Hacking microsoft remote desktop services

broken image
broken image

One advantage of using Remote Desktop rather than 3rd party remote admin tools is that components are updated automatically with the latest security fixes in the standard Microsoft patch cycle. This approach utilizes the Remote Desktop host itself, in conjunction with YubiKey and RSA as examples. Other unsupported by campus options available would be a simple mechanism for controlling authentication via two-factor certificate based smartcards. This topic is beyond the scope of this article, but RD Gateways can be configured to integrate with the Campus instance of DUO. Use Two-factor authenticationĭepartments should consider using a two-factor authentication approach.

broken image

Refer to the campus password complexity guidelines for tips.

broken image

Strong passwords on any accounts with access to Remote Desktop should be considered a required step before enabling Remote Desktop.

broken image