TruGrid SecureRDP - Downloads

Direct download links for every TruGrid SecureRDP component. All installers are digitally signed by TruGrid. Verify the publisher in the file's Digital Signatures tab before running if your environment requires it.


In this article



Connectors


End-user software for accessing TruGrid SecureRDP from a workstation. Install one of these on every machine a user connects from.


TruGrid Windows Connector


For end users connecting to assigned desktops from a Windows workstation.
Download: https://trugrid.com/downloads/winconnector


Requirements:

  • Windows 10 or Windows 11
  • Standard user rights for the user-mode installer; Administrator rights for the per-machine installer
  • Internet access to TruGrid endpoints


For installation troubleshooting, see Resolving issues with TruGrid Windows Connector Installation or use the TruGrid Toolkit.


TruGrid Mac Connector


For end users connecting to assigned desktops from a Mac.
Download: https://trugrid.com/downloads/macconnector


Requirements:

  • macOS 12 or later
  • TruGrid subscription


Broker software


Server-side software that sits between user connections and the desktops they're connecting to. Install one or both of these in your environment depending on your directory model. Sentry and Secure Connect are alternatives, but can, in some cases be used to compliment each other.


TruGrid Sentry


For organizations with on-premises Active Directory. Sentry runs on a Windows Server in the domain and brokers RDP traffic to AD-joined hosts and pools.


Download: https://trugrid.com/downloads/sentry


Requirements:

  • Windows Server 2016, 2019, 2022, or 2025
  • Domain-joined to the Active Directory you want to broker for
  • Administrator rights on the server during installation
  • Outbound HTTPS to TruGrid endpoints


TruGrid Secure Connect


For organizations without on-premises Active Directory, or for hybrid scenarios using Microsoft Entra ID (Azure AD). Secure Connect runs on a Windows Server or supported workstation and brokers connections to non-domain-joined or Entra-joined hosts.


Download: https://trugrid.com/downloads/secureconnect


Requirements:

  • Windows Server 2016, 2019, 2022, or 2025, or Windows 10/11
  • Administrator rights during installation
  • Outbound HTTPS to TruGrid endpoints


Diagnostic toolkits


Self-contained diagnostic applications for troubleshooting TruGrid SecureRDP deployments. Toolkits don't require installation and don't modify the system unless you explicitly apply a remediation.


Windows Toolkit


Diagnostic tool for Windows machines running any TruGrid component (Connector, Sentry, or Secure Connect) or for testing connectivity from a workstation that has none.


Download: TruGridToolkit.exe


Requirements:

  • Windows 10, Windows 11, or Windows Server 2016 through 2025
  • Approximately 80 MB of free disk space
  • No prerequisites: the Toolkit is self-contained, no .NET Framework or PowerShell version dependency


Full documentation: TruGrid SecureRDP - Windows Toolkit



The Toolkit checks for newer versions automatically (v1.10 and later). Earlier versions don't include the update checker; if you're on v1.7-v1.9, the link above always points at the latest release.


Mac Toolkit


Diagnostic tool for Mac machines running the TruGrid Mac Connector or for testing connectivity from a Mac workstation.


Download: Mac Toolkit 1.3.0


Requirements:

  • macOS 12 or later
  • TruGrid Mac Connector (recommended but not required for connectivity-only diagnostics)


Full documentation: TruGrid SecureRDP - Mac Toolkit


What to install where


The Toolkits are optional in normal operation but recommended for anyone administering a TruGrid SecureRDP deployment. Most support tickets are resolved faster when a Toolkit report is attached.


Machine role

Install

End user's Windows workstation

TruGrid Windows Connector

End user's Mac

TruGrid Mac Connector

Domain-joined broker server (AD environment)

TruGrid Sentry

Broker server in non-AD or Entra-only environment

TruGrid Secure Connect

Any Windows machine for troubleshooting

TruGrid Windows Toolkit

Any Mac for troubleshooting

TruGrid Mac Toolkit


Install locations


Windows Connector


The TruGrid Windows Connector runs per-user. Its native (interactive) and headless (background) components are separate binaries with separate log paths.


Item

Location

Local application data

%LOCALAPPDATA%\TruGrid

Local application data (Connector-specific)

%LOCALAPPDATA%\TruGrid Connector

Roaming application data

%APPDATA%\TruGrid

Roaming application data (Connector-specific)

%APPDATA%\TruGrid Connector

Headless Connector log directory

%LOCALAPPDATA%\TruGrid\Logs

Headless Connector log filename pattern (current)

win_headless_logs_*.txt

Machine-wide install log prefix (introduced in recent release)

m_*

Per-user install log prefix (introduced in recent release)

u_*

Native Connector log filename pattern (historical)

win_native_loggs_*.txt (double-g is intentional)

Version reference (typical current)

Native: 2026.4.x, Headless: 2.0.7.x


Note on log path change: The historical AppData\Roaming\TruGrid Connector\ path for headless logs is stale. Current headless logs live under %LOCALAPPDATA%\TruGrid\Logs only.


Note on machine-wide vs per-user install: The m_ and u_ filename prefixes distinguish logs from a machine-wide Connector install (all users on the machine) from a per-user install (single user profile). Both may be present on the same system if both install modes were used at different times.


Mac Connector


The TruGrid Mac Connector installs to /Applications and writes logs under the user's Library folder. Distributed as a signed and notarized .app inside a .dmg.


Item

Location

App bundle

/Applications/TruGrid Mac ``Connector.app ```

Log directory

~/Library/Application Support/TruGrid Mac Connector/Logs/

Log format

Contains GUID-to-hostname mapping for tunnel setup, useful for session resolution

Distribution

Signed and notarized .dmg (Developer ID)

System requirements

macOS 13.0+, Universal binary (Intel + Apple Silicon)


Sentry


The TruGrid Sentry broker service runs on the customer's on-prem gateway server. It has a Program Files install with a single primary log file held open by the running service.


Item

Location




Install directory

C:\Program Files\TruGrid\Sentry




Primary log file

C:\Program Files\TruGrid\Sentry\Agent.log




Log file access

Open with shared read (Notepad++, VS Code, Get-Content -Wait). Do not use tools that take an exclusive lock.




Log line format (main process)

`yyyy-MM-dd HH:mm:ss.ffff UTC

LEVEL

message`


Log line format (broker)

`yyyy-MM-dd HH:mm:ss.ffffUTC

LEVEL

Component

Broker_N:msg`

Windows service

Sentry broker service (TruGrid Sentry or similar; verify via Get-Service *TruGrid*)




Azure App Insights workspace (referenced for escalations)

TruGrid-Relay-Instances (classic App Insights schema, not workspace-based)




Relay-secured log line pattern

Connection to :443 Relay has been secured.




Secure Connect


Secure Connect installs alongside Sentry under Program Files. Note the space in both the folder name and the log filename these are consistent oddities that automated tools must handle explicitly.


Item

Location



Install directory

C:\Program Files\TruGrid\Secure Connect (with space)



Primary log file

C:\Program Files\TruGrid\Secure Connect\Secure Connect.log (with space, NOT Agent.log)



Log line format

`yyyy-MM-dd HH:mm:ss.ffffUTC

LEVEL

message`

Windows service

TruGrid Secure Connect



Common log events

Secure Connect service session changedStarting Secure ConnectReporting machines...




RDSM Enterprise


TruGrid RDS Manager Enterprise consists of the Data Collector, the Enterprise Client, and an optional Session Host Agent. Runs on a domain-joined Windows Server.


Item

Location

Data Collector executable

TruGrid-RDSM-DC-Config.exe

Enterprise Client executable

TruGrid-RDSM-Enterprise.exe

Session Host Agent executable

TruGrid-RDSM-Agent.exe

SQLite database path

C:\ProgramData\TruGrid RDS Manager Enterprise

Data Collector service

Managed via the Configurator, installed as Windows service

Data Collector network ports

TCP 5743 (HTTP), TCP 5744 (HTTPS)

WMI namespace queried (agentless)

root\CIMV2

Session Host Agent telemetry interval

30 seconds

Agentless polling interval

60 seconds

Firewall rules required on session hosts

RPC Endpoint Mapper, dynamic RPC, WMI, DCOM-In, ICMPv4, Remote Desktop Services - Shadow (TCP-In) group


SecureRDP Toolkit


The Toolkit is self-contained and installs to whatever directory the user launches it from. It writes reports and cache to the user's Desktop.


Item

Location

Install location

Wherever the user saves and runs the executable (no installer)

Reports output directory

\TruGrid Reports

Session name cache

\TruGrid Reports\toolkit-cache\session-names.json

Update manifest URL

https://tgpublic.blob.core.windows.net/noncore/SecureRDP-Toolkit/latest.json

Update manifest schema

latestVersionreleaseDatedownloadUrlreleaseNotesUrlminimumSupportedVersionsha256

Signed executable

Yes, verified via SHA256 in the manifest

Updated on: 18/08/2026

Was this article helpful?

Share your feedback

Cancel

Thank you!