{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/dse-20260908-142-inventory-trusted-rdp-publishers-before-restricting-which-files-can-open/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/dse-20260908-142-inventory-trusted-rdp-publishers-before-restricting-which-files-can-open/",
        "slug": "dse-20260908-142-inventory-trusted-rdp-publishers-before-restricting-which-files-can-open",
        "url": "https://update.dsesecurity.com/updates/dse-20260908-142-inventory-trusted-rdp-publishers-before-restricting-which-files-can-open/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/dse-20260908-142-inventory-trusted-rdp-publishers-before-restricting-which-files-can-open.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/dse-20260908-142-inventory-trusted-rdp-publishers-before-restricting-which-files-can-open/"
        },
        "title": "Inventory trusted RDP publishers before restricting which files can open",
        "summary": "Which RDP files and launch paths would a trusted-publisher-only policy block?",
        "format": {
            "slug": "guide",
            "name": "Guide"
        },
        "priority": {
            "slug": "info",
            "name": "Information"
        },
        "featured": false,
        "image": {
            "theme": "network-infrastructure",
            "label": "Networks & infrastructure",
            "alt": "Resilient network core with engineered blue and gold data paths.",
            "card_url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-card.webp?v=1.8.20",
            "hero_url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-hero.webp?v=1.8.20",
            "social_url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-social-v2.jpg?v=1.8.20",
            "width": 2400,
            "height": 1350
        },
        "topics": [
            {
                "slug": "it",
                "name": "IT",
                "url": "https://update.dsesecurity.com/topic/it/"
            },
            {
                "slug": "networks-infrastructure",
                "name": "Networks & Infrastructure",
                "url": "https://update.dsesecurity.com/topic/networks-infrastructure/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team",
            "type": "Organization"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-09-08T18:14:49+00:00",
        "modified_at": "2026-09-08T18:23:27+00:00",
        "reviewed_on": "2026-09-08",
        "reading_minutes": 1,
        "word_count": 207,
        "potentially_affected": "Administrators reviewing Group Policy controls for Remote Desktop Connection RDP files.",
        "dse_recommendation": "Build an inventory of approved signed files and their publisher identities.",
        "primary_source": {
            "name": "RDP file security in Group Policy on Windows and Windows Server",
            "url": "https://learn.microsoft.com/en-us/windows-server/remote/remote-desktop-services/remotepc/manage-rdp-file-security-settings-with-group-policy",
            "published_on": null,
            "authority": "Microsoft Learn"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<h2>Source facts</h2>\n<p>RDP file policies control which configuration files the Remote Desktop Connection client can open. One configuration documented by Microsoft permits only files signed by publishers that are explicitly trusted. It also blocks valid signatures from untrusted publishers and connections started directly through the client’s interface. The settings are available under the Remote Desktop Connection Client policy branch, with configuration details in each policy’s Help text. <a href=\"https://learn.microsoft.com/en-us/windows-server/remote/remote-desktop-services/remotepc/manage-rdp-file-security-settings-with-group-policy\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft documentation</a>.</p>\n<h2>Applicability</h2>\n<p>Identify the installed client updates, actual policy definitions, RDP publishers, unsigned files, and support workflows. Review which users connect through files and which use the client interface before selecting a restriction.</p>\n<h2>DSE recommendation</h2>\n<p>Build an inventory of approved signed files and their publisher identities. Ask service owners to identify legitimate unsigned or interface-launched connections that require a migration decision. Pilot the proposed policy with clear support instructions and retain the existing policy settings.</p>\n<h2>Verification</h2>\n<p>Test a trusted file, a validly signed file from an untrusted publisher, an unsigned file, and a direct client launch. Record the observed acceptance or rejection for each. Resolve any required workflow that is blocked unexpectedly before applying the setting across managed endpoints.</p>\n<h2>Official references</h2>\n<p><a href=\"https://learn.microsoft.com/en-us/windows-server/remote/remote-desktop-services/remotepc/manage-rdp-file-security-settings-with-group-policy\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn: RDP file security in Group Policy on Windows and Windows Server</a>. Source reviewed September 8, 2026.</p>",
        "content_text": "Source facts\nRDP file policies control which configuration files the Remote Desktop Connection client can open. One configuration documented by Microsoft permits only files signed by publishers that are explicitly trusted. It also blocks valid signatures from untrusted publishers and connections started directly through the client’s interface. The settings are available under the Remote Desktop Connection Client policy branch, with configuration details in each policy’s Help text. Microsoft documentation.\nApplicability\nIdentify the installed client updates, actual policy definitions, RDP publishers, unsigned files, and support workflows. Review which users connect through files and which use the client interface before selecting a restriction.\nDSE recommendation\nBuild an inventory of approved signed files and their publisher identities. Ask service owners to identify legitimate unsigned or interface-launched connections that require a migration decision. Pilot the proposed policy with clear support instructions and retain the existing policy settings.\nVerification\nTest a trusted file, a validly signed file from an untrusted publisher, an unsigned file, and a direct client launch. Record the observed acceptance or rejection for each. Resolve any required workflow that is blocked unexpectedly before applying the setting across managed endpoints.\nOfficial references\nMicrosoft Learn: RDP file security in Group Policy on Windows and Windows Server. Source reviewed September 8, 2026.",
        "content_markdown": "## Source facts\n\nRDP file policies control which configuration files the Remote Desktop Connection client can open. One configuration documented by Microsoft permits only files signed by publishers that are explicitly trusted. It also blocks valid signatures from untrusted publishers and connections started directly through the client’s interface. The settings are available under the Remote Desktop Connection Client policy branch, with configuration details in each policy’s Help text. [Microsoft documentation](https://learn.microsoft.com/en-us/windows-server/remote/remote-desktop-services/remotepc/manage-rdp-file-security-settings-with-group-policy).\n\n## Applicability\n\nIdentify the installed client updates, actual policy definitions, RDP publishers, unsigned files, and support workflows. Review which users connect through files and which use the client interface before selecting a restriction.\n\n## DSE recommendation\n\nBuild an inventory of approved signed files and their publisher identities. Ask service owners to identify legitimate unsigned or interface-launched connections that require a migration decision. Pilot the proposed policy with clear support instructions and retain the existing policy settings.\n\n## Verification\n\nTest a trusted file, a validly signed file from an untrusted publisher, an unsigned file, and a direct client launch. Record the observed acceptance or rejection for each. Resolve any required workflow that is blocked unexpectedly before applying the setting across managed endpoints.\n\n## Official references\n\n[Microsoft Learn: RDP file security in Group Policy on Windows and Windows Server](https://learn.microsoft.com/en-us/windows-server/remote/remote-desktop-services/remotepc/manage-rdp-file-security-settings-with-group-policy). Source reviewed September 8, 2026."
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo-20260812.png?v=1.8.20"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/dse-20260908-142-inventory-trusted-rdp-publishers-before-restricting-which-files-can-open/",
                "url": "https://update.dsesecurity.com/updates/dse-20260908-142-inventory-trusted-rdp-publishers-before-restricting-which-files-can-open/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-09-08"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/dse-20260908-142-inventory-trusted-rdp-publishers-before-restricting-which-files-can-open/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Inventory trusted RDP publishers before restricting which files can open",
                        "item": "https://update.dsesecurity.com/updates/dse-20260908-142-inventory-trusted-rdp-publishers-before-restricting-which-files-can-open/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/dse-20260908-142-inventory-trusted-rdp-publishers-before-restricting-which-files-can-open/#article",
                "identifier": "https://update.dsesecurity.com/updates/dse-20260908-142-inventory-trusted-rdp-publishers-before-restricting-which-files-can-open/",
                "url": "https://update.dsesecurity.com/updates/dse-20260908-142-inventory-trusted-rdp-publishers-before-restricting-which-files-can-open/",
                "headline": "Inventory trusted RDP publishers before restricting which files can open",
                "description": "Which RDP files and launch paths would a trusted-publisher-only policy block?",
                "abstract": "Which RDP files and launch paths would a trusted-publisher-only policy block?",
                "articleBody": "Source facts\nRDP file policies control which configuration files the Remote Desktop Connection client can open. One configuration documented by Microsoft permits only files signed by publishers that are explicitly trusted. It also blocks valid signatures from untrusted publishers and connections started directly through the client’s interface. The settings are available under the Remote Desktop Connection Client policy branch, with configuration details in each policy’s Help text. Microsoft documentation.\nApplicability\nIdentify the installed client updates, actual policy definitions, RDP publishers, unsigned files, and support workflows. Review which users connect through files and which use the client interface before selecting a restriction.\nDSE recommendation\nBuild an inventory of approved signed files and their publisher identities. Ask service owners to identify legitimate unsigned or interface-launched connections that require a migration decision. Pilot the proposed policy with clear support instructions and retain the existing policy settings.\nVerification\nTest a trusted file, a validly signed file from an untrusted publisher, an unsigned file, and a direct client launch. Record the observed acceptance or rejection for each. Resolve any required workflow that is blocked unexpectedly before applying the setting across managed endpoints.\nOfficial references\nMicrosoft Learn: RDP file security in Group Policy on Windows and Windows Server. Source reviewed September 8, 2026.",
                "datePublished": "2026-09-08T18:14:49+00:00",
                "dateModified": "2026-09-08T18:23:27+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/dse-20260908-142-inventory-trusted-rdp-publishers-before-restricting-which-files-can-open/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@type": "Organization",
                    "name": "DSE Security Editorial Team",
                    "url": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": {
                    "@type": "ImageObject",
                    "@id": "https://update.dsesecurity.com/updates/dse-20260908-142-inventory-trusted-rdp-publishers-before-restricting-which-files-can-open/#primaryimage",
                    "url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-social-v2.jpg?v=1.8.20",
                    "contentUrl": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-social-v2.jpg?v=1.8.20",
                    "width": 1200,
                    "height": 630,
                    "caption": "Inventory trusted RDP publishers before restricting which files can open"
                },
                "articleSection": [
                    "IT",
                    "Networks & Infrastructure"
                ],
                "keywords": [
                    "IT",
                    "Networks & Infrastructure",
                    "Guide",
                    "Information priority"
                ],
                "genre": "Guide",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "IT",
                        "url": "https://update.dsesecurity.com/topic/it/"
                    },
                    {
                        "@type": "Thing",
                        "name": "Networks & Infrastructure",
                        "url": "https://update.dsesecurity.com/topic/networks-infrastructure/"
                    }
                ],
                "wordCount": 207,
                "timeRequired": "PT1M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "RDP file security in Group Policy on Windows and Windows Server",
                    "url": "https://learn.microsoft.com/en-us/windows-server/remote/remote-desktop-services/remotepc/manage-rdp-file-security-settings-with-group-policy"
                }
            }
        ]
    }
}