What you need to know
Which Remote Desktop URI scheme can a managed client actually interpret?
Potentially affected
Administrators distributing links that launch Microsoft Remote Desktop clients.
DSE recommendation
Maintain a small catalog of approved link patterns with their intended client, command, and parameter names.
Source facts
Microsoft documents URI formats that invoke Remote Desktop clients with commands or preset attributes. The ms-rd scheme is documented for the Windows Desktop client, MSRDC. The legacy rdp scheme is documented for the macOS, iOS, and Android clients. Microsoft Learn.
Applicability
Identify the installed client and platform before publishing a launch link. Review the source attribute table for each target population. Keep the command being requested, the destination information, and platform support visible to the person reviewing the link.
DSE recommendation
Maintain a small catalog of approved link patterns with their intended client, command, and parameter names. Use a nonproduction destination while building the pattern. Have a second reviewer inspect encoded values and the resulting destination before distribution. Avoid embedding sensitive material in a link merely because an attribute field exists. Provide a clear owner for correcting or retiring stale links.
Verification
Open each pattern on every supported managed client and record which application launches and which settings it receives. Test an unsupported client as a negative case and document the user-facing result. Confirm the destination before completing an authorized connection. Retest the catalog when the client application or platform changes.
Official references
Microsoft Learn: Remote Desktop URI scheme. Source reviewed September 8, 2026.
Review the official source
Remote Desktop URI scheme · Verified September 8, 2026
Need help applying this guidance safely?
DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.
Talk with DSE