Add RDP hosts
Requires the manage targets permission.
Tessera brokers Windows Remote Desktop (RDP). A user opens a native remote-desktop window; the controller tunnels the RDP stream (TCP), and the desktop app injects the Windows credential into its bundled RDP client in memory — never written to disk or saved to the OS credential store, though it is handled by the desktop process.
Create an RDP target
Section titled “Create an RDP target”- Go to RDP → Add host.
- Enter a name and host. The port defaults to 3389.
- Optionally set a domain (for Active Directory logins), a project and group.
Set the credential
Section titled “Set the credential”Open Credentials and provide the Windows username and password (and domain if used). It’s encrypted at rest and never shown again.
When a user connects, the controller tunnels the RDP stream and the desktop app injects the password into its bundled RDP client over an in-memory channel — it is never written to disk or saved to the OS credential store, and it’s never shown in the desktop app. (The CLI instead opens a local port and prints the credential to the terminal so you can connect with your own RDP client.) The user lands on the Windows desktop already signed in.
How users connect
Section titled “How users connect”From the desktop app, Open RDP window launches a native remote-desktop window through the broker — a remote-desktop client is bundled with the app, so there’s nothing to install. The CLI can instead open a local port for your own remote-desktop client.
RDP connects and disconnects are recorded in the audit log with the user, target and time. Read-only mode isn’t enforced inside the Windows desktop — grant RDP as read-write, and rely on just-in-time access and audit for control.
Grant access
Section titled “Grant access”An RDP host is invisible until someone has a grant. Add grants under Access — see Access control.
We would like to count visits with Google Analytics, which needs a cookie. Nothing is loaded and nothing is stored unless you accept. What this sets.