> For the complete documentation index, see [llms.txt](https://docs.devolutions.net/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.devolutions.net/rdm/ribbon-menu-bar/file/settings/security.md).

# Security

Configure Remote Desktop Manager security settings for application locking, multifactor authentication, offline access, and certificates.

Use ***File – Settings – Security*** to configure security settings related to local application security, multifactor authentication, locking, offline security, certificate security, and more.

### Settings

{% tabs %}
{% tab title="Windows" %}
Use ***File – Settings – Security*** to configure security settings related to local application security, multifactor authentication, locking, offline security, certificate security, and more.

### Settings <a href="#settings" id="settings"></a>

#### Application security (local) <a href="#application-security-local" id="application-security-local"></a>

| OPTION                                            | DESCRIPTION                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| ------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Authentication mode**                           | Select how Remote Desktop Manager is secured locally: ***No PIN code*** (no authentication is required to open the application), ***Use a PIN code*** (secure the application with a custom PIN code), ***Use this computer's credentials*** (use the credentials of any user already logged on to this computer, whether a local or a domain account), or ***Windows Hello*** (available once Windows Hello has been configured on your computer). |
| **Encrypt**                                       | Available when ***Use a PIN code*** is selected. Check this option to use the PIN code to encrypt your local Remote Desktop Manager files. Click ***Set a PIN code*** (or ***Change PIN code*** if one is already set) to open a dialog where you enter the ***New PIN*** and ***Confirm PIN*** (and the ***Current PIN*** when changing an existing one).                                                                                          |
| **Advanced options**                              | Available only if ***Encrypt*** is enabled. Clicking it opens a new window. In this window, define the ***Number of key derivation iterations***, which is the number of derivations used for the key derivation function during encryption. A larger number is safer, but may affect performance. The default value is 10 000.                                                                                                                     |
| **Force currently logged-on username and domain** | Available when ***Use this computer's credentials*** is selected. Forces the use of the username and domain used to log in to the current Windows session.                                                                                                                                                                                                                                                                                          |
| **Encrypt local files with Windows Hello**        | Available when ***Windows Hello*** is selected. Windows Hello can be enabled after configuring it on your computer; once enabled, your local Remote Desktop Manager files are encrypted using Windows Hello.                                                                                                                                                                                                                                        |

#### Multifactor authentication <a href="#multifactor-authentication" id="multifactor-authentication"></a>

| OPTION                                                                        | DESCRIPTION                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| ----------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Authentication mode**                                                       | <p>Select <em><strong>Default (Prompt for selection on use)</strong></em> to be asked which MFA to configure on use, or select <em><strong>Check against all configured methods</strong></em> to be prompted with the configured methods only.<br><br>Note that the MFA is set locally. To enforce this setting, enable <em><strong>Force multifactor authentication on the application login</strong></em> and <em><strong>Disable the menu File – Settings</strong></em> <a href="/rdm/knowledge-base/how-to-articles/apply-policies-gpos.md">policies</a> to prevent a user to deactivate these settings. The MFA can also be enabled at the workspace level in <em><strong>Administration – System settings – Application specific – Applications</strong></em> instead of using the policies to block the <em><strong>Options</strong></em>.</p> |
| **Require YubiKey authentication**                                            | Check this option to authenticate in your Remote Desktop Manager application using one or more YubiKey devices. Manage your keys in the ***Registered keys*** list using the ***Add Yubikey*** and ***Remove selected*** buttons.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| **Require a TOTP validation (Password Manager apps or Google Authenticator)** | Check this option to validate your authentication to your Remote Desktop Manager application with a Time-based one-time password (TOTP) generated by a compatible Password Manager app or Google Authenticator. Set it up using the ***Configure*** button below this option.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| **Override account name**                                                     | Enter a new name for your TOTP account that will override the current one.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |
| **Require Duo authentication**                                                | Check this option to authenticate in your Remote Desktop Manager application using Duo authentication. Set it up using the ***Configure*** button below this option.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| **Duo automatic action**                                                      | Select the action that Duo must use to validate the authentication: ***None***, ***Push***, ***Phone***, or ***SMS***.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |

#### Lock <a href="#lock" id="lock"></a>

| **OPTION**          | **DESCRIPTION**                                                                                                                                                                                                             |
| ------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **On minimize**     | Check this option to lock Remote Desktop Manager after minimizing it. Unlock the application using the configured security method(s).                                                                                       |
| **On idle**         | Check this option to lock Remote Desktop Manager after it has been idle for a certain time (define that period under this option). Unlock the application using the configured security method(s).                          |
| **On Windows lock** | Check this option to lock Remote Desktop Manager after your Windows session is locked (for example, when pressing Win+L or when the lock screen activates). Unlock the application using the configured security method(s). |
| **On standby**      | Check this option to lock Remote Desktop Manager after your computer goes into sleep mode / hibernation (standby). Unlock the application using the configured security method(s).                                          |

#### Offline security <a href="#offline-security" id="offline-security"></a>

| **OPTION**                          | **DESCRIPTION**                                                                                                                                                                                                                                                                                                      |
| ----------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Authentication mode**             | In the drop-down list, select between **Default security** and **Enhanced security**. The enhanced security allows you to set up an offline password. The offline cache will then be encrypted. The password is required when switching to Offline mode only if the **Prompt for offline access** option is enabled. |
| **New password / Confirm password** | This is only available with enhanced offline security. Enter an offline password in the **New password** field, then enter it again in the **Confirm password** field.                                                                                                                                               |
| **Prompt for offline access**       | This is only available with enhanced offline security. If enabled, Remote Desktop Manager will ask if you want to access the application offline on startup.                                                                                                                                                         |

#### Certificate security <a href="#certificate-security" id="certificate-security"></a>

| **OPTION**                                | **DESCRIPTION**                                                                                                                                                                                                                                               |
| ----------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Ignore application certificate errors** | Check this option to disable the application certificate validation. This is not recommended, as it would compromise confidentiality and integrity of communications between the client and the server and could expose the application to potential threats. |
| **Enforce certificate revocation check**  | Check this option to enable the validation that the certificate has not been revoked. This is necessary if any of the URLs for certificate validation are unavailable for any reason.                                                                         |
| **Certificate revocation check timeout**  | Set the maximum time limit (in seconds) for the certificate revocation check.                                                                                                                                                                                 |
| **Enhanced certificate validation**       | Check this option to enable enhanced certificate validation. Note that this can be deactivated for certificate validation troubleshooting purposes.                                                                                                           |
| **Reset known certificates**              | Click this button to reset the certificates that Remote Desktop Manager has recorded as known. This button is only shown once at least one certificate has been recorded.                                                                                     |

#### Other <a href="#other" id="other"></a>

| **OPTION**                                 | **DESCRIPTION**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |
| ------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| **Enable secure desktop**                  | In the drop-down list, select **Yes** or **No**. If enabled, secure desktop opens password dialogs on another desktop to add an extra level of security and prevent keyloggers from logging what you write.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| **Session events**                         | <p>Enable session events that can perform powerful actions such as running an external program or script. These events represent a risk if they are modified by a malicious actor.</p><ul><li>Default (Enabled)</li><li>Enabled</li><li>Warn on risky events</li><li>Disable risky events</li><li>Disable all events</li></ul>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |
| **Enable DPAPI encryption on local files** | <p>Encrypts Remote Desktop Manager configuration files on the workstation using Windows' native encryption capabilities (DPAPI - Data Protection API). This provides additional security for the sensitive information contained in these files (such as workspace connection information). DPAPI is a robust additional encryption tool managed by the operating system that ensures that the configuration files containing sensitive information and the offline cache files can only be decrypted on your own machine. Enabling DPAPI and Offline Security will encrypt the files twice since DPAPI is a separated encryption step. In addition to the offline files, this option encrypts the following Remote Desktop Manager configuration files:</p><ul><li>RemoteDesktopManager.enb</li><li>RemoteDesktopManager.enc</li><li>RemoteDesktopManager.stb</li><li>RemoteDesktopManager.stv</li></ul><p><br>The feature is disabled by default, because under certain rare conditions (beyond Remote Desktop Manager's control), data decrypted by DPAPI may be unrecoverable, preventing Remote Desktop Manager from starting up.</p> |
| **Enable anti-malware scanning**           | In the drop-down list, select **Default (no)**, **Yes**, or **No** to enable Remote Desktop Manager to scan for malware. This feature might not be compatible with your anti-malware provider. It supports Microsoft Defender, Avast, AVG, and ESET.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| **Protect data from screen capture**       | In the drop-down list, select **Default (Disabled)**, **Enabled**, or **Disabled** to allow Remote Desktop Manager to prevent external applications or tools from capturing its content.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| **Reset known events**                     | Click this button to reset all known events configured on session entries. This button is only shown once at least one known event has been recorded.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
| {% endtab %}                               |                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |

{% tab title="macOS" %}

#### Application security (local) <a href="#application-security-local" id="application-security-local"></a>

<table><thead><tr><th width="239">OPTION</th><th>DESCRIPTION</th></tr></thead><tbody><tr><td><strong>No application password</strong></td><td>No password will be requested to access the application.</td></tr><tr><td><strong>Use application password</strong></td><td>Define a specific password to access the application.</td></tr><tr><td><strong>Use computer credentials as application password</strong></td><td>Requires the same credential as your computer credential to access the application.</td></tr><tr><td><strong>Requires Touch ID authentication</strong></td><td>If your Mac supports Touch ID, check this option to require Touch ID authentication in addition to your chosen application security method to unlock or open Remote Desktop Manager.</td></tr></tbody></table>

#### Multifactor authentication <a href="#multifactor-authentication" id="multifactor-authentication"></a>

<table><thead><tr><th width="273">OPTION</th><th>DESCRIPTION</th></tr></thead><tbody><tr><td><strong>Require YubiKey authentication</strong></td><td>Use a YubiKey device to get access to the application when it starts or when it is locked.</td></tr><tr><td><strong>Require a TOTP validation</strong></td><td>Use a Password Manager app or Google Authenticator on your device to get access to the application when it starts or when it is locked.</td></tr><tr><td><strong>Override account name</strong></td><td>If you wish to use a different Devolutions Workspace or Google Authenticator account than the one previously linked to your Remote Desktop Manager account, you could override the account name but you will have to reconfigure it.</td></tr><tr><td><strong>Require Duo authentication</strong></td><td>Check this option to authenticate in your Remote Desktop Manager application using <em><strong>Duo authentication</strong></em>. Set it up using the Configure button below this option. Select the <em><strong>Duo automatic action</strong></em> by choosing None, Push, Phone or SMS.</td></tr></tbody></table>

#### Lock <a href="#lock" id="lock"></a>

<table><thead><tr><th width="289">OPTION</th><th>DESCRIPTION</th></tr></thead><tbody><tr><td><strong>Lock application when minimized</strong></td><td>Check this option to lock Remote Desktop Manager after minimizing it.</td></tr><tr><td><strong>Lock application when idle</strong></td><td>Check this option to lock Remote Desktop Manager after it has been idle for a certain time (define that period under this option).</td></tr></tbody></table>

#### Offline security <a href="#offline-security" id="offline-security"></a>

<table><thead><tr><th width="181">OPTION</th><th>DESCRIPTION</th></tr></thead><tbody><tr><td><strong>Default security</strong></td><td>Select to set the security to <em><strong>Default</strong></em>.</td></tr><tr><td><strong>Enhanced security</strong></td><td>The <em><strong>Enhanced security</strong></em> allows you to set up an offline password. The offline cache will then be encrypted. The password is required when switching to <em><strong>Offline mode</strong></em> only if the <em><strong>Prompt for offline access</strong></em> option is enabled.</td></tr><tr><td><strong>New password / Confirm password</strong></td><td>Available only with <em><strong>Enhanced security</strong></em>. Enter an offline password in the <em><strong>New password</strong></em> field, then enter it again in the <em><strong>Confirm password</strong></em> field.</td></tr><tr><td><strong>Prompt for offline access</strong></td><td>Available only with <em><strong>Enhanced security</strong></em>. If enabled, Remote Desktop Manager will ask if you want to access the application offline on startup.</td></tr></tbody></table>

#### Other <a href="#other" id="other"></a>

<table><thead><tr><th width="314">OPTION</th><th>DESCRIPTION</th></tr></thead><tbody><tr><td><strong>Enforce certificate revocation check</strong></td><td>Automatically checks against the CRL for revoked certificates</td></tr><tr><td><strong>Ignore application certificate errors</strong></td><td>Check this option to disable the application certificate validation. This is not recommended, as it would compromise confidentiality and integrity of communications between the client and the server and could expose the application to potential threats.</td></tr><tr><td><strong>Session events</strong></td><td><p>Enable session events that can perform powerful actions such as running an external program or script. These events represent a risk if they are modified by a malicious actor.</p><ul><li>Default (Enabled)</li><li>Enabled</li><li>Warn on risky events</li><li>Disable risky events</li><li>Disable all events</li></ul></td></tr><tr><td><strong>Reset known events</strong></td><td>Select to reset all <em><strong>known events</strong></em> configured on session entries.</td></tr></tbody></table>
{% endtab %}
{% endtabs %}


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.devolutions.net/rdm/ribbon-menu-bar/file/settings/security.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
