General Policy Group
This article describes the policies that appear for a host in the General Policy Group.
cla140
You can modify policy parameter values by double-clicking a policy to display the Setting Properties dialog. The following policies for the host appear in the General policy group and pane.
For all policy settings that specify a time period, the units are seconds.
- Abnormal disconnect action:This parameter specifies the action that the host takes after an abnormal disconnect from a viewer.Default: Lock the workstation. Valid values are as follows:
- Do nothing
- Reboot computer
- Logoff current user
- Forcibly reboot computer
- Forcibly logoff current user
- Lock the workstation
- Allow printer driver installation:This parameter indicates whether the Remote Control viewer is permitted to install required printer drivers. If the printer redirection is enabled, printer drivers are automatically installed when a viewer connects to a printer.Default: True
- Always disable screensaver:This parameter indicates whether the screen saver on the desktop of the host user is always disabled.Default: False
- Always disable wallpaper:This parameter disables the wallpaper and any embedded web pages on the desktop of the host user. You can set this parameter and other visual effects to True to improve performance. The performance increases by decreasing the amount of video data that the host transmits. This setting overrides the corresponding viewer setting.Default: False
- Always encrypt:This parameter encrypts all messages (keyboard or video) between the host and viewer regardless of the viewer setting.Default: FalseIf the target host is operating in FIPS‑preferred or FIPS‑only mode, this option has no effect. The data is always encrypted using FIPS‑compliant cryptography.
- Always hide window contents when dragging:This parameter controls whether the host disables the visual effect in which the contents of windows are displayed as the host user drags them around the desktop. You can set this parameter and other visual effects to True to improve performance. The performance increases by decreasing the amount of video data that the host transmits. This setting overrides the corresponding viewer setting.Default: False
- Animate connection icon:This parameter specifies that the host icon in the taskbar become animated when the host is connected to the viewer.Default: <locally managed>
- Connection dialog text:This parameter names the fully qualified path of a plain-text file containing EULA or other explanatory text. The text is displayed on the login confirmation dialog of the Host. This dialog appears when a viewer connects to a host that is configured to request confirmation from the end user before a remote control session can be established. The file that is referenced here must be present on the host computer. If the text file is on a network share, a UNC network path can be specified. The permissions of the network share must permit read access to the end users who confirm the connection request.Default: empty
- Defer reboot retries:This parameter specifies the number of times a user can postpone, or can defer, a manager-initiated reboot.Default: 1
- Defer reboot time:This parameter specifies the amount of extra time that a user deferral can add to the wait time for a manager-initiated reboot.Default: 300
- Enable chat:This parameter enables a chat session from a viewer if set to True and the viewer user also has this permission. If False, then no chat session is permitted to the host regardless of the viewer user permissions.Default:True
- Enable classroom:This parameter enables a classroom style connection from a viewer if set to True and the viewer user also has this permission. If False, no classroom style connection is permitted to the host regardless of the viewer user permissions. Classroom connections permit a "teacher" host to be connected to by a classroom of "pupil" viewers. Only one viewer has control that can be passed from viewer to viewer by the host.Default: True
- Enable exclusive control:This parameter enables an exclusive connection from a viewer if set to True and the viewer user also has this permission. If False, an exclusive connection is not permitted regardless of the viewer user permissions. An exclusive connection means that only one viewer at a time can connect. The host mouse and keyboard are disabled. Only the viewer user has control of the host computer.Windows: In Secure Control and Exclusive Control modes, the Ctrl-Alt-Del key sequence cannot be blocked, because it is a low-level security feature of the operating system. The host user cannot interfere with remote control operations by repeatedly pressing Ctrl-Alt-Del to switch to the login desktop or to open the Task Manager. However, after issuing a Ctrl-Alt-Del, the host user will still not have keyboard or mouse control of the desktop.Linux: This option prevents other users from connecting when there is a session in progress; the mouse and keyboard of the Host are not disabled.Default: True
- Enable lock:This parameter indicates whether the host user can lock the host. This policy setting is used during security alerts to "lock down" remote control. If True, the host closes all connections and stops listening for more. In a centrally managed installation, the domain manager can send the lock command even if this setting is False. This policy setting controls only whether the host user can lock.Default: False
- Enable lock desktop:This parameter enables the viewer to lock the desktop of the host computer. This parameter also applies to locks initiated by disconnections of any type, normal or abnormal, when the operating system supports locking the workstation or desktop. If False, the host user can refuse lock requests.Linux: The disconnect and lock actions lock only the operating systems that support this feature. For example, in the GNOME GUI environment on Linux, it is not possible to lock the desktop of a root user.If either the Enable lock desktop or Enable logoff policy is set to False, the related normal and abnormal disconnect options are also affected.For example, the default abnormal disconnect action for a remote control session is to lock the desktop of the Host. If you disable the lock feature of the host, the abnormal disconnect action does not lock the desktop of the Host. As a result, the Disconnect and Lock option is not available in the viewer.Default: True
- Enable logoff:This parameter enables the viewer to log out the host computer. This parameter also applies to log outs that the disconnections of any type, normal or abnormal initiate. If False, the host user can refuse log out requests.Default: True
- Enable manual recording:This parameter enables users to manually record desktop activity independently of any remote control sessions.Default: True
- Enable meeting:This parameter enables meeting mode remote control connections from any viewer, with or without explicitly defined user permissions. With these requests, a connection confirmation dialog appears displaying the user name of the viewer and computer name. The host user can then accept the connection or deny it. If the Require meeting confirmation password policy is also set to True, then Remote Control prompts for the password of the currently logged on user before permitting a meeting session to proceed. If False, a request by the viewer for a meeting mode connection is rejected and a Security validate permissions failed event is raised.Default: True
- Enable printer redirection:This parameter indicates whether host printing can be directed to a printer of the Viewer.Default: True
- Enable reboot:This parameter enables the host to reboot the host computer when requested by a viewer or domain manager. This parameter also applies to the reboots initiated by disconnections of any type, normal or abnormal.Default: False
- Enable secure control:This parameter enables a secure connection from a viewer user if set to True and the viewer user also has this permission. If False, the host does not permit any secure connections from viewers regardless of the viewer user permissions.Default: True
- Windows: In a secure mode connection, only one viewer at a time is permitted to connect. The host user cannot use the host computer because the screen, mouse, and keyboard are all disabled. A secure control message screen is displayed; this screen is configurable and displays a static HTML page.
- Windows: In Secure Control and Exclusive Control modes, the Ctrl-Alt-Del key sequence cannot be blocked, because it is a low-level security feature of the operating system. The host user cannot interfere with remote control operations by repeatedly pressing Ctrl-Alt-Del to switch to the login desktop or to open the Task Manager. However, after issuing a Ctrl-Alt-Del, the host user will still not have keyboard or mouse control of the desktop.The secure control mode uses multiple-monitor operating system features with which some versions of the Intel Display drivers are not fully compatible. If Remote Control detects a driver compatibility problem, it does not display the Secure Control Message, “Remote Control Session In Progress.” Instead, the host screen becomes black. Using the latest display drivers from Intel resolves the problem.
- Linux: In a secure mode connection, a new login session with a hidden desktop is created that only the viewer can see. Remote control connections to Linux hosts in this mode do not control the desktop of the currently logged on user. Multiple concurrent secure control connections are supported, and each connection creates a separate hidden desktop.The secure control feature in Linux requires the Virtual frame buffer X server (Xvfb) utility. If the utility is not present, the secure control connections are refused. This utility can typically be installed from the Linux installation media, if not already installed by default.Mac OS X: The secure control feature is not supported.
- Enable shared control:This parameter enables a shared control connection from a viewer user if set to True and the viewer user also has this permission. If False, the host does not permit any shared control connections from viewers regardless of the viewer user permissions. In a shared mode connection, both the host and viewer user have control of the host computer. Any number of viewers can connect.Default: True
- Enable smart card redirection:This parameter indicates whether the smart card redirection of user credentials from a viewer to a remote host computer is enabled.Default: True
- Enable stealth view:This parameter enables a stealth view connection from the viewer user if set to True and the user of the viewer also has this permission. If False, the host does not permit any stealth view connections from viewers regardless of the viewer user permissions. In a stealth mode connection, the host retains control of the host computer but is unaware that a connection has been made. Normally, the host icon changes to indicate that a connection is in progress and the host menu shows the connections. Any number of viewers can connect.Default: True
- Enable the reception of files from viewers:This parameter indicates whether the host can receive files from viewer users. If False, the host does not receive any files that are sent from viewers. To receive files, the viewer user permission, Send Files, must also be specified.Default: True
- Enable the sending of files to viewers:This parameter indicates whether the host can send files to viewers. If False, the host does not send any files to viewers regardless of the viewer user permissions. To send files, the viewer user permission, Receive Files, must also be specified.Default: True
- Enable view:This parameter enables a view-only connection from a viewer user if set to True and the user of the viewer also has this permission. If False, the host does not permit any view-only connections from viewers regardless of the viewer user permissions. In a view mode connection, the host retains control of the host computer and the viewers can only see. Any number of viewers can connect.Default: True
- Host:. Always disable menu and window animationThis parameter controls whether the host disables the menu and window animation effects that are provided by Windows. You can set this parameter and other visual effects to improve performance by decreasing the amount of video data that the host transmits. This setting overrides the corresponding viewer setting.Default: False
- Host: Always disable visual styles:This parameter controls whether the host disables the visual styles and effects that Microsoft Windows provides. The animation effects that the common controls, the taskbar, and themes use are included. You can set this and other visual effects to improve performance. The performance is increased by decreasing the amount of video data that the host transmits. This setting overrides the corresponding viewer setting.Default: False
- Inactivity timeout:This parameter specifies the inactivity timeout period in seconds, that is, the maximum time a viewer can be connected to a host and can be inactive before a timeout occurs. Only controlled remote control sessions are subject to inactivity timeouts. The inactivity timer does not affect View-only sessions. If set to 0 (zero), the inactivity timer is disabled.Default: 0
- Login timeout:This parameter specifies the login timeout period in seconds, that is, the maximum time a login from a viewer to a host can take before a timeout occurs. This period includes the time that is taken to answer a confirmation dialog (if Require local confirmation is set).Default: 120
- Normal disconnect action:This parameter specifies the action the host computer must take after a normal disconnect from a viewer user.Default: Do nothing. Valid values are as follows:
- Do nothing
- Reboot computer
- Logoff current user
- Forcibly reboot computer
- Forcibly logoff current user
- Lock the workstation
- Override confirm at login:When the Require local confirmation host property is True and a viewer connects, the host user is prompted to confirm the connection. However, if the Windows login window is visible, the host refuses by default to connect because it assumes that nobody is available to confirm the connection. If Override confirm at login is set to Allow, the local host user confirmation requirement is overridden and the host accepts the connection. If Override confirm at login is set to Prompt, the connection confirmation dialog appears. If this setting is Deny, the Require local confirmation setting remains valid. If a meeting mode connection is requested and the Windows login window is visible, the local host user confirmation requirement is not overridden and the connection confirmation dialog appears independent of the Override confirm at login setting.Default: Deny
- Require local confirmation:When a viewer connects regardless of the viewer user permissions, a local confirmation from the host user is required. If False, the viewer user permissions control whether confirmation is required. This feature can be used with Require local confirmation password.Default: False
- Require local confirmation password:This parameter indicates whether a local confirmation password is required. When the Require local confirmation host property is True and a viewer connects, the host user is prompted to confirm the connection by clicking Yes. However, if the Require local confirmation password property is also set to True for increased security purposes, Remote Control prompts for the password of the currently logged on user before permitting the connection to proceed.Default: False
- Require meeting confirmation password:This parameter indicates whether a meeting confirmation password is required. The Remote Control prompts for the password of the host user before permitting a meeting session to proceed in the following scenarios:
- The Enable meeting host property is set to True.
- The Require meeting confirmation password property is also set to True.
Default: True
- Secure Control Message URL:This parameter specifies the full URL of a static HTML page to be shown on the host during secure control sessions. This setting is effective only if the Show HTML Secure Control Message policy is enabled. The URL must point to a page that does not require scripts or active content to display correctly. If the page is hosted on a web server, it must permit anonymous access. Leave this setting empty for a default message.Example:http://myserver/rcmessage.htmlDefault: empty
- Show HTML Secure Control Message:This parameter enables the display of a static HTML page to be used for the "Remote Control Session in Progress" message that is shown on the host computer during Remote Control secure control connections.Default: True
- Start locked:This parameter indicates whether the host always starts up in a locked state. This parameter is useful in situations when the user wants to be able to decide whether someone can connect to the host computer. To enable the user to unlock, ensure that the Enable lock property is also set to True. If False, only a domain manager can unlock the host.Default: False
- Time before logoff:When the host receives a log out request from the viewer when it disconnects, this policy setting specifies the time in seconds to wait before the host logs out. A countdown dialog is displayed starting now.Limits: 1–3000Default: 30
- Time before reboot:When the host receives a reboot request from the domain manager or from a viewer when it disconnects, this policy setting specifies the time in seconds to wait before the reboot takes place. A countdown dialog is displayed starting now.Limits: 1–3000Default: 30
- Use XDMCP for Secure Control login(Linux): This parameter specifies that X Display Manager Control Protocol (XDMCP) be used to display the login screen for a remote control session in secure mode.Local XDMCP connections must be enabled in your display manager configuration before setting this option.Default: False
- Record all sessions on viewer:This parameter specifies whether to automatically record all the RC Host sessions on the Viewer side. This parameter overrides other recording parameters that are specified on the Viewer.Values: True/FalseDefault: False
- Enable receiving of clipboard data from viewers:This parameter specifies whether the clipboard data is received from the RC Viewer.Values: True/FalseDefault: True
- Enable sending of clipboard data to viewers:This parameter specifies whether the clipboard data is sent to the RC Viewer.Values: True/FalseDefault: True
- SysTray Notification:The time in seconds that the 'Connection Established dialog box' text is displayed on the host desktop. Limits: 0–60 Default:5
- Connection Established dialog box Text:The text to be displayed in the session connection dialog box. The characters may also include the following variables: $Viewer_Name, $Vewer_IP, and $Vewer_User. Limits: 250 Characters
- Connection Ended Dialog box Text:The text to be displayed in the session terminated dialog box. The characters may also include the following variables: $Viewer_Name , $Vewer_IP, $Vewer_User. Limits: 250 characters
- Connection Ended message box displayed:The host can configure the connection establishment and connection ended messages. If the ConnectionEndedDlgBoxdisplayed value is 0, the default text is displayed. If the ConnectionEndedDlgBoxdisplayed value is 1, the text configured in 'ConnectionEstbDlgBoxText' and 'ConnectionEndedDlgBoxText' is displayed.