Kaspersky Next XDR Expert

Remote access from a Windows-based device with OSMP Console to a Windows-based managed device

Remote desktop connection (RDP)

Prerequisites

Before you start, make sure that you have done the following:

  • On the managed device running Windows, Network Agent version 13.0 or later is installed.
  • The administrator has the Start RDP sessions right to establish RDP connections.
  • A remote connection is allowed in the operating system settings of the managed device.

To connect to a Windows-based managed device from a Windows-based OSMP Console by using RDP:

  1. In the main menu, go to the Assets (Devices) → Managed devices section or open a device selection.
  2. Select the check box next to the managed device to which you want to connect remotely, and then click the Connect to Remote Desktop button.

    The Connect to Remote Desktop window opens.

    If you select multiple devices, a mobile device, or a device running macOS, the Connect to Remote Desktop button will be disabled.

  3. In the Connect to Remote Desktop window, select the Remote Desktop Connection connection type.
  4. If a remote connection is not allowed in the operating system settings of the managed device, allow the remote connection centrally by clicking the Change settings button.

    If the settings are applied correctly, a notification is displayed. Also, on the managed device, in the SettingsSystemRemote Desktop section, the Enable Remote Desktop option is enabled.

    If the remote connection is allowed in the operating system settings of the managed device, the Change settings button is not displayed.

  5. Download the klsctunnel utility by clicking the Download button, and then run it.

    If the utility file is unavailable for download, an error message is displayed. In this case, download the utility manually.

  6. Generate a text blob with encoded connection parameters by clicking the Generate blob button, and then copy and paste the text into the corresponding field in the klsctunnel utility.

    A blob contains the settings required to establish a connection between Administration Server and the managed device. A blob is valid for three minutes. If it has expired, generate a new blob.

  7. In the klsctunnel utility, if you use a proxy server, specify the proxy server connection settings.

    To do this, select the Use proxy server check box, and then specify the connection settings.

  8. Click the Open port button.

    The Remote Desktop Connection login window opens.

  9. Specify the credentials of the account under which you are currently logged in to OSMP Console, and then connect to the managed device.

    The klsctunnel utility displays the address and port of the connection to the remote device.

    The utility allows the administrator to close the tunnel connection. If the tunnel connection is closed, the current connection to the remote desktop is terminated.

When connection to the device is established, the desktop is available in the Remote Desktop Connection window of Microsoft Windows.

Connection to the current remote desktop session of the user is established without the user's knowledge. Once the administrator connects to the session, the device user is disconnected from the session without notification.

Windows Desktop Sharing (WDS)

Prerequisites

Before you start, make sure that you have done the following:

  • On the managed device running Windows, Network Agent version 13.0 or later is installed.
  • The administrator has the Connect to existing RDP sessions right to establish the WDS connection.
  • The license for Vulnerability and patch management is available.
  • Microsoft Windows Vista or later is installed on the administrator's workstation. The type of operating system of the device hosting Administration Server imposes no restrictions on connection through Windows Desktop Sharing.

    Check whether the Windows Desktop Sharing feature is included in your Windows edition, and make sure that the CLSID\{32BE5ED2-5C86-480F-A914-0FF8885A1B3F} key exists in the Windows Registry.

  • Microsoft Windows Vista or later is installed on the client device.

To connect to a Linux-based managed device from a Windows-based OSMP Console by using VNC:

  1. In the main menu, go to the Assets (Devices) → Managed devices section or open a device selection.
  2. Select the check box next to the managed device to which you want to connect remotely, and then click the Connect to Remote Desktop button.

    The Connect to Remote Desktop window opens.

    If you select multiple devices, a mobile device, or a device running macOS, the Connect to Remote Desktop button will be disabled.

  3. In the Connect to Remote Desktop window, select the connection type Windows Desktop Sharing.

    If the Vulnerability and patch management license is not available, an error message is displayed.

  4. Download the klsctunnel utility by clicking the Download button, and then run it.

    When downloading the utility, take into account the following:

  5. In the list of available user sessions active on the selected device, select the session to which you want to connect.

    The remote user must allow the connection. If the remote user refuses to connect or if the remote user does not allow the connection during the timeout period, an error message is displayed.

  6. Generate a text blob with encoded connection parameters by clicking the Generate blob button, and then copy and paste the text into the corresponding field in the klsctunnel utility.

    A blob contains the settings required to establish a connection between Administration Server and the managed device. A blob is valid for three minutes. If it has expired, generate a new blob.

  7. In the klsctunnel utility, if you use a proxy server, specify the proxy server connection settings.

    To do this, select the Use proxy server check box, and then specify the connection settings.

  8. Click the Open port button.

    The klsctunnel utility displays the address and port for the local connection of the VNC client.

    The utility allows the remote user to close the tunnel connection. If the tunnel connection is closed, the current connection to the remote desktop is terminated.

Desktop sharing starts in a new window. If you want to interact with the device, click the menu icon () in the upper-left corner of the window, and then select Interactive mode.