Best Practices for Use Cases

Terrazone Documentation

To configure access to the Remote Desktop access for users and groups, do the following:

1. On the “Security Policies” page, click the required policy.

2. Go to Application and Services tab.

 

3. Click “Add” button to add new RDP and VDI application.

 

4. Click “Remote Desktop /App” item and press “Select” button.

 

5. “Security” tab of RDP and VDI application looks in the following way:

 

To configure RDP and VDI application security restrictions for users/groups and devices, do the following:

5.1. Enable/disable additional MFA request that will be sent to the user while accessing the application.

 
 

5.2. Enable/disable restricted access per machine.

5.3. To set up devices restrictions – allow/disallow redirects for the following options:

  • Clipboard” – allows or disallows the use of the clipboard for copy and paste operations between the local computer and the remote desktop session.
  • Smartcard” – allows or disallows the use of smart cards for authentication and other operations within the remote desktop session.
  • Drivers” – allows or disallows the installation of device drivers on the remote desktop session, which may be necessary for certain hardware to function correctly.
  • Printers” – allows or disallows the redirection of local printers, enabling the remote desktop session to print to printers connected to the local computer.
  • Ports” – allows or disallows the redirection of local serial and parallel ports, enabling devices connected to these ports on the local computer to be used in the remote desktop session.
  • PnP” – allows or disallows the redirection of Plug and Play devices, enabling the remote desktop session to use hardware devices that are connected to the local computer via USB or other interfaces.
 
 

6. “Connection” tab of RDP and VDI application looks in the following way:

 

To configure RDP and VDI application connection restrictions for users and groups, do the following:

 

6.1. To set the maximum amount of time an active Remote Desktop Service session can be idle, enter the desired time in the “Idle Timeout” input field (after running the desired program on the VDI and closing the RDP connection, some programs stop working because the idle remote desktop session is terminated after a short time).

6.2. Set the desired value in the “Session Timeout” input field (in minutes) (typically, the session timeout is 15 minutes).

 
 

6.3. To add the new domain name press “Add” button in the “RDP File” section.

 

6.4. Enter the domain name and press “OK” button.

 

The new domain name will appear and be selected by default:

 
6.5. To see the content of RDP file, press “RDP Default Template” button.
 
 
RDP file template with placeholders will be open in Notepad.exe:
 
 
6.6. By default, the RDP file will be signed with an SSL certificate to eliminate the yellow warning message and have a message recognizing the issuer of the RDP. To disable signing with the certificate check “Do not sign RDP files” checkbox.
 
 

6.7. To change the format of UPN select one of the list into “User Format” section.

 

7. “Session” tab of RDP application looks in the following way:

 

To set up RDP and VDI application session monitoring, you can set the following configurations:

7.1. Check “Monitoring enabled” inside “Workflow Integration” section.

 
The “Monitoring Configuration” button will become active, click this button.
 
7.2. Click on the “allowedSystemAppsProcesses” item and then click on the “” button on the same line.
 
 

7.3. The “Properties” windows will appear with a list of system application processes. Allow/disallow the desired applications to restrict users from launching them in RDP and press “Save” button.

 
7.4. Click on the “ApplicationPrivilegedAccess” item and then click on the “” button on the same line.
 
 
 

7.5. The “Properties” windows will appear. You can configure the following settings:

  • “Username” – enter the username of the account that will be used for the remote desktop session. This ensures that the correct user credentials are applied for accessing the VDI.
  • “allowedPrivilegedApplication” – specify which applications are permitted to run with elevated privileges. This setting controls which programs can execute with administrative rights, ensuring that only trusted applications are allowed to perform sensitive operations.
  • “enableApplicationAccessElevation” – toggle this setting to allow or disallow applications to request elevation to higher privilege levels. When enabled, applications can prompt the user for administrative permissions to perform tasks that require elevated rights.

7.6. Press “Save” button.

 
 
 
8. “Computers” tab of RDP and VDI application looks in the following way:
 
 
To configure related computers for RDP and VDI application, do the following:
 
8.1. Check “Related Computers enabled” checkbox.
 
 
8.2. Select “Computer Attributes” option and enter username into “Runtime Variable” input.
 
 
8.3. Select “Computer Groups” option and enter group name into “Runtime Variable” input.
 
 
 8.4. Enter Company, Info or Description into “User Attributes” input.
 
 
8.5. To check related computes in Active Directory, press “Test” button.
 
 
8.6. Enter UPN and press “OK” button.
 
 
 
The window “Properties (RDP and VDI)” will appear with search results.
 
 
9. Press “OK” button to save RDP and VDI application configuration.