5.13 Remote Desktop Protocol Relay

The Remote Desktop Protocol Relay (RDP Relay) feature offers Single Sign-on capability and remote access to desktops through a secured connection.In a privileged session, an administrator user who is allowed to access various devices can sign on to many managed devices from a single workstation without knowing the authentication passwords of those devices. In addition, the user can remotely view the desktops of the managed devices and work on them.

You enable privileged sessions for an administrator user with the user's user group information. Then you associate the privileged session with a rule that controls the commands that the user can run on permitted devices and applications.

NOTE:RDP Relay is supported with the following installers:

  • Windows Installers

  • SLES Installers

  • Generic Linux Installers

5.13.1 Configuring the Windows Machine for the RDP Session

You can configure a RDP Relay for Windows machines to allow users to remotely access these machine without the privileged account credentials.

Before configuring an RDP relay, you need to create a host. For detailed information on creating a host, see Section 3.2.1, Adding a Host.

Configuring a machine for an RDP relay involves the following:

Creating a Privileged Account Domain

For information on creating a privileged account domain, see Creating an Account Domain for Windows Systems.

Adding a Rule

After creating an account, you need to set up the rules using the RDP session command for the user to log in with a credential. For detailed information on adding a rule, see Section 5.6.1, Adding a Rule.

5.13.2 Starting a Remote Desktop Session by Using an RDP Relay

  1. In a browser specify the IP address of the Framework Manager in the address bar in the following format:

    https:// <IP address of the Framework Manager>/rdprelay /index.htm

  2. Press Enter. A Login screen appears.

  3. Specify the username and password to log in to Privileged User Manager and click Login.

    A list of rules defined for that particular user is displayed in the following format:

    <rulename>(<username>@<machinename>)

  4. Select the rule required for remotely accessing the Windows machine and click Connect to start the remote desktop session.

NOTE:

  • RDP Relay works only on Internet Explorer 8.0 or later.

  • RDP Relay Manager name is always shown in the RDP connection bar.