Available now Core platform

Lira RDP Security

RDP security, automatic IP blocking, 2FA/MFA, and Windows Server operations

A Windows agent sends authentication events through its outbound HTTPS/WSS channel. Block attackers on the host, enforce MFA, and manage Defender, updates, and firewall from one console. Paid use starts only after the customer purchases server licenses, from €6 per server per month.

Capabilities

Security validation

Lira is assessed against the OWASP Top 10 risk categories as part of the internal application-security review.

This describes internal security testing and does not constitute independent certification.

What is RDP security for Windows Server?

RDP security is the combination of access controls, authentication monitoring, automatic response, secure transport and recoverable administration used to protect Remote Desktop on Windows Server. A strong configuration does not rely on a password or a single firewall rule: it combines 2FA/MFA, event visibility, temporary IP blocking, trusted administration paths, TLS certificates and maintained Windows security controls.

How Lira protects Remote Desktop

The Lira Windows agent reads supported authentication and system state locally, then initiates an outbound HTTPS/WSS connection to the management portal. Failed sign-ins can trigger temporary Windows Firewall blocks, while administrators review attack sources, active bans and successful or failed authentication across their servers.

For protected users, Lira adds TOTP two-factor authentication (2FA/MFA) at the Windows logon layer before the desktop session starts. The same portal also shows Defender, Windows Update, firewall, disk and RDP TLS state, so an access incident can be investigated without losing the operational context around the server.

A safe deployment model

Start with one non-critical server and one named user. Keep a separate console, hypervisor or other tested recovery path, allowlist the administrator network, verify agent communication and only then enable 2FA/MFA. Expand the policy after checking a fresh RDP sign-in, rejection of an invalid code, audit events and the documented rollback procedure.

Capabilities

RDP security questions

Does Lira require an RD Gateway?

No. Lira can protect supported Windows sign-in scenarios on the server through its agent and Credential Provider. An RD Gateway, VPN or jump host can still be used as an additional network control.

Is 2FA the same as MFA?

2FA uses exactly two factors; MFA is the broader term for two or more. Lira's password plus TOTP flow is two-factor authentication and is also a form of MFA, so both terms accurately describe it.

Does automatic IP blocking replace 2FA/MFA?

No. Blocking reduces repeated credential attacks, while 2FA/MFA protects a user when a password is known. They address different parts of RDP security and should be deployed together.

Start free trialGetting startedRDP 2FA/MFA guideRDP TLS certificate guideLive demo