Endpoint Security for Terminal Server/ Remote Desktop Services

Endpoint Security for Terminal Server Remote Desktop Service is a physical server that allows multiple users to log on and access desktops remotely (For example, from a PC).

Check Point Endpoint Security supports these servers through the Endpoint Security client E86.20 or higher:

  • Microsoft Terminal Services

  • Microsoft Remote Desktop Services

  • Citrix Xen App (Formerly known as Virtual app)

  • VMware Horizon App

Software Blades for Terminal Servers

  • Anti-Malware

  • Firewall and Application Control

  • URL Filtering

  • Anti-Bot

  • Anti-Ransomware

  • Behavioral Guard

  • Forensics

  • Threat Emulation and Extraction

  • Anti-Exploit

Licensing

Licensing is per user. Each user is counted as a seat (using existing SKUs).

Limitations

  • User-based policy is not supported. By default, computers will receive the entire organization policy unless you create a computer-based Rule Base.

  • By default, the Endpoint Security client icon is turned off in the notification area (system tray) for all the users logged on to the server. This is to prevent client notifications triggered by a specific user action sent to all users. User checks (For example, Malware detections, upgrade process and push operations) are not displayed. To turn on the Endpoint Security client icon in the notification area for a specific user, see step 3 in the #procedure_id below.

  • The Logs menu does not show user details. The Terminal Server shows all logged on users as ntlocal.

  • Compliance Remediation Run as User is not supported. For more information, see Compliance.

  • For the Anti-Malware capability:

    • Terminal Server exclusions does not support User Environment Variables.

    • Scanning and quarantine are supported only for a directory that can be accessed by the System Account.

    • Reporting - When infections are found, the Network Drive appears as "unknown" when a network drive cannot be accessed by System Account.

  • Configure proxy settings for the Windows Server machine in the System Account.

  • The Full Disk Encryption blade is not supported.

  • The Media Encryption blade is not be supported.

  • Windows Subsystem for Linux (WSL) is not be supported.

  • Internet Explorer extension is not supported.