Configuring Support for Microsoft Remote Desktop Services

This topic includes information about configuring Imprivata Virtual Desktop Access with Microsoft Remote Desktop Services (RDS). Imprivata Authentication Management and Virtual Desktop Access licenses are required for this feature.

Before You Begin

Supported Components and Endpoint Devices

Review the Imprivata OneSign Supported Components guide to confirm that your Remote Desktop Services environment meets all of the minimum or recommended requirements.

Communication Ports

The following ports are utilized with Remote PC RDP automation.

Port Protocol Direction

135

TCP Two-way
49666 TCP Two-way

Session Persistence

Session persistence (roaming) is managed by your virtual environment, not Imprivata Virtual Desktop Access. If your virtual environment is configured correctly for session persistence, Imprivata Virtual Desktop Access seamlessly roams user sessions, on authentication, to the endpoint computers in your environment.

NOTE: For more information about configuring session persistence, see your vendor–specific documentation.

Microsoft Session Collection Limitations

While Imprivata Virtual Desktop Access supports both Microsoft Remote Desktops and Microsoft RemoteApps delivered through a single broker, Microsoft does not support mixed session collections of these resource types.

If you intend to deploy both Remote Desktops and RemoteApps to your end users, review Microsoft's guidance on Session Collection creation and plan your server deployment accordingly.

For more information, see the Microsoft TechNet article concerning mixed session collections: 

https://social.technet.microsoft.com/wiki/contents/articles/10817.publishing-remoteapps-in-windows-server-2012.aspx

Note the Required RDS Connection Information

Configuring support for Microsoft RDS requires specific connection details about the deployment. The required information depends on the type of resources users have access to and how they are accessing them.

Configure the RD Session Hosts for Single User Sessions

If your environment includes session-based desktops or RemoteApp programs, configure the RD Session Hosts to restrict users to a single RDS session.

To configure the required local policy setting:

  1. From the Windows Server that is running the RD Session Host role service, open a command prompt window and enter gpedit.msc to open the Local Group Policy Editor.

  2. Go to Computer Configuration > Administrative Templates > Windows Components > Remote Desktop Services > Remote Desktop Session Host> Connections.

  3. Double-click Restrict Remote Desktop Services to a single Remote Desktop Services session to edit the policy setting.

  4. Select Enabled and click OK.

  5. Repeat these steps for each Windows Server running the RD Session Host role service.

Best Practices and Limitations

Review the following best practices and limitations.

Installation Sequence

Branding Login and Enrollment Screens

You can display your corporate logo on the Imprivata login and enrollment screens for Imprivata single-user and shared-kiosk workstations. See Branding the Login and Self-Service Experience.