# Review RDS collection access at the collection boundary

> Which directory groups should be allowed into each RDS collection?

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260908-201-review-rds-collection-access-at-the-collection-boundary/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-08T18:13:50+00:00
- Modified: 2026-09-08T18:29:33+00:00
- Last reviewed by DSE: 2026-09-08
- Resource type: Guide
- DSE priority: Information
- Topics: IT, Networks & Infrastructure
- Reading time: 1 minutes

## What you need to know

Which directory groups should be allowed into each RDS collection?

## Potentially affected

Administrators assigning user and group access to Remote Desktop Services collections.

## DSE recommendation

Have each application owner approve the groups that should reach the collection and identify a reviewer for future membership changes.

## Article

## Source facts

Microsoft documents separate collection access assignments so different user populations can receive different sets of applications. In the documented domain deployment, AD DS supplies the users and groups used for these assignments. After users and groups exist in the directory, administrators assign them to the intended Remote Desktop collections. [Microsoft Learn](https://learn.microsoft.com/en-us/windows-server/remote/remote-desktop-services/rds-user-management).

## Applicability

List the collections, application owners, and intended populations before changing membership or access settings. Review existing directory groups rather than creating a new group solely to match a collection name. Keep the collection-access decision separate from privileges inside an application or session.

## DSE recommendation

Have each application owner approve the groups that should reach the collection and identify a reviewer for future membership changes. Record the collection-to-group mapping and the reason for any broad group. Use representative eligible and ineligible accounts in a pilot. Preserve the initial assignment list and agree on how access will be removed when a person changes roles.

## Verification

Test access to the intended collection with each approved population and confirm that an excluded account does not gain access. Review another collection as a boundary check so a broad assignment does not go unnoticed. Verify the expected applications appear, then record membership, collection settings, and actual outcomes together.

## Official references

[Microsoft Learn: Manage users in your RDS collection](https://learn.microsoft.com/en-us/windows-server/remote/remote-desktop-services/rds-user-management). Source reviewed September 8, 2026.

## Primary reference

- Name: Manage users in your RDS collection
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/windows-server/remote/remote-desktop-services/rds-user-management
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Review RDS collection access at the collection boundary,” DSE Security, https://update.dsesecurity.com/updates/dse-20260908-201-review-rds-collection-access-at-the-collection-boundary/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
