Terminal Server & RDS User Monitoring

See what each user does on Windows Terminal Server and Remote Desktop Services—activity, screens, and DLP—in one Web Console. Install the Grabber once on the host. Available in Cloud or On-Premise.

Why monitoring users on a Terminal Server is different

On a Terminal Server or RDS host, many people share one Windows machine. User monitoring has to follow each session—not just whether the server is healthy.

Office staff, remote workers, and thin-client users can all be logged on at the same time. If you treat the host like a single PC, their activity gets mixed together—or thin clients never get an agent at all.

With OctoWatch, you install the Grabber on the Windows TS/RDS host and attribute activity per user session: apps, websites, screens, keystrokes (Employee Monitoring edition), files, and DLP Rules. You review it in the same Web Console you use for workstations. For the full PC feature set, see Employee Monitoring. This page covers the shared-host setup.

Teams adopt Terminal Server and RDS to cut endpoint cost and centralize apps. The downside is concentration of risk: productivity, attendance, and insider threats all sit on the same host. Without per-session monitoring, you cannot tell who was idle on non-work sites, who copied files to USB, or who triggered a Rules hit on a busy afternoon.

Productivity on shared desktops

See apps, websites, and active vs. idle time for each user—even when many sessions share one Windows Server.

Insider risk & DLP

Rules can notify or block USB, file, and web misuse. Hits show up in Risks, with optional email alerts.

One platform—not a separate TS SKU

Same Grabber, profiles, and Web Console for PCs and Terminal Servers. Cloud or On-Premise.

Evidence when you need it

Day Viewer, screens, channel views, and scheduled reports support reviews and investigations.

User activity monitoring vs. RDS performance tools

Search results for “terminal server monitoring” often mix performance tools with employee monitoring. They solve different problems.

Question RDS performance / session admin RDP audit logs OctoWatch user monitoring
Primary data CPU, memory, latency, connection quality Logon, logoff, client IP, duration Apps, websites, screens, keystrokes, files, Rules hits
Typical action Shadow, disconnect, log off, fix slow sessions Show who connected and when Review Risks, investigate behavior, notify or block
Buyer RDS / EUC operations IT security / AD audit IT, security, and ops enforcing workplace policy
Install model Often agentless admin consoles Event log collection Grabber on the Windows TS/RDS host

OctoWatch is not a Terminal Services Manager replacement and not an RDS latency dashboard. It records what users do inside sessions and can enforce DLP Rules on the same host.

Install the Grabber on the host—not on every thin client

One install on the Windows Terminal Server or RDS session host covers concurrent users who connect over RDP or from thin clients.

You manage Grabber on the servers you already patch and back up. A new thin client only needs RDP access to the host; monitoring follows the session on the server. Assign users or Active Directory groups the same way you do on workstations—include or exclude people without redeploying thin clients.

Where it runs

Grabber installs on the Windows TS/RDS host that runs the sessions.

Thin clients

Thin clients and remote PCs are RDP endpoints. You do not need a separate agent on each thin client for host-side monitoring.

How you deploy

Manual install, Active Directory GPO, Installation Utility, or PsTools—same options as for workstations.

What operators see

Tracked users show up in the Web Console with per-session activity—not one mixed record for the server name.

Per-session architecture

Activity is tied to the user session. You can open Live, Day Viewer, Risks, or channel views for one person without guessing which concurrent RDP session produced an event—unlike host-level tools that only show “someone on SERVER01 was busy.”

Assign Settings, Rules, Timetable, and Computer profiles by user or group, just as you do for PCs. Tighten capture for high-risk roles on the same host and keep lighter profiles for others. Changes usually apply within about five minutes. Web Console operators are unlimited; licenses follow active tracked users.

Monitoring runs in stealth by default. For an open program, turn on Show monitoring warning under Settings Profile → Additional settings. A Timetable profile can limit recording to work hours when policy requires it.

One host

Windows Terminal Server or RDS session host

Many sessions

Concurrent RDP users monitored separately

One console

Same Web Console as workstation deployments

What you see in each RDS session

What you capture is set in the Settings Profile. Here is the shared-host view; linked pages cover each module in more detail.

Employee Monitoring includes the full channel set (keystrokes, Live, and deeper DLP). Time Tracking focuses on activity, apps and websites, and attendance-style views when you need session time without every investigative channel. Both editions use the same Grabber-on-host model.

You can also record email and IM, clipboard, web forms, and webcam or microphone when policy calls for it—still per user on the shared host. Search and Day Viewer help you reconstruct a specific day without browsing the entire farm.

Activity

Apps & websites

See which programs and sites each session uses, and how long people stay in them. Application & Website Monitoring

Visual

Screenshots & videos

Capture screen evidence per user for reviews and investigations—not one mixed feed for the whole server. Screenshots & Video

EMS edition

Keystrokes

Optional keylogger when you need typed content for investigations. Leave it off for lighter Time Tracking deployments. Keystroke Logging

Data paths

Files, USB & prints

Track file operations, removable media, and prints on the shared host. File, USB & Print

Live

Live view

Remote view and control from the Web Console when you need to see a live session. Live View & Remote Control

Time

Active & idle time

Session time via Activity, Chrono, and Timesheet—who was active vs. idle on the RDS host. Active & Idle · Timesheets

DLP and policy on a multi-user host

On a shared desktop, one weak USB or web policy affects everyone on the machine. OctoWatch uses a Rules Profile (notify or block) plus Computer Profile Internet Traffic Filtering and File Operation Filtering when you need enforcement. Hits appear in Risks and can email operators. About eighteen example rules ship by default; you adapt them to your shared-desktop policy.

Common policies: alert or block removable media, stop uploads to unapproved sites, flag sensitive keywords in keystrokes or web forms, and review clipboard or print spikes after hours. Because Rules attach to users and groups, you can protect finance sessions on the same RDS host that runs lighter call-center profiles.

For the full DLP story, see Data Loss Prevention, DLP Rules & Alerts, and Security Investigations.

Windows RDS and Terminal Services scope

OctoWatch monitors Windows Terminal Services and Remote Desktop Services with per-session Grabber monitoring. There is no separate Citrix module. If you run Microsoft RDS/TS multi-user hosts, this is the supported path. If you need a dedicated Citrix Virtual Apps and Desktops product, do not expect a Citrix Ready package here.

Grabber is Windows-only—including Terminal Servers and RDS. There is no Mac, Linux, or Android Terminal Server agent.

Reports, operator access, and multi-host setups

Many Terminal Server tools stop at local logs. OctoWatch uses the same reporting and access model for PCs and session hosts.

Reports. Web Console reports and report delivery can send scheduled activity to managers—attendance-style views, productivity, and risk summaries, based on what you enabled.

Operator access. Web Console operators are unlimited and do not use licenses. With Profiles & Access, a supervisor can review a department without seeing the entire RDS farm.

Multiple hosts. Install Grabber on each Windows TS/RDS host. Activity still lands in one Web Console—whether you run a single session host or several servers. Details: Reports & Analytics.

Who it is for

Built for teams that run shared Windows session hosts—not for teams that only need RDP latency graphs.

RDS and IT admins

Install once per host, keep users attributed correctly, and use one console for PCs and session hosts.

Security and insider risk

Rules, Risks, and session evidence when a shared desktop is part of an investigation.

Shared-desktop operations

Call centers, branch thin clients, and contractor RDS pools where many users share one server.

Regulated On-Premise buyers

Keep monitoring data on your server when Cloud is not an option. See On-Premise.

How it works

Three steps from an empty host to per-user visibility in the Web Console.

1

Choose Cloud or On-Premise

Create an account at app.octowatchdlp.com, or install Server and the database on your network for On-Premise.

2

Install Grabber on each TS/RDS host

Deploy the agent on Windows Terminal Server or RDS session hosts—manual, GPO, Installation Utility, or PsTools.

3

Assign profiles and monitor

Apply Settings, Rules, Timetable, and Computer profiles. Review users in Live, Analytics, Risks, and channel views.

Common scenarios

Where shared Windows session hosts show up in day-to-day work.

Call center / shared RDS desks

Many agents on one host. Keep productivity and policy reviews per person, not per server name. Related: Call Center Monitoring.

Branch thin clients

Install Grabber on the session host. Thin clients connect over RDP; you do not need a separate endpoint agent for that host.

Contractors on corporate RDS

Give external users a published desktop and still apply Rules and Settings profiles to their sessions.

Investigation on a multi-user host

After a Risks hit, open Day Viewer, screens, and channel data for the right user without mixing neighboring sessions. See Insider Risk Management.

Mixed PC + Terminal Server estate

One platform for laptops and RDS hosts—same console, same profile model, floating licenses by active tracked users.

Time Tracking on session hosts

Need attendance and app time without full EMS depth? Start with Time Tracking on the pricing calculator, then expand modules later.

Terminal Server vs. workstation monitoring

Same product, different install target. Use this table when you decide where the Grabber belongs.

Topic Workstation Terminal Server / RDS
Install target Each Windows PC Each Windows TS/RDS host
Session model Usually one interactive user Many concurrent sessions on one host
Thin clients Not the main pattern RDP clients; agent stays on the host
Licensing Active tracked users Same—active tracked users (floating)
Where to read more Employee Monitoring This page

Cloud vs. On-Premise for RDS hosts

Cloud: Grabbers send encrypted data to the OctoWatch distributed cloud. You work in app.octowatchdlp.com. That is usually the fastest way to start a trial. You still install Grabber on each TS/RDS host—only where the data is stored changes.

On-Premise: Server and MS SQL stay on your network. Agents talk over LAN or a white IP. Choose this when session hosts and monitoring data must stay inside your perimeter. After Server install, configure Admin Console, then deploy Grabbers. Optional Recognition Server (OCR) is a separate On-Prem add-on and should not run on the same machine as Server. See Cloud and On-Premise.

Avoid unstable VPN tunnels for Grabbers—drops can interrupt data delivery. Keep a reliable path to the Cloud console or On-Prem Server, especially when many concurrent sessions upload screenshots and activity from one host.

Unlike on-premises-only Terminal Server products, OctoWatch covers PCs and RDS hosts with both deploy models. You do not buy a separate “TS Monitor” edition just for session hosts.

What you need Typical dedicated TS tool OctoWatch
Install model Often a separate TS product Same Grabber as workstations on each TS/RDS host
Deploy Usually on-premises / self-hosted only Cloud trial or full On-Premise Server
DLP depth Alerts and logging; blocking varies Rules Profile + Computer Profile filtering + Risks
Citrix Often marketed as Citrix Ready / XenApp Windows Terminal Services / RDS only—no Citrix module
Mixed estate May need a second product for PCs One console for PCs and session hosts

Choose OctoWatch when you want Microsoft RDS/TS user monitoring in the same employee monitoring and DLP platform as your Windows PCs—not when you need a Citrix-certified Virtual Apps appliance.

Licensing for concurrent sessions

OctoWatch licenses by active tracked users—floating, not tied to a PC or server SKU. Ten people who rotate across two RDS hosts count as the users you actively track, not as “two servers.” Web Console operators are unlimited and do not use licenses. Blocked users do not use licenses.

Some vendors price Terminal or Citrix monitoring per server. OctoWatch follows how many people you track, which fits high session density better when finance cares about headcount, not server count. Compare Time Tracking vs. Employee Monitoring and Cloud vs. On-Premise on the pricing calculator.

FAQ

Common questions from IT and security teams evaluating terminal server monitoring software.

Do I install the agent on each thin client?

No. Install the Grabber on the Windows Terminal Server or RDS host. Thin clients connect as RDP sessions; host-side monitoring covers those users.

Can OctoWatch monitor multiple concurrent RDP sessions on one server?

Yes. That is what per-session monitoring on Windows TS/RDS is for. Each user session is tracked separately in the Web Console.

Is this the same as RDS performance or Terminal Services Manager tools?

No. Those tools focus on session health, shadowing, and resource metrics. OctoWatch focuses on user activity, visuals, and DLP Rules inside sessions.

How is this different from OctoWatch employee monitoring for PCs?

Same product and console. On PCs you install Grabber per workstation; on TS/RDS you install on the shared host for concurrent sessions. See Employee Monitoring for the full PC feature story.

Does OctoWatch include a Citrix module?

No. There is no separate Citrix module. OctoWatch covers Windows Terminal Services and Remote Desktop Services with per-session monitoring.

Does monitoring run in stealth? Do users see a notice?

Monitoring runs in stealth by default. Turn on Show monitoring warning in Settings Profile → Additional settings for transparent mode. You can also let users enable or disable monitoring. We do not claim Task Manager invisibility.

Can we apply DLP rules on Terminal Server sessions?

Yes. Rules Profile notify or block actions apply to tracked users on the host. Use Computer Profile filtering for Internet or file-operation enforcement. Hits appear in Risks.

Cloud or On-Premise for RDS hosts?

Both are supported. Cloud is usually the fastest trial path; On-Premise keeps Server and data on your network. Choose based on residency and network design—not a separate TS product.

Is the Web Console the same for workstations and Terminal Servers?

Yes. One Web Console for overview, Live, analytics, Risks, and channel views—whether the Grabber runs on a PC or a TS/RDS host.

Can we monitor several RDS hosts in one place?

Yes. Install Grabber on each Windows TS/RDS host. Users and Risks consolidate in the same Web Console—whether you run one session host or several.

Is workplace monitoring on Terminal Server legal?

On company-owned servers, monitoring is usually lawful when you follow local employment and privacy rules—typically written notice and an acceptable-use policy. Use transparent mode (Show monitoring warning) when policy requires disclosure. Ask your attorney for your jurisdiction; see also GDPR Compliance.

Where can I read system requirements?

See the user guide for Grabber and Server requirements. Grabber: Windows Vista or later. On-Prem Server: Windows plus MS SQL Server 2014 or later. Expect roughly 200–400 MB of traffic per tracked user per day, depending on capture settings.

Ready to monitor users on Windows Terminal Server or RDS? Start a free trial, review pricing, or contact support. Product documentation: User guide.