Already a NinjaOne customer? Log in to view more guides and the latest updates.

Access Devices via Microsoft Cloud RDP

Topic

This article explains how to use the Cloud Remote Desktop Protocol (RDP) in NinjaOne. 

Environment

NinjaOne Endpoint Management

Description

NinjaOne's Cloud RDP feature allows users to remotely access devices using Microsoft's Remote Desktop Protocol technology.

For more information about basic architecture and main features, refer to Remote Desktop Protocol - Win32 apps | Microsoft Learn (external). 

Select a category from the following options to learn how Cloud RDP works in NinjaOne: 

Rendezvous Points Allowlist Requirements

In addition to the following allowlist requirements, you must ensure that the RDP application is installed on the computers attempting to establish a connection. 
DescriptionScopeURL
Cloud RDP Rendezvous PointsAll customershttps://agent-tun-apse2-0.ninjarmm.com
Cloud RDP Rendezvous PointsAll customershttps://agent-tun-ca-1.ninjarmm.com
Cloud RDP Rendezvous PointsAll customershttps://agent-tun-euc-0.ninjarmm.com
Cloud RDP Rendezvous PointsAll customershttps://agent-tun-euw2-0.ninjarmm.com
Cloud RDP Rendezvous PointsAll customershttps://agent-tun-use2-0.ninjarmm.com
Cloud RDP Rendezvous PointsAll customershttps://agent-tun-use2-0.us2.ninjarmm.com
Cloud RDP Rendezvous PointsAll customershttps://agent-tun-use2-1.ninjarmm.com
Cloud RDP Rendezvous PointsAll customershttps://agent-tun-usw-0.ninjarmm.com
Cloud RDP Rendezvous PointsAll customershttps://agent-tun-usw-1.ninjarmm.com
Cloud RDP Rendezvous PointsAll customershttps://agent-tun-usw-2.ninjarmm.com
Cloud RDP Rendezvous PointsAll customershttps://agent-tun-usw-3.ninjarmm.com
Cloud RDP Rendezvous PointsAll customershttps://tun-apse2-0.ninjarmm.com
Cloud RDP Rendezvous PointsAll customershttps://tun-ca-central-1.ninjarmm.com
Cloud RDP Rendezvous PointsAll customershttps://tun-eu-central-0.ninjarmm.com
Cloud RDP Rendezvous PointsAll customershttps://tun-uk-0.ninjarmm.com
Cloud RDP Rendezvous PointsAll customershttps://tun-use2-0.us2.ninjarmm.com
Cloud RDP Rendezvous PointsAll customershttps://tun-useast-0.ninjarmm.com
Cloud RDP Rendezvous PointsAll customershttps://tun-useast-1.ninjarmm.com
Cloud RDP Rendezvous PointsAll customershttps://tun-uswest-0.ninjarmm.com
Cloud RDP Rendezvous PointsAll customershttps://tun-uswest-1.ninjarmm.com
Cloud RDP Rendezvous PointsAll customershttps://tun-uswest-2.ninjarmm.com
Cloud RDP Rendezvous PointsAll customershttps://tun-uswest-3.ninjarmm.com

Configure Permissions for Technicians to Access Devices via Cloud RDP 

You must enable the following permissions for technicians to use Cloud RDP: 

  • Devices Remote AccessRemote Desktop

tech_devices_remote_desktop.png
Figure 1: Remote access permission for technicians

  • Devices Remote Tools → Command Line

tech_devices_remote_command line.png
Figure 2: Remote tools permission for technicians

To learn more about enabling technician permissions, refer to User Roles and Permissions.

Initiate the Remote Connection and Configure RDP

To initiate the remote session, perform the following steps:

  1. Access the device dashboard in NinjaOne for the device you want to connect with.
  2. Click the remote desktop connection icon at the top of the page. 

RDP icon.png
Figure 3: Remote desktop connection icon on the device dashboard in NinjaOne

  1. When the Remote Desktop modal displays, use the following table to customize your connection, and then click Connect:
    FieldDescription
    Credential

    This setting allows you to choose whether to pass credentials to the device for RDP access. You have two options:

    • None: No credentials are passed for the session.
    • RDP access credential: The assigned default credentials for RDP access are passed for the session. Default credentials are assigned from the organization settings, but can be overridden for a specific device under its Settings tab. For more information, refer to our documentation about Credential Exchange.

    The Administrative session checkbox allows you to log in with administrative credentials, which grants elevated privileges to perform system-level tasks.

    GatewayThis setting allows you to choose which gateway region to use to connect. "Auto" is selected by default, but you can also specify one of the five available gateway regions.
    Connection

    These settings allow you to specify numerous options about your RDP connection. There are four pre-canned setting configurations: Custom, Performance, Standard, and Multimedia. Selecting any option other than Custom automatically configures the recommended settings for that type of connection. You always have the option to customize the settings beyond the automated recommendations.

    The Connection configuration settings are divided into the General, Local Resources, and Experience tabs. Click each of these tabs to see additional customization options. 

    Provision

    This setting indicates whether or not the device is provisioned for RDP access. If it is, you will see a message that says, "Machine is ready to accept RDP connection." If you do not select the option to "Configure RDP automatically," NinjaOne does not alter the device's configured settings.

    If the device is not currently provisioned for RDP access, you will see a message that says "Provision RDP access" with a checkbox. Enabling this option and clicking Connect provisions the device to allow RDP access. Refer to the following section of this article for more information. 

RDP Provisioning Information

When NinjaOne provisions a device for RDP access, two changes are made on the device:

  1. The service Remote Desktop Services starts.
  2. The box for the remote access setting “Allow connections only from computers running Remote Desktop with Network Level Authentication” is unchecked to allow for remote access. You can find this setting locally on the device by navigating to Control Panel → System and Security → System → Remote Settings.
RDP system properties.png

Figure 4: RDP provisioning

Once you provision a device for RDP access, RDP remains enabled after you end your session. If you wish to de-provision a device for RDP access, you need to do so locally on the machine.

Additional Resources

For a list of frequently asked questions regarding Cloud RDP, refer to Remote Desktop Protocol: Frequently Asked Questions.

FAQ

Next Steps