Allow administrators to enable the agent RDP proxy from the web interface
Currently, enabling browser-based RDP requires manually editing the Windows agent configuration:
integrations: rdp-proxy-enabled: true
Then restarting the PatchMonAgent service.
The agent is already installed and connected to PatchMon, but administrators still need another way to access each machine before they can enable remote access through the dashboard. This adds considerable manual work when enrolling multiple Windows hosts.
Suggested improvement
Add an RDP proxy control to the host’s Integrations or RDP tab, allowing authorized administrators to:
- View whether the agent’s RDP proxy is enabled.
- Enable or disable it through the existing agent connection.
- Receive confirmation that the configuration was applied.
- See actionable errors if Windows Remote Desktop is unavailable.
Security considerations
Since remote access is security-sensitive, this feature could require:
- A dedicated permission to manage remote access configuration.
- Explicit confirmation before enabling the proxy.
- An audit trail identifying the administrator, host, action and time.
- An installation option allowing administrators to opt in to remote management of this setting.
The control would manage only the PatchMon agent’s RDP proxy. Windows Remote Desktop settings, account permissions and authentication requirements would remain independently enforced.
Environment
PatchMon server and Windows agent: 2.1.3
Windows host: Windows 10 22H2
Expected benefit
Administrators could finish configuring browser-based remote access from the dashboard after agent enrollment, reducing manual steps while preserving explicit authorization and accountability.
0 Comments
No comments yet. Be the first to share your thoughts!
