Updated on 2023-06-12 GMT+08:00

Modifying the Group Policy

Prerequisites

You have obtained the account and its password of the server administrator.

Starting Local Group Policy Editor

Open the command line interface and enter gpedit.msc to open Local Group Policy Editor.

Selecting the Specified Remote Desktop License Servers

  1. Choose Computer Configuration > Administrative Templates > Windows Components > Remote Desktop Services > Remote Desktop Session Host > Licensing.
  2. Double-click Use the specified Remote Desktop license servers.
  3. In the displayed dialog box, select the Enabled option.
  4. Click OK.

Hiding Notifications About RD Licensing Problems that Affect the RD Session Host Server

  1. Choose Computer Configuration > Administrative Templates > Windows Components > Remote Desktop Services > Remote Desktop Session Host > Licensing.
  2. Double-click Hiding notifications about RD Licensing problems that affect the RD Session Host Server.
  3. Select the Enable option.
  4. Then, click OK.

Setting the Remote Desktop Licensing Mode

  1. Choose Computer Configuration > Administrative Templates > Windows Components > Remote Desktop Services > Remote Desktop Session Host > Licensing.
  2. Double-click Set the Remote Desktop licensing mode.
  3. Select Enabled to enable the remote desktop licensing mode.

    In the displayed window, select the Enabled option. In the Options area, under Specify the licensing mode for the RD Session Host server, select Per User from the drop-down list.

  4. Then, click OK.

Limit number of connections

  1. Choose Computer Configuration > Administrative Templates > Windows Components > Remote Desktop Services > Remote Desktop Session Host > Connections.
  2. Double-click Limit Number of Connections.
  3. Select the Enabled option.

    Set RD Maximum Connections allowed to 999999.

  4. Then, click OK.

Allowing Remote Start of Unlisted Programs

  1. Choose Computer Configuration > Administrative Templates > Windows Components > Remote Desktop Services > Remote Desktop Session Host > Connections.
  2. Double-click Allow remote start of unlisted programs.
  3. In the displayed dialog box, select the Enabled option.
  4. Then, click OK.

Restrict Remote Desktop Services users to a single Remote Desktop Services session

  1. Choose Computer Configuration > Administrative Templates > Windows Components > Remote Desktop Services > Remote Desktop Session Host > Connections.
  2. Double-click Restrict Remote Desktop Services users to a single Remote Desktop Services session.
  3. In the displayed window, select the Disabled option.
  4. Then, click OK.

Setting Time Limit for Disconnected Sessions

  1. Choose Computer Configuration > Administrative Templates > Windows Components > Remote Desktop Services > Remote Desktop Session Host > Session Time Limits.
  2. Double-click Set time limit for disconnected sessions.
  3. In the displayed dialog box, select the Enabled option.

    Set End a disconnected session to 1 minute.

  4. Then, click OK.

Disabling Automatic Root Certificates Update (CBH V3.3.26.0 or Later)

If your CBH system is earlier than V3.3.26.0, skip this operation. If your CBH system is upgrade to V3.3.26.0 or later, perform the following steps.

  1. Choose Administrative Templates > System > Internet Communication Management.
  2. Double-click Turn off Automatic Root Certificates Update.
  3. Select Enabled.
  4. Then, click OK.

Configuring Certificate Path Validation Settings (CBH V3.3.26.0 or Later)

If your CBH system is earlier than V3.3.26.0, skip this operation. If your CBH system is upgrade to V3.3.26.0 or later, perform the following steps.

  1. Choose Windows Settings > Security Settings > Public Key Policies.
  2. Double-click Certificate Path Validation Settings.
  3. Click the Network Retrieval tab.
  4. Clear the Automatically update certificates in the Microsoft Root Certificate Program (recommended) check box.

    Set Default URL retrieval timeout (in seconds) to 1.

  5. Then, click OK.

Refreshing the Local Group Policy

  1. Close the Local Group Policy Editor window.
  2. Open the Run box and run the gpupdate /force command to refresh the local policy.
  3. The application publish server has been deployed. To test its function, add this server and applications on it to the CBH system.