Ask the Community
Groups
Terminal server shadow support is not available - Connect IT Community | Kaseya
<main> <article class="userContent"> <h3 data-id="symptoms">SYMPTOMS</h3> <p>When connecting to a Windows terminal server using Kaseya Remote Control (KRC) in R8 or above, drop-down to select console or terminal server user sessions is not displayed. This is what it looks like <em>when shadow support is available</em>: -</p> <p><img src="/attachments/token/Xzxh3SmJANyZTQvoQpitos5tF/?name=dropdown.png" alt="dropdown.png" width="826" height="164" class="embedImage-img importedEmbed-img"></img></p> <h3 data-id="cause">CAUSE</h3> <p><strong>1) Agent Operating System not supported</strong></p> <p>Please refer to <a rel="nofollow" href="/home/leaving?allowTrusted=1&target=http%3A%2F%2Fhelp.kaseya.com%2Fwebhelp%2FEN%2FVSA%2FR8%2FReqs%2Findex.asp%2318007.htm">on-line help</a> for OS requirements for Terminal Server Shadow Support. Please note that <em>Windows XP and Windows Server 2003 are not supported.</em></p> <p><strong>2) Terminal Server policy</strong></p> <p>Terminal Server Shadow support is only enabled if the Remote Desktop Services policy on the agent machine allows remote control without the user's permission.</p> <p>If the policy requires terminal user permission to shadow sessions, KRC does <em>not</em> allow access to the session.</p> <p>Please note, this refers to the user notification policy on the terminal server machine, not the Kaseya VSA. Further information about the policy can be found here - <a href="/home/leaving?allowTrusted=1&target=http%3A%2F%2Fblogs.technet.com%2Fb%2Faskperf%2Farchive%2F2013%2F10%2F22%2Fwindows-8-1-windows-server-2012-r2-rds-shadowing-is-back.aspx">http://blogs.technet.com/b/askperf/archive/2013/10/22/windows-8-1-windows-server-2012-r2-rds-shadowing-is-back.aspx</a></p> <p><em>NB - the default Windows configuration requires user consent, so it does NOT support this feature.</em></p> <p><strong> 3) User session type</strong></p> <p>KRC only supports the shadowing of RDP / RDC user sessions. To check what type of connection a user session has, go to the <em>Users</em> tab in <em>Task Manager</em> on the agent machine and look at the <em>Session</em> column (as shown below).</p> <p><em>KRC does not support the shadowing of Citrix ICA client user sessions.</em></p> <p><img src="/attachments/token/erv2UrZiYDa0GBCxxYwpfaPsn/?name=rdp.png" alt="rdp.png" class="embedImage-img importedEmbed-img"></img></p> <h3 data-id="solution">SOLUTION</h3> <p>To enable shadowing of terminal services sessions, configure terminal server policy on Windows server to allow full control without user permission: -</p> <p>1) Run Group Policy editor (gpedit.msc)</p> <p>2) Navigate to Computer Configuration > Administrative Templates > Windows Components > Remote Desktop Services > Remote Desktop Session Host > Connections</p> <p>3) Enable the policy called "Set rules for remote control of Remote Desktop Services user sessions" and set to "Full Control without user's permission"</p> <p><img src="/attachments/token/GbVJ8SwHcUyhSJn5XB6VKXEz1/?name=gpo.png" alt="gpo.png" width="814" height="512" class="embedImage-img importedEmbed-img"></img> </p> <p><em>NB - if the computer belongs to a domain, a group policy may need to be configured at the domain level</em></p> <p><strong>FURTHER INVESTIGATION</strong></p> <p>If the issue is not resolved after reviewing this article, please provide the Kaseya Support team with the following information: -</p> <p>1) KRC logs from agent and "viewer" computers: -</p> <p><em>Agent Logs</em></p> <ul><li> <p><em>Windows XP and 2003:</em> C:\Documents and Settings\All Users\Application Data\Kaseya\Log</p> </li> <li> <p><em>Windows Vista and later:</em> C:\ProgramData\Kaseya\Log</p> </li> <li> <p><em>OS X:</em> /Library/Logs/com.kaseya</p> </li> </ul><p><em>Viewer Logs</em></p> <ul><li> <p><em>Windows XP and 2003:</em> C:\Documents and Settings\<user>\Application Data\Kaseya\Log</p> </li> <li> <p><em>Windows Vista and later:</em> C:\Users\<user>\AppData\Local\Kaseya\Log</p> </li> <li> <p><em>OS X:</em> /Users/<user>/Library/Logs/com.kaseya</p> </li> </ul><p>2) Screenshot showing: -</p> <ul><li>the whole KRC connection window</li> <li>"users" tab from Task Manager on the agent machine (showing current RDC user sessions at the time)</li> </ul><p>3) screenshot showing the group policy described above (captured soon after the remote session was established)</p> <p><strong>APPLIES TO</strong></p> <p>Kaseya VSA R8 and above</p> </article> </main>