Adding and preparing hosts
A host is a Windows machine that runs the applications and desktops you publish. This page explains how to add one, how DartRelay checks whether it is ready, and how it can prepare the host for you remotely.
What a host is, and why it needs preparing
Everything a user opens in the portal actually runs on a host. When somebody clicks an application, DartRelay opens a Remote Desktop session to the host on their behalf and shows that session inside the browser tab. The host does the work; DartRelay delivers the picture.
Most hosts are Windows Server machines. To let several people work on one at the same time, Windows Server needs the Remote Desktop Session Host role. Without it, Windows Server runs in a mode meant for administering the machine, which allows only two connections at once. A desktop published from such a host works for the first two people and then refuses everyone else. This is the single most common reason a new installation "works in testing and fails on Monday morning", so DartRelay checks for it on every host and tells you plainly.
A Windows 10 or Windows 11 desktop edition can be added as a host, but it allows only one session at a time. DartRelay recognises a desktop edition and says so rather than offering to install a role that does not exist there.
Nothing is installed on the host
DartRelay is agentless. There is no DartRelay software, service or agent to install on a host, and nothing to keep up to date there. Instead, you give DartRelay a management account for each host, and it uses Windows' own remote administration features to read the host's state and, when you ask it to, to change it.
It helps to know exactly what DartRelay touches, because you are handing it an administrator account:
| What DartRelay does | When | How |
|---|---|---|
| Reads the Windows edition, whether the Session Host role is installed, whether a restart is pending, and Remote Desktop licensing status | When you press Connect, and quietly afterwards while a restart is pending | The host's administrative file share and remote registry, falling back to Windows Remote Management |
| Reads the Start Menu, installed programs and published RemoteApp entries, and the icons inside program files | When you browse a host for applications | Read-only, over the administrative file share |
| Installs the Remote Desktop Session Host role, and optionally restarts the host | Only when you press Install RD Session Host role | A one-off scheduled task that runs once, then deletes itself |
| Adds the domain's Domain Users group to the host's Remote Desktop Users group | During the role install (ticked by default), or when you press Let domain users sign in | The same one-off task |
| Registers each application you publish in the host's RemoteApp list, and removes it again when you take it away | Every time you save an app group | Remote registry. Only entries DartRelay created itself are ever changed or removed |
| Registers the Windows sign-out program so a shared session can be signed out when its last tab closes | During the role install, and the first time a shared Windows login is used on the host | Remote registry |
| Applies the host's session settings (one or several sessions per account, and how long disconnected sessions are kept) | When you save those settings on the host page | Local policy on the host, followed by a policy refresh |
| Signs out disconnected Windows sessions | Only when you press Sign out disconnected sessions | The one-off task |
DartRelay never switches on RemoteApp list enforcement, never removes RemoteApp entries somebody published by hand, and never runs a command it was not built with: every script it sends is fixed. Every role install, sign-in grant and session sign-out is recorded in the audit log with the administrator who asked for it. See Logs and audit.
The checks that read the host's registry, browsing for applications, and registering published applications need DartRelay itself to be installed on Windows. On a Linux installation, Connect and the role install use Windows Remote Management over HTTPS instead, and that route needs an HTTPS listener on each host (see What the host must allow).
Before you begin
- A management account for the host. It must be a member of the host's local Administrators group. A domain account works (
CORP\svc-dartrelayorsvc-dartrelay@corp.example.com), and so does a local account on the host (.\Administrator). The.\prefix tells DartRelay the account is local to the host, even when the host belongs to a domain. - Network access from the DartRelay server to the host on the ports in the next section.
- The host's name or IP address, as the DartRelay server can reach it.
What the host must allow
| Port | Used for | Notes |
|---|---|---|
| TCP 3389 | The Remote Desktop sessions themselves | Needed for every host. Allow it from the DartRelay server only; there is no need to expose it to the internet. |
| TCP 445 | Reading the host's state, browsing for applications, registering published applications | The administrative share (C$) and the Remote Registry service must be reachable. |
| TCP 135 and the dynamic RPC ports | Running the one-off task that installs the role | Windows keeps this closed by default. Open it with one command on the host, or the equivalent Group Policy: Enable-NetFirewallRule -Group '@FirewallAPI.dll,-33252' (the Remote Scheduled Tasks Management rule group). |
| TCP 5986 | Windows Remote Management over HTTPS, the fallback route | Optional when DartRelay runs on Windows. winrm quickconfig on its own does not create this listener; use winrm quickconfig -transport:https. |
Add a host
- Open the Hosts page. In the console, go to Catalog → Hosts. The list shows every host with a Readiness column.
- Start a new host. Click the button to add a host. The new-host form opens.
- Give the host a name. This is the name administrators see in the console; pick something people recognise, such as "Finance RDS 1".
- Enter the host's address. Type the host name or IP address the DartRelay server uses to reach it.
- Fill in the domain if the host needs one. For a host in an Active Directory domain, enter the domain's short (NetBIOS) name. For a stand-alone host that is not in a domain, enter the host's own computer name. See The Domain field below.
- Enter the management account. Type the username and password in the Management account panel.
- Press Connect. DartRelay contacts the host with that account and reports what it found: the Windows edition, whether the Session Host role is installed, and anything that needs attention. If the password is wrong, it says so here, before you have saved anything.
- Save the host. The result of the check is saved with the host, so the host page opens already showing it. If you change the address after pressing Connect, the result is withdrawn, because it described a different machine; press Connect again.
The role cannot be installed from the new-host form. Installing a Windows role, and possibly restarting a host, is the most consequential thing DartRelay does, so it is only offered on a host that has been saved. Continue on the host's own page.
The Domain field
When DartRelay opens a session with a saved account, Windows needs to know which account database the name belongs to. The host's Domain field supplies it when the account itself does not:
- A saved account written as
NAME\userusesNAME, whatever the host's Domain field says. - Otherwise the host's Domain field is used.
- When the host is the same machine DartRelay is installed on, and nothing else gives a domain, DartRelay uses the machine's own name.
For a stand-alone (workgroup) host with local accounts only, put the host's computer name in the Domain field. Windows refuses a local account with an empty domain when Network Level Authentication is on, and the symptom is the unhelpful "Server refused connection (wrong security type?)".
Readiness: what the host page tells you
Open a host from the list to see its page. The Management account panel at the top holds the account, the Connect button and the readiness verdict, because the verdict describes what that account found.
The same verdict also appears, read-only, on the pages where you publish desktops and applications from that host, with an Open host settings → link for administrators who are allowed to manage hosts. You do not have to remember to check: if a host will refuse the third user, the page you are publishing from says so.
| What you see | What it means | What to do |
|---|---|---|
| ✔ … has the Remote Desktop Session Host role | The host is ready for several people at once. | Nothing. Publish from it. |
| No RD Session Host role | The host is in administration mode and accepts two connections. | Install the role (next section). |
| ⚠ Restart needed | The role is installed, but Windows has not restarted since, so it is not in effect yet. The host still refuses the third user. | Restart the host. The warning clears by itself the next time any page showing the host is opened. |
| A desktop edition message | The host runs Windows 10 or 11, which allows one session. | Use it for a single user, or use Windows Server. |
| Connected, but the role state could not be determined (dark orange) | The account worked, but neither route could read the role. | Check that the Remote Registry service is running, or enable the HTTPS management listener, then press Connect again. |
| This host has not been checked (dark orange) | Nobody has pressed Connect yet. | Press Connect. |
| A Remote Desktop licensing line | See Remote Desktop licensing. | Configure a licence server before the grace period ends. |
The verdict is stored and is not re-checked on a timer. If somebody changes the host by hand, press Connect again to refresh it.
Remote Desktop licensing
Once the Session Host role is installed, Microsoft requires a Remote Desktop Services client access licence (RDS CAL) for every connecting user or device, after a grace period of 120 days. When the grace period ends with no licence server configured, Windows refuses everyone except administrators. What a user sees is a connection error about the security type, which points nowhere near licensing.
To catch this before it happens, the readiness check reads the host's licensing mode, the days left in its grace period, the licence servers it is configured to use, and whether it can reach them. The host page shows a plain sentence, such as a countdown of days left, or a warning that the configured licence server cannot issue licences, with what to do about each case. DartRelay does not sell or manage Microsoft licences; it only tells you what the host reports.
Install the Remote Desktop Session Host role
If a host has no Session Host role, DartRelay can install it for you.
- Open the host's page from Catalog → Hosts.
- Make sure the management account is saved and Connect succeeds. The install panel appears when the role is missing.
- Leave Let the domain's users sign in ticked unless you manage Remote Desktop access yourself. See Who may sign in through Remote Desktop.
- Decide whether DartRelay may restart the host. Restarting is a separate tick box. If you leave it clear, the role is installed and the host shows ⚠ Restart needed until you restart it at a time that suits you.
- Press Install RD Session Host role. A progress bar and an elapsed-time counter run while Windows installs the role. This usually takes several minutes, and Windows reports no percentage, so the counter is the honest measure. Leave the page open.
- Read the result. If you allowed a restart, the host goes down about a minute later and, once it is back, the next page that shows it confirms the role. If you did not, restart it yourself; the warning clears on its own afterwards.
If you have restarted and the host still reports no role, the panel offers the install again under Already restarted, and still no role?. Running it again is safe: a host that already has the role answers that nothing needed changing.
Some antivirus and endpoint-protection products treat "a remote scheduled task running a PowerShell command" as suspicious by design. In a hardened environment you may need to allow it. The task is named DartRelay- followed by an identifier, runs once and removes itself, which makes it easy to recognise in an allow rule.
Who may sign in through Remote Desktop New in 2.0
A Windows server that has just joined a domain lets only administrators sign in through Remote Desktop. Ordinary users are refused during the connection, before a session exists, and the browser can only report it as "Server refused connection".
So the role install, with Let the domain's users sign in ticked, also adds the host's own domain's Domain Users group to the host's Remote Desktop Users group. It finds both groups by their security identifier, so it works on Windows in any language. On a host where the role is already present, the same step is offered on its own under a folded section, Users other than administrators refused with "Server refused connection"?, with a Let domain users sign in button.
Only the host's own domain is added. People from another domain (for example, users of a trusted domain signing in to a host in a child domain) need their group added by hand, on the host:
net localgroup "Remote Desktop Users" "OTHERDOMAIN\Domain Users" /add
If the step fails, the host page shows the exact command to run instead.
Session settings on the host page
The host page also holds settings that decide how Windows sessions behave for the people using that host: whether the same person gets one session or one per device, and how long disconnected sessions are kept before Windows ends them. These are explained on their own page, Host session options.
Certificate sign-in New in 2.1
When Relay Pass is in use, the host page also carries a Certificate sign-in card with Check and Prepare this host, which check and apply the settings a host needs for passwordless Windows logon. The same card holds the Sign out disconnected sessions button described in Host session options.
Example: a small office with one new host
A company has bought one Windows Server 2022 machine, RDS01, joined to its CORP domain, and wants to publish its accounts package to twelve people.
- Prepare the firewall. On
RDS01the administrator runsEnable-NetFirewallRule -Group '@FirewallAPI.dll,-33252'once. - Add the host. Name "Accounts server", address
rds01.corp.example.com, domainCORP, management accountCORP\svc-dartrelay(a member of the server's local Administrators group). Connect reports "Windows Server 2022 Standard" and no Session Host role. - Install the role. On the host page, with Let the domain's users sign in ticked and the restart box ticked, the administrator installs the role during a quiet hour. The host restarts, and the next time the Hosts list is opened it shows the host as ready.
- Plan licensing. The licensing line shows the grace-period countdown, a reminder to configure an RDS licence server within 120 days.
- Publish. The accounts package is then published as described in Publishing applications.
If something goes wrong
| Symptom | Likely cause and fix |
|---|---|
| Connect reports a credential error | The username or password is wrong, or a local account was entered without .\ and is being tried as a domain account. |
| Connect fails with a message naming two routes | Neither the file share and remote registry (TCP 445) nor the HTTPS management listener (TCP 5986) could be reached. Check the host's firewall and that the Remote Registry service is running. |
| "Actively refused" on port 5986 | There is no HTTPS management listener. This is normal on a healthy server and only matters if the other route also fails. |
| The role install says Access is denied | The management account is not a local administrator on the host, or belongs to a domain the host does not trust. Make it a member of the host's local Administrators group. |
| The role install says the RPC server is unavailable | The Remote Scheduled Tasks Management firewall rules are off. Run the command in What the host must allow. |
| Desktops work for two people and then nobody else can connect | The host has no Session Host role, or it is still waiting for a restart. |
For more, including users being refused at sign-in, see Troubleshooting.
Related pages
Publishing applications
Choose programs from a host and put them in the portal.
Desktops and web applications
Publish a whole desktop, or a link to a web site.
Host session options
One session or several per person, and disconnected sessions.
System requirements
What DartRelay and its hosts need.
Troubleshooting
Hosts that refuse users, and other common problems.
