Configuring remote desktop access
When you onboard a cloud account, PingOne Privilege automatically discovers all remote desktop protocol (RDP) instances, which are then listed as targets under Access Management > Targets.
To enable passwordless access to these targets, you must first configure an access method. The configuration depends on whether the target machine is joined to an Active Directory (AD) domain.
Configuring access for non-domain-joined machines
For standalone Windows servers, use the Local User mode to store and manage a local administrator account:
-
In the PingOne Privilege admin console, go to Settings > AD Domain Controllers .
-
Click Create New.
-
Enter a Name for this configuration (for example,
Standalone Web Servers). -
Enable Local User Mode.
-
In the Username and Password fields, enter the credentials for a local administrator account on the target machine. These credentials will be stored securely in the PingOne Privilege vault.
-
(Optional) Enable the Rotate Passwords feature to have PingOne Privilege periodically change this password on the target machine.
-
Configure the auto-approval schedule, specifying the times during which user access requests can be approved automatically.
-
Click Save.
Configuring access for domain-joined machines
For Windows servers joined to an Active Directory domain, you create a configuration that stores domain credentials:
-
In the PingOne Privilege admin console, go to Settings > AD Domain Controllers.
-
Click Create New.
-
Enter a Name for this configuration (for example,
Corporate AD Domain). -
Disable Local User Mode.
-
Enter the credentials for a privileged Domain Admin account. This account is used to manage other user passwords within the domain.
-
For each standard domain user account you want to manage, click Add User and enter their
UsernameandPassword. -
Select the Cloud Type (AWS, GCP, or Azure).
This domain controller configuration becomes the default for RDP targets in that cloud provider.
-
(Optional) Enable the Rotate Passwords feature.
-
Configure the auto-approval schedule.
-
Click Save.
Binding an RDP instance to a domain controller configuration
After creating a configuration, bind each RDP target to it:
-
In the PingOne Privilege admin console, go to Access Management > Targets.
-
Find the target RDP instance and click More Info.
-
In the AD Domain Controller list, select the appropriate configuration you created earlier.
-
Enable Managed for the RDP instance
-
Click Update.