SOLVED
Home

RDP gateway to secure rdp access to vm

%3CLINGO-SUB%20id%3D%22lingo-sub-281265%22%20slang%3D%22en-US%22%3ERDP%20gateway%20to%20secure%20rdp%20access%20to%20vm%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-281265%22%20slang%3D%22en-US%22%3E%3CP%3EHello%2C%3C%2FP%3E%3CP%3Ecan%20I%20set%20up%20RDP%20gateway%20as%20Azure%20Service%3F%3C%2FP%3E%3CP%3EI%20like%20to%20secure%20my%20lab%20vm%20with%20rdp%20access.%20VPN%20is%20not%20so%20good%2C%20because%20I%20access%20the%20vms%20from%20different%20location%20and%20laptops.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ERegards%3C%2FP%3E%3CP%3EStefan%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-281265%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3ECompute%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EHands-on-Labs%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EVirtual%20Machine%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-285509%22%20slang%3D%22en-US%22%3ERe%3A%20RDP%20gateway%20to%20secure%20rdp%20access%20to%20vm%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-285509%22%20slang%3D%22en-US%22%3E%3CP%3EHi%20Stephan%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EA%20good%20starting%20point%20is%20the%20following%20series%20of%20blogs%20by%20%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F106532%22%20target%3D%22_blank%22%3E%40Arjan%20Vroege%3C%2FA%3E%3A%3CBR%20%2F%3E%3CBR%20%2F%3E%3CA%20href%3D%22https%3A%2F%2Fwww.vroege.biz%2F%3Fp%3D2462%22%20target%3D%22_blank%22%20rel%3D%22nofollow%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fwww.vroege.biz%2F%3Fp%3D2462%3C%2FA%3E%3C%2FP%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Fwww.vroege.biz%2F%3Fp%3D2563%22%20target%3D%22_blank%22%20rel%3D%22nofollow%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fwww.vroege.biz%2F%3Fp%3D2563%3C%2FA%3E%3CBR%20%2F%3E%3CA%20href%3D%22https%3A%2F%2Fwww.vroege.biz%2F%3Fp%3D2647%22%20target%3D%22_blank%22%20rel%3D%22nofollow%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fwww.vroege.biz%2F%3Fp%3D2647%3C%2FA%3E%3CBR%20%2F%3E%3CBR%20%2F%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-281581%22%20slang%3D%22en-US%22%3ERe%3A%20RDP%20gateway%20to%20secure%20rdp%20access%20to%20vm%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-281581%22%20slang%3D%22en-US%22%3E%3CP%3EThe%20AD%20Application%20Proxy%20acts%20as%20a%20hosted%20revers%20proxy%20service%20in%20Azure.%26nbsp%3B%20The%20downside%20is%20it%20requires%20Azure%20AD%2C%20so%20if%20you%20don%E2%80%99t%20have%20that%20it%20may%20not%20work%20for%20you.%26nbsp%3B%20I%20published%20the%20RD%20Web%20page%20through%20the%20Proxy%20to%20avoid%20opening%20ports%20on%20the%20firewall.%26nbsp%3B%20Users%20hit%20the%20proxy%20URL%20prior%20to%20the%20RDWeb%20page%2C%20forcing%20them%20to%20log%20in.%3C%2FP%3E%3CP%3EIf%20you%20are%20looking%20for%20one-off%20VM%20access%2C%20Just%20in%20Time%20is%20probably%20the%20better%20bet.%26nbsp%3B%20Microsoft%20has%20another%20product%20Remote%20Desktop%20Modern%20Infrastructure%20that%20will%20provide%20most%20of%20the%20RDP%20infrastructure%20as%20a%20service.%26nbsp%3B%20That%E2%80%99s%20still%20in%20private%20preview.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-281575%22%20slang%3D%22en-US%22%3ERe%3A%20RDP%20gateway%20to%20secure%20rdp%20access%20to%20vm%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-281575%22%20slang%3D%22en-US%22%3E%3CP%3EHallo%20Travis%2C%20thanks%20for%20your%20response.%20Can%20you%20please%20give%20me%20more%20details.%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ESince%20yesterday%20I%20use%20Just%20in%20time%20access%20for%20secure%20my%20azure%20vm.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-281570%22%20slang%3D%22en-US%22%3ERe%3A%20RDP%20gateway%20to%20secure%20rdp%20access%20to%20vm%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-281570%22%20slang%3D%22en-US%22%3E%3CP%3EI%20was%20able%20to%20host%20the%20RDWeb%20page%20behind%20an%20AD%20Application%20Proxy%20and%20use%20Azure%20AD%20authentication%20before%26nbsp%3Bhitting%20the%20web%20page.%26nbsp%3B%20You%20can%20use%20AD%20App%20Proxy%20with%20the%20RD%20Gateway%20URL%20but%20not%20with%20authentication%2C%20it%20just%20acts%20as%20a%20reverse%20proxy.%3C%2FP%3E%3C%2FLINGO-BODY%3E
Highlighted
Frequent Contributor

Hello,

can I set up RDP gateway as Azure Service?

I like to secure my lab vm with rdp access. VPN is not so good, because I access the vms from different location and laptops.

 

Regards

Stefan

4 Replies
Solution

I was able to host the RDWeb page behind an AD Application Proxy and use Azure AD authentication before hitting the web page.  You can use AD App Proxy with the RD Gateway URL but not with authentication, it just acts as a reverse proxy.

Hallo Travis, thanks for your response. Can you please give me more details. 

 

Since yesterday I use Just in time access for secure my azure vm.

The AD Application Proxy acts as a hosted revers proxy service in Azure.  The downside is it requires Azure AD, so if you don’t have that it may not work for you.  I published the RD Web page through the Proxy to avoid opening ports on the firewall.  Users hit the proxy URL prior to the RDWeb page, forcing them to log in.

If you are looking for one-off VM access, Just in Time is probably the better bet.  Microsoft has another product Remote Desktop Modern Infrastructure that will provide most of the RDP infrastructure as a service.  That’s still in private preview.

Related Conversations
How to Prevent Teams from Auto-Launch
chenrylee in Microsoft Teams on
28 Replies
Tabs and Dark Mode
cjc2112 in Discussions on
2 Replies
*Updated 9/3* Syncing in Microsoft Edge Preview Channels
Elliot Kirk in Articles on
203 Replies
Early preview of Microsoft Edge group policies
Sean Lyndersay in Discussions on
65 Replies