Logging Remote Server Access via Remote Desktop

Posted by Nate Bross on Server Fault See other posts from Server Fault or by Nate Bross
Published on 2010-06-15T20:37:12Z Indexed on 2010/06/15 20:43 UTC
Read the original article Hit count: 216

The objective here is to start a simple .NET application I've written which captures some environment variables (time, username, computername, etc) upon login. This .NET application subscribes to the Windows "User logout" event.

Upon launch, the application captures the above variables, and creates a record in my database, upon logout (which I'm capturing) I update another field in the same record, with the logout time.

The above is working exactly as I would like, when I launch the binary, it makes its initial log entry, then waits for the logout event and updates the same record.

Restrictions, the .NET binary should be able to live on a share point (\server\share\myapp\v1) so I can update the application to (\server\share\myapp\v2) and simply update the GPO/Logon script.

My initial thought was to use the \domaincontroller\sysvol\ directory to store the binary and then update all user accounts to include a call to my application. Can you see any flaws in this approach?

My question is this: First, is there anything wrong with my idea above? Second, if so, what is the best way (through group policy or otherwise) to ensure this application launches whenever a session is started on a server?

© Server Fault or respective owner

Related posts about Windows

Related posts about active-directory