For the Application Availability Monitor (GAAM) to run successfully, review the following maintenance items.
LogonSimulator.exe
This process must always be running on the launch endpoint for GAAM launches to take place. When you configured the launch endpoint, this process was added to the startup folder for the user who ran it. That user is now tied to the LogonSimulator.exe process and must always be signed in to the launch endpoint in either an active or a disconnected session. The session must not be locked.
Google Chrome
Some settings are saved in the Google Chrome browser cache. If you clear the browser cache on the launch endpoint, subsequent launches are likely to fail. To resolve this, repeat the steps in the Launch Preparation section of the Launch Endpoint Installation & Configuration article
Also, before a GAAM schedule runs on the launch endpoint, GAAM exits any open Google Chrome sessions. If you need a web browser open during a GAAM launch, use a different browser, such as Microsoft Edge.
Reboot Schedule
Depending on how frequently your launches are scheduled, Goliath recommends a reboot schedule on your launch endpoint to ensure optimal success:
- For launches every 5 to 15 minutes, reboot nightly.
- For launches every 30 minutes or more, reboot weekly.
Before you configure the reboot schedule, configure automatic Windows sign-in for the local endpoint user, which is the user that runs LogonSimulator.exe. Automatic sign-in signs that user into the console session at startup, which also satisfies the console session requirement in Screenshot feature after an unattended restart.
To configure automatic sign-in, use Autologon, a Microsoft Sysinternals tool that encrypts the credential in the registry as an LSA secret rather than storing it as plaintext.
Caution: Automatic sign-in stores a reusable credential on the launch endpoint. As Microsoft documents, a user with administrative rights can retrieve and decrypt an LSA secret. Use an account with the minimum privileges the launch endpoint requires, and review the configuration with your security team.
Screenshot Feature
When you view GAAM results in the Goliath web console, GAAM can capture screenshots of the launches in action and display them with the launch results. To enable screenshots, an active console session for the local endpoint user is required. Without one, the product still works and reports as expected, but it doesn't capture screenshots.
The following options each produce an active console session. Choose the one that fits your environment.
-
Hypervisor Console:
- Connect to your hypervisor that hosts the launch endpoint, if the endpoint is a VM.
- Open a console session to the launch endpoint as the local endpoint user.
- This is the account configured to run the
LogonSimulator.exeprocess.
- This is the account configured to run the
- Go to Control Panel > Power Options and set the display to never turn off and the computer to never sleep.
- Exit all open programs and close the console session.
The console session must always exist in order for the screenshots to capture.
-
Redirect an RDP session to the console:
The Windows tscon command redirects an existing Remote Desktop Services session to the console. Use this option when configuring the launch endpoint over RDP to leave without disconnecting the local endpoint user.
- Use RDP to connect to the launch endpoint as the local endpoint user.
- Go to Control Panel > Power Options and set the display to never turn off and the computer to never sleep.
- Turn off the screen saver, and confirm that no machine inactivity limit policy applies to the account. A locked desktop produces blank screenshots even when the console session is active.
- Exit all open programs.
- Open Command Prompt as an administrator, and then run query session to identify your session ID. A
>character marks the current session. -
Redirect the session to the console, replacing SESSION_ID with the ID from the previous step:
tscon SESSION_ID /dest:console
Your RDP client disconnects, and the session continues to run on the console. To restore the console session after a restart, also configure automatic sign-in as described in Reboot schedule.
Tip: Windows assigns session IDs dynamically, so avoid reusing a fixed ID. To read the current session ID and redirect it in one step, run the following command in an elevated PowerShell prompt instead of the two steps above:
tscon (Get-Process -Id $PID).SessionId /dest:consoleCaution: Session redirection with
tsconis also a documented lateral movement technique, identified as RDP hijacking, T1563.002 in MITRE ATT&CK. Endpoint detection and response tools might flag or block it. Before using this option, please review it with your security team, as an exception may be needed. -
Double hop RDP session:
- RDP into any server in the environment with a user that will always be in an active or disconnected state
- From the above RDP session, RDP to the launch endpoint as the local endpoint user
- Go to Control Panel > Power Options and set the display to never turn off and the computer to never sleep.
- Exit all open programs.
- minimize the launch endpoint RDP session.
- Disconnect from the original RDP session.
Screenshot feature examples:
Screenshots enabled:
Screenshots disabled: