RDP Server Configuration and Security SOP
Purpose
Deploy a licensed, hardened and recoverable Remote Desktop Services environment.
Decision Summary
Never expose TCP/UDP 3389 directly to the internet. Ordinary RDS users receive no local Administrator rights.
Use Cases
RDS Session Host, RemoteApp, RD Gateway and internal multi-user application hosting.
Hardware Requirements
Supported server, secure management path, current backup and adequate workload capacity.
Backup Strategy
Export permissions and back up configuration/application data before material changes.
Recovery Strategy
Use approved break-glass access or restore known-good configuration; revoke unintended access and validate.
Secure Boot Notes
Keep Secure Boot enabled where supported; access administration does not require disabling it.
Version History
v1.0 — 2026-08-04 — Initial controlled SOP.
Technology Register Metadata
- CSI Classification: Production Ready
- CSI Tech ID: 148
- Category: Field SOPs
- Client Approved: No
- Commercial Use: Allowed
- Current Version: 1.0 — 2026-08-04
- Documentation URL: https://learn.microsoft.com/windows-server/remote/remote-desktop-services/
- Evidence Complete: Yes
- Last Updated: August 4, 2026 3:16 AM
- Licence: CSI Internal SOP — underlying product licence terms apply.
- Lifecycle Status: Done
- Risk Flag: High Risk
- Ventoy Compatibility: Not Applicable
Migration Record
Imported deterministically from the CSI Technology Register.
Source classifications, approval state, risk state, version information and testing status have been preserved. No additional approval or validation has been inferred during migration.
Cyber Space Infocom
Making Technology Work for You