New version Termidesk VDI 7.0 enhances infrastructure security and expands administrative capabilities
Uveon – Cloud Technologies (part of Astra Group) releases a major update to its desktop and application virtualization platform Termidesk VDI 7.0.
The key innovation in version 7.0 is the support for mutual TLS (mTLS) two-way authentication between system components, virtualization platforms, gateways, and external systems. This interaction at all levels becomes a foundational element of the Zero Trust concept. It ensures invulnerability to MitM attacks, protection against bots and unauthorized scanners that are blocked already at the TLS handshake stage, and helps comply with stringent regulatory requirements for transmitting sensitive data. Since all communication participants undergo authentication, the audit log now includes complete data about connection participants extracted from the client certificate.
On the server side, network-based delivery of a single master image has been introduced — a new provider that enables the use of diskless machines or repurposing old PCs. This model reduces VDI storage requirements by up to 90%, simplifies image management, and enables near-instant rollback to a previous version with a simple workstation reboot.
Additionally, version 7.0 overhauls the licensing system. Instead of the previous two editions — Termidesk Terminal and Termidesk VDI — three tariff plans are now available: "Basic", "Standard", and "Advanced". The new model is more flexible and allows customers to choose exactly the feature set that matches their real-world needs.
The security enhancement line continues with support for RADIUS multi-factor authentication with one-time passwords via the Access-Challenge mechanism. Upon connection, the user enters a login and password, after which the RADIUS server requests a one-time code in a separate field of the web interface. Combining RADIUS with an LDAP domain allows configuring login for external users with one-time passwords, while leaving internal employees with seamless access via credential passthrough or Kerberos SSO. An additional layer of protection is provided by logging failed authentication events.
Termidesk VDI 7.0 introduces the long-awaited ability for users to independently restart their virtual workspace. A frozen application, black screen, or peripheral failure can now be resolved in a couple of minutes without waiting for technical support, and employees can restore their desktop even from a personal device.
Equally useful is the ability to save device redirection settings: the user selects the desired peripherals and parameters once, and they are automatically available for subsequent connections. In version 7.0, this is implemented for USB devices, folders, and smart cards, with future updates covering other device types. Client-side development also includes HiDPI screen scaling support, a unified installer and installation package for Linux-based OSes, display of a clear farm name instead of a URL or IP address, and an updated in-session toolbar that can now be minimized, pinned, or freely moved across the window while maintaining quick access to key functions.
Support for multiple sessions within a single server allows the administrator to precisely address an individual message to the desired session, ensuring the user receives it.
The administrator portal in the new version has fully transitioned to an updated design — the old interface is no longer used. The layout has become adaptive, better adjusting to display scale and size, and the dark theme has been refined based on feedback from version 6.1 users. Group actions for users, groups, and pools have been added, as well as a dedicated section for assessing load on terminal servers. The pools section now displays data on providers, templates, and guest OS parameters. The web portal now shows online metrics for user sessions: where the user connected from and to, what resources were consumed, and which policies were applied, enabling real-time infrastructure load assessment.
The dispatcher now includes a new template for standalone machines for FQDN-based operation and Kerberos support, workstation health checking before assignment to a user, support for VMware vSphere 8 and 9, template versioning for zVirt, SASL bind authentication for LDAP servers, management of token validity duration, and flexible tag management for virtual machines and their groups. Administrators can now send messages to users directly within a session, monitor agent and component metrics in the portal, and apply new policies — such as prohibiting editing of a created connection in the client.
The new "read-only" remote assistant mode allows the administrator to connect to a session solely for observation, without mouse and keyboard control capability. To transition to actual control, a special request must be sent to the user. This approach eliminates covert intervention and balances high-quality technical support with the integrity of the employee's workspace.
The aggregator has switched to the least connections balancing algorithm instead of round-robin, gained session reconnection via site policies, and integration with OpenBao. A proprietary message broker with ZeroMQ-based clustering has also been implemented, giving Astra Group full control over the platform's architecture and data.
«Security, functionality, and user experience are the three main priorities of the new Termidesk release. We didn't just add dozens of new features — we rethought the platform's overall logic of operation. For IT departments — we simplified installation, configuration, and administration, reducing operational costs and maintenance time. For end users — we significantly improved the interaction with desktops and applications, making work with Termidesk as comfortable and intuitive as possible,» summarized Denis Mukhin, Director of Virtualization and Cloud Services at Astra Group.