Isolate RDP Sessions

Markus Pfohl 0 Reputation points
2023-03-23T14:19:31.2033333+00:00

Hi all,

I'm trying to isolate remote app sessions of users from each other and from the system on Windows Server 2019.

So no viewing of system disk, control panel or any other backdoors.

People are very inventive in that matter...

e.g.: From the context menu of Chrome you can get to the print dialog and then find your way to the control panel.

I played around with Group policies preventing nearly everything the user is able to do, except the published apps (Chrome, Office and a customer app)

Is there any further dokumentation how to refine this.

Windows Server 2019
Windows Server 2019
A Microsoft server operating system that supports enterprise-level management updated to data storage.
3,458 questions
Remote Desktop
Remote Desktop
A Microsoft app that connects remotely to computers and to virtual apps and desktops.
4,243 questions
0 comments No comments
{count} votes

2 answers

Sort by: Most helpful
  1. Limitless Technology 43,931 Reputation points
    2023-03-24T12:17:51.18+00:00

    Hello

    Thank you for your question and reaching out. I can understand you are having query\issues related to GPO settings in RDS or RDP.

    If you set GPO for User level then it should be also applied to Published apps as Users will first login to RDS then Published app will be open , Hence GPO settings should be applied during that process.

    For Printers Add a security group 'Deny Printing' to all printers with the setting Print -> Select Deny. Use GPO to 'Disable the addition of printers' for this group.

    --If the reply is helpful, please Upvote and Accept as answer--

    0 comments No comments

  2. Markus Pfohl 0 Reputation points
    2023-03-29T19:22:55.7733333+00:00

    Thanks for your answer.

    Unfortunately users need to be able to print, so I have to disable settings at more specified point.

    And that was only an example of how users might end up seeing and changing parameters in the system they are not supposed to. There might be other ways that I dnon't know about.

    Is there any defined use case like mine with some documentation?

    0 comments No comments