SlideShare a Scribd company logo
Module 14 Extending Remote Desktop Services Outside the Organization
Module Overview ,[object Object],[object Object]
Lesson  1 : Configuring the RD Gateway  ,[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object]
Internet  Corporate LAN Business Partner/ Client Site Hotel Home External Firewall Internal Firewall Remote Desktop Services Remote Desktop Services Remote Desktop– enabled host Network Policy Server Active Directory How RD Gateway Works Tunnels RDP over HTTPs Strips off HTTPs Passes RDP traffic to RDS
Benefits of RD Gateway RD Gateway provides the following benefits: ,[object Object],[object Object],[object Object],[object Object],[object Object],[object Object]
Requirements for Installing and Configuring RD Gateway To install and configure RD Gateway: ,[object Object],[object Object],[object Object],[object Object],[object Object]
Demonstration: Installing the RD Gateway ,[object Object]
 
Securing the RD Gateway Configurable idle and session timeouts  Background session  authentication and  authorization  Pluggable authentication and authorization  System and  logon messages   Network Access Protection (NAP) remediation Device redirection  enforcement
Authorization Policies with RD Gateway Connection Authorization Policies: ,[object Object],[object Object],Resource Authorization Policies: ,[object Object],[object Object]
Demonstration: Configuring Connection and Resource Authorization Policies ,[object Object]
 
Implementing NAP Integration with RD Gateway To implement NAP integration with RD Gateway: ,[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object]
Considerations for Implementing Certificates for RD Gateway ,[object Object],Certificate Option Considerations Self-signed certificates ,[object Object],[object Object],[object Object],Internal CA certificates ,[object Object],[object Object],[object Object],Public CA certificates ,[object Object],[object Object],[object Object]
Lesson 2: Configuring RD Web Access  ,[object Object],[object Object],[object Object],[object Object],[object Object],[object Object]
What Is RD Web Access? RD Web Access enables: ,[object Object],[object Object],[object Object],[object Object]
Installing RD Web Access To install RD Web Access: ,[object Object],[object Object],[object Object],[object Object],[object Object]
Configuring RD Web Access
Configuring User Access to RD Web Access  To enable user access to RD Web Access: ,[object Object],[object Object],To configure RemoteApp and Desktop Connections: ,[object Object],[object Object]
Configuring Internet Access To RD Web Access To configure Internet access to RD Web Access: ,[object Object],[object Object],[object Object]
Demonstration: Configuring RD Web Access  ,[object Object]
L ab : Integrating RD Web Access into the Desktop Virtualization Infrastructure  ,[object Object],[object Object],[object Object],Logon information: Estimated time:  75  minutes NYC-Host1, NYC-Host2 Host machines Virtual machines NYC-DC1, NYC-CL1, NYC-SVR4, NYC, SVR5, NYC-SVR6 User name Administrator Password Pa$$w0rd
Lab Scenario ,[object Object]
Lab Review ,[object Object],[object Object],[object Object]
Module Review and Takeaways ,[object Object],[object Object]
Course Evaluation

More Related Content

What's hot

RADIUS
RADIUSRADIUS
RADIUS
amogh_ubale
 
Radius1
Radius1Radius1
Cisco acs configuration guide
Cisco acs configuration guideCisco acs configuration guide
Cisco acs configuration guide
RichardsCCNA
 
Implementing 802.1x Authentication
Implementing 802.1x AuthenticationImplementing 802.1x Authentication
Implementing 802.1x Authentication
dkaya
 
Server 2012 r2 remote desktop services
Server 2012 r2 remote desktop servicesServer 2012 r2 remote desktop services
Server 2012 r2 remote desktop services
Nihat ALTINMAKAS
 
Radiojungle AAA RADIUS introduction
Radiojungle AAA RADIUS introductionRadiojungle AAA RADIUS introduction
Radiojungle AAA RADIUS introduction
smoscato
 
Radius Protocol
Radius ProtocolRadius Protocol
Radius Protocol
Netwax Lab
 
Routing host certificates in eduroam/govroam
Routing host certificates in eduroam/govroamRouting host certificates in eduroam/govroam
Routing host certificates in eduroam/govroam
Karri Huhtanen
 
Deploy and Configure an Enterprise Root CA & Subordinate CA in Windows Server...
Deploy and Configure an Enterprise Root CA & Subordinate CA in Windows Server...Deploy and Configure an Enterprise Root CA & Subordinate CA in Windows Server...
Deploy and Configure an Enterprise Root CA & Subordinate CA in Windows Server...
Md. Abdul Barek
 
EAP-TLS (extended version)
EAP-TLS (extended version)EAP-TLS (extended version)
EAP-TLS (extended version)
Karri Huhtanen
 
TLS and Certificates
TLS and CertificatesTLS and Certificates
TLS and Certificates
Karri Huhtanen
 
At8000 s configurando_8021x
At8000 s configurando_8021xAt8000 s configurando_8021x
At8000 s configurando_8021xNetPlus
 
Remote Desktop Services and Virtual Desktop infrastructure in Windows Server ...
Remote Desktop Services and Virtual Desktop infrastructure in Windows Server ...Remote Desktop Services and Virtual Desktop infrastructure in Windows Server ...
Remote Desktop Services and Virtual Desktop infrastructure in Windows Server ...
ctc TrainCanada
 
WinConnections Spring, 2011 - How to Securely Connect Remote Desktop Services...
WinConnections Spring, 2011 - How to Securely Connect Remote Desktop Services...WinConnections Spring, 2011 - How to Securely Connect Remote Desktop Services...
WinConnections Spring, 2011 - How to Securely Connect Remote Desktop Services...
Concentrated Technology
 
802.1x Authentication Standard
802.1x Authentication Standard802.1x Authentication Standard
802.1x Authentication StandardDan Miller
 
802.1x Implementation Plan for Seacoast
802.1x Implementation Plan for Seacoast802.1x Implementation Plan for Seacoast
802.1x Implementation Plan for SeacoastSithideth Banavong
 
EAP-TLS
EAP-TLSEAP-TLS
Security issues in RADIUS based Wi-Fi AAA
Security issues in RADIUS based Wi-Fi AAASecurity issues in RADIUS based Wi-Fi AAA
Security issues in RADIUS based Wi-Fi AAA
Karri Huhtanen
 
Terminal Services in Windows Server® 2008
Terminal Services in Windows Server® 2008Terminal Services in Windows Server® 2008
Terminal Services in Windows Server® 2008
Sergi Duró
 

What's hot (20)

RADIUS
RADIUSRADIUS
RADIUS
 
Radius1
Radius1Radius1
Radius1
 
Cisco acs configuration guide
Cisco acs configuration guideCisco acs configuration guide
Cisco acs configuration guide
 
Implementing 802.1x Authentication
Implementing 802.1x AuthenticationImplementing 802.1x Authentication
Implementing 802.1x Authentication
 
Server 2012 r2 remote desktop services
Server 2012 r2 remote desktop servicesServer 2012 r2 remote desktop services
Server 2012 r2 remote desktop services
 
Radiojungle AAA RADIUS introduction
Radiojungle AAA RADIUS introductionRadiojungle AAA RADIUS introduction
Radiojungle AAA RADIUS introduction
 
Radius Protocol
Radius ProtocolRadius Protocol
Radius Protocol
 
Routing host certificates in eduroam/govroam
Routing host certificates in eduroam/govroamRouting host certificates in eduroam/govroam
Routing host certificates in eduroam/govroam
 
Deploy and Configure an Enterprise Root CA & Subordinate CA in Windows Server...
Deploy and Configure an Enterprise Root CA & Subordinate CA in Windows Server...Deploy and Configure an Enterprise Root CA & Subordinate CA in Windows Server...
Deploy and Configure an Enterprise Root CA & Subordinate CA in Windows Server...
 
EAP-TLS (extended version)
EAP-TLS (extended version)EAP-TLS (extended version)
EAP-TLS (extended version)
 
TLS and Certificates
TLS and CertificatesTLS and Certificates
TLS and Certificates
 
At8000 s configurando_8021x
At8000 s configurando_8021xAt8000 s configurando_8021x
At8000 s configurando_8021x
 
Remote Desktop Services and Virtual Desktop infrastructure in Windows Server ...
Remote Desktop Services and Virtual Desktop infrastructure in Windows Server ...Remote Desktop Services and Virtual Desktop infrastructure in Windows Server ...
Remote Desktop Services and Virtual Desktop infrastructure in Windows Server ...
 
WinConnections Spring, 2011 - How to Securely Connect Remote Desktop Services...
WinConnections Spring, 2011 - How to Securely Connect Remote Desktop Services...WinConnections Spring, 2011 - How to Securely Connect Remote Desktop Services...
WinConnections Spring, 2011 - How to Securely Connect Remote Desktop Services...
 
802.1x Authentication Standard
802.1x Authentication Standard802.1x Authentication Standard
802.1x Authentication Standard
 
802.1x Implementation Plan for Seacoast
802.1x Implementation Plan for Seacoast802.1x Implementation Plan for Seacoast
802.1x Implementation Plan for Seacoast
 
EAP-TLS
EAP-TLSEAP-TLS
EAP-TLS
 
Security issues in RADIUS based Wi-Fi AAA
Security issues in RADIUS based Wi-Fi AAASecurity issues in RADIUS based Wi-Fi AAA
Security issues in RADIUS based Wi-Fi AAA
 
Ieee 802.1 x
Ieee 802.1 xIeee 802.1 x
Ieee 802.1 x
 
Terminal Services in Windows Server® 2008
Terminal Services in Windows Server® 2008Terminal Services in Windows Server® 2008
Terminal Services in Windows Server® 2008
 

Similar to 10215 A 14

VDI-in-a-Box: Microsoft Desktop Virtualization for Smaller Businesses and Uses
VDI-in-a-Box:  Microsoft Desktop Virtualization for Smaller Businesses and UsesVDI-in-a-Box:  Microsoft Desktop Virtualization for Smaller Businesses and Uses
VDI-in-a-Box: Microsoft Desktop Virtualization for Smaller Businesses and Uses
Concentrated Technology
 
Download Microsoft Windows Server 2022 RDS
Download Microsoft Windows Server 2022 RDSDownload Microsoft Windows Server 2022 RDS
Download Microsoft Windows Server 2022 RDS
Direct Deals, LLC
 
AWS Webcast - Deploying Remote Desktop Gateway on the AWS Cloud
AWS Webcast - Deploying Remote Desktop Gateway on the AWS CloudAWS Webcast - Deploying Remote Desktop Gateway on the AWS Cloud
AWS Webcast - Deploying Remote Desktop Gateway on the AWS Cloud
Amazon Web Services
 
Drilldown Into RDS (TS) And RDV (VDI)
Drilldown Into RDS (TS) And RDV (VDI)Drilldown Into RDS (TS) And RDV (VDI)
Drilldown Into RDS (TS) And RDV (VDI)Amit Gatenyo
 
Connect Remotely Using Windows® 7 Direct Access
Connect Remotely Using Windows® 7 Direct AccessConnect Remotely Using Windows® 7 Direct Access
Connect Remotely Using Windows® 7 Direct Access
Microsoft TechNet
 
10135 a 04
10135 a 0410135 a 04
10135 a 04Bố Su
 
Rsa archer 6.9 platform installation and upgrade guide (3)
Rsa archer 6.9 platform installation and upgrade guide (3)Rsa archer 6.9 platform installation and upgrade guide (3)
Rsa archer 6.9 platform installation and upgrade guide (3)
AnkurGarg165647
 
Windows Server 2008 R2 Overview
Windows Server 2008 R2 OverviewWindows Server 2008 R2 Overview
Windows Server 2008 R2 Overview
Jaguaraci Silva
 
6421 b Module-05
6421 b Module-056421 b Module-05
6421 b Module-05
Bibekananada Jena
 
Creating Web Services with Zend Framework - Matthew Turland
Creating Web Services with Zend Framework - Matthew TurlandCreating Web Services with Zend Framework - Matthew Turland
Creating Web Services with Zend Framework - Matthew TurlandMatthew Turland
 
Embarcadero RAD server Launch Webinar
Embarcadero RAD server Launch WebinarEmbarcadero RAD server Launch Webinar
Embarcadero RAD server Launch Webinar
Embarcadero Technologies
 
Web375 course project web architecture plan for the de vry daily tribune new...
Web375 course project  web architecture plan for the de vry daily tribune new...Web375 course project  web architecture plan for the de vry daily tribune new...
Web375 course project web architecture plan for the de vry daily tribune new...
bestwriter
 
What is Remote Desktop Services For Windows Server 2022
What is Remote Desktop Services For Windows Server 2022What is Remote Desktop Services For Windows Server 2022
What is Remote Desktop Services For Windows Server 2022
SoftwareDeals
 
Cloud Circle Talk - Enterprise Architecture, Cloud Computing and Integrations
Cloud Circle Talk - Enterprise Architecture, Cloud Computing and IntegrationsCloud Circle Talk - Enterprise Architecture, Cloud Computing and Integrations
Cloud Circle Talk - Enterprise Architecture, Cloud Computing and Integrationspaulfallon
 
Introduction to Microsoft R
Introduction to Microsoft RIntroduction to Microsoft R
Introduction to Microsoft R
Cheah Eng Soon
 
AWS re:Invent 2016: Managing and Supporting the Windows Platform on AWS (GPSS...
AWS re:Invent 2016: Managing and Supporting the Windows Platform on AWS (GPSS...AWS re:Invent 2016: Managing and Supporting the Windows Platform on AWS (GPSS...
AWS re:Invent 2016: Managing and Supporting the Windows Platform on AWS (GPSS...
Amazon Web Services
 
Windows Server 2008 R2 Overview Jordan Remix
Windows Server 2008 R2 Overview Jordan RemixWindows Server 2008 R2 Overview Jordan Remix
Windows Server 2008 R2 Overview Jordan Remix
Jordan Remix
 
Win08 R2 It Pro Overview
Win08 R2 It Pro OverviewWin08 R2 It Pro Overview
Win08 R2 It Pro Overviewguest092b9a8
 

Similar to 10215 A 14 (20)

VDI-in-a-Box: Microsoft Desktop Virtualization for Smaller Businesses and Uses
VDI-in-a-Box:  Microsoft Desktop Virtualization for Smaller Businesses and UsesVDI-in-a-Box:  Microsoft Desktop Virtualization for Smaller Businesses and Uses
VDI-in-a-Box: Microsoft Desktop Virtualization for Smaller Businesses and Uses
 
Download Microsoft Windows Server 2022 RDS
Download Microsoft Windows Server 2022 RDSDownload Microsoft Windows Server 2022 RDS
Download Microsoft Windows Server 2022 RDS
 
AWS Webcast - Deploying Remote Desktop Gateway on the AWS Cloud
AWS Webcast - Deploying Remote Desktop Gateway on the AWS CloudAWS Webcast - Deploying Remote Desktop Gateway on the AWS Cloud
AWS Webcast - Deploying Remote Desktop Gateway on the AWS Cloud
 
Drilldown Into RDS (TS) And RDV (VDI)
Drilldown Into RDS (TS) And RDV (VDI)Drilldown Into RDS (TS) And RDV (VDI)
Drilldown Into RDS (TS) And RDV (VDI)
 
Vdi in-a-box
Vdi in-a-boxVdi in-a-box
Vdi in-a-box
 
Connect Remotely Using Windows® 7 Direct Access
Connect Remotely Using Windows® 7 Direct AccessConnect Remotely Using Windows® 7 Direct Access
Connect Remotely Using Windows® 7 Direct Access
 
10135 a 04
10135 a 0410135 a 04
10135 a 04
 
Rsa archer 6.9 platform installation and upgrade guide (3)
Rsa archer 6.9 platform installation and upgrade guide (3)Rsa archer 6.9 platform installation and upgrade guide (3)
Rsa archer 6.9 platform installation and upgrade guide (3)
 
Windows Server 2008 R2 Overview
Windows Server 2008 R2 OverviewWindows Server 2008 R2 Overview
Windows Server 2008 R2 Overview
 
6421 b Module-05
6421 b Module-056421 b Module-05
6421 b Module-05
 
Creating Web Services with Zend Framework - Matthew Turland
Creating Web Services with Zend Framework - Matthew TurlandCreating Web Services with Zend Framework - Matthew Turland
Creating Web Services with Zend Framework - Matthew Turland
 
Embarcadero RAD server Launch Webinar
Embarcadero RAD server Launch WebinarEmbarcadero RAD server Launch Webinar
Embarcadero RAD server Launch Webinar
 
Web375 course project web architecture plan for the de vry daily tribune new...
Web375 course project  web architecture plan for the de vry daily tribune new...Web375 course project  web architecture plan for the de vry daily tribune new...
Web375 course project web architecture plan for the de vry daily tribune new...
 
What is Remote Desktop Services For Windows Server 2022
What is Remote Desktop Services For Windows Server 2022What is Remote Desktop Services For Windows Server 2022
What is Remote Desktop Services For Windows Server 2022
 
Cloud Circle Talk - Enterprise Architecture, Cloud Computing and Integrations
Cloud Circle Talk - Enterprise Architecture, Cloud Computing and IntegrationsCloud Circle Talk - Enterprise Architecture, Cloud Computing and Integrations
Cloud Circle Talk - Enterprise Architecture, Cloud Computing and Integrations
 
Resume
ResumeResume
Resume
 
Introduction to Microsoft R
Introduction to Microsoft RIntroduction to Microsoft R
Introduction to Microsoft R
 
AWS re:Invent 2016: Managing and Supporting the Windows Platform on AWS (GPSS...
AWS re:Invent 2016: Managing and Supporting the Windows Platform on AWS (GPSS...AWS re:Invent 2016: Managing and Supporting the Windows Platform on AWS (GPSS...
AWS re:Invent 2016: Managing and Supporting the Windows Platform on AWS (GPSS...
 
Windows Server 2008 R2 Overview Jordan Remix
Windows Server 2008 R2 Overview Jordan RemixWindows Server 2008 R2 Overview Jordan Remix
Windows Server 2008 R2 Overview Jordan Remix
 
Win08 R2 It Pro Overview
Win08 R2 It Pro OverviewWin08 R2 It Pro Overview
Win08 R2 It Pro Overview
 

More from Juanchi_43

System Center 2012
System Center 2012System Center 2012
System Center 2012Juanchi_43
 
Configurando Private Cloud con System Center 2012
Configurando Private Cloud con System Center 2012Configurando Private Cloud con System Center 2012
Configurando Private Cloud con System Center 2012Juanchi_43
 
VDI Infraestructure
VDI InfraestructureVDI Infraestructure
VDI InfraestructureJuanchi_43
 
020811 Introduction To Virtualization 279337
020811 Introduction To Virtualization 279337020811 Introduction To Virtualization 279337
020811 Introduction To Virtualization 279337
Juanchi_43
 
Mof
MofMof
ITIL FOUNDATION
ITIL FOUNDATIONITIL FOUNDATION
ITIL FOUNDATIONJuanchi_43
 

More from Juanchi_43 (19)

System Center 2012
System Center 2012System Center 2012
System Center 2012
 
Configurando Private Cloud con System Center 2012
Configurando Private Cloud con System Center 2012Configurando Private Cloud con System Center 2012
Configurando Private Cloud con System Center 2012
 
10215 A 00
10215 A 0010215 A 00
10215 A 00
 
10215 A 01
10215 A 0110215 A 01
10215 A 01
 
10215 A 02
10215 A 0210215 A 02
10215 A 02
 
10215 A 03
10215 A 0310215 A 03
10215 A 03
 
10215 A 04
10215 A 0410215 A 04
10215 A 04
 
10215 A 05
10215 A 0510215 A 05
10215 A 05
 
10215 A 06
10215 A 0610215 A 06
10215 A 06
 
10215 A 07
10215 A 0710215 A 07
10215 A 07
 
10215 A 08
10215 A 0810215 A 08
10215 A 08
 
10215 A 09
10215 A 0910215 A 09
10215 A 09
 
10215 A 10
10215 A 1010215 A 10
10215 A 10
 
10215 A 11
10215 A 1110215 A 11
10215 A 11
 
10215 A 12
10215 A 1210215 A 12
10215 A 12
 
VDI Infraestructure
VDI InfraestructureVDI Infraestructure
VDI Infraestructure
 
020811 Introduction To Virtualization 279337
020811 Introduction To Virtualization 279337020811 Introduction To Virtualization 279337
020811 Introduction To Virtualization 279337
 
Mof
MofMof
Mof
 
ITIL FOUNDATION
ITIL FOUNDATIONITIL FOUNDATION
ITIL FOUNDATION
 

10215 A 14

  • 1. Module 14 Extending Remote Desktop Services Outside the Organization
  • 2.
  • 3.
  • 4. Internet Corporate LAN Business Partner/ Client Site Hotel Home External Firewall Internal Firewall Remote Desktop Services Remote Desktop Services Remote Desktop– enabled host Network Policy Server Active Directory How RD Gateway Works Tunnels RDP over HTTPs Strips off HTTPs Passes RDP traffic to RDS
  • 5.
  • 6.
  • 7.
  • 8.  
  • 9. Securing the RD Gateway Configurable idle and session timeouts Background session authentication and authorization Pluggable authentication and authorization System and logon messages Network Access Protection (NAP) remediation Device redirection enforcement
  • 10.
  • 11.
  • 12.  
  • 13.
  • 14.
  • 15.
  • 16.
  • 17.
  • 19.
  • 20.
  • 21.
  • 22.
  • 23.
  • 24.
  • 25.

Editor's Notes

  1. Module 14: Extending Remote Desktop Services Outside the Organization Course 10215A Presentation: 60 minutes Lab: 60 minutes This module helps students extend Remote Desktop Services outside the organization. After completing this module, students will be able to: Configure the Remote Desktop Gateway Configure Remote Desktop Web Access Required materials To teach this module, you need the Microsoft Office PowerPoint® file 10215A_14.ppt. Important It is recommended that you use PowerPoint 2002 or a later version to display the slides for this course. If you use PowerPoint Viewer or an earlier version of PowerPoint, all the features of the slides might not be displayed correctly. Preparation tasks To prepare for this module: Read all of the materials for this module. Practice performing the demonstrations and the lab exercises. Work through the Module Review and Takeaways section and determine how you will use this section to reinforce student learning and promote knowledge transfer to on-the-job performance. Make sure that students are aware that there are additional online resources for the module on the Course CD.
  2. Briefly present module content. Since RDS is new with Windows Server 2008 R2, ask the students if they have had any experience with previous versions of Terminal Services . Module 14: Extending Remote Desktop Services Outside the Organization Course 10215A
  3. Introduce the lesson content. Emphasize that this is an overview of Remote Desktop Services Module 14: Extending Remote Desktop Services Outside the Organization Course 10215A
  4. Explain the RDP/HTTPS flow when an external user is connecting to RDS through RD Gateway. Explain how and why RDP traffic is encapsulated to HTTPS and the prerequisites for encapsulation, such as defining digital certificate on the RD Gateway, RD CAP, and RD RAP policies. Review the benefits of RD Gateway. Students should be able to explain that RDP traffic (port 3389) is usually blocked on the firewall. Using RD Gateway, you can use HTTPS (port 443), which is allowed through a firewall. Point out that RDP traffic is encapsulated into HTTPS only to RD Gateway. RDS traffic is transmitted from RD Gateway to RDS host. Mention that RD Gateway role service is installed on the server in DMZ. Question : Does RD Gateway provide full end-to-end protection of RDP traffic? Answer : No; RD Gateway protects RDP traffic between RD client and RD Gateway. From RD Gateway to RDS host, the traffic is transmitted through RDP. Hence, RD Gateway does not provide additional protection there. You should be aware that RDP uses encryption, and from RD Gateway to RDS host, is a local network; not a public network like Internet. Course 10159A Module 6: Configuring Remote Desktop Services and Virtual Desktop Infrastructure in Windows Server 2008 R2
  5. If students are familiar with the RD Gateway role service, make the session more interactive by asking for their experience with RD Gateway. Question: In which situations would you use RD Gateway? Answer: You can use RD Gateway if you need to provide remote users with access to RDS hosts over the Internet. Local users can access RDS hosts directly, but remote users need to establish a connection to the local network. Earlier, remote users needed to first establish a VPN connection to access RDS hosts, but with RD Gateway, they can access internal RDS hosts without establishing a VPN connection. Module 14: Extending Remote Desktop Services Outside the Organization Course 10215A
  6. Cover the requirements needed for RD Gateway: Permissions – Local Admins group Certificates – SSL Certificate required Domain Membership – RD Gateway must be domain member of require users in CAP to be domain members IIS Module 14: Extending Remote Desktop Services Outside the Organization Course 10215A
  7. On LON-SVR1, install the Remote Desktop Services server role by using the Server Manager console with the following information: Role Services: Remote Desktop Session Host, Remote Desktop Connection Broker, Remote Desktop Gateway , and Remote Desktop Web Access Authentication Method for Remote Desktop Session Host: Do not require Network Level Authentication Licensing Mode: Configure later Server Authentication Certificate for SSL Encryption: LON-SVR1.Contoso On the Start menu of LON-SVR1, point to Administrative Tools , and then click Server Manager . In the tree pane of the Server Manager console, click Roles . In the Role Summary area of the Roles result pane, click Add Roles . On the Before You Begin page of the Add Roles Wizard, click Next . On the Select Server Roles page, under Roles , select the Remote Desktop Services check box, and then click Next . On the Remote Desktop Services page, click Next . On the Select Role Services page, under Role services , select the Remote Desktop Session Host, Remote Desktop Connection Broker , and Remote Desktop Gateway check boxes. On the Select Role Services page, under Role services , select the Remote Desktop Web Access check box. On the Select Role Services page, click Next . On the Uninstall and Reinstall Applications for Compatibility page, click Next . On the Specify Authentication Method for Remote Desktop Session Host page, click Do not require Network Level Authentication , and then click Next . On the Specify Licensing Mode page, ensure that the Configure later option is selected, and then click Next . On the Select User Groups Allowed Access To This RD Session Host Server page, click Next . On the Configure Client Experience page, click Next . On the Start menu of LON-SVR1, click Run . In the Open box of the Run dialog box, type mmc , and then click OK . On the File menu of the Console1- [Console Root] console, click Add/Remove Snap-in . In the Available snap-ins area of the Add or Remove Snap-ins dialog box, in the Snap-in list, click Certificates , and then click Add . Module 14: Extending Remote Desktop Services Outside the Organization Course 10215A
  8. In the Certificates snap-in wizard, click Computer account , click Next . In the Select Computer wizard, click Finish . In the Add or Remove Snap-ins dialog box, click OK . In the tree pane of the Console1- [Console Root] console, expand Certificates (Local Computer) , expand Personal , and then click Certificates . On the Action menu, point to All Tasks , and then click Request New Certificate . On the Before You Begin page of the Certificate Enrollment wizard, click Next . On the Select Certificate Enrollment Policy page, click Next . On the Request Certificates page, select the DirectAccess check box, and then click More information is required to enroll for this certificate . Click here to configure settings. In the Subject Name area of the Certificate Properties dialog box, in Type box, click Common name , in the Value box, type external.contoso.com , and then click Add . In the Alternative name area, in the Type box, click DNS , in the Value box type external.contoso.com , click Add , and then click OK . On the Request Certificates page, click Enroll . On the Certificate Installation Results page, click Finish . Note : Verify that certificate for external.contoso.com is listed in the Certificates result pane. In the Console1 - [Console Root\\Certificates (Local Computer)\\Personal\\Certificates] console, click the Close button. In the Microsoft Management Console message box, click No . Module 14: Extending Remote Desktop Services Outside the Organization Course 10215A
  9. Cover the new security features of RD Gateway in Windows Server 2008 R2. Enhancements are security related and require RDC 7.0. This connection client is included in Windows 7 and Windows Server 2008 R2, and it is available as a download for Windows Vista SP1 and Windows XP SP3. Cover the improvements in RD Gateway and why they are important. Ask for input on new functionalities and provide scenarios that can benefit from the new RD Gateway functionalities. Question: What should you do to take advantage of the RD Gateway functionality introduced in Windows Server 2008 R2? Answer: You must use RDC 7.0 to take advantage of the new RD Gateway functionality. Module 14: Extending Remote Desktop Services Outside the Organization Course 10215A
  10. Discuss the purpose and creation of: Connection Authorization Policies Resource Authorization Policies Discuss how RAPs can be used to control access to internal resources. Module 14: Extending Remote Desktop Services Outside the Organization Course 10215A
  11. On LON-SVR1, create a Connection Authorization Policy (CAP) to restrict the users from accessing the RD Gateway Server with the following information: Type a name for the RD CAP: Authorized Remote Users User group membership: RD Users On LON-SVR1, in the tree pane of the Server Manager console, under RD Gateway Manager , expand LON-SVR1 (Local) , expand Policies , and then click Connection Authorization Policies . In the Actions pane, click Create New Policy , and then click Wizard . On the Create Authorization Policies for RD Gateway page of the Create New Authorization Policies Wizard, click Next In the Type a name for the RD CAP box of the Create an RD CAP page, type Authorized Remote Users , and then click Next . In the User group membership (required) area of the Select Requirements page, click Add Group In the Enter the object names to select (examples) box of the Select Groups dialog box, type RD Users , and then click OK . On the Select Requirements page, click Next . On the Enable or Disable Device Redirection page, click Next . On the Set Session Timeouts page, click Next . On the RD CAP Settings Summary page, click Finish . On the Confirm Creation of Authorization Policies page, click Close . On LON-SVR1, create a Resource Authorization Policy to control the connection between the internal resources and the Remote Desktop Gateway with the following information: Type a name for the RD RAP: Authorized Target Computers User Groups: RD Users Network Resources: RD Web Computers On LON-SVR1 server, in the tree pane of the Server Manager console, under Policies , click Resource Authorization Policies . In the Actions pane, click Create New Policy , and then click Wizard . On the Create Authorization Policies for RD Gateway page of the Create New Authorization Policies Wizard, click Next . In the Type a name for the RD RAP box of the Create an RD RAP page, type Authorized Target Computers , and then click Next . Module 14: Extending Remote Desktop Services Outside the Organization Course 10215A
  12. On the Select User Groups page, click Add Group . In the Enter the object names to select (examples) box of the Select Groups dialog box, type RD Users , and then click OK . On the Select User Groups page, click Next . On the Select Network Resources page, ensure that the Select an Active Directory Domain Services network resource group option is selected, and then click Browse . In the Enter the object names to select (examples) box of the Select Group dialog box, type RD Web Computers , and then click OK . On the Select Network Resources page, click Next . On the Select Allowed TCP Ports page, click Next . On the RD RAP Settings Summary page, click Finish On the Confirm Creation of Authorization Policies page, click Close . In the Server Manager console, click the Close button. Module 14: Extending Remote Desktop Services Outside the Organization Course 10215A
  13. Module 14: Extending Remote Desktop Services Outside the Organization Course 10215A
  14. Module 14: Extending Remote Desktop Services Outside the Organization Course 10215A
  15. Introduce the lesson content. Emphasize that this is an overview of Remote Desktop Services Module 14: Extending Remote Desktop Services Outside the Organization Course 10215A
  16. Cover how a user might use RD Web access for remote users or access a Remote Desktop Web Access session. Explain process that happens when a user accesses a RemoteApp program. Module 14: Extending Remote Desktop Services Outside the Organization Course 10215A
  17. Cover the roles required, the clients that can access a RD Web Access. Module 14: Extending Remote Desktop Services Outside the Organization Course 10215A
  18. Module 14: Extending Remote Desktop Services Outside the Organization Course 10215A
  19. Explain how the published RemoteApp applications, to which we subscribe through feed, are available on the Start menu. Explain that RemoteApp and Remote Desktops are available only on Window 7 and Windows Server 2008 R2. Clients using older versions can access the same applications through RD Web Access or shortcuts, but they will not be integrated on the Start menu. Question: When would you use RDS Web Access to access RemoteApp applications, instead of RemoteApp and Desktop Connection? Answer : RemoteApp and Desktop Connection requires Windows 7 as a client. If your client is running an older operating system, you cannot use RemoteApp and Desktop Connection, but you can still access the RDS Web portal and run RemoteApps from there. The RD Connection Broker will ensure that the same RemoteApps are available through both interfaces. Module 14: Extending Remote Desktop Services Outside the Organization Course 10215A
  20. Module 14: Extending Remote Desktop Services Outside the Organization Course 10215A
  21. In this lab, students will plan the implementation of Remote Desktop Services. Exercise 1 In this exercise, students will install the Remote Desktop Gateway . Exercise 2 In this exercise, students will install Remote Desktop Web Access Exercise 3 In this exercise, students will configure remote Desktop Web Access Exercise 4 In this exercise, students will integrate RemoteApp and Desktop Connection with Remote Desktop Web Access Before the students begin the lab, read the scenario associated with each exercise to the class. This will reinforce the broad issue that the students are troubleshooting and will help to facilitate the lab discussion at the end of the module. Remind the students to complete the discussion questions after the last lab exercise. Note: The lab exercise answer keys are provided on the Course Companion CD. To access the answer key, click the link located at the bottom of the relevant lab exercise page. Module 14: Extending Remote Desktop Services Outside the Organization Course 10215A
  22. Module 14: Extending Remote Desktop Services Outside the Organization Course 10215A
  23. Use the questions on the slide to guide the debriefing after students have completed the lab exercises. Question 1 : How Contoso will benefit from deploying Remote Desktop Services ? Answer: The period of 120 days is the grace period to install RD Licensing, after installing RDS Session Host. You probably did not install the RD Licensing role service in the testing environment, and when the grace period expired, you are no longer able to connect to the RDS Session Host server Question 2: How will you restrict the user from viewing the icon for RemoteApp program? Answer: Virtual Desktop Infrastructure types are personal virtual desktops and pooled virtual desktops. When using personal virtual desktops, each user has a unique virtual machine. When using pooled virtual desktops, user can connect to any virtual machine in a pool Question 3: How will the deployment of Remote Desktop Connection Virtualization benefit Contoso Ltd Answer: RemoteApp and Desktop Connection will integrate published RemoteApps and Desktop Connections with the Start menu of Windows 7 computers. When using RD Web Access, you must open the Web page and run RemoteApps from there Module 14: Extending Remote Desktop Services Outside the Organization Course 10215A
  24. Review Questions 1 You installed RDS in a testing environment. After 120 days, you are no longer able to connect to the RDS server. What is the most probable reason for this? Answer : The period of 120 days is the grace period to install RD Licensing, after installing RDS Session Host. You probably did not install the RD Licensing role service in the testing environment, and when the grace period expired, you are no longer able to connect to the RDS Session Host server. 2. Why must you have a certificate for the Remote Desktop Gateway server? Answer : The certificate is used to encrypt communications between Remote Desktop clients and RD Gateway servers over the Internet. 3. How is the use of RemoteApp and Desktop Connection different from simply accessing RemoteApp from RD Web Access? Answer : RemoteApp and Desktop Connection will integrate published RemoteApps and Desktop Connections with the Start menu of Windows 7 computers. When using RD Web Access, you must open the Web page and run RemoteApps from there. Module 14: Extending Remote Desktop Services Outside the Organization Course 10215A
  25. Module x: Title Course xxxxy Remind students to complete the course evaluation.