> For the complete documentation index, see [llms.txt](https://docs.vectra.ai/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.vectra.ai/deployment/getting-started/respond-ux-deployment-guide/fedramp-high-deployment-guidance.md).

# FedRAMP High environment deployment guidance (RUX)

{% hint style="info" %}
**Please Note:**

This page of the Respond UX Deployment Guide only applies to FedRAMP High environment deployments. For commercial environment RUX deployments, this page can be skipped and you can move on to [Firewall Requirements](/deployment/getting-started/respond-ux-deployment-guide/firewall-requirements.md).
{% endhint %}

## Introduction

Vectra AI Platform (RUX deployments) can be provisioned in our **US Gov (FedRAMP High)** region. This is a FedRAMP High authorized environment.

Customer Brain appliances and Sensors are deployed in the required customer premises locations and all Vectra services are provided from the FedRAMP high environment.

As it relates to [firewall requirements](/deployment/getting-started/respond-ux-deployment-guide/firewall-requirements.md), FedRAMP High changes are primarily to Vectra cloud connectivity and there are a few changes to the appliance connectivity requirements as well.

Please see [#fedramp-high-vectra-ai-platform-capabilities](#fedramp-high-vectra-ai-platform-capabilities "mention") for details regarding specific feature/capability availability for FedRAMP high deployments.

## Deployment Process for FedRAMP High

A FedRAMP High RUX deployment follows a very similar process to a commercial deployment with a few differences. It is expected that this article will provide the added details required for such deployments and the Vectra's other deployment documentation can still be relied on for the bulk of RUX deployment.

For example, when deploying a physical appliance for use as a Brain in a FedRAMP High deployment, the quick start guide for the appliance does not change. The rest of the RUX deployment guide doesn't change, but what is different is that the Brain must be licensed after the UI is available. This licensing step tells the Brain to talk to a different updater endpoint in Vectra's cloud that is only used for FedRAMP High. The Brain will then register with Vectra, and can then be linked to a RUX tenant in Vectra's FedRAMP High environment.

{% hint style="info" %}
**Please Note:**

If you are not using network Sensors (network data sources) with your RUX deployment, then the rest of this Deployment Process section about Physical, Virtual, and Cloud appliances does NOT apply to your FedRAMP High deployment.

If you are using network Sensors and therefore will be deploying a Brain, the below steps are necesssary to set up your Brain. Please see the section below that matches the type of appliance you are deploying.
{% endhint %}

Please read each applicable section below for FedRAMP High deployment guidance.

### Physical Appliances

{% stepper %}
{% step %}

#### Perform Initial Appliance Deployment

Follow the quick start guide for your specific [NDR physical appliances](/deployment/ndr-physical-appliances.md). You should have the appliance available on your network via IP or hostname when complete.

If this is Brain appliance, please move on to step 2 below.

If you are installing a Sensor/Stream appliance after your Brain is already deployed and connected to the FedRAMP high environment, [Pairing appliances](/deployment/appliance-operations/pairing-appliances.md) will provide guidance for pairing with your Brain. You do NOT need to continue further with the steps below.
{% endstep %}

{% step %}

#### License the Physical Brain Appliance

In FedRAMP high deployments, licensing the Brain appliance before it is connected to a RUX tenant enables the Brain to connect to Vectra AI Updater system for FedRAMP high deployments instead of the default commercial environment Updater. Once licensed, all communications between the Brain and the Vectra cloud are to FedRAMP High endpoints.

* Log in to the UI of the Brain Appliance at:\
  `https://your_brain_hostname_or_ip_address`
* Default passwords can be found at [Default usernames and passwords](/deployment/getting-started/default-usernames-and-passwords.md)

What you see after logging in is the Quadrant UX. This UI will no longer be enabled after the appliance has been connected to a RUX tenant, and the UI is then served from the Vectra FedRAMP High environment.

{% hint style="warning" %}
**Please Note:**

After logging in you will see a number of default screens before the full UI is available. These are specific to QUX deployments and do not apply to FedRAMP High RUX deployments. Details for each screen are below.

**Communication Attempts Prior to Licensing**

If you elected to use our FedRamp High Environment the appliance will need to be manually licensed in a later step before any communication to the Vectra cloud is allowed, and all Vectra cloud communication will then be to our FedRamp High Environment.

**In-App Support**

* This is not supported for FedRAMP High deployments. You can just click **Got it** and proceed to the next screen.
* If you are concerned about the system attempting to communicate to the endpoints associated with this feature, because you won't be connected to a FedRAMP High RUX tenant before the default 3 day period before In-App Support turns on, you can disable the feature once you can access the UI.
  * *Configuration → SETUP → General Settings* has the **In-App Support** setting.
* As per **Communication Attempts Prior to Licensing**, any communication attempt would fail.

**Change Default Password**

* The password for the QUX UI is stored locally and is not communicated to Vectra.
* It is recommended to change this password per the dialog.

**Enable Vectra AI Metadata Services to Improve Detection Efficacy**

* This only applies to QUX deployments.
* Metadata sharing for RUX is covered separately in the RUX EULA.
* It is recommended to just **Decline** this and proceed to the next step.
* As per **Communication Attempts Prior to Licensing**, any communication attempt would fail.

**Vectra Detect End User License Agreement**

* This must be completed to gain access to the rest of the QUX UI so that licensing can be completed.
* You can put in any entry you like, it does not need to be accurate, and will NOT apply to your RUX deployment. RUX deployments have a separate EULA.
* As per **Communication Attempts Prior to Licensing**, any communication attempt would fail.

**Welcome to Vectra!**

* This tour can be exited as soon as you wish.

You should NOT perform any configuration outside of the licensing steps before Vectra connects your Brain to a RUX tenant.
{% endhint %}

* Navigate in your UI to *Configuration → Setup → Licensing.*

<figure><img src="/files/ah0sqfbUBOFOeRWyFFi9" alt=""><figcaption></figcaption></figure>

* Copy the **authorization code** using the **Copy** button on the right.
* Email the authorization code to the Vectra team member you are working with for the FedRAMP High deployment. If they are not authorized themselves, they will work with team members who are authorized to access the FedRAMP High licensing system.
* The **License Key** will be emailed to you.
* Input the **License Key** in the window and click **Activate License**.
* Upon successful processing, your Brain will then only communicate with Vectra's FedRAMP High environment and you can proceed with the rest of your RUX deployment.
  {% endstep %}
  {% endstepper %}

### Virtual Appliances

{% hint style="info" %}
**Please Note:**

This section ONLY applies to virtual appliances deployed in traditional hypervisor environments such as VMware as VMware and Nutanix (among others)

This section does NOT apply to cloud deployments in environments such as AWS, Azure, and GCP.
{% endhint %}

{% stepper %}
{% step %}

#### Perform Initial Appliance Deployment

Follow the quick start guide for your specific [NDR virtual / cloud appliances](/deployment/ndr-virtual-cloud-appliances.md). You should have the appliance available on your network via IP or hostname when complete.

If this is Brain appliance, please move on to step 2 below.

If you are installing a Sensor/Stream appliance after your Brain is already deployed and connected to the FedRAMP high environment, [Pairing appliances](/deployment/appliance-operations/pairing-appliances.md) will provide guidance for pairing with your Brain. You do NOT need to continue further with the steps below.
{% endstep %}

{% step %}

#### License the Virtual Brain Appliance

In FedRAMP high deployments, licensing the Brain appliance before it is connected to a RUX tenant enables the Brain to connect to Vectra AI Updater system for FedRAMP high deployments instead of the default commercial environment Updater. Once licensed, all communications between the Brain and the Vectra cloud are to FedRAMP High endpoints.

During deployment for virtual Brains, before the system serves the full QUX UI, there is a System Setup and Provisioning UI that must be accessed to license the virtual Brain. This licensing process is already documented in the **Initial startup and licensing section** for the [NDR virtual Brain](/deployment/ndr-virtual-cloud-appliances.md) you are deploying.

Please follow the instructions for licensing at the link above but bear in mind that:

* You will email the authorization code to the Vectra team member you are working with for the FedRAMP High deployment. If they are not authorized themselves, they will work with team members who are authorized to access the FedRAMP High licensing system.
* After licensing is completed, your Brain will then only communicate with Vectra's FedRAMP High environment and you can proceed with the rest of your RUX deployment.

{% hint style="info" %}
**Please Note:**

You do NOT need to login to the locally served QUX UI that becomes available after the licensing has been completed unless Vectra personnel ask you to during the time before your Brain is connected to a RUX tenant.

If you login to the QUX UI of the virtual Brain that is served locally before it is connected to your RUX deployment, please see the guidance for what to do on any screens you see above in the [#license-the-physical-brain-appliance](#license-the-physical-brain-appliance "mention") section that talks about the screens you see before licensing a physical Brain appliance.

You should NOT perform any configuration outside of the licensing steps before Vectra connects your Brain to a RUX tenant.
{% endhint %}
{% endstep %}
{% endstepper %}

### Cloud Appliances

{% hint style="info" %}
**Please Note:**

Cloud Brain appliances are NOT supported for FedRAMP High deployments during the initial availability of Vectra's FedRAMP High environment. Vectra plans to add support for Cloud deployed Brain appliances in the future.

Once cloud Brains are supported, a different template will be provided for the FedRAMP High deployment. These templates are setup similarly to the Vectra commercial environment templates, but point to the FedRAMP High environment updater instead of the commercial updater. Once deployed, Brains deployed with the FedRAMP High deployment template will then only communicate with Vectra's FedRAMP High environment and you can proceed with the rest of your RUX deployment.
{% endhint %}

## FedRAMP High Vectra AI Platform Capabilities

Not all capabilities of the Vectra AI Platform are available when doing a FedRAMP High deployment. The table below will be updated over time as new capabilties are added to the Vectra AI Platform and as the availability of those capabilities changes for FedRAMP High deployments.

#### Table Column Definitions and Nomenclature

**Capability** - the Vectra AI Platform capability

**Commercial** - Whether the capability is supported in Vectra AI's commercial environment.

**FedRAMP High** - Whether the capability is supported in Vectra AI's FedRAMP High environment.

**Notes** - Any applicable notes

**Nomenclature**

* Yes - capability exists today
* No - not supported
* Planned - not supported today but is planned for a future update
  * Any dates given should not be considered a promise and only represent Vectra's current plan at the time this article was last updated.

<table><thead><tr><th width="222.18359375">Capability</th><th width="114.13671875" align="center">Commercial</th><th width="133.25" align="center">FedRAMP High</th><th width="299.5078125">Notes</th></tr></thead><tbody><tr><td><strong>Appliances / Provisioning</strong></td><td align="center">---</td><td align="center">---</td><td>---</td></tr><tr><td>Physical Appliances (All)</td><td align="center">Yes</td><td align="center">Yes</td><td></td></tr><tr><td>Virtual Appliances (All)</td><td align="center">Yes</td><td align="center">Yes</td><td></td></tr><tr><td>Cloud Brains</td><td align="center">Yes</td><td align="center">Planned</td><td></td></tr><tr><td>Cloud Sensors/Stream</td><td align="center">Yes</td><td align="center">Yes</td><td></td></tr><tr><td>QUX to RUX Migration</td><td align="center">Yes</td><td align="center">Planned</td><td>Targeted for FYQ3 (Aug-Oct) availability</td></tr><tr><td><strong>Cloud Data Sources</strong></td><td align="center">---</td><td align="center">---</td><td>---</td></tr><tr><td>AWS Commercial Data Source (CloudTrail)</td><td align="center">Yes</td><td align="center">No</td><td>A FedRAMP High RUX deployment can only monitor GovCloud regions in AWS.</td></tr><tr><td>AWS GovCloud Data Source (CloudTrail)</td><td align="center">No</td><td align="center">Yes</td><td>A commercial environment RUX deployment can only monitor commerical AWS regions.</td></tr><tr><td>Microsoft Azure Commercial</td><td align="center">Yes</td><td align="center">Yes</td><td></td></tr><tr><td>Microsoft Azure GCC</td><td align="center">No</td><td align="center">No</td><td></td></tr><tr><td>Microsoft Azure GCC High</td><td align="center">No</td><td align="center">No</td><td></td></tr><tr><td>Entra ID (Azure AD)/M365<br>Commercial</td><td align="center">Yes</td><td align="center">Yes</td><td></td></tr><tr><td>Entra ID (Azure AD)/M365<br>GCC</td><td align="center">Yes</td><td align="center">Yes</td><td></td></tr><tr><td>Entra ID (Azure AD)/M365<br>GCC High</td><td align="center">Yes</td><td align="center">Yes</td><td></td></tr><tr><td><strong>Integrations</strong></td><td align="center">---</td><td align="center">---</td><td>---</td></tr><tr><td>API-based SIEM/SOAR</td><td align="center">Yes</td><td align="center">Yes</td><td></td></tr><tr><td>External App Alerts<br>(Webhook)</td><td align="center">Yes</td><td align="center">Yes</td><td></td></tr><tr><td>EDR Integrations</td><td align="center">Yes</td><td align="center">Yes</td><td></td></tr><tr><td><strong>Support &#x26; Managed Services</strong></td><td align="center">---</td><td align="center">---</td><td>---</td></tr><tr><td>Remote Support (UI)</td><td align="center">Yes</td><td align="center">Yes</td><td>Customers can choose to allow Vectra to connect to their UI for assistance. Please see <a data-mention href="/pages/g3nKv5VEJBk4eFX2TXpa">/pages/g3nKv5VEJBk4eFX2TXpa</a> for details</td></tr><tr><td>Remote Support (CLI)</td><td align="center">Yes</td><td align="center">No</td><td>FedRAMP High deployments cannot utilize the VPN connection required for CLI assistance that is available for commercial environments.</td></tr><tr><td>Proactive Support</td><td align="center">Yes</td><td align="center">No</td><td>See <a href="/pages/tj2meHLl64QtNVYsgXOv#proactive-monitoring">Monitoring appliance health</a> and <a href="https://support.vectra.ai/s/article/KB-VS-1238">Proactive monitoring</a> for details.</td></tr><tr><td>MDR/MXDR</td><td align="center">Yes</td><td align="center">No</td><td></td></tr><tr><td>api.vectranetworks.com</td><td align="center">Yes</td><td align="center">Planned</td><td>See <a data-mention href="/pages/QqjhezgB1jfjSjQl0IVU">/pages/QqjhezgB1jfjSjQl0IVU</a> for more details. This is used for lightweight health monitoring, retrieving added context for some detections, and proxying external queries for data.</td></tr><tr><td>In-App Support</td><td align="center">Yes</td><td align="center">No</td><td>See <a data-mention href="/pages/I5DSCVUGx9Hrte6rYY51">/pages/I5DSCVUGx9Hrte6rYY51</a> for details.</td></tr><tr><td><strong>Product Features (RUX)</strong></td><td align="center">---</td><td align="center">---</td><td>---</td></tr><tr><td>Entra ID (Azure AD) Account Lockdown</td><td align="center">Yes</td><td align="center">No</td><td></td></tr><tr><td>Host Lockdown (EDR)</td><td align="center">Yes</td><td align="center">Yes</td><td></td></tr><tr><td>Asset Inventory</td><td align="center">Yes (Preview)</td><td align="center">Planned</td><td></td></tr><tr><td>Exposure Management<br>(Findings)</td><td align="center">Yes (Preview)</td><td align="center">Planned</td><td></td></tr><tr><td>Cloud Flow Logs / DNS</td><td align="center">Yes (via Fusion)</td><td align="center">Planned</td><td></td></tr><tr><td>Investigation</td><td align="center">Yes</td><td align="center">Yes</td><td>Includes Instant Investigation and all Investigate functionality</td></tr><tr><td>AI Summary and Agentic Investigations</td><td align="center">Yes</td><td align="center">Yes</td><td></td></tr></tbody></table>

## Licensing Enforcement

For FedRAMP High deployments, licensing is required for physical and virtual Brain appliances so that they know they MUST connect to the FedRAMP High environment. The licensing enforcement details as described below do not change.

Vectra NDR (Detect for Network) supports licensing functionality regardless of the type of deployment (physical appliance, cloud IaaS, VMware). All versions will be able to see license status and enable requests for and application of licenses.

Enforcement of NDR licensing is only enabled on VMware and Nutanix Brains. Any other Brain type does NOT currently have licensing for NDR enforced. Vectra does plan to add licensing enforcement for other Brain types in the future.

It is recommended that all customers work with their account teams to ensure their licensing is up to date. Please refer to the following table for additional detail:

<table data-header-hidden><thead><tr><th width="218.875" align="center"></th><th width="207.60546875" align="center"></th><th width="321.703125" align="center"></th></tr></thead><tbody><tr><td align="center"><strong>Product</strong></td><td align="center"><strong>Deployment Type</strong></td><td align="center"><strong>License Enforcement</strong></td></tr><tr><td align="center">NDR (Detect for Network)</td><td align="center">VMware Brain<br>Nutanix Brain</td><td align="center">Algorithms stop producing Detections when expired.</td></tr><tr><td align="center">NDR (Detect for Network)</td><td align="center">Physical or Cloud Brains</td><td align="center">Not currently enforced. Planned for future (timing TBD).</td></tr></tbody></table>

Other Vectra products are also licensed but enforcement of the license is a matter of contract compliance between sales teams and customers or partners.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.vectra.ai/deployment/getting-started/respond-ux-deployment-guide/fedramp-high-deployment-guidance.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
