TruGrid SecureRDP - Sentry Enterprise Design
TruGrid Sentry is a light-weight software that brokers Remote Desktop Protocol (RDP) connections between End Users and Desktops & Apps. It serves as a core component of the TruGrid SecureRDP architecture, functioning as an invisible gatekeeper that eliminates the need for exposed firewall ports or complex VPNs.
This article describes the recommended TruGrid Sentry architecture for enterprise environments with multiple datacenters on a Wide Area Network (WAN). It covers TruGrid Sentry placement, system requirements, active-passive design, active-active design, failover, and the authentication features most relevant to enterprise deployments: Trusted Locations and Passthrough Authentication.
For an overview of how Sentry brokering works, see TruGrid SecureRDP - Multi-site brokering.
Design Principle: Active-Active or Active-Passive
Depending on business needs, TruGrid Sentry instances can be placed in the following scenarios:
- Active-Active: TruGrid Sentry instances active in both Site A and Site B:
- WAN Users: For WAN End Users connecting to Desktops and Apps on the same WAN, TruGrid uses its Local Awareness feature such that network connection flow is direct - not through TruGrid Sentry - in order to achieve maximum scalability. In this scenario, there is no brokering load on TruGrid Sentry servers. TruGrid Sentry servers are only leveraged for pre-connection intelligence.
- Remote Users: For Remote / BYOD Users connecting over the internet, TruGrid Sentry server in any datacenter will handle brokering between external (over the Internet) End Users and Desktops & Apps in the datacenter, using reverse-connect technology and zero inbound exposure. TruGrid Sentry instances currently do not support pinning to a particular datacenter; thus, in this scenario, it is possible for a TruGrid Sentry in Site A to broker connection to Desktops and Apps in Site B.
- Active-Passive:
- Site A (primary): Sentry services running
- Site B (standby): Sentry software installed and fully configured, but the Sentry services are disabled. Site B Sentry instances do not participate in brokering until activated during failover
- WAN Users: TruGrid Sentry servers are only leveraged for pre-connection intelligence. TruGrid uses its Local Awareness feature such that network connection flow is direct - not through TruGrid Sentry - in order to achieve maximum scalability.
- Remote Users: Using reverse-connect technology and zero inbound exposure, TruGrid Sentry servers in active datacenter ensure successful cloud authentication before brokering access to internal resources, while leveraging TruGrid Global Fiber Optic mesh for low latency experience.
System requirements
Per Sentry server:
- A fully patched 64-bit Windows Server OS. Windows Server 2019 or later is highly recommended. Windows Server 2016 is supported but not recommended for new deployments as it is past end of mainstream support.
- 16 GB RAM, 2 CPUs, disk with high IOPS. The server does not need to be dedicated, but CPU and memory utilization should not exceed 70%. Do not co-locate Sentry on a resource-overloaded server.
- The Sentry server's network card DNS settings must point to Active Directory DNS servers, not external DNS. The same applies to all RDP hosts.
- No inbound firewall exposure is required. Ensure RDP over port 3389 is enabled only on machines that will be accessed.
Per site:
- Recommended minimum - two Sentry servers per site. Within the active site, the Sentry instances jointly provide pre-connection intelligence and brokering for external users.
- The standby site mirrors the primary site with two pre-configured Sentry instances with the "TruGrid Sentry" service disabled, until failover is activated.
- All four servers (two per site) should be built and configured identically.
Scalability and Load Balancing:
- Scalability: Out of the box, each TruGrid Sentry server can handle 3,000 concurrent sessions. This figure can be increased via Windows registry update to a maximum of 10,000 concurrent sessions per Sentry server. With adequate sizing (CPU and RAM), four (4) Sentry servers can handle 40,000 concurrent sessions. Since there is no technical limit to how many Sentry servers an environment can have, Organizations can add as many Sentry servers as necessary to achieve desired scale.
- Load Balancing: TruGrid Sentry servers do not need to be aware of each other. When a new Sentry server is added to an Active Directory domain, it announces itself to TruGrid Cloud. TruGrid Cloud sends connection and brokering requests only to Sentry servers that announce their presence. In this regard, load balancing is automatic.
Site design: Active-Passive or Active-Active
Normal operations
ACTIVE-ACTIVE Design

Authentication: Trusted Location Login and Passthrough Authentication
Enterprise deployments on hybrid domains (AD synced to Entra ID) can combine two features for a frictionless on-network login experience:
- Trusted Location Login: End Users connecting from Trusted IP locations authenticate against On-Premises AD with no MFA prompt. Users outside trusted locations authenticate against Entra ID with full MFA and Conditional Access enforcement.
- Passthrough Authentication: With Remote Credential Guard enabled on the End User windows Connector, an AD-joined user's credentials are passed through at login. The user is signed in, authenticated over Kerberos, and their application shortcuts are created automatically. No password is sent to or cached on the session host.
Enterprise Design Notes:
- Add every LAN / WAN site's public IP to the Trusted Location list. End users on domain-joined devices in Trusted Locations across multiple datacenters in Active-Active setup enjoy frictionless productivity.
- Register the SPN for standby Sentries in advance. Kerberos authentication for Credentials Passthrough requires an SPN per Sentry FQDN. Registering both sites' SPNs ahead of time keeps failover to a service start in Active-Passive scenarios.
- Trusted Location Login requires a Sentry online. During the failover window between Site A loss and Site B activation, logins will not complete. This is another reason to keep the failover procedure short and rehearsed.
- Target machine configuration for Credentials Passthrough (
DisableRestrictedAdmin= 0) is deployed by GPO and applies to machines at all sites uniformly. No per-site work is needed.
SecureConnect: Special Use Cases
Enterprise environments broker through Sentry. The TruGrid SecureConnect agent is reserved for machines that fall outside Sentry's reach. For example:
- LAB or isolated-segment devices not reachable from the Sentry network
- Machines not on the corporate LAN, in Microsoft Azure, Amazon AWS, or other cloud environments
- Special machines that require self-brokering
A machine can be brokered by both Sentry and SecureConnect simultaneously where needed. See Utilizing Sentry and SecureConnect brokering for accessing the same machine.
Quick reference
Item | Recommendation |
|---|---|
Sentry instances per site | Two or more Sentry servers, identically configured |
Site Model | Active-Active - All Sentry instances across multiple sites online. Active-Passive. One site's Sentries online at a time. |
Standby Site State | Fully configured, services Disabled |
Failover Action | Enable and start Sentry services at standby site |
WAN Traffic | AD replication, DNS, authentication only. RDP sessions if using Active-Active with resources across multiple sites |
Trusted Location IPs | All Trusted Locations registered in advance, including standby |
SPN registration | All Sentries at all sites, in advance |
SecureConnect | Special cases only: LAB, off-LAN, self-brokering machines |
If you are planning an enterprise deployment and want a design review, contact TruGrid support and we will walk through your topology with you.
Updated on: 11/08/2026
Thank you!
