started with Policies. For specific details about writing policies for Secure Desktops, see Secure Desktop Policies.

If you are a desktop user who needs to use the Oracle Cloud Infrastructure resources that your company owns, contact your administrator to set up a user ID for you. The administrator can confirm which compartment or compartments you should be using.

Limits on Secure Desktops Resources

Secure Desktops has various default limits.

Resource Monthly or Annual Universal Credits Pay-as-You-Go or Promo
Desktop pools per tenancy 5 Not available
Desktops per pool 240

(minimum 10 required)

Not available

See About Service Limits and Usage.

Quotas for Secure Desktops

Secure Desktops administrators can set quota policies to enforce restrictions on the number of resources used.

For information about how Oracle Cloud Infrastructure handles quotas, see Compartment Quotas.

Family name: secure-desktops

Resource Name Scope Description
desktop-pool-count Tenancy Number of desktop pools
desktops-per-pool-count Desktop Pool Number of desktops per pool

Example Quota Statement for Secure Desktops

Set secure-desktops quota desktop-pool-count to <value> in compartment <compartment_name>