RDP Proxy Session Log Control
Kron PAM allows privileged users to view Session Logssession logs. If a user is authorized to view session logs, they can access an RDP session’s video records, OCR logs, key logs, and command logs. Some properties can be configured for user groups (see User Group Properties) to control the users’ ability to view RDP session video and command logs:
- Navigate to Users > User > User Groups.
- Open the Users tab and click Search to list all User Groups.
- Choose the desired User Group, and select Add New Properties.
- Add the parameters below to configure.
Parameter | Definition |
|---|---|
sc.command.log.disabled | To enable/disable the privilege to view command logs for users who can see session logs. The default value is “false”. If the parameter is set as “true”, the users in the related user group are unable to view the command logs. |
sc.session.video.record.disabled | Prevents session video recording. Default value is false. When set to true, session videos will not be recorded. This parameter controls recording itself, not viewing permissions. |
sc.ocr.log.disabled | To enable/disable the privilege to view OCR logs generated during RDP sessions. The default value is “false”. If the parameter is set as “true”, the users in the related user group are unable to view the OCR logs. |
sc.keylog.log.disabled | To enable/disable the privilege to view key logs generated during RDP sessions. The default value is “false”. If the parameter is set as “true”, the users in the related user group are unable to view the keystroke logs. |