Join our Newsletter — 33% off our NHI Course

Notifications
Clear all

Remote desktop management: are your credential controls keeping up?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 19382
Topic starter  

TL;DR: Sysadmins still juggle SSH, RDP, VPNs and other remote tools while storing dozens or hundreds of credentials in insecure places such as spreadsheets and script files, according to Devolutions. The governance gap is not just usability: it is centralised control over sessions, credentials, roles and logging across a fragmented remote access estate.

NHIMG editorial — based on content published by Devolutions: Top 5 features to look for in a remote desktop management solution

By the numbers:

Questions worth separating out

Q: How should teams secure shared remote sessions without losing productivity?

A: Use a central session repository with role-based visibility, directory-backed permissions and logging on every open, change and close action.

Q: Why do remote desktop platforms create identity governance risk even without secret exposure?

A: Because the platform can still hold delegated authority over inventory, provisioning, and power-state operations.

Q: What do security teams get wrong about emergency access for password vaults?

A: They often treat emergency access as a convenience feature instead of privileged delegation.

Practitioner guidance

  • Inventory every remote access path Map each protocol, client and shared session workflow so you know where credentials are stored, copied and reused across the environment.
  • Move all administrative secrets into a governed vault Eliminate spreadsheets, script files and ad hoc storage, and block export paths that allow secrets to leave the managed control plane.
  • Bind session access to RBAC and directory groups Use role assignments and Active Directory group membership as the source of truth for who can open, view or modify sessions.

What's in the full article

Devolutions' full white paper covers the operational detail this post intentionally leaves for the source:

  • A product-level view of how one remote desktop management platform integrates with VPNs, password tools and remote clients
  • Examples of how credential vaulting and session sharing work in day-to-day administrator workflows
  • The specific ways role management, logging and session organisation are implemented inside the product
  • A feature-by-feature description of the interface and management functions for implementation planning

👉 Read Devolutions' white paper on the five features of remote desktop management →

Remote desktop management: are your credential controls keeping up?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 18973
 

Remote desktop management is now a lifecycle governance problem, not just an operations problem. The article shows how credential storage, session sharing and access rights converge in one administrative plane. That means provisioning, review and offboarding all matter, even when the primary subject is a sysadmin workflow. Practitioners should stop treating remote access tools as neutral containers and start governing them as identity infrastructure.

A few things that frame the scale:

  • Only 5.7% of organisations have full visibility into their service accounts, according to the Ultimate Guide to NHIs.
  • Another 71% of NHIs are not rotated within recommended time frames, which shows how often lifecycle control lags behind operational reality.

A question worth separating out:

Q: How do you know if remote work security controls are actually working?

A: Look for fewer standalone passwords, consistent SSO adoption, enforced MFA or passwordless authentication, and access scopes that stay narrow after login. If users can still reach too many systems after authentication, the programme is secure at the front door but loose inside the building.

👉 Read our full editorial: Remote desktop management needs vaulting, RBAC and session control



   
ReplyQuote
Share: