Devolutions Gateway offers a feature for the injection of credentials through a proxy, allowing users to connect to remote sessions without ever having access to its credentials on their machine. Follow the steps below to configure proxy-based credential injection on an entry:
Configure Devolutions Gateway in Devolutions Server or Devolutions Hub Business.
Edit an RDP entry, and link it to a Gateway ruleset (these steps are the same for Devolutions Server and Devolutions Hub Business).
Head over to your chosen data source's web interface, go to Administration – Devolutions Gateway, and click to Edit button on the linked Gateway ruleset.
Then, check the Enable proxy-based credential injection option under Security.
From then on, launching the session will not expose its credentials on the user's machine.
For maximum security when dealing with external users, create a Contractor user with the Execute permission but NOT the View password permission.