Limit number of sessions per user or group
hi.
i´m working on project need allow multiple sessions ( done ), limit number of concurrent sessions on rds farm...
at moment, we're using 1 rds server ( r&d stage ), in future, there'll farm rds connection broker , many rds session hosts.
i've come conclusion best approach create custom gpo, apply rds session hosts, , use vbscript or powershell block logon when number of sessions reaches defined limit.
i'd achieve group based ( groups: 1rdssession, 2rdssession , on ... ) user logon limit. have ideas in mind single server, , possible solution farm.
but before spending time on "adventure" ( kind of challenge :) ), i'd know if windows2012 provides means doing kind of control.
i know there's per server sessions limit, doesn't solve problem.
thanks in advance!
hi,
i recommend go team and consider making adjustments to your model instead use unique accounts each person , (preferably) restrict each account single session. if want layer maximum concurrent use per company limitation on top.
alternatively can make generic accounts work, however, need address issues described below:
licensing
in case need license under services provider license agreement (spla). under spla, each unique human authorized connect during month needs have a rds subscriber access license (sal). in addition, if a person accesses environment more than one physical device concurrently, they need have enough sals total number of concurrent connections.
whether or not person connects , uses software during month irrelevant spla rds licensing purposes. example, authorize ten unique people connect, 3 of them connect during month. when file report microsoft report ten rds sals, since number of people authorized during previous month. i'm assuming here simplicity none of 3 people connected more 1 session @ time.
having multiple people share same logon not reduce number of rds sals required.
how plan on tracking unique people authorized use software each month? going have fee for concurrent user + fee each unique person? if not, happens if 1 of customers has multiple people , wind owing microsoft more in rds sal fees collecting concurrent use? i'm asking these questions make sure think through inherent conflicts of licensing model versus spla address them front.
if focus solely on concurrent use, without tracking specific people rds sals assigned each month, setting potential red flag auditor. it is have unbroken process/documentation/etc. chain show auditor covers the entire spectrum with elements that map to specific requirements in service provider use rights (spur) , spla documents.
in summary want able substantiate numbers you report , using generic ad accounts makes more challenging (though not impossible).
security
if multiple people each company use same account log on servers, there no security between sessions/people using same account.
even if implement own authentication mechanism (common), aware there still not hard security boundary between each person's screen/data. one example, if 2 people same company logged on, 1 of users access other person's session/data (accidently or purposefully) since same user far operating system concerned.
provided understand issues involved can take steps mitigate potential security risks as they apply application, however, additional work , can challenging if not impossible right, depending.
user data , settings
if using generic accounts have ability used concurrently need take consideration when designing architecture profiles and/or roaming settings and/or roaming data. if considering user profile disks not work. traditional roaming profiles may problematic many other roaming strategies.
your design needs account data @ rest in-memory state data while logged on. one example, 2 people log on same server @ same time, can inadvertently modify each other's settings causing unexpected behavior. keep in mind isn't application need concerned in regard--windows may have issue in cases.
load balancing , reconnection
you need decide how handle load balancing , reconnection in case multiple concurrent connections same user accounts each collection is permitted. 1 example, if there brief network issue , users disconnected, reconnected session , not 1 belonging person in every scenario?
----------
now, question regarding limiting number of sessions. there many different ways handle it. example, basic technique have service on broker keeping track of users along current concurrency count , max limit. when user logs on have small script/program make call (canilogon(username, rdshservername, sessionid)) service , depending on response, either display error few seconds , log them off or allow logon.
-tp
Windows Server > Remote Desktop Services (Terminal Services)
Comments
Post a Comment