TruGrid SecureRDP - Sentry Enterprise Design
This article describes the recommended TruGrid Sentry architecture for enterprise environments with multiple datacenters or sites. It covers TruGrid Sentry placement, system requirements, active-passive site design, failover, and the authentication features most relevant to enterprise deployments: Trusted Location Login and Credentials Passthrough.
For an overview of how Sentry brokering works, see TruGrid SecureRDP - Multi-site brokering.
Design principle: each site is self-contained
In an enterprise deployment, every site runs its own Sentry infrastructure and brokers its own Remote Desktops.
Depending on business needs, and because Sentry is not network topology aware, these sites can be organized in a few ways:
- Site A (primary): Sentry services running. All brokering happens here.
- Site B (standby): Sentry software installed and fully configured, but the Sentry services are disabled. Site B Sentries do not participate in brokering until activated during failover.
- Both Site A and Site B active: In cases where local awareness is the primary means of connection, both Sentries can be on and actively broker connections.
This guarantees predictable session paths, keeps RDP session traffic off the WAN, and gives the enterprise a documented recovery path if the primary site becomes unavailable.
System requirements
Per Sentry server:
- A fully patched 64-bit Windows Server OS. Windows Server 2019 or later is highly recommended. Windows Server 2016 is supported but not recommended for new deployments as it is past end of mainstream support.
- 16 GB RAM, 2 CPUs, disk with high IOPS. The server does not need to be dedicated, but CPU and memory utilization should not exceed 70%. Do not co-locate Sentry on a resource-overloaded server.
- The Sentry server's network card DNS settings must point to Active Directory DNS servers, not external DNS. The same applies to all RDP hosts.
- No inbound firewall exposure is required. Ensure RDP over port 3389 is enabled only on machines that will be accessed.
Per site:
- Recommended two Sentry servers per site. Within the active site, the two Sentries coordinate automatically and provide local failover.
- The standby site mirrors this with two pre-configured Sentries, depending on Local awareness utilization, these can be active or disabled.
- All four servers (two per site) should be built and configured identically.
For sizing beyond the baseline, or environments above 6,000 concurrent sessions, contact TruGrid support for a sizing review.
Site design: active-passive
Normal operations
The WAN between sites carries Active Directory replication, DNS, and authentication traffic only. No RDP session traffic crosses it.

Authentication: Trusted Location Login and Credentials Passthrough
Enterprise deployments on hybrid domains (AD synced to Entra ID) can combine two features for a frictionless on-network login experience:
- Trusted Location Login: users connecting from a trusted public IP authenticate against On-Premises AD with no MFA prompt. Users outside trusted locations authenticate against Entra ID with full MFA and Conditional Access enforcement.
- Credentials Passthrough: with Remote Credential Guard enabled on the Connector, an AD-joined user's credentials are passed through at login. The user is signed in, authenticated over Kerberos, and their application shortcuts are created automatically. No password is sent to or cached on the session host.
Together with the Local Awareness feature (enabled per domain by TruGrid support), a domain-joined user at a trusted site logs in and reaches their resources with no additional prompts.
Enterprise design notes for these features
- Add every site's public IP to the Trusted Location list from day one, including the standby site. If Site A fails and users egress through Site B's connection, the trusted-location match must still succeed. If users work from untrusted locations during a DR event, they fall back to Entra ID with MFA. This is expected behavior, not a fault.
- Register the SPN for standby Sentries in advance. Kerberos authentication for Credentials Passthrough requires an SPN per Sentry FQDN. Registering both sites' SPNs ahead of time keeps failover to a service start.
- Trusted Location Login requires a Sentry online. During the failover window between Site A loss and Site B activation, logins will not complete. This is another reason to keep the failover procedure short and rehearsed.
- Target machine configuration for Credentials Passthrough (
DisableRestrictedAdmin= 0) is deployed by GPO and applies to machines at all sites uniformly. No per-site work is needed.
SecureConnect: special use cases
Enterprise environments broker through Sentry. The TruGrid SecureConnect agent is reserved for machines that fall outside Sentry's reach:
- LAB or isolated-segment devices not reachable from the Sentry network
- Machines not on the corporate LAN
- Special machines that require self-brokering
A machine can be brokered by both Sentry and SecureConnect simultaneously where needed. See Utilizing Sentry and SecureConnect brokering for accessing the same machine.
Quick reference
Item | Recommendation |
|---|---|
Sentries per site | Two, identically configured |
Site model | Active-passive. One site's Sentries online at a time |
Standby site state | Fully configured, services Disabled |
Failover action | Enable and start Sentry services at standby site |
WAN traffic | AD replication, DNS, authentication only. No RDP sessions |
Trusted Location IPs | All sites registered in advance, including standby |
SPN registration | All Sentries at all sites, in advance |
SecureConnect | Special cases only: LAB, off-LAN, self-brokering machines |
If you are planning an enterprise deployment and want a design review, contact TruGrid support and we will walk through your topology with you. |
Updated on: 23/07/2026
Thank you!
