Tell us how we could make TSplus products even more useful to you.
Have something to say?
SSO (SAML) with Entra for Webinterface
Hello TSplus Team, our goal is a real SSO solution for customers with Microsoft 365 / Entra. We achieved this partial with the Connection Client. The problem The load-balancing decision happens before the user has signed in, so at that point the Connection Client doesn't know who the user is: With Enable Windows SSO, the client sends the local Windows user name of the workstation. That name has nothing to do with the account that later signs in through Entra ID. Sticky Sessions look for the wrong user and never resume a disconnected session. With *SSO, the user enters their AD user name and a dummy password once (firststart) and the client stores them on the workstation. This breaks sticky sessions on workplaces with one local user (autologon) and on a rename (i.e. User changes surname because of a wedding) Proposal Move the Entra ID sign-in in front of the load-balancing decision: The Connection Client starts a sign-in at the Gateway / Web Portal using SAML or OpenID Connect against Entra ID. This would build on the web portal SSO you are already developing. Now that the user's identity is known (UPN → on-prem account via onPremisesSamAccountName), the Gateway evaluates load balancing and Sticky Sessions for the correct user. The Gateway hands the chosen session host to the Connection Client. The client connects to that host with Entra ID authentication. As today, the host receives the Entra RDP token and exchanges it for a Kerberos ticket. Bonus: Reverse Proxy together with Entra ID Today Entra ID authentication only works with the Reverse Proxy turned off. Every session host therefore needs its own public DNS name, port or public IP. The Reverse Proxy could carry the connection through the Gateway while keeping the session host as the RDP target, the way Microsoft RD Gateway does (the session host stays in full address). Entra token and certificate would then match again. Only the Gateway would be exposed to the internet: fewer open ports and a smaller attack surface.
2FA: allow multiple methods per user (App + SMS + Email) with a default method and "Sign in another way"
Current behavior Today each user can be configured with only ONE two-factor authentication method: authenticator app, SMS, or email. If that method is not available at login time, the user cannot sign in and an administrator has to reset or change the 2FA configuration. This happens when the phone is lost, broken, or not at hand, when SMS does not arrive, or when email is not reachable. Proposal Allow each user to have MORE THAN ONE 2FA method enrolled at the same time, similar to Microsoft 365 / Entra ID ("Sign in another way"). Login (Web Portal) The user's DEFAULT method is shown first, as it is today. For example: "Enter the code from your authenticator app". A new link "Sign in another way" opens the list of the other methods the user has enrolled: • Use a code from my authenticator app • Text a code to +39 ••• ••• ••42 • Email a code to d••••@domain.com Phone numbers and email addresses are partially masked. The SMS or email code is sent only when the user picks that method, not before. Optional: "Remember this device for X days". Administration (Admin Tool / Advanced Security) Global setting: which methods are allowed (App / SMS / Email), with each one enabled or disabled separately. Per user: view the enrolled methods, set the default method, reset one method without resetting the others. Optional policy: "Require at least 2 methods per user" so every user always has a backup. Optional: allow users to add methods and change their default method themselves after a successful 2FA login. Logging Record in the logs which method was used for each successful or failed 2FA login. Benefits Fewer lockouts: if one method fails, the user can sign in with another one. Fewer support calls and fewer admin resets of 2FA. Same user experience as Microsoft 365, which our users already know. Security stays the same, because every method is still a second factor enrolled by the user. A mock-up of the proposed screens is attached. It is based on the current Web Portal 2FA dialog ("Protect your account with 2-step verification").
Manage HTML5 client settings (settings.js) from the Admin Tool and deploy them across the farm
Today several important HTML5 client options can only be changed by manually editing: C:\Program Files (x86)\TSplus\Clients\www\software\html5\settings.js Real case: users of our farm were being logged off and losing their work when the browser WebSocket dropped briefly. The HTML5 client treated the drop as "browser closed" and, because of W.send_logoff = true, sent an explicit logoff to the session, even when the browser had already reconnected. Following TSplus support's advice, we set W.send_logoff = false and the disconnections stopped. The problem is how this setting has to be managed: The HTML5 client is served by each application server (/~~SERVERNAME/), so the file has to be edited on every server. Our farm has about 50 application servers. New servers added to the farm keep the default value unless someone remembers to edit the file. There is no central place to see which value each server is using. Editing a JavaScript file by hand on production servers is error-prone. Requested feature: Show the main HTML5 client options in the Admin Tool (for example in Web > HTML5 Client), at least: W.send_logoff (log off session when the browser is closed) W.sendidlemovements (send idle movements to keep the connection alive) W.connectiontimeout From the farm controller, apply these settings to all application servers in the farm (or to selected servers), the same way other farm-wide settings are already deployed. Keep the values across TSplus updates and show the current value per server. Add a short explanation in the interface of what each option does, because the effect of send_logoff is not obvious and makes HTML5 disconnections much worse. Benefit: fewer support cases for "users disconnected while working", consistent configuration across large farms, and no manual file editing on production servers.
Session Selection When Resuming a Session
Title Allow users to select which session to resume when using Sticky Session Description Currently, it is possible to open multiple sessions simultaneously through Session Management Settings under the Session tab. It is also possible to resume an existing session using the Sticky Session feature. However, when multiple sessions are open and Sticky Session is used, the expected behavior is not clearly defined. In particular, it is unclear which criteria the system uses to determine which session should be resumed. Proposed Solution Add a popup when resuming a session, allowing the user to explicitly select the session they want to resume. The popup could display the list of available sessions along with relevant information to help the user easily identify them, and then allow them to select the session to resume. Benefits This enhancement would: Give users more control over session management. Avoid ambiguity when multiple sessions are active. Make the behavior of Sticky Session more predictable. Make it easier to work with multiple sessions simultaneously.
Remote Access – Improved Log Management
We would like to propose an enhancement to the current log management system in TSplus Remote Access, to improve centralization, configuration robustness, and overall maintainability. Current issues: - Log files are spread across multiple folders, making them difficult to centralize or monitor - The log configuration file currently combines: - technical settings for the log4net library - file management parameters (log path, size, retention, verbosity level) - These configuration files may be overwritten during a TSplus Remote Access upgrade when the log4net library evolves, leading to a loss of any custom configuration.. Proposed improvements: - Separate the configuration into two distinct files: - One file dedicated to log4net library settings (dependencies) - One file for log file management parameters by module (file location, file size, retention policy, verbosity) - Store global log settings: - Either in the Windows Registry (HKLM\Software\Digital River\JWTS\Logs) - Or in a separate configuration file (e.g. C:\ProgramData\TSplus\Logs\global-config.json) Expose these settings in the Admin Tool: - Add a new "Advanced > Logs" tab that displays log settings per module - Allow specifying a centralized log folder, including UNC paths (e.g. \\server\logs\TSplus\) to support open-source log collection tools such as ELK, Graylog, or Wazuh Benefits: - Easier centralization and monitoring of logs - Custom configurations preserved during updates - Better compatibility with log aggregation and analysis tools Clearer, more maintainable setup aligned with industry standards. We believe this improvement would provide real value for administrators, especially in multi-server environments and for managed service providers (MSPs). Best Regards
Remote Access - Implementing File Transfer Logs
Several customers are asking us for a log file concerning file uploads and downloads for the Remote Access solution. This request is linked to input/output monitoring and session host security. File transfers concerning the web part are stored in web_log.txt. They are difficult to consult, as they are 'drowned' in the mass of information linked to the operation of the web server. Would it be possible for you to carry out a feasibility study and implement one or more log files concerning - file transfer to and from the Remote Access server in HTML5 mode - file transfer to and from the Remote Access server in rdp / remoteApp mode. We currently have several validation servers, and with your help we'll be able to test a Beta version. Thank you for your consideration of this development request. Best Regards
Remote Access - Web Portal - Multiple Connexion Display Modes
Customers requested multiple connection modes via the Web Portal's RemoteApp module: single-screen windowed rdp access, multi-screen rdp access, RemoteApp access for users associated with application publishing. Since the beginning of the year, we've had to implement this solution for four new customers who operate remote access instances for specific user populations. We have the possibility of adapting the Portal to the needs of our customers, but maintainability is not guaranteed, because an UpdateRelease that would impact the Web Portal would totally ‘break’ the development carried out, and it would be necessary to carry out a new adaptation. could you take this request into account and indicate whether it will be included in the TSplus Remote Access roadmap ? Thank you very much. Regards
License Portal – Request for Enhancements to Improve Security
The license management portal is a central component of the TSplus ecosystem for partners and distributors. This portal enables, in particular: - management of customer licenses, - tracking of activations, - access to technical and, in some cases, commercial information (in the comments), - renewal and maintenance operations, As a result, this portal represents a sensitive access point that potentially grants access to strategic information as well as critical operations for partners and their end customers. In the current context of increasing cybersecurity requirements, compliance standards, and security audits conducted at end-customer sites, several partners have noted that certain security measures now considered standard on professional portals do not yet appear to be implemented or widely adopted on the licensing portal. The purpose of this request is not to call into question the existing system, but to propose a gradual evolution of the portal in order to align it with modern security best practices expected for this type of platform exposed on the Internet. 1. Enhanced Password Policy Implementation of a minimum password complexity policy: - minimum length, - combination of characters, - prohibition of weak or overly common passwords. Example: - minimum 12 characters, - uppercase/lowercase letters, - numbers, - special characters. 2. Protection Against Brute-Force Attacks Implementation of a mechanism to limit authentication attempts: - progressive timeouts, - temporary account lockout after multiple failed attempts, - optional CAPTCHA after a certain threshold. Example: 5 failed attempts → temporary blocking of the account or IP address for a few minutes. This measure is now a standard security practice on publicly accessible portals. 3. User Account and Role Management In the medium term, it may be worthwhile to explore the implementation of: - named accounts, - as well as role-based access control (RBAC). This would enable: - better traceability of actions, - more granular access management, - and alignment with current standards for professional platforms. As this change is potentially more significant, it could be addressed in a second phase. 4. Multi-factor authentication (MFA / 2FA) Addition of a second authentication factor for partner accounts. Recommended method: TOTP (Google Authenticator, Microsoft Authenticator, Authy, etc.) or Email. This change would: - significantly reduce the risk of account compromise, - secure access even in the event of a password leak, - increase partners’ and customers’ trust in the portal. 5. Access Logging and Traceability Add logging for connections and security events: - date and time, - source IP address, - authentication success/failure, - password change, - MFA enable/disable. This traceability is now essential: - for security audits, - for incident investigations, - and to meet the growing demands of end customers. The licensing portal is now a critical component of the TSplus ecosystem. In a context where partners and end customers are increasingly concerned about cybersecurity issues, the gradual implementation of modern security mechanisms would: - strengthen trust in the platform, - reduce the risk of compromise, - improve compliance with current best practices, - and position the portal at the level expected for a professional solution exposed to the Internet.  
Remote Access - Web Portal - Account Disabled Message
When connecting via RDP—whether through a third-party client or via .connect—the message below appears when a user attempts to connect to the remote server using a Windows account that has been disabled. Could you consider displaying a message such as “Account disabled” or “Your account is currently disabled” when connecting in HTML5 mode, instead of “Invalid credentials”? Thank you in advance for your response. Best regards
Remote Access - Lockout & IP Address
The Lockout module associated with the web server allows you to restrict access to the Web Portal based on the number of login attempts. The CSV file organized by username provides a certain amount of information, but not the requester’s IP address. However, this IP address is indeed logged in the hb.log file when the verbosity level is set to “Debug” or “All.” Would it be possible to include the requester’s IP address in the .csv file within the Lockout module? Thank you in advance for your feasibility analysis and your response. Best regards
Dynamic tab names in HTML5
We have customers who administer more than one company. If they start the same application for five different companies and the applications are running under a single browser tab, they cannot easily tell the different sessions apart. Alternatively, if they log in five times and open each application in a separate browser tab, all the tabs are labeled "HTML5", which makes it difficult to identify which company each tab belongs to. Would it be possible to dynamically set the browser tab name, for example based on the company currently running in the application? Ideally, we would like to be able to set the tab name from within the application itself.
Correction Needed for Persian Language Direction (RTL)
Dear TSplus Support Team, I would like to thank you for adding the Persian language to your software. I appreciate your effort in supporting more languages. However, the Persian translation is currently displayed with a left-to-right (LTR) direction, while Persian (Farsi) is a right-to-left (RTL) language. This causes incorrect text alignment, punctuation, and overall layout, making the interface difficult to read for Persian users. I have spent considerable time preparing the attached image, which clearly illustrates the problem. The left side shows the current incorrect LTR layout, and the right side shows the correct RTL layout that I created as an example. Please note that this is just one example; the issue exists across the entire application, including all menus, dialogs, settings windows, messages, tooltips, and other UI elements. Please adjust the Persian language settings so that the RTL direction is applied consistently throughout the entire program.. It is essential for the usability and readability of the software for Persian-speaking users. I trust that you will treat this issue with the necessary priority. I look forward to your confirmation and the implementation of this correction. Best regards, Ehsan Ghadiri
Subscription management UI
Hi team, I would like to request a revision of how the management of subscriptions works in the portal, specifically speaking the user count increase for the sub itself. Currently you need to go into Subscriptions > Manage/Upgrade > Manage dropdown menu > Modify Subscription and then you can change the number of users. This is quite hidden and counter intuitive. Can we please consider something simpler? On a side note, when increasing the number of users per subscription, it would be nice to have a prompt that reminds the client to assign the extra users to the computer(s), because they tend to think it happens automatically. Cheers, Daniel
Request the addition of a "search feature" to the TSplus Floating Panel
Dear Tsplus Team, I would like to request the addition of a search feature to the TSplus Floating Panel. TSplus Floating Panel to make finding File,Folder easier.
Ability to view and terminate active Remote Support sessions
Current issue A Remote Support session may occasionally remain active after the connection has ended. When that session cannot be disconnected manually, it prevents the user from starting a new connection. This can happen when switching between devices or using different network connections. Suggested feature Add a session management page where users or administrators can: View all active sessions associated with a user account See the connected device and session start time Terminate an individual session Terminate all active sessions using a “Disconnect all sessions” button This could work similarly to the session management and “sign out everywhere” features available in Microsoft 365. Benefit This feature would let users quickly recover from blocked or orphaned sessions without waiting for a timeout or contacting technical support.
Search Feature in remoteapp mode (no explorer.exe)
Currently, users cannot type into the Windows Search field in Explorer or standard Open/Select File dialogs when connected through TSPlus RemoteApp. We confirmed that starting explorer.exe within the user's RemoteApp session immediately restores search functionality. However, this also launches the Windows taskbar/desktop shell, so it isn't a practical solution for RemoteApp deployments. from my understanding and testing this issue exists on windows server 2022, An easy way to reproduce this issue is by going to any windows 2022 server, killing the explorer.exe process for that user and then via the task manager opening notepad and using the “open” feature (ctrl+o) and finally typing into the “search” box.
USB SCANNER
Currently, in order to use any USB scanner, we have to use third‑party programs. Will it be possible to do this directly through TSplus in the future?
SIGNATURE TABLETS SUCH AS WACOM
Hi, Currently, in order to use Wacom signature tablets, we have to use third‑party programs. Will it be possible to do this directly through TSplus in the future? Thanks, David
Print Driver Microsoft Ipp Class Driver Compatibility
Most of our clients have their own IT team or handle it themselves. When they replace their old printer with a new one, they simply connect it and usually don’t use the printer’s own drivers; Windows uses the “Microsoft IPP Class Driver,” which is not compatible with TSplus printers, and it’s necessary to change the driver to the correct one. Could you look into this issue?
Reverse Drive Mapping from TSplus Server to Client Workstation
TSplus Remote Access currently supports redirecting local client drives into the remote session through paths such as: \\tsclient\[letter] I would like to request the reverse functionality. After a TSplus RemoteApp connection has been established, the TSplus Connection Client should optionally create a mapped drive on the user's local Windows workstation that points to a predefined directory on the TSplus server. Conceptually, this could work similarly to: \\tsserver\[share] The user could then access server-side files directly from the local Windows File Explorer and open them using locally installed applications. The mapping should exist only while the TSplus connection is active and should be removed automatically when the session ends. Administration requirements Ideally, administrators could configure: Server source directory Client drive letter or share name User-specific paths using variables such as %USERNAME% or %USERPROFILE% Read-only or read/write access User/group-based assignment Automatic mapping when the RemoteApp session starts Automatic removal when the RemoteApp session ends Multiple mappings if required File access should be transported through the existing encrypted TSplus connection, without requiring direct SMB connectivity between the workstation and the TSplus server.