Server 2012 R2 Remote Desktop Gateway. Most Simple and Secure Design For Small Environment?

We would like users to be able to connect remotely over the Internet from their personal devices to their primary Windows 7 workstation (a physical box on their desk) by using the Microsoft RDP Client For Windows, Mac, iOS and Android.  There is no
plan to use RDWeb or Remote Apps, or VDI.  Just plain remote access to their desktop PC without VPN plus a third party 2nd factor authentication product that can text them back a code to enter with their AD credentials (AuthAnvil or Duosecurity)
We do not have TMG or ISA.
We would like to get these services all running in a single server and be as simple as possible while still being very secure.
The recommendations I see seem to suggest putting the RDG in a DMZ with either a domain controller on a new domain with a one-way trust to your internal domain or else a read-only domain controller on your domain and then RD Session Host and License server
located on different servers on your internal LAN.
http://blogs.msdn.com/b/rds/archive/2009/07/31/rd-gateway-deployment-in-a-perimeter-network-firewall-rules.aspx
That sounds like a lot of separate servers and cost for not a lot of users in our environment.
Do we even need a separate session host server if there are no RDP sessions being hosted directly on the servers because  the users are only being redirected to connect to their workstations and will never be using terminal sessions on the server?
Can the RODC or the Domain controller on new domain with the one-way trust be the same server as the Remote Desktop Gateway server and not separate servers?
What is the most minimalist way to set this up with good security when opening all the ports needed to authenticate with internal DC is not secure enough?

#2 sounds like we would need 2 Essentials servers and we will not have that.
We currently have Server 2008 R2 and have 2012 Standard licenses that are not yet used.
We have much more than 75 users total, but 75 is more than the number of users that will probably take advantage of using RD Gateway any time soon.  It will probably take time to catch on.
If RD Gateway usage was to get super popular and more than 75 users were depending on access to it, then we could financially justify paying to buy all the CALs needed to run RD Gateway without Essentials.  Right now, they are skeptical that it will
be worth spending much money on this and don't want to invest a lot  of money up front.
My understanding is that if we have 75 or fewer users using RD Gateway then we need to by no CALs, just apply a Server Standard Edition License to the server, but if we had 76, we would need to turn off Essentials and buy 76 new CALs.
Or would we need to add 50 CALs to the 25 that automatically come with Essentials?
Also does "turning off" Essentials mean we would have to reinstall and redeploy the RDG or is it just a matter of enabling the RD license server and adding purchased CALs?
No, when you buy essentials you get the right to create 25 users that access the server, when you create the 26th user you will need to have 26 CAL and RDS CAL. 

Similar Messages

  • Does Windows Server 2012 support Remote Desktop Client 6.1?

    Hi,
    Does Windows Server 2012 support Remote Desktop Client 6.1? IU can't find a link anywhere on the Microsoft site to confirm this!
    Thanks,
    Jim

    this should help you
    http://social.technet.microsoft.com/Forums/windowsserver/en-US/b664ddaf-6c11-49e2-8a69-0df3b8ef13a1/server-2012r2-rds-farm-with-xp-and-windows-vista-clients?forum=winserverTS

  • Server 2012 R2 Remote Desktop Services Licensing

    I currently have a single Remote App server running on server 2012 (not R2). Let's call it Remote1 for simplicity.  I want to add a second individual server (Remote2) running it's own connection broker, gateway and session host on one machine. 
    Is it possible to do this while having Remote1 acting as the license server or would I have to add Remote2 to the server pool acting as a session host only?  Would purchasing Remote2's own set of CAL's make this work?

    Is the license server and the session host in the same domain? You don't have to put Remote2 into pool where you have Remote1.
    They both can act as seperate entity as you said. But if the only need is to have remote1 as a license server for remote2 then you can use the following method to specify the license mode and license server on remote2
    Configure the Remote Desktop Session Host role with to use the localRemote Desktop Licensing server. Follow these steps:
    Open an elevated Windows PowerShell prompt
    Type the following command on the PS prompt and press Enter:
    $obj = gwmi -namespace "Root/CIMV2/TerminalServices" Win32_TerminalServiceSetting
    Run the following command to set the licensing mode:
    Note: Value = 2 for Per device, Value = 4 for Per User
    $obj.ChangeMode(value)
    Run the following command to replace the machine name with License Server:
    $obj.SetSpecifiedLicenseServerList("LicServer")
    Run the following command to verify the settings that are configured using above mentioned steps:
    $obj.GetSpecifiedLicenseServerList()
    You should see the server name in the output.
    Hari Kumar --- Disclaimer: This posting is provided AS-IS with no warranties or guarantees and confers no rights

  • Server 2012 R2 Remote Desktop Connection Broker

    I have installed RDS on a server named PLUTO on which Windows 2012 R2 datacenter is in. There is a domain controller (domain name: AGROSY) running on a Linux server. We have used Samba 3.6.6 to control the file sharing system.
    When I attempt to install RDS in Server Manager, it states as following: could not retrieve the deployment information from RD connection broker server pluto.AGROSY.
    Then, I searched a lot of solutions, e.g.  and tried as following:
    Enter-PSSession -ComputerName pluto   --> which works;
    but Enter-PSSession -ComputerName pluto.AGROSY   --> which gives the error message as: Enter-PSSession : Connecting to remote server pluto.AGROSY failed with the following error message : WinRM cannot process the request. The following
    error with errorcode 0x80090311  occurred while using Kerberos authentication: There are currently no logon servers available to service the logon request.
    If I ping the pluto.AGROSY, it works as well.
    I have no idea how it can be solved, please help me out. Thanks a lot!

    Hi,
    Thanks for your comment. Sorry for late reply.
    Initially please enable the PowerShell remoting in your case. 
    Enable-PSRemoting
    http://technet.microsoft.com/en-us/library/hh849694.aspx
    For FQDN name, please see that RDCB is properly configured and also certificate which you have used for RDS environment must be trusted with its private key and must match the FQDN name of the server. Did you seen the certificate has been properly used and
    configured. You can go through following article for certificate and also for configuring RDCB role.
    Configuring RDS 2012 Certificates and SSO
    Configuring HA for the Remote Desktop Connection Broker in a 2012 RDS Farm
    Hope it helps!
    Thanks.
    Dharmesh Solanki
    TechNet Community Support

  • Server 2012 RTM Remote Desktop Connection Broker Role Won't Install

    Hey guys,
    I have been searching for and trying fixes for this for 3 days, and I've gotten no where.  Thanks in advance for trying to help me out.
    Here's the situation:
    I have a brand new installation of the Windows Server 2012 Datacenter 64-Bit RTM from MSDN.  This is my one and only server (just my personal one for home), so I'm using this single server to run all of the services that I need.  After a fresh
    installation, I added the AD and DNS roles and promoted the server to the PDC.  Then I go to add the Remote Desktop Virtualization Services (the VM virtualization role).  The installation fails, but I can't find any explanation as to why.
    I've wiped out the OS and reinstalled from scratch at leat 15 times, trying various combinations, fixes, approaches, etc.  including powershell, Remote Desktop Services Deployment, standard role-based deployment, etc.
    Using the role-based deployment, I can get every 'Remote Desktop Services' component to install except the Remote Desktop Connection Broker.  I've tried enabling RDMSUI_TRACING, but didn't get any information at all as to why it's failing.  I also
    cannot find RDMSDeploymentUI.txt log.
    I've also tried to deploy this using Powershell using this command:
    New-SessionDeployment [-ConnectionBroker] <string> [-WebAccessServer] <string> [-SessionHost] <string>
    That particular item does provide some error messages, but they seem to complain about the Session Host not being able to install due to not being able to find the connection string key in the registry for the Windows Internal Database.  However, I can
    get the session host and every other component to install using role-based deployment, except the Connection Broker.
    I've run an SFC scan, which found no issues.   I've also tried applying the one update available in Microsoft Update, and tried it without applying that update (reinstalling between attempts of course).
    I'm completely at a loss.  Has anyone encountered this before?  Any suggestions would be greatly appreciated.  Is there a powershell command for just installing the Connection Broker that might provide some additional error information, or any
    information at all?
    I would greatly appreciate any help anyone could offer.  I'm willing to try anything.  Thanks for taking the time to read this.
    Sincerely,
    Dominick

    Also Found this:
    1. You try to install the Remote Desktop Connection Broker (RDCB) on a server that also has the Active Directory Domain Server (domain
    controller) role installed. This configuration is not supported by Microsoft. You need to install the RDCB on a server that does not have this role installed. See: Remote Desktop Services role cannot co-exist with AD DS role on Windows Server 2012 http://support.microsoft.com/kb/2799605
    2. If you don’t have the Active Directory Domain Service install, this issue might be caused by the Windows internal database (WID) that
    the connection broker installs and the Windows Update KB2821895. If you have KB2821895 installed, unfortunately you can not uninstall this KB. Try to install the Remote Desktop Connection Broker (RDBC) role on a server that does not have this Windows update.
    Note: There is currently no official communication from Microsoft that here is an issue with RDBC and KB2821895. However, try the RDBC installation
    without this KB and see what happens.
    For more information, Refer below link...
    http://fabrikam.wordpress.com/2013/07/15/connection-broker-installation-failedremote-desktop-deployment-issues/

  • Windows Server 2012 Standard - Remote Desktop Management service won't start

    Dear colleges, I'm seeking your help in resolving a weird issue with Remote Desktop.
    The Remote Desktop Management service gives the following error message any  time it is attempted to start:
    "The Remote Management Service on Local Computer started and then stopped. Some services stop automatically if they are not in use by other services or programs."
    The Event Viewer error message is as follows:
    "The Remote Desktop Management service failed to start. Error code: 0x88250001"
    Whenever I connect to the server with RD I get error message that the Remote Desktop Licensing Server isn't configured and that the RD trill will expire in N-days. The server is up to date updates wise and has been licensed for 5 RD CALs. The server hosts DNS
    server and has AD DS role installed, is virtualized to have one Hyper-V server.
    I read some blogs about having both DNS and AD DS on one box is a bad sea and a root cause of the issue. Well, that very well may be, but for me that's an option as I'm not going to get a box to just host DNS. There should a solution to this as I shouldn't
    only one suffering from this issue.
    I also read about KB2871777 - Servicing stack update supposedly addressign this issue. Well, it's on my system and the issue is there too. :)
    Will I loose ability to RD when the trial expires or it's just another misleading MS message that can be ignored?
    How do I mend Remote Desktop Management service to start?
    Appreciate your help!
     

    Hi,
    Thank you for posting in Windows Server forum.
    Can administrators perfectly connect to RDS environment?
     In meantime please check that you have properly configured and activated RD License role service and install RDS CAL on it. It might also possible that you have configured RD License server but it server can’t find it and giving you error due to certificate
    also. Please check that you have properly configured certificate on your RDS Server. Try to install and update below hotfix for License related issue.
    No RDS license when you connect to an RDS farm in Windows Server 2012
    http://support.microsoft.com/kb/2916846
    If you have configured both RDS and AD DS on single server then also you may find some error reading this. If so please try to setup both roles on different server and check the result. In addition to this, please check below articles.
    What's New in Remote Desktop Services in Windows Server 2012
    http://technet.microsoft.com/en-in/library/hh831527.aspx
    Install Remote Desktop Services Failed on Windows 2012 Server
    http://social.technet.microsoft.com/Forums/windowsserver/en-US/bbf47aa2-8ae5-4f22-9827-afee5a11417a/install-remote-desktop-services-failed-on-windows-2012-server?forum=winserverTS
    Hope it helps!
    Thanks.
    Dharmesh Solanki

  • Server 2012 RDS - Remote Desktop Connection Broker Client failed to redirect the user domain\username. Error: NULL

    Seeing the error listed here.
    The Remote Desktop Connection Broker server could not enumerate the targets for the provider named NULL from the database.
    Pooled virtual desktop collection name: NULL
    Error: Error code: 0xFFFFFFFF.
    Broker and Hyper-V are on the same physical machine.
    Any ideas on where to start troubleshooting this?
    Used the happy wizard to create everything, and got no errors.
    I have created a small pool collection, and given rights to domain users. Everything "looks" good.

    I have the same problem.
    (Making this long hand for those who come after)
    I have installed SQl Management Studio Express 2012 SP1
    http://www.microsoft.com/en-us/download/details.aspx?id=29062 
    (You only need the one file "SQLManagementStudio_x64_ENU.exe")
    Ran this as Administrator 
    And typed in the Server Name field
    \\.\pipe\MICROSOFT##WID\tsql\query
    Then hit connect.
    Expanded Databases (+sign)
    Expanded RDCms 
    Expanded Tables
    Right Clicked on rds.target, select Edit top 200 rows
    Right Clicked and copied, then pasted this into a notepad file on the desktop (As a backup)
    Right Clicked and selected Delete to delete the row with the data in it (and PoolID was set to Null in this row)
    Did the same for rds.pool
    Manually added Remote Desktop server into the MEMBER OF tab of
    “Windows Authorization Access Group” via Active Directory Users and Computers. As this domain was Windows 2003 Native when the RDS server was first installed.
    Rebooted server and same issue>
    Checked SQL again and rows had come back.
    Is that what you meant by "delete
    the rds.target and rds.pool with pool id = NULL"?
    Not a SQL guru, so any help appreciated.

  • Server 2012 r2 /Remote Desktop

    I am connecting to a Server 2012 R2 server and it connects shows the desktop for a split second and then dissconnects. I tried connecting with a rdp client Win 7 pro from different locations and different machines. The only thing the event log displays is
    the following:
    Log Name:      Application
    Source:        Desktop Window Manager
    Date:          3/28/2014 10:08:33 AM
    Event ID:      9009
    Task Category: None
    Level:         Information
    Keywords:      Classic
    User:          N/A
    Computer:      Server2014.Purgistics.local
    Description:
    The Desktop Window Manager has exited with code (0xd00002fe)
    Event Xml:
    <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
      <System>
        <Provider Name="Desktop Window Manager" />
        <EventID Qualifiers="16384">9009</EventID>
        <Level>4</Level>
        <Task>0</Task>
        <Keywords>0x80000000000000</Keywords>
        <TimeCreated SystemTime="2014-03-28T14:08:33.000000000Z" />
        <EventRecordID>11842</EventRecordID>
        <Channel>Application</Channel>
        <Computer>Server2014.Purgistics.local</Computer>
        <Security />
      </System>
      <EventData>
        <Data>0xd00002fe</Data>
      </EventData>
    </Event>
    Any help with this matter would be greatly appreciated. Help!

    Below are the answers you asked for.
    Is this same when you rdp using IP or Hostname?
    Yes
    Is this same for all users or any particular?
    Administrator account. Any other user with full Enterpise Admin rights it says The Local Session Manager service failed the logon. The requested session is not supported.
    What is the status of the firewall on both machines? Off
    RDP services are running properly? Yes I can RDP to another server on the WAN.
    What is the status of Remote tab of System Properties? It is enabled with No security.
    Help!!!!
    I

  • Setting display language Server 2012 R2 Remote Desktop Services

    I'm trying to setup local display language when user logs on to my Remote Desktop Services server.
    I have configured the following GPO:
    User Configuration/Policies/Administrative Templates/Control Panel/Regional
    and Language Options/
    Restrict selection of Windows menus and dialogs language
    Restricts the UI languages Windows should use for the selected user
    When I log on the user display language is not set, but it seems that the GPO has been applied correctly (GPResult)....
    What am I doing wrong ?

    Hi,
    Thank you for your posting in Windows Server Forum.
    As you have configured GPO setting, please have a look at registry setting and check whether it is properly configured over there.
    The Display Language was controlled by the REG_MULTI_SZ key PreferredUILanguages under
    HKCU\Control Panel\Desktop
    Create this key "PreferredUILanguages" with ja-jp when need Japanese and delete it to get back English. 
    You can export this Registry Key and import it instead of edit this key directly. 
    [HKEY_CURRENT_USER\Control Panel\Desktop]
    "PreferredUILanguages"=hex(7):6a,00,61,00,2d,00,6a,00,70,00,00,00,00,00
    Hope it helps!
    Thanks.
    Dharmesh Solanki

  • Dictionary Option in Word 2013 Standard on Server 2012 R2 Remote Desktop Services Server

    We have a customer running Server 2012 R2 RDS with Office 2013 Standard. They are licensed for Office 2013 via Office 365. Office 2013 Standard is installed on the server via a using the Volume license as directed by MS. 
    Each user has a Microsoft Office 365 account.
    When the user attempts to use the Right Click -> Define Option in MS Word, the user is prompted to sign in so they can select a dictionary. 
    This is where the problem begins. The login process does not accept the users Office365 account. I was able to create a new Microsoft account (using the same email address as the Office 365 account) and select a dictionary.
    Is this the only method to get the dictionary to work? All 100 users must create another Microsoft account and use that to select a dictionary?

    Hi,
    What Word prompts when user attempts to login with the original account? Any error messages?
    Since the feature will work if you create a new account, have you ever compared the property of these two accounts? Maybe the security or permission setting during the creation process?
    We lack testing environment here for this kind of issues, and we have another dedicated support teams in
    Microsoft Office 365 Community. I would suggest you to post there, where you can get more experienced responses:
    http://community.office365.com/en-us/f/default.aspx
    The reason why we recommend posting appropriately is you will get the most qualified pool of respondents, and other partners who read the forums regularly can either share their knowledge or learn from your interaction with us. Thank you for your understanding.
    Thanks,
    Ethan Hua CHN
    Forum Support
    Come back and mark the replies as answers if they help and unmark them if they provide no help.
    If you have any feedback on our support, please click
    here

  • Acrobat Pro XI, Server 2012 r2 Remote Desktop, cannot print until server reboot, No Pages Selected

    Ever since we migrated to terminal services (remote desktop) this problem has plagued us.
    We are a terminal services environment with 25 users.
    Our version of Adobe is 11.0.10
    I've believe I have traced the issue to temp files in \users\username\appdata\local\temp\XX
    There are [email protected] files that the system locks.
    Once those files are written out and the server locks them down the user cannot print .pdf files any longer.
    ALL OTHER APPLICATIONS WORK PERFECTLY!
    The only way to clear the situation is to reboot the server (not optimal).
    And even then the problem reappears within a day.
    I have read many different versions of this problem and tried many different solutions.
    I have tried having the users go the advanced tab when printing and choose "print as image"
    FAIL!
    I have put a acroct.ini with the following parameters in the windows directory
    [WinFntSvr]
    TTToSysPrintDisabled=1
    T1ToTTDisabled=1
    FAIL!
    I have tried to remove Microsoft security updates related to this issue and 3rd party fonts.
    FAIL!
    I've tried the "Disable Protected Mode at Startup"
    FAIL!
    I have rebuilt our print server with the latest drivers.
    FAIL!
    Since we deal with thousands of .pdf files on a daily basis this has become CRITICAL!
    Please Help!

    Please see this thread: No Pages Selected RDS Server 2012r2

  • Logging into Windows Server 2012 from Remote Desktop requires "Connect with Smart Card"; how do I disable this?

    I am using pretty much the default setup. I cannot figure out how to disable this. I do not want to use smart cards.
    Any ideas?

    Does this mean you're trying to RDP from an XP box, therfore have the Remote Desktop feature on the server set to "less secure"? Sounds like thats what disables network authentication, prompting the Smart Card request.
    If you simply click to login as a different user, you can login without a smart card, to include the same user as was being prompted for the card.
    I expect if you choose the Remote Desktop feature requires network authentication on the server, the smart card requirement goes away, but you'll need to login from Win7 or newer clients. Not sure where Vista falls, probably okay too.

  • Installing Windows Server 2012 RC Remote Desktop (ISSUE)

    Installing the RD Host Service doesn't work and I get several errors. Any Hints?

    You cannot be serious. I approached your Microsoft "Gold certified" software partner 'Cancom Germany' with the following requirement:
    - Need a Windows 2012 "Terminal Server"
    - for 15 client devices
    - currently no AD or other Windows servers installed
    What do I get sold:
    - Windows Server 2012
    - 15 Device CALs
    - 15 RDS device CALs
    and the information that I need to setup AD and the RDS roles. So far so good.But I run into these error messages when setting up the RDS roles.
    Now you are telling me that I need another server running just for the AD? Which I do not need for anything except for the internal requirement of the RDS services?
    Please elaborate a bit more on the way to get it work on the same machine or suggest another solution (btw buying another license for the AD server is not a solution).
    Totally agree with you. buying extra server just for AD or broker frustrated me. but I found a patch here
    http://support.microsoft.com/kb/2799605
    I don't know if it is too late, but hope it can help others

  • Server 2012 R2 Remote Desktop Connection Broker, Server Name Change.

    We have a server that was the connection broker, We changed its name and now the connection broker wont recognize the new name.  It continutes to want the old server.  Unfortunately we cant change it back.  Is there a fix for this? 
    We tried the powershell command but it doesnt see the old server name and errors out.

    Hi,
    Changing the name of a RD Connection Broker server is not supported.  If you are able to remove RD Connection Broker Role Service and install a new RDS deployment you may be able to get it working again (with perhaps a few registry fixes),
    but you will lose all of the configuration data associated with your deployment.  If you have a very basic RDS deployment it may not be a big deal to recreate the collections, configure settings, publish
    RemoteApps, etc., as they were before.
    Another potential option if you were able to temporarily change the name back would be to switch to HA mode with the database stored on the local server (in SQL Express), add another RDCB server, remove RDCB from the original (leaving the SQL Express database
    still functional), rename the server, add it back as a RDCB server, then remove RDCB from the second server.  I have not tried this procedure but at first glance I believe it should work, although it may be a bit complicated if you are not well versed
    with 2012 R2 RDS.
    If this is a small environment you may want to consider backing up any data on the servers and then reinstalling all of the RDS servers from scratch.  
    It is possible to manually fix the issue you are seeing by editing the RDMS database, editing the registries of all the RDS servers, and other related tasks, however, I would not suggest it due to the complexity.
    -TP

  • Is there a way to Report out Remote Desktop Gateway Manager Monitor data?

    We are running Windows Server 2012 R2 Remote Desktop Services configured to provide a managed pool of VMs through a RD Gateway server. Everything is working well. We would like to generate a regular report on the information that shows up in the Gateway
    Monitoring window about connections and users etc. Is there any way to generate such a report without purchasing 3rd party software?

    Hi,
    Based on my experience, you can use Remote Desktop Gateway Manager to view information about active connections from Remote Desktop Services clients to internal network resources through an RD Gateway server. However, there is no such options in
    RD gateway manager to create reports for that.
    It seems that System Center Operations Manager can monitor Remote Desktop Gateway Service and the number of sessions that run through the RD Gateway are monitored.
    Best regards,
    Susie
    Please remember to mark the replies as answers if they help and unmark them if they provide no help. If you have feedback for TechNet Subscriber Support, contact [email protected]

Maybe you are looking for

  • Will the late 2013 Mac Pro boot from an external drive (4Tb, USB 3) with a cloned Win7 x64 partition on it?

    Hello all, I ordered a CTO Mac Pro for heavy rendering and animating work, and I am planning on using bootcamp to install a windows partition (for 3DsMax). As I am now using a HP Elitebook 8770W that has several valuable files and projects on it, I h

  • Creating Custom WCF in sharePoint 2013

    Hello,  I read the following article to create Custom wcf "http://www.robertseso.com/2013/05/adding-custom-wcf-services-to.html". I have followed the steps . when I open the .svc  from browser I got the following error :            "sharepoint  provi

  • Down payment to vendors

    Down payment to Vendors made and it is adjusted proportionetly with recipt of material. what is it mean? proportionetly means raising more than one invoice? or not. before giving the advance to vendors, did we have create the purchse order or not nec

  • Get part of variable and provide to others variable

    Hi, I am having V_Flatfilename variable in ssis package which is used to store the filepath with file name in sql table. I want to get only filename and give to another variable using expression another variable is V_Src_Filename V_Flatfilename=\\RLD

  • IMPORT FROM MEMORY in job submitted program

    Hi experts, In a method I do:       SUBMIT zemr0044 USER sy-uname                      VIA JOB lc_jobname                      NUMBER lv_jobcount                      AND RETURN. Before this submit I have done:   IMPORT ls_header = ls_header FROM DAT