question

DescatDominiqueNokiaFRParisSaclay-9181 avatar image
0 Votes"
DescatDominiqueNokiaFRParisSaclay-9181 asked DescatDominiqueNokiaFRParisSaclay-9181 answered

Multiple RDP access environment depending of the origin

Hi all,
I would like to access by RDP to the ‘App File server’ to 2 disjointed environments from one ‘SiteX App Server’ or from another one.
How can I manage these ‘rdp’ access? By GPO and/or ps-script?
The user has only one Uid/Pwd within the AD. An easy solution will be to have 2 (or 3, or 4) Uid/Pwd for one user coming from 2, 3 or 4 'SiteX App Server'.
But I think it would be possible to have a segregation that consider the origine of the previous 'rdp' connection.
The ‘SX Environment’ could then be of the type 'Disk:\Users\SiteX\User1'.
Please, thank you to help me.
Kind regards.
Dominique

Please see the attached file:

[1]: /answers/storage/attachments/10372-multiple-rdp-access.pdf

windows-server-2016
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

JoydeepDutt-2506 avatar image
0 Votes"
JoydeepDutt-2506 answered

Hi @DescatDominiqueNokiaFRParisSaclay-9181

One of networking options here for your scenario -- Create 2 different subnets --Subnet 1 (calling it DEV) for AVM1 and Subnet2 (calling it PROD) for AVM2 . Then all subnets 's Route Table to have entry for SRV server. A lot of control can be made from route tables of subnets. Single user id can be used.



(If this reply was helpful please don't forget to Upvote and/or Accept as an answer, Thank You)

Regards,
J.D.


Disclaimer: This posting is provided "AS IS" with no warranties or guarantees, and confers no rights.

5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

TravisCragg-MSFT avatar image
0 Votes"
TravisCragg-MSFT answered

Are you using [Azure Bastion][1] for this scenario? If not, [your question is best asked by selecting the best category Here for Windows OS specific assistance][2]. I can also re-route this existing issue if you tell me the proper tag.

https://docs.microsoft.com/en-us/answers/questions/37525/index.html#editor-source-2
[1]: https://docs.microsoft.com/en-us/azure/bastion/bastion-overview
[2]: https://docs.microsoft.com/en-us/answers/products/windows

5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

TravisCragg-MSFT avatar image
0 Votes"
TravisCragg-MSFT answered

Are you using [Azure Bastion][1] for this scenario? If not, [your question is best asked by selecting the best category Here for Windows OS specific assistance][2]. I can also re-route this existing issue if you tell me the proper tag.

https://docs.microsoft.com/en-us/answers/questions/37525/index.html#editor-source-2
[1]: https://docs.microsoft.com/en-us/azure/bastion/bastion-overview
[2]: https://docs.microsoft.com/en-us/answers/products/windows

5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

DescatDominiqueNokiaFRParisSaclay-9181 avatar image
0 Votes"
DescatDominiqueNokiaFRParisSaclay-9181 answered TravisCragg-MSFT commented

Thank you Travis for this feedback.
Indeed, AzureBastion could have done part of the job, but my question is beyond the 'Taget VM subnet (s)'. Let me explain, based on the diagram contained in the link you provided (https://.../bastion/bastion-overview):
A user authenticates on AzureBastion, accesses the environment 'Azure VM 1' (AVM1), then accesses beyond on a server 'SRV' to an environment associated with 'AVM1'.
This same user during another session authenticates on AzureBastion, accesses the environment 'Azure VM 2', then accesses beyond on the same server 'SRV' to another environment from the previous one is in relation with ' AVM2 '.
Regarding the best category for this post, during my research on the Internet, seemed to me to be this one, but indeed, maybe the section 'Windows Server for IT pros' would be a good choice, but then what to choose in the sub-sections?
We work with Win Srv 2016, this is architecture setup using AD and RDP, maybe with network considerations.
I would be happy if you can redirect this post to the most appropriate tag.
Thank you in advance for your help.
Kind regards. Dominique

· 1
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

Issue has been re-tagged!

0 Votes 0 ·
DescatDominiqueNokiaFRParisSaclay-9181 avatar image
0 Votes"
DescatDominiqueNokiaFRParisSaclay-9181 answered

Hi JoydeepDutt-2506,
Thank you very much for this reply.
I think this solution will be appropriate for my problem avoiding to implement additional 'AzureBastion' servers.
In the meantime, I implemented a solution depositing a sticker on the target system and I use it to mount a disk / sticker / user directory providing a differentiation of sources and a mastery of these differentiated environments.
Kind regards.
Dominique

5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.