Remote Desktop Access Procedure

IT & Security Network & Access Last reviewed: 2025-08-10 Owner: IT Operations

Purpose

This document outlines the procedure for accessing Global Bank workstations and servers remotely using Remote Desktop Protocol (RDP) through the bank's secure Remote Desktop Gateway. Remote desktop access is restricted to authorised personnel who require direct access to specific systems that cannot be reached via standard VPN connectivity alone.

Policy Reference: IT-NET-003
Applies To: IT administrators, application support teams, and authorised business users

When to Use Remote Desktop

Remote Desktop access should only be used when:

  • You need to administer a server or workstation that requires a graphical console session.
  • You need to access a legacy application that is not published through the Virtual Application Platform.
  • You are performing authorised maintenance or troubleshooting on behalf of IT Operations.

For general remote working, employees should use the VPN (see VPN Setup and Usage Guide, IT-NET-001) and access applications through the standard published application catalogue.

Prerequisites

  • An active VPN connection to the Global Bank network.
  • Membership in the appropriate Active Directory security group (e.g., GBL-RDP-Servers, GBL-RDP-Workstations).
  • A completed and approved Remote Access Request Form (ITOPS-RF-012), signed by your line manager and the system owner.
  • Multi-Factor Authentication (MFA) enrolment.

Requesting Access

  1. Log in to the IT Service Portal at servicedesk.globalbank.com.
  2. Navigate to Request a Service > Remote Desktop Access.
  3. Complete the request form, specifying:
    • Target system hostname or IP address
    • Business justification
    • Required duration (maximum 90 days per request)
    • Approving manager's name and employee ID
  4. Submit the request. Your line manager and the system owner will receive approval notifications.
  5. Once both approvals are obtained, IT Operations will add your account to the relevant security group within two business days.

Connecting via Remote Desktop Gateway

  1. Establish a VPN connection using CiscoSecure Connect.
  2. Open Remote Desktop Connection (mstsc.exe) on your device.
  3. Click Show Options and navigate to the Advanced tab.
  4. Under Connect from anywhere, click Settings and enter the gateway server: rdgw.globalbank.com
  5. Select Use my RD Gateway credentials for the remote computer.
  6. Return to the General tab and enter the target computer name.
  7. Click Connect and authenticate with your corporate credentials.
  8. Approve the MFA prompt when presented.

Session Management Rules

RuleDetail
Maximum session duration8 hours (auto-disconnect)
Idle timeout30 minutes
Concurrent sessions1 per user (unless exception granted)
Clipboard redirectionDisabled by default on servers
Drive redirectionDisabled on all sessions
Session recordingEnabled for privileged accounts

Security Considerations

  • All RDP sessions are routed through the Remote Desktop Gateway; direct RDP connections to internal hosts are blocked at the firewall.
  • Sessions to servers classified as Tier 0 or Tier 1 are recorded and subject to audit by the IT Security Team.
  • File transfer via RDP is prohibited. Use approved secure file transfer mechanisms instead.
  • Report any suspicious activity observed during an RDP session to the Security Operations Centre immediately.

Access Revocation

Remote Desktop access is automatically revoked after the approved duration expires. If access is no longer required before the expiry date, submit a cancellation request through the IT Service Portal. Access may also be revoked immediately by IT Security in the event of a security incident.

Support

For assistance with Remote Desktop access:

  • IT Operations: itops@globalbank.com | Ext. 2100
  • IT Service Desk: servicedesk@globalbank.com | Ext. 2000