I support a Hospice and our clinicians use laptops to do "Point of Care". All logons are domain logons. The domain GPO restricts the end user form doing anything other than running the software we install and installing updates from our WSUS servers.We also use Sophos End Point Security on all computers. This provides a firewall, replacing the built-in Windows FW.
I can access our laptops (and desktops) using RDP, but they have to be in one of our two locations and I can't share/view what they are doing to cause their problem since I have to logon to the computer. Also, most of our clinicians use their laptops at home behind their personal router/firewall.
What exactly has to be done on/by the end user so that I can access their computers wherever they are? Is there something we administrators can do one time to get them ready? Keep in mind that they are very limited in what they can do as a user and the skill set here is not very high.
TIA,
Hank Arnold (Microsoft MVP)