> ## Knowledge Base Index
> Fetch the complete knowledge base index at: https://help.trugrid.com/sitemap.xml
> Use this file to discover available pages before exploring further.
> Pure-Markdown content can be obtained by appending a '.md' suffix to the content URLs listed in the sitemap (without the trailing slash).

# TruGrid SecureRDP - Downloads

Direct download links for every TruGrid SecureRDP component. All installers are digitally signed by TruGrid. Verify the publisher in the file's Digital Signatures tab before running if your environment requires it.

### In this article

* [__Connectors__](https://help.trugrid.com/en/article/trugrid-securerdp-downloads-vu950h/#1-connectors)
* [__Broker software__](https://help.trugrid.com/en/article/trugrid-securerdp-downloads-vu950h/#1-broker-software)
* [__Diagnostic toolkits__](https://help.trugrid.com/en/article/trugrid-securerdp-downloads-vu950h/#1-diagnostic-toolkits)
* [__What to install where__](https://help.trugrid.com/en/article/trugrid-securerdp-downloads-vu950h/#3-what-to-install-where)
* [__Install locations__](#1-Install-locations)

# Connectors

End-user software for accessing TruGrid SecureRDP from a workstation. Install one of these on every machine a user connects from.

### TruGrid Windows Connector

For end users connecting to assigned desktops from a Windows workstation.
**Download:** [__https://trugrid.com/downloads/winconnector__](https://trugrid.com/downloads/winconnector)

**Requirements:**
* Windows 10 or Windows 11
* Standard user rights for the user-mode installer; Administrator rights for the per-machine installer
* Internet access to TruGrid endpoints

For installation troubleshooting, see Resolving issues with TruGrid Windows Connector Installation or use the [__TruGrid Toolkit.__](https://help.trugrid.com/en/article/trugrid-securerdp-windows-toolkit-1xejitj/)

### TruGrid Mac Connector

For end users connecting to assigned desktops from a Mac.
**Download:** [__https://trugrid.com/downloads/macconnector__](https://trugrid.com/downloads/macconnector)

**Requirements:**
* macOS 12 or later
* TruGrid subscription

# Broker software

Server-side software that sits between user connections and the desktops they're connecting to. Install one or both of these in your environment depending on your directory model. Sentry and Secure Connect are alternatives, but can, in some cases be used to compliment each other. 

### TruGrid Sentry

For organizations with on-premises Active Directory. Sentry runs on a Windows Server in the domain and brokers RDP traffic to AD-joined hosts and pools.

**Download:** [__https://trugrid.com/downloads/sentry__](https://trugrid.com/downloads/sentry)

**Requirements:**
* Windows Server 2016, 2019, 2022, or 2025
* Domain-joined to the Active Directory you want to broker for
* Administrator rights on the server during installation
* Outbound HTTPS to TruGrid endpoints

### TruGrid Secure Connect

For organizations without on-premises Active Directory, or for hybrid scenarios using Microsoft Entra ID (Azure AD). Secure Connect runs on a Windows Server or supported workstation and brokers connections to non-domain-joined or Entra-joined hosts.

**Download:** [__https://trugrid.com/downloads/secureconnect__](https://trugrid.com/downloads/secureconnect)

**Requirements:**
* Windows Server 2016, 2019, 2022, or 2025, or Windows 10/11
* Administrator rights during installation
* Outbound HTTPS to TruGrid endpoints

# Diagnostic toolkits

Self-contained diagnostic applications for troubleshooting TruGrid SecureRDP deployments. Toolkits don't require installation and don't modify the system unless you explicitly apply a remediation.

### Windows Toolkit

Diagnostic tool for Windows machines running any TruGrid component (Connector, Sentry, or Secure Connect) or for testing connectivity from a workstation that has none.

**Download:** [__TruGridToolkit.exe__](https://tgpublic.blob.core.windows.net/noncore/SecureRDP-Toolkit/TruGridToolkit.exe)

**Requirements:**
* Windows 10, Windows 11, or Windows Server 2016 through 2025
* Approximately 80 MB of free disk space
* No prerequisites: the Toolkit is self-contained, no .NET Framework or PowerShell version dependency

Full documentation: [__TruGrid SecureRDP - Windows Toolkit__](https://help.trugrid.com/en/article/trugrid-securerdp-windows-toolkit-1xejitj/)


The Toolkit checks for newer versions automatically (v1.10 and later). Earlier versions don't include the update checker; if you're on v1.7-v1.9, the link above always points at the latest release.

### Mac Toolkit

Diagnostic tool for Mac machines running the TruGrid Mac Connector or for testing connectivity from a Mac workstation.

**Download:** [__Mac Toolkit 1.3.0__](https://tgpublic.blob.core.windows.net/noncore/SecureRDP-Toolkit/TruGrid-Toolkit-Mac.dmg)

**Requirements:**
* macOS 12 or later
* TruGrid Mac Connector (recommended but not required for connectivity-only diagnostics)

Full documentation: [__TruGrid SecureRDP - Mac Toolkit__](https://help.trugrid.com/en/article/trugrid-securerdp-mac-toolkit-eiudgq/)

### What to install where

The Toolkits are optional in normal operation but recommended for anyone administering a TruGrid SecureRDP deployment. Most support tickets are resolved faster when a Toolkit report is attached.

| Machine role | Install |
| ---- |
| End user's Windows workstation | TruGrid Windows Connector |
| End user's Mac | TruGrid Mac Connector |
| Domain-joined broker server (AD environment) | TruGrid Sentry |
| Broker server in non-AD or Entra-only environment | TruGrid Secure Connect |
| Any Windows machine for troubleshooting | TruGrid Windows Toolkit |
| Any Mac for troubleshooting | TruGrid Mac Toolkit |

# Install locations

## Windows Connector

The TruGrid Windows Connector runs per-user. Its native (interactive) and headless (background) components are separate binaries with separate log paths.

| Item | Location |
| ---- |
| Local application data | `%LOCALAPPDATA%\TruGrid` |
| Local application data (Connector-specific) | `%LOCALAPPDATA%\TruGrid Connector` |
| Roaming application data | `%APPDATA%\TruGrid` |
| Roaming application data (Connector-specific) | `%APPDATA%\TruGrid Connector` |
| Headless Connector log directory | `%LOCALAPPDATA%\TruGrid\Logs` |
| Headless Connector log filename pattern (current) | `win_headless_logs_*.txt` |
| Machine-wide install log prefix (introduced in recent release) | `m_*` |
| Per-user install log prefix (introduced in recent release) | `u_*` |
| Native Connector log filename pattern (historical) | `win_native_loggs_*.txt` (double-g is intentional) |
| Version reference (typical current) | Native: 2026.4.x, Headless: 2.0.7.x |

**Note on log path change:** The historical AppData\Roaming\TruGrid Connector\ path for headless logs is stale. Current headless logs live under `%LOCALAPPDATA%\TruGrid\Logs` only.

**Note on machine-wide vs per-user install:** The `m_` and `u_` filename prefixes distinguish logs from a machine-wide Connector install (all users on the machine) from a per-user install (single user profile). Both may be present on the same system if both install modes were used at different times.

## Mac Connector

The TruGrid Mac Connector installs to /Applications and writes logs under the user's Library folder. Distributed as a signed and notarized `.app` inside a `.dmg`.

| Item | Location |
| ---- |
| App bundle | /Applications/TruGrid Mac \`\`Connector.app \`\`\` |
| Log directory | `~/Library/Application Support/TruGrid Mac Connector/Logs/` |
| Log format | Contains GUID-to-hostname mapping for tunnel setup, useful for session resolution |
| Distribution | Signed and notarized `.dmg` (Developer ID) |
| System requirements | macOS 13.0+, Universal binary (Intel + Apple Silicon) |

## Sentry

The TruGrid Sentry broker service runs on the customer's on-prem gateway server. It has a Program Files install with a single primary log file held open by the running service.

| Item | Location |  |  |  |
| ---- |
| Install directory | `C:\Program Files\TruGrid\Sentry` |  |  |  |
| Primary log file | `C:\Program Files\TruGrid\Sentry\Agent.log` |  |  |  |
| Log file access | Open with shared read (Notepad++, VS Code, `Get-Content -Wait`). Do not use tools that take an exclusive lock. |  |  |  |
| Log line format (main process) | \`yyyy-MM-dd HH:mm:ss.ffff UTC | LEVEL | message\` |  |
| Log line format (broker) | \`yyyy-MM-dd HH:mm:ss.ffffUTC | LEVEL | Component | Broker\_N:msg\` |
| Windows service | Sentry broker service (`TruGrid Sentry` or similar; verify via `Get-Service *TruGrid*`) |  |  |  |
| Azure App Insights workspace (referenced for escalations) | `TruGrid-Relay-Instances` (classic App Insights schema, not workspace-based) |  |  |  |
| Relay-secured log line pattern | `Connection to <ip>:443 Relay has been secured.` |  |  |  |
## Secure Connect

Secure Connect installs alongside Sentry under Program Files. Note the space in both the folder name and the log filename these are consistent oddities that automated tools must handle explicitly.

| Item | Location |  |  |
| ---- |
| Install directory | `C:\Program Files\TruGrid\Secure Connect` (with space) |  |  |
| Primary log file | `C:\Program Files\TruGrid\Secure Connect\Secure Connect.log` (with space, NOT `Agent.log`) |  |  |
| Log line format | \`yyyy-MM-dd HH:mm:ss.ffffUTC | LEVEL | message\` |
| Windows service | `TruGrid Secure Connect` |  |  |
| Common log events | `Secure Connect service session changed`, `Starting Secure Connect`, `Reporting machines...` |  |  |

## RDSM Enterprise

TruGrid RDS Manager Enterprise consists of the Data Collector, the Enterprise Client, and an optional Session Host Agent. Runs on a domain-joined Windows Server.

| Item | Location |
| ---- |
| Data Collector executable | `TruGrid-RDSM-DC-Config.exe` |
| Enterprise Client executable | `TruGrid-RDSM-Enterprise.exe` |
| Session Host Agent executable | `TruGrid-RDSM-Agent.exe` |
| SQLite database path | `C:\ProgramData\TruGrid RDS Manager Enterprise` |
| Data Collector service | Managed via the Configurator, installed as Windows service |
| Data Collector network ports | TCP 5743 (HTTP), TCP 5744 (HTTPS) |
| WMI namespace queried (agentless) | `root\CIMV2` |
| Session Host Agent telemetry interval | 30 seconds |
| Agentless polling interval | 60 seconds |
| Firewall rules required on session hosts | RPC Endpoint Mapper, dynamic RPC, WMI, DCOM-In, ICMPv4, Remote Desktop Services - Shadow (TCP-In) group |

## SecureRDP Toolkit

The Toolkit is self-contained and installs to whatever directory the user launches it from. It writes reports and cache to the user's Desktop.

| Item | Location |
| ---- |
| Install location | Wherever the user saves and runs the executable (no installer) |
| Reports output directory | `<Desktop>\TruGrid Reports` |
| Session name cache | `<Desktop>\TruGrid Reports\toolkit-cache\session-names.json` |
| Update manifest URL | [`https://tgpublic.blob.core.windows.net/noncore/SecureRDP-Toolkit/latest.json`](https://tgpublic.blob.core.windows.net/noncore/SecureRDP-Toolkit/latest.json) |
| Update manifest schema | `latestVersion`, `releaseDate`, `downloadUrl`, `releaseNotesUrl`, `minimumSupportedVersion`, `sha256` |
| Signed executable | Yes, verified via SHA256 in the manifest |
