Unauthorized RDP Access Outside Approved Gateway

Last updated on:

In this page

About the rule

Rule Type

Standard

Rule Description

Detects RDP logons from non-approved sources that may bypass PMP-enforced privileged access controls. Note: Exclude the PMP server IP in the Remote DeviceIp field to avoid triggering on approved RDP sessions initiated through PMP.

Severity

Attention

Detection

Execution Mode

realtime

Log Sources

Windows