# Inventory trusted RDP publishers before restricting which files can open

> Which RDP files and launch paths would a trusted-publisher-only policy block?

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260908-142-inventory-trusted-rdp-publishers-before-restricting-which-files-can-open/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-08T18:14:49+00:00
- Modified: 2026-09-08T18:23:27+00:00
- Last reviewed by DSE: 2026-09-08
- Resource type: Guide
- DSE priority: Information
- Topics: IT, Networks & Infrastructure
- Reading time: 1 minutes

## What you need to know

Which RDP files and launch paths would a trusted-publisher-only policy block?

## Potentially affected

Administrators reviewing Group Policy controls for Remote Desktop Connection RDP files.

## DSE recommendation

Build an inventory of approved signed files and their publisher identities.

## Article

## Source facts

RDP file policies control which configuration files the Remote Desktop Connection client can open. One configuration documented by Microsoft permits only files signed by publishers that are explicitly trusted. It also blocks valid signatures from untrusted publishers and connections started directly through the client’s interface. The settings are available under the Remote Desktop Connection Client policy branch, with configuration details in each policy’s Help text. [Microsoft documentation](https://learn.microsoft.com/en-us/windows-server/remote/remote-desktop-services/remotepc/manage-rdp-file-security-settings-with-group-policy).

## Applicability

Identify the installed client updates, actual policy definitions, RDP publishers, unsigned files, and support workflows. Review which users connect through files and which use the client interface before selecting a restriction.

## DSE recommendation

Build an inventory of approved signed files and their publisher identities. Ask service owners to identify legitimate unsigned or interface-launched connections that require a migration decision. Pilot the proposed policy with clear support instructions and retain the existing policy settings.

## Verification

Test a trusted file, a validly signed file from an untrusted publisher, an unsigned file, and a direct client launch. Record the observed acceptance or rejection for each. Resolve any required workflow that is blocked unexpectedly before applying the setting across managed endpoints.

## Official references

[Microsoft Learn: RDP file security in Group Policy on Windows and Windows Server](https://learn.microsoft.com/en-us/windows-server/remote/remote-desktop-services/remotepc/manage-rdp-file-security-settings-with-group-policy). Source reviewed September 8, 2026.

## Primary reference

- Name: RDP file security in Group Policy on Windows and Windows Server
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/windows-server/remote/remote-desktop-services/remotepc/manage-rdp-file-security-settings-with-group-policy
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Inventory trusted RDP publishers before restricting which files can open,” DSE Security, https://update.dsesecurity.com/updates/dse-20260908-142-inventory-trusted-rdp-publishers-before-restricting-which-files-can-open/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
