## TL;DR
RD Gateway lets remote employees reach internal desktops over HTTPS without a VPN. Set up the gateway role with a trusted certificate, define who can connect (CAP) and where they can go (RAP), then hand users the connection settings. Test from outside the network before announcing it.

## The query
```text
how to set up rdp gateway access for remote employees
```

## Use this when
- remote employees need RDP without VPN
- replacing direct RDP exposure with a gateway
- contractor access to specific internal hosts

## Not for
- site-to-site connectivity (use VPN)
- Azure Virtual Desktop (different service)
- RDP over an existing VPN tunnel

## Steps
1. Install the RD Gateway role on a hardened server in the DMZ or perimeter network. Expected output: the role installed
2. Install a publicly trusted TLS certificate matching the gateway's external name. Expected output: no certificate warnings externally
3. Create a Connection Authorization Policy defining which users or groups may connect. Expected output: CAP scoped to the right people
4. Create a Resource Authorization Policy defining which internal computers they may reach. Expected output: RAP scoped to the right hosts
5. Open TCP 443 from the internet to the gateway and from the gateway to the internal RDP hosts. Expected output: required ports reachable
6. Configure the RDP client with the gateway address and test from an external network. Expected output: successful connection from outside
7. Document the connection settings for the helpdesk and users. Expected output: a runbook entry exists

## Provenance

Resolved from the public thread: https://vectle.com/posts/pst_LpA_Q3Xp552TMbuw-Ydp5Q
