Securing Remote Access – and Offshore & Outsourced Partners – Creating Secure Zones
The VigilancePro® Terminal Server Agent enables full monitoring of users when access to applications, and data, is provided over terminal services. Often when business functions or processes are outsourced, access is granted to IT systems with little real-time monitoring or control in place over exactly what third party users are doing, including users with privilege. In many cases companies have no influence over the software build on remote third party desktops, so an endpoint agent is not an option.
If access is granted over terminal services, with VigilancePro installed on the terminal server, visibility and control over every action third party users in outsourcing partners and vendors carry out is provided.
Monitoring and control is exactly the same as if the agent was installed on the endpoint down to specific keystrokes, buttons, menu options, even the individual commands that can be typed at a command prompt. VigilancePro provides comprehensive monitoring but also much greater granularity of control than can be configured within the terminal server software - which is usually limited to allowing (or disallowing) access to local hard drives and USB ports.
The same applies when terminal services is used to provide internal staff with remote access, or when terminal services is used internally to protect critical applications or high-value information assets, creating secure zones, or domains within the domain. The VigilancePro terminal server agent can be configured to give a higher level of monitoring and control over activity when users are connected to a sensitive application or accessing key data via a terminal server session.
Solution Highlights:
- Supports strategic use of terminal services
- Complete monitoring and control of remote desktops
- offshore call centres
- outsourced partner / third party access
- Lockdown of internal access to critical assets and applications
- Simple cost-effective deployment
- one agent on each terminal server
- nothing required on the endpoint