TL;DR: Windows RDP still often relies on shared admin accounts and static credentials, while P0 Security’s video shows a time-bound access model tied to corporate identity with approval history, session recording and real-time revocation. The practical issue is not remote access itself but whether runtime control, auditability and zero standing privilege can keep pace with agents, users and machines.
NHIMG editorial: based on content published by P0 Security: Just-in-time RDP access
Questions worth separating out
Q: What breaks when Windows RDP still depends on shared admin accounts?
A: Shared admin accounts break accountability and make access reviews almost useless, because no one can reliably prove who used the session or why.
Q: Why do static credentials create more risk than short-lived access tokens?
A: Static credentials create more risk because they remain valid until someone finds and removes them, which gives attackers a durable entry path.
Q: What are the signs that RDP access controls are not working as intended?
A: Warning signs include repeated failed logins, simultaneous access from different locations, unexpected session counts, and access attempts from machines outside the expected network boundary.
Practitioner guidance
- Audit shared RDP paths for standing privilege Inventory every Windows RDP path that still depends on shared admin accounts or long-lived credentials, then classify which ones can be converted to time-bound access.
- Tie privileged sessions to named corporate identity Require each RDP session to resolve to a real corporate identity with explicit approval history before access is granted.
- Enable session recording for privileged access Capture privileged RDP sessions so every administrative action has reviewable context for audit and incident reconstruction.
What's in the full article
P0 Security's full video covers the operational detail this post intentionally leaves for the source:
- A walkthrough of time-bound RDP issuance tied to real corporate identity
- Approval-history and session-recording workflow detail for privileged sessions
- How real-time revocation is handled during an active access window
- The runtime access platform view across users, machines and AI agents
👉 Watch P0 Security's video on just-in-time RDP access and runtime control →
Just-in-time RDP access: are your controls keeping up with runtime use?
Explore further
View Full Forum → | NHI Foundation Course → | Our Services →
Standing RDP access is the wrong default for runtime work. The article reinforces a simple point: if remote access is not time boxed, it becomes governance debt. Shared admin accounts and static credentials turn every later audit into a reconstruction exercise instead of a control check, so the core programme question is whether access can expire as quickly as the task that created it.
A few things that frame the scale:
- 67% of organisations still rely heavily on static credentials despite the risks they pose to agentic AI deployments, according to the 2026 Infrastructure Identity Survey.
- Only 20% have formal processes for offboarding and revoking API keys, and even fewer have procedures for rotating them, according to the Ultimate Guide to NHIs.
A question worth separating out:
Q: How should teams govern just-in-time access across users, machines and AI agents?
A: Treat just-in-time access as a runtime governance pattern, not a human-only convenience. Define who or what can request access, require proof of identity at issuance, record the approval chain and make revocation available while the session is still active. The same rules should apply whether the actor is a person, a workload or an AI agent.
👉 Read our full editorial: Just-in-time RDP access exposes the limits of static admin control