Set a Remote Desktop Timeout

You may wish to set a timeout for users of Remote Desktop. Set a Remote Desktop connection timeout to avoid accidental or deliberate changes to Windows server content and settings.

Consider a user of Remote desktop who isn’t active, maybe they have left the RDP window and are preoccupied with other activities, or perhaps working within another window on their computer. The content could now be liable to accidental changes within the remote desktop window.

Just as with any computer you set a timeout so that your colleagues or family/friends can’t make mischief, so a timeout to restrict Remote Desktop access can be applied.

If there is no activity within the Remote Desktop connection after a prescribed time then the connection can be closed, thus avoiding intended changes.

To set the timeout for Remote Desktop.

From the start menu click on the windows icon and begin typing gpedit. This will show a popup window of search matches. Click on the entry for Edit Group Policy.

The Local Group Policy Editor window has a tree menu on the left with results for the menu item selected in the right hand pane.

Using the tree menu select:

Computer Configuration > Administrative Templates > Windows Components > Remote Desktop Services > Remote Desktop Session Host > Session Time Limits.

From the right hand pane double click on the entry for

Set time limit for active but idle Remote Desktop Services sessions policy

In the upper part there are radio buttons to select

  • Not configured
  • Enabled
  • Disabled

Select the enabled option

Below this there are two panes:

  • Options
  • Help

Within the Options pane there is a single option available: Idle session limit. From the drop down list select the timeout which appeals to you. A balance between closing the remote desktop link promptly when there is no activity and not too long to present a security risk.

Having made your timeout selection click on the OK button in the bottom right hand corner of the window.