{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/dse-20260908-201-review-rds-collection-access-at-the-collection-boundary/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/dse-20260908-201-review-rds-collection-access-at-the-collection-boundary/",
        "slug": "dse-20260908-201-review-rds-collection-access-at-the-collection-boundary",
        "url": "https://update.dsesecurity.com/updates/dse-20260908-201-review-rds-collection-access-at-the-collection-boundary/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/dse-20260908-201-review-rds-collection-access-at-the-collection-boundary.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/dse-20260908-201-review-rds-collection-access-at-the-collection-boundary/"
        },
        "title": "Review RDS collection access at the collection boundary",
        "summary": "Which directory groups should be allowed into each RDS collection?",
        "format": {
            "slug": "guide",
            "name": "Guide"
        },
        "priority": {
            "slug": "info",
            "name": "Information"
        },
        "featured": false,
        "image": {
            "theme": "network-infrastructure",
            "label": "Networks & infrastructure",
            "alt": "Resilient network core with engineered blue and gold data paths.",
            "card_url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-card.webp?v=1.8.20",
            "hero_url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-hero.webp?v=1.8.20",
            "social_url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-social-v2.jpg?v=1.8.20",
            "width": 2400,
            "height": 1350
        },
        "topics": [
            {
                "slug": "it",
                "name": "IT",
                "url": "https://update.dsesecurity.com/topic/it/"
            },
            {
                "slug": "networks-infrastructure",
                "name": "Networks & Infrastructure",
                "url": "https://update.dsesecurity.com/topic/networks-infrastructure/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team",
            "type": "Organization"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-09-08T18:13:50+00:00",
        "modified_at": "2026-09-08T18:29:33+00:00",
        "reviewed_on": "2026-09-08",
        "reading_minutes": 1,
        "word_count": 219,
        "potentially_affected": "Administrators assigning user and group access to Remote Desktop Services collections.",
        "dse_recommendation": "Have each application owner approve the groups that should reach the collection and identify a reviewer for future membership changes.",
        "primary_source": {
            "name": "Manage users in your RDS collection",
            "url": "https://learn.microsoft.com/en-us/windows-server/remote/remote-desktop-services/rds-user-management",
            "published_on": null,
            "authority": "Microsoft Learn"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<h2>Source facts</h2>\n<p>Microsoft documents separate collection access assignments so different user populations can receive different sets of applications. In the documented domain deployment, AD DS supplies the users and groups used for these assignments. After users and groups exist in the directory, administrators assign them to the intended Remote Desktop collections. <a href=\"https://learn.microsoft.com/en-us/windows-server/remote/remote-desktop-services/rds-user-management\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn</a>.</p>\n<h2>Applicability</h2>\n<p>List the collections, application owners, and intended populations before changing membership or access settings. Review existing directory groups rather than creating a new group solely to match a collection name. Keep the collection-access decision separate from privileges inside an application or session.</p>\n<h2>DSE recommendation</h2>\n<p>Have each application owner approve the groups that should reach the collection and identify a reviewer for future membership changes. Record the collection-to-group mapping and the reason for any broad group. Use representative eligible and ineligible accounts in a pilot. Preserve the initial assignment list and agree on how access will be removed when a person changes roles.</p>\n<h2>Verification</h2>\n<p>Test access to the intended collection with each approved population and confirm that an excluded account does not gain access. Review another collection as a boundary check so a broad assignment does not go unnoticed. Verify the expected applications appear, then record membership, collection settings, and actual outcomes together.</p>\n<h2>Official references</h2>\n<p><a href=\"https://learn.microsoft.com/en-us/windows-server/remote/remote-desktop-services/rds-user-management\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn: Manage users in your RDS collection</a>. Source reviewed September 8, 2026.</p>",
        "content_text": "Source facts\nMicrosoft documents separate collection access assignments so different user populations can receive different sets of applications. In the documented domain deployment, AD DS supplies the users and groups used for these assignments. After users and groups exist in the directory, administrators assign them to the intended Remote Desktop collections. Microsoft Learn.\nApplicability\nList the collections, application owners, and intended populations before changing membership or access settings. Review existing directory groups rather than creating a new group solely to match a collection name. Keep the collection-access decision separate from privileges inside an application or session.\nDSE recommendation\nHave each application owner approve the groups that should reach the collection and identify a reviewer for future membership changes. Record the collection-to-group mapping and the reason for any broad group. Use representative eligible and ineligible accounts in a pilot. Preserve the initial assignment list and agree on how access will be removed when a person changes roles.\nVerification\nTest access to the intended collection with each approved population and confirm that an excluded account does not gain access. Review another collection as a boundary check so a broad assignment does not go unnoticed. Verify the expected applications appear, then record membership, collection settings, and actual outcomes together.\nOfficial references\nMicrosoft Learn: Manage users in your RDS collection. Source reviewed September 8, 2026.",
        "content_markdown": "## Source facts\n\nMicrosoft documents separate collection access assignments so different user populations can receive different sets of applications. In the documented domain deployment, AD DS supplies the users and groups used for these assignments. After users and groups exist in the directory, administrators assign them to the intended Remote Desktop collections. [Microsoft Learn](https://learn.microsoft.com/en-us/windows-server/remote/remote-desktop-services/rds-user-management).\n\n## Applicability\n\nList the collections, application owners, and intended populations before changing membership or access settings. Review existing directory groups rather than creating a new group solely to match a collection name. Keep the collection-access decision separate from privileges inside an application or session.\n\n## DSE recommendation\n\nHave each application owner approve the groups that should reach the collection and identify a reviewer for future membership changes. Record the collection-to-group mapping and the reason for any broad group. Use representative eligible and ineligible accounts in a pilot. Preserve the initial assignment list and agree on how access will be removed when a person changes roles.\n\n## Verification\n\nTest access to the intended collection with each approved population and confirm that an excluded account does not gain access. Review another collection as a boundary check so a broad assignment does not go unnoticed. Verify the expected applications appear, then record membership, collection settings, and actual outcomes together.\n\n## Official references\n\n[Microsoft Learn: Manage users in your RDS collection](https://learn.microsoft.com/en-us/windows-server/remote/remote-desktop-services/rds-user-management). Source reviewed September 8, 2026."
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo-20260812.png?v=1.8.20"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/dse-20260908-201-review-rds-collection-access-at-the-collection-boundary/",
                "url": "https://update.dsesecurity.com/updates/dse-20260908-201-review-rds-collection-access-at-the-collection-boundary/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-09-08"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/dse-20260908-201-review-rds-collection-access-at-the-collection-boundary/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Review RDS collection access at the collection boundary",
                        "item": "https://update.dsesecurity.com/updates/dse-20260908-201-review-rds-collection-access-at-the-collection-boundary/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/dse-20260908-201-review-rds-collection-access-at-the-collection-boundary/#article",
                "identifier": "https://update.dsesecurity.com/updates/dse-20260908-201-review-rds-collection-access-at-the-collection-boundary/",
                "url": "https://update.dsesecurity.com/updates/dse-20260908-201-review-rds-collection-access-at-the-collection-boundary/",
                "headline": "Review RDS collection access at the collection boundary",
                "description": "Which directory groups should be allowed into each RDS collection?",
                "abstract": "Which directory groups should be allowed into each RDS collection?",
                "articleBody": "Source facts\nMicrosoft documents separate collection access assignments so different user populations can receive different sets of applications. In the documented domain deployment, AD DS supplies the users and groups used for these assignments. After users and groups exist in the directory, administrators assign them to the intended Remote Desktop collections. Microsoft Learn.\nApplicability\nList the collections, application owners, and intended populations before changing membership or access settings. Review existing directory groups rather than creating a new group solely to match a collection name. Keep the collection-access decision separate from privileges inside an application or session.\nDSE recommendation\nHave each application owner approve the groups that should reach the collection and identify a reviewer for future membership changes. Record the collection-to-group mapping and the reason for any broad group. Use representative eligible and ineligible accounts in a pilot. Preserve the initial assignment list and agree on how access will be removed when a person changes roles.\nVerification\nTest access to the intended collection with each approved population and confirm that an excluded account does not gain access. Review another collection as a boundary check so a broad assignment does not go unnoticed. Verify the expected applications appear, then record membership, collection settings, and actual outcomes together.\nOfficial references\nMicrosoft Learn: Manage users in your RDS collection. Source reviewed September 8, 2026.",
                "datePublished": "2026-09-08T18:13:50+00:00",
                "dateModified": "2026-09-08T18:29:33+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/dse-20260908-201-review-rds-collection-access-at-the-collection-boundary/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@type": "Organization",
                    "name": "DSE Security Editorial Team",
                    "url": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": {
                    "@type": "ImageObject",
                    "@id": "https://update.dsesecurity.com/updates/dse-20260908-201-review-rds-collection-access-at-the-collection-boundary/#primaryimage",
                    "url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-social-v2.jpg?v=1.8.20",
                    "contentUrl": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-social-v2.jpg?v=1.8.20",
                    "width": 1200,
                    "height": 630,
                    "caption": "Review RDS collection access at the collection boundary"
                },
                "articleSection": [
                    "IT",
                    "Networks & Infrastructure"
                ],
                "keywords": [
                    "IT",
                    "Networks & Infrastructure",
                    "Guide",
                    "Information priority"
                ],
                "genre": "Guide",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "IT",
                        "url": "https://update.dsesecurity.com/topic/it/"
                    },
                    {
                        "@type": "Thing",
                        "name": "Networks & Infrastructure",
                        "url": "https://update.dsesecurity.com/topic/networks-infrastructure/"
                    }
                ],
                "wordCount": 219,
                "timeRequired": "PT1M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "Manage users in your RDS collection",
                    "url": "https://learn.microsoft.com/en-us/windows-server/remote/remote-desktop-services/rds-user-management"
                }
            }
        ]
    }
}