Implemented

Application password (local)

avatar

I need to use "Use Windows credentials as application password" under Options > Security.

Is possible to prevent that user can change this settings?

2019-09-30_10-36-50.jpg

All Comments (10)

avatar

Hello,

Sure it is possible if you are using an Advanced Data Source.

Please go in Administration - System Settings - Applications and set the Force application security with Windows credentials option.



Best regards,

Érica Poirier

avatar

Good! But in this case, how i can protect this setting?
Is possible to prevent that user can change this settings Force application security with Windows credentials?

avatar

Hello,

The users won't be able to disable the option locally when it is configured in the System Settings. The option will be greyed out.



Best regards,

Érica Poirier

avatar

Hi,

we have not rolled out the RDM on a global level on my company.
So not all useres are using the Advanced Data Source (we´re using MS SQL DB).

Is there a way that we can have the setting enfroced somehow (Registry, etc.).
We have an SCCM environment and i want to talk to the admins to add RDM ask a package
for the "Shop", that all our users can get them directly... to run a powershell script or a set by GPO
would be possible...
Is there a way to trick that? I would like to set this option together with the "Force currenly logged on username and domain" function.

Otherwise the local datasource is not encrypted and i can´t go ahead and hand it out to the users.

Thanks for your feedback.


Br,
Kasi


P.S.: We are using a Enterprise RDM... Version is not defined yet, but i´m developing it on the latest vesion now.

RDM_localSec.jpg

avatar

Hello Kasi,

this is indeed possible with the GPO extensions. You'll find exactly the option you're looking for:



Regards,
Min

avatar

Hi,

many thanks for this good news.
That will enable both values?
Meaning the "Force currently logged on username and domain" as well?

Br,
Kasi

avatar

Hi,

sorry... but this is not working as expected.
I was setting the regkey as mentioned in the GPO Link:
%Root%\SOFTWARE\Policies\Devolutions\RemoteDesktopManager\ForceLogin

Executed this here:
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Devolutions\RemoteDesktopManager]
"ForceLogin"="1"

Once i start now the RDM i get this:

After click on "OK" the RDM Options pops and under "Security" the correct options are set:

Sadly the RDM is not recognizing the computer´s credential of the logged user along with the password.

Even more curios:
Once i set it to "use application password" and add a password --> close the RDM -> open up again and switch to the "Force currently logged on username and domain" it works!
From here RDM is using the credentials from the current logged on user and his password.

Do i miss something?
Have i done an mistake?

Thanks for your reply.

Br,
Kasi

2020-03-14 22_55_30-Window.png

2020-03-14 22_50_42-Window.png

avatar

Hello,

It seems to be an issue when choosing "Use this computer's credentials as application password" in this scenario. We'll take a look.
As a workaround, choosing "use application password" should work.

Regards,

Hubert Mireault

avatar

Hello,

We've identified the issue and have made a fix. This will be available in RDM 2020.1.18.0. Please let us know if you still encounter issues after the update.

Regards,

Hubert Mireault

avatar

Hi Hubert,

awesome!
Thanks for your Feedback.
I´ll report back once the 2020.1.18.0 is out -> will install right away.

Br,
Kasi