[GSA 4.2] Build Sheet: On-Prem File Shares and RDP Through Private Access

A laptop that never touches the corporate network mounts a file share and opens a remote desktop session, with Kerberos single sign-on intact and multifactor authentication enforced at the identity layer. Domain controllers published properly, the Kerberos negative cache defused, and an honest account of what this does not replace.









