# Choose personal RDS host assignment and privileges independently

> How should personal-session host assignment be separated from granting administrator rights?

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260908-148-choose-personal-rds-host-assignment-and-privileges-independently/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-08T18:14:43+00:00
- Modified: 2026-09-08T18:23:27+00:00
- Last reviewed by DSE: 2026-09-08
- Resource type: Guide
- DSE priority: Information
- Topics: IT, Networks & Infrastructure
- Reading time: 1 minutes

## What you need to know

How should personal-session host assignment be separated from granting administrator rights?

## Potentially affected

Administrators configuring Remote Desktop Services personal session collections.

## DSE recommendation

Prepare a user-to-host allocation record and approve privileges independently of assignment.

## Article

## Source facts

Microsoft’s personal-session collection parameter associates users with their own session hosts instead of assigning the next available host at sign-in. A separate option grants the assigned user administrative privileges; omitting it leaves standard-user privileges. Automatic assignment also has its own option. With it, a new user needs an unassigned host or receives an error; without it, an administrator must assign the host before sign-in. [Microsoft documentation](https://learn.microsoft.com/en-us/windows-server/remote/remote-desktop-services/rds-personal-session-desktops).

## Applicability

Identify the intended users, available hosts, assignment method, privilege requirement, and collection. Review whether a personal host is needed and whether local administrative rights are separately justified.

## DSE recommendation

Prepare a user-to-host allocation record and approve privileges independently of assignment. Have the service owner define who can reassign a host and how departing users are handled. Check available unassigned capacity before enabling automatic assignment for additional users.

## Verification

Query the collection’s actual associations and sign in with representative assigned and unassigned users. Check the resulting host and privilege level, including the no-capacity case in an approved test. Record an unexpected assignment or excessive privilege as a configuration failure before opening the collection more broadly.

## Official references

[Microsoft Learn: Use personal session desktops with Remote Desktop Services](https://learn.microsoft.com/en-us/windows-server/remote/remote-desktop-services/rds-personal-session-desktops). Source reviewed September 8, 2026.

## Primary reference

- Name: Use personal session desktops with Remote Desktop Services
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/windows-server/remote/remote-desktop-services/rds-personal-session-desktops
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Choose personal RDS host assignment and privileges independently,” DSE Security, https://update.dsesecurity.com/updates/dse-20260908-148-choose-personal-rds-host-assignment-and-privileges-independently/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
