Service account
Service account used to read sessions on each bench (stored encrypted on this server).
RDP firewall guard (legacy)
Legacy hard-lock using remote netsh -r from this server.
Once you install the bench agent below, this is superseded automatically.
Bench Agent recommended
A PowerShell agent on each bench locally manages the
"Remote Desktop Users" group and a local Windows Firewall
rule on TCP 3389. When locked, only the lock owner's PC IP can reach
3389 on the bench — this blocks even local Administrators from
RDPing directly.
- Set
RDD_BENCH_AGENT_TOKEN=<long-random-string> in
%LOCALAPPDATA%\RemoteDesktopDashboard\admin.env and
restart the dashboard.
- Make sure the service account above is a local admin
on every bench.
- Type your Admin PIN, then click Push install
next to a bench below.
On the bench, the one-liner just downloads these two files from the dashboard: