# Match Remote Desktop launch links to the intended client

> Which Remote Desktop URI scheme can a managed client actually interpret?

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260908-172-match-remote-desktop-launch-links-to-the-intended-client/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-08T18:14:19+00:00
- Modified: 2026-09-08T18:26:31+00:00
- Last reviewed by DSE: 2026-09-08
- Resource type: Guide
- DSE priority: Information
- Topics: IT, Networks & Infrastructure
- Reading time: 1 minutes

## What you need to know

Which Remote Desktop URI scheme can a managed client actually interpret?

## Potentially affected

Administrators distributing links that launch Microsoft Remote Desktop clients.

## DSE recommendation

Maintain a small catalog of approved link patterns with their intended client, command, and parameter names.

## Article

## Source facts

Microsoft documents URI formats that invoke Remote Desktop clients with commands or preset attributes. The ms-rd scheme is documented for the Windows Desktop client, MSRDC. The legacy rdp scheme is documented for the macOS, iOS, and Android clients. [Microsoft Learn](https://learn.microsoft.com/en-us/windows-server/remote/remote-desktop-services/remote-desktop-uri).

## Applicability

Identify the installed client and platform before publishing a launch link. Review the source attribute table for each target population. Keep the command being requested, the destination information, and platform support visible to the person reviewing the link.

## DSE recommendation

Maintain a small catalog of approved link patterns with their intended client, command, and parameter names. Use a nonproduction destination while building the pattern. Have a second reviewer inspect encoded values and the resulting destination before distribution. Avoid embedding sensitive material in a link merely because an attribute field exists. Provide a clear owner for correcting or retiring stale links.

## Verification

Open each pattern on every supported managed client and record which application launches and which settings it receives. Test an unsupported client as a negative case and document the user-facing result. Confirm the destination before completing an authorized connection. Retest the catalog when the client application or platform changes.

## Official references

[Microsoft Learn: Remote Desktop URI scheme](https://learn.microsoft.com/en-us/windows-server/remote/remote-desktop-services/remote-desktop-uri). Source reviewed September 8, 2026.

## Primary reference

- Name: Remote Desktop URI scheme
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/windows-server/remote/remote-desktop-services/remote-desktop-uri
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Match Remote Desktop launch links to the intended client,” DSE Security, https://update.dsesecurity.com/updates/dse-20260908-172-match-remote-desktop-launch-links-to-the-intended-client/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
