For the complete documentation index, see llms.txt. This page is also available as Markdown.

System settings

The System settings allow the administrators to control many global aspects of the Devolutions Server workspace and manage settings such as Password policy, Type availability, Vault permissions, and more.

Logs

The Logs section allows administrators to define the behavior of logs when certain conditions are met, such as when they are opened, closed, or when credentials are viewed. This is also where administrators can determine if and when it is appropriate to automatically mark logs as closed.

System message

In System message, administrators can set a message that to be displayed every time a user connects to the Devolutions Server workspace no matter which method is used (web interface, Remote Desktop Manager).

Notification

SETTINGS
DESCRIPTION

User subscriptions

Enable or disable user subscriptions.

Available actions

Determine which actions can be the object of notifications.

Notify for expiring entries

Set a time for notification of expiring entries.

Secure message

SETTINGS
Description

Permission

Determine whether secure messages can contain attachments or not.

Default expiration time

Set a default expiration time. This can be set independently when sending messages.

Ticketing service

SETTINGS
DESCRIPTION

Ticketing type

The ticketing system you wish to integrate with Remote Desktop Manager.

Ticketing server URI

The URL to reach your instance of Jira, e.g., https://yourorganization.atlassian.net/.

Username

The username of the account used to create the API token.

API token

The API token created beforehand. If this is not already done.

Default filter

This field is required; you must have at least one filter set as a Favorite in Jira. If you do not have a favorite filter already, head over to Jira, choose one, and then hit the Refresh button located in the field itself. Alternatively, you can head over to FileMy account settings, click on Jira under Ticketing service, and enable Assigned to me. This lets you filter tickets based on whether they are assigned to you or not.

Ticketing enforcement

Your preference between enforcing this ticketing service or not.

Type availability

This section allows administrators to control the availability of entries for the workspace. Each section contains different entry types you can choose to be available.

Advanced

Option

Description

Disable stack trace

Disable the stack trace of Devolutions Server in Remote Desktop Manager's error logs.

General

SETTINGS

Description

Allow user-specific settings

Allow user-specific settings to override the properties of an entry. Several settings can be overridden, such as the credentials or custom fields.

Allow entry states (locked, running, checked out)

Allow entries to have states assigned to them to reflect their current usage.

Force default status for new entries

Select a default status to apply to new entries.

Automatic check in after

Allow to automatically check in an entry after the defined time.

Add entry mode

Select if users are prompted to choose a template when creating a new entry. Select between:

  • Default (Template list including blank)

  • Template list including blank

  • Template list only

  • No template selection

Allow users to see user emails

User email addresses are visible to other users.

Allow portable license

Allow Remote Desktop Manager users to use their Remote Desktop Manager licenses across workspaces.

Force data/time format

Apply a single, predefined data/time format. Select one of the following options:

  • Default

  • US

  • Custom

Allow log comments editing

Enable the log comment editing for all users. Select the minimum length for the comment.

Maximum file size (MB)

Limit the file size to prevent overloading the workspace.

Allow favorites

Allow to flag entries as favorites.

Allow user vault

Allow users to use user vaults.

Log user vault activities

Include the logs of the user vaultfor all users of the workspace.

Allow "Linked (Vault)" credentials in user vault

Allow users to link vault credentials to their personal user vault.

Allow Macros/Scripts/Tools usage from user vault

Use Macros, Scripts, and Tools associated with entries in the user vault.

Disable user vault export

Prevent users from exporting their user vault data.

Allow system vault in user vault

This setting allows users to access entries from the System vault within their user vault.

Create vault with restricted access by default

Create vaults with a restricted access by default. Checking this option sets all the permissions of the root folder to Never as opposed to Inherited if the option is left unchecked.

Risky events

Configure risky events notifications.

Time Zone

Select the time zone you are currently in.

Days

Select which days the session is available for. Select between:

  • Any day: the session can be used any day of the week or weekend.

  • Weekdays: the session can be used only in the weekdays.

  • Weekends: the session can be used only the weekends.

  • Custom: manually select each day the session is available for.

Time of day

Select the hours which the session is limited to. Select between:

  • Any time: the session can be used at any hour.

  • Inherited: the session inherits the time of day setting from its parent (e.g., the vault or folder).

  • Custom: manually select the time frame the session is available for.

Tag configuration mode

Select how tags are managed for entries:

  • Custom: Tags are assigned manually on each entry, with no inheritance.

  • Custom + Inherited: entries automatically inherit the tags of their parent folder.

Default dashboard layout

Select the dashboard layout shown to users by default.

Application access

SETTINGS

Description

Enable application access in user groups

Enable the application access parameters in user groups properties.

Precedence

Set to Allow or Denied.

Application-specific

SETTING
DESCRIPTION

Enable synchronization by non-administrators

Enable users that are not administrators to activate the synchronization feature.

Recording server

SETTINGS
DESCRIPTION

Enable Devolutions Gateway recording

Activate Devolutions Gateway recording for the

Recording framerate

Set a framerate for the recording.

SSH recording type

Choose an SSH recording type between:

  • WebM

  • TRP

  • Asciicast

Enable Devolutions Gateway recording automatic cleanup

Allow Devolutions Server to delete Devolutions Gateway recordings after a set time.

RDM and password manager clients

General

SETTING

DESCRIPTION

Cache/offline expiration

Number of days before the offline cache expires. You must go online prior to the end of that period to re-validate the data. It is not recommended to set the Expiration to 0, as this will disable the expiration of the offline cache.

RDM

SETTING

DESCRIPTION

Disconnect workspace

Set application to lock:

  • On minimize: Lock the application when minimized in the taskbar.

  • On Windows lock: Lock the application on Windows lock.

  • On go offline: Lock application when switched to offline mode.

  • On idle: Lock the application when not in use after a set number of minutes.

  • On standby: Lock the application when in standby mode.

  • On close: Lock application when closed.

Maximum document size for offline synchronization (MB)

Maximum size of each document saved in the database that will be available for synchronization in offline mode.

Devolutions Password Manager browser extension

SETTINGS
DESCRIPTION

Enforce biometric lock or master password

Force the use of biometric lock or master password when connecting to the workspace in Devolutions Password Manager.

Force background lock

Activating this feature provides an additional layer of security by preventing unauthorized access to the Devolutions Server workspace in Devolutions Password Manager if a user switches to another task or window.

Force auto-lock after a delay of

When activated, the Devolutions Server workspace in Devolutions Password Manager will lock itself after a specified delay (e.g., 30 seconds) of inactivity.

Security

SETTING

DESCRIPTION

Disconnect workspace

Determine the disconnecting behavior of the Devolutions Server workspace. Choose between:

  • On idle: set an idleness time limit after which the workspace automatically disconnects.

  • On close: automatically disconnects when the app is closed.

Version management

SETTINGS

DESCRIPTION

Minimal version

Forces users of the workspace to use a minimal version of Remote Desktop Manager. Enter the entire version number (20XX.X.0.0) to force a specific version. Use this to disable connecting to the workspace with an older version.

Minimal version custom message

Enter a custom message for the minimal version notification.

Maximal version

Forces users of the workspace to use a maximal version. Enter the entire version number (20XX.X.0.0) to force a specific version. Use this to disable connecting to the workspace with a newer version.

Maximal version custom message

Enter a custom message for the maximal version notification.

Recommended version

Recommended version will be displayed to the user via the updater as the recommended version to be downloaded and installed.

Disable checks for updates

Disable the auto update notification message. Use this to manually update the application and prevent from getting notified when new versions are available.

Show custom minimal/maximal version message for administrators

Show the custom minimal/maximal version message to administrators.

Download URL

Use in conjunction with the minimal or maximal version, once a minimal or maximal version requirement is not met the system will prompt the user that the version is no longer valid and it will open the link (path/URL) to download the newer or older version.

Vault management

Default vault visibility

SETTINGS

DESCRIPTION

Public - Allow access requests

Users can request access to the vault.

Private - Invitation only

This setting makes the vault accessible only to users who are invited.

Default permissions

SETTINGS

DESCRIPTION

Permission

Set all the default permissions in the different tabs to Default, Custom, or Disallowed.

Grant access

Get access to the Batch grant access feature when selecting Custom in the Permission drop-down list. It allows you to set permissions and permission sets to multiple users, user groups, and/or application users at once.

My account settings

SETTING

DESCRIPTION

Forced save location

Choose to force or not My account settings to be saved in the database or locally.

Permission sets

SETTING

DESCRIPTION

Add "+"

Create a custom list of permissions that can be applied to the permissions of an entry/folder/vault through the Batch grant access feature. Some permission sets already exist by default.

Security settings

Option

Description

Allow Devolutions Password Manager browser extension autofill

Enable or disable Devolutions Password Manager browser extension autofill in Devolutions Server.

PAM vault management

Default vault visibility

SETTING
DESCRIPTION

Public – Allow access requests

PAM vaults are visible to all by default, and access to them can be freely requested.

Private – Invitation only

PAM vaults are hidden by default, users can only be granted access by administrators.

Default vault permissions

SETTINGS
DESCRIPTION

Permission

Set all the default permissions in the different tabs to Default, Custom, or Disallowed.

Grant access

Get access to the Batch grant access feature when selecting Custom in the Permission drop-down list. It allows you to set permissions and permission sets to multiple users, user groups, and/or application users at once.

Permission sets

SETTING

DESCRIPTION

Add "+"

Create a custom list of permissions that can be applied to the permissions of an entry/folder/vault through the Batch grant access feature. Some permission sets already exist by default.

Password management

SETTINGS

Description

Password history

Indicate the maximum saved password to keep in history.

Password strength calculator

Select the tool to use to analyze the password strength.

Disable password saving (shared)

Prevent users from saving passwords in entries.

Disable password saving (user-specific settings)

Prevent users from saving passwords in the User-specific settings.

Allow reveal credentials (if enabled in the entry)

Shows the credentials if the box "Allow show credentials (everybody)" is check inside the entry.

Disable password saving (tools)

Prevent users from saving passwords in the Tools tab of a session.

Allow password variables for all entries

Renders the $PASSWORD$ variable usable for this workspace.

Allow password variable in macros

Renders the $MACRO_PASSWORD$ variable usable for this workspace.

Default policy

Default password policy used by the system. Password policies can be created in Password policy.

Force default password policy

Force the usage of the default policy.

Forbidden password check

A verification of the password against the forbidden password list is done if enabled.

Password policy check

  • None: No policy will be used when creating a password.

  • Required: When a user creates a password, they will get a warning that the password does not respect the policy. The user cannot save the password.

  • Warning: When a user creates a password, they will get a warning that the password does not respect the policy. The user can save the password.

Compromised (pwned) check

Verify if the used passwords have already been exposed to data breaches.

Forbidden password

Forbidden passwords allow to create a list of blacklisted passwords to forbid usage in the application. Once set in this list, the password cannot be used anymore in the Devolutions Server workspace.

Option

Description

Case sensitive

Make the verification mode case sensitive.

Verification mode

Select the verification mode between: Contains: the password will be forbidden if it contains a word in the blacklist. Exact match: the password will be forbidden if it matches a word in the blacklist.

Import

Import a list from your computer (*.pwd or .txt).

Export

Export your forbidden password list. By default the list will be exported in a password file format (.pwd).

Users

SETTINGS
DESCRIPTION

Enable auto-deletion of users marked as "deleted"

Automatically delete the users marked as deleted, meaning that their user vaults are definitely deleted after the delay defined in the Delete after field.

RDM offline mode

Determine how users can interact with the workspace when using Remote Desktop Manager's offline mode.

Devolutions Password Manager offline mode

Determine how users can interact with the workspace when using Devolutions Password Manager's offline mode.

User type

Set the default user type for the workspace.

Language

Set a language for the workspace.

Allow user vault

Enable or disable the use of user vault in the workspace.

Devolutions Server user

Password policy

Setting
Description

Password policy

Select the password policy applied to accounts created directly in Devolutions Server (as opposed to domain, SSO, or Devolutions Cloud accounts). Select Custom to define the requirements below, or select an existing named policy.

Minimum length

Enforce a minimum number of characters required in the password.

Minimum lowercase characters

Enforce a minimum number of lowercase letters required in the password.

Minimum uppercase characters

Enforce a minimum number of uppercase letters required in the password.

Minimum number of numeric characters

Enforce a minimum number of digits required in the password.

Minimum symbols

Enforce a minimum number of special characters (symbols) required in the password.

Compromised password (pwned) check

Verify if the password has already been exposed in known data breaches. Select None, Warning, or Required.

Security

Setting
Description

Devolutions Server user password expiration (days)

Set the number of days before a Devolutions Server user's password expires and must be changed. A value of 0 disables expiration.

See also

Last updated

Was this helpful?