Link to home
Start Free TrialLog in
Avatar of Bill H
Bill H

asked on

Terminal Server Security

Hey guys,

We have a bunch of terminal servers behind our gateway. Now, we have users from random places who connect.

How can i secure it against threats/hacks sinces it kind of "open"
ASKER CERTIFIED SOLUTION
Avatar of Cliff Galiher
Cliff Galiher
Flag of United States of America image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
You can also look at blocking access to the Terminal Server from the Internet altogether and force external users to connect via VPN first before they can log into the TS.
Avatar of Bill H
Bill H

ASKER

Cliff what's MFA ?
Multi-factor Authentication. Things like smartcards, PIN FOBs, Fingerprint scanners. All fall under the MFA umbrella. For the SMB, SMS or smartphone apps are my current recommended options. Inexpensive and easy.
Avatar of Bill H

ASKER

Cliff, any cost effective options?
PhoneFactor - Per user       $1.40 per month (unlimited authentications) or Per authentication       $1.40 per 10 authentications
, Google Authenticator
Avatar of Bill H

ASKER

Which is the easiest to setup and sync with AD?
Azure MFA or Azure AD premium are very easy to set up and directory syncing is a key component of Azure AD.
Avatar of Bill H

ASKER

Do i have to an Azure cloud server?
No. You have to have an Azure account, but Azure has many services, not just virtual machines. Azure AD and MFA are their own products and don't require any VMs.