How to Install and Configure TSplus Advanced Security: Step-by-Step Guide
Quick Answer To install TSplus Advanced Security, download its installer from the official TSplus website and run it as an administrator on the Windows compu...
Quick Answer
To install TSplus Advanced Security, download its installer from the official TSplus website and run it as an administrator on the Windows computer you want to protect. Complete setup, open the administration console, and configure trusted administrator IP addresses before applying connection restrictions. Then verify Bruteforce Protection, configure Geographic Protection, and enable the additional features available in your license.
Apply settings gradually and test a new connection after each change. For ransomware protection, complete and review the learning period before relying on enforcement. Keep a working console recovery method available throughout deployment.
Before You Begin
This guide is intended for IT support technicians and administrators protecting Windows servers or workstations. Remote Desktop Protocol, or RDP, is the Windows technology used for remote desktop connections. Interface labels can differ between TSplus builds and between the simplified and advanced administration views.
Check Operating System and Software Requirements
The dedicated TSplus prerequisites page lists Windows 11 Pro and Windows Server 2016, 2019, 2022, and 2025 among compatible systems. It also lists older Windows releases. Use an operating system that remains covered by your organization's security update arrangements; product compatibility alone does not establish operating system support.
TSplus specifies .NET Framework 4.7.2 or later and supports 32-bit and 64-bit architectures. The installer can install missing prerequisites. Check the dedicated prerequisites page for your target system before deployment. :chatgpt-content-reference{index="0"}
Confirm Your License and Required Features
| Edition | Main features relevant to this guide |
|---|---|
| Essentials | Bruteforce Protection, Hacker IP Protection, Firewall, Geographic Protection, and working hours restrictions. |
| Ultimate | Essentials features plus Ransomware Protection, Trusted Devices, and Permissions. |
Licenses are assigned per server. Confirm your purchased edition and subscription status before depending on a feature tested during the trial. Check the trial expiry displayed in the installed console rather than assuming a fixed duration from marketing material. :chatgpt-content-reference{index="1"}
Prepare Access, Backups, and a Test Account
- Use an account with local administrator rights.
- Confirm that a recent server and business-data backup is recoverable.
- Arrange physical, hypervisor, or cloud console access that does not depend on the RDP connection being protected.
- Record the administrator connection's source IP address as observed by the server.
- List required countries, remote access ports, applications, users, and support access routes.
- Create or select a non-administrator pilot account.
- Schedule a maintenance window and notify affected users.
Step 1: Download and Install TSplus Advanced Security
- On the Windows machine to be protected, open the official TSplus Advanced Security installation page.
- Follow its download link to obtain the installer.
- Right-click the downloaded installer and select Run as administrator. Approve the Windows elevation prompt after checking that it is the expected installer.
- Select the installation language.
- Choose Recommended for a standard installation. Choose Advanced when you need the documented proxy or download-only options.
- Read and accept the license agreement, then allow installation to finish.
- Open TSplus Advanced Security using its desktop shortcut.
Verification: The administration console should open and display the dashboard. Record the installed version and license status. If setup requests a restart, complete it during the maintenance window before testing protection. :chatgpt-content-reference{index="2"}
Step 2: Activate Your License
- Open the License tab.
- Select Activate your License.
- Enter the activation or subscription key supplied with your purchase.
- Click Next and select the applicable Advanced Security license and support items.
- Complete activation, then refresh the licensing status.
Verification: Confirm that the console shows the expected edition and entitlement. If online activation is unavailable, follow the offline activation procedure linked from the official licensing documentation. Keep activation keys out of screenshots and support logs shared publicly. :chatgpt-content-reference{index="3"}
Step 3: Protect Your Administrator Access
- Open Firewall, where TSplus manages blocked and allowed IP addresses.
- Locate the IP whitelist, also called the list of allowed IP addresses.
- Add the narrowly scoped, trusted administrator source IP address.
- Give it a useful description, such as the office administration connection.
- Check that the saved entry matches the address the server actually sees.
If a legitimate address is already blocked, the interface provides an Add Existing to Whitelist operation. Use an exception only after checking why the address was blocked. :chatgpt-content-reference{index="4"}
An IP whitelist bypasses relevant IP blocking controls. Avoid allowing an entire provider network or a broadly shared connection merely for convenience. If your administrator IP changes frequently, plan an approved stable management route and retain console recovery access.
Verification: Establish a second administrator connection before proceeding. A whitelisted connection checks administrator accessibility; it does not prove that blocking works for other clients.
Step 4: Verify the Firewall Enforcement Method
When Windows Firewall is enabled, TSplus recommends using it to enforce Advanced Security rules. The documented setting is Settings > Advanced > Product > Use Windows Firewall. A value of Yes uses Windows Firewall; No selects TSplus's built-in firewall for blocking. :chatgpt-content-reference{index="5"}
- Review the current enforcement setting.
- For a standard Windows Firewall deployment, retain the documented Windows Firewall integration.
- If another firewall product is installed, review the vendor's integration guidance before changing the enforcement method.
- Confirm that required application and management connections still work.
Step 5: Configure Bruteforce Protection
Bruteforce Protection monitors failed logons and blocks source IP addresses that reach the configured threshold. The documentation gives defaults of 10 failed attempts and a two-hour counter reset. Check the actual values in your installation. :chatgpt-content-reference{index="6"}
- Open Bruteforce Protection.
- Check the status indicators for Windows failed-logon monitoring, the Advanced Security service, and the applicable firewall integration.
- If TSplus Remote Access is installed, also inspect HTML5 Web Portal failed-logon monitoring.
- Review the maximum failed-attempt threshold and counter reset period.
- Where available, review temporary blocking and escalation settings separately. A counter reset period is not the same setting as a temporary block duration.
- Keep the initial settings unless your access pattern or security policy justifies an adjustment.
Verification: In an isolated test environment, use a disposable account and a separate, non-whitelisted source IP to confirm blocking and the corresponding event. Account lockout policies may trigger first. Do not deliberately cause repeated failures from a shared production office IP.
Step 6: Configure Geographic Protection
- Open Geographic Protection.
- Select Allow connections only from this list of countries.
- Click Add country and add every country required for legitimate users and support staff.
- Include the country associated with your current connection or approved VPN exit point.
- Click Apply and review the confirmation carefully.
- Under Settings > Advanced > Geographic Protection, check monitored ports and processes, especially if you use a custom RDP port.
Country filtering evaluates connection information; it does not establish a user's identity. Do not assume it covers every network service automatically. :chatgpt-content-reference{index="7"}
Verification: Test legitimate access through the actual user connection path using a non-whitelisted test source. Check the event record and observed source IP. For a server behind a gateway or proxy, establish which source address reaches the protected machine before relying on country-based decisions.
Step 7: Check Hacker IP Protection
Hacker IP Protection uses a maintained list of malicious IP addresses. TSplus documents daily automatic updates and requires an active Support and Updates Services subscription. You can request a manual update using Refresh Hacker IP from the blocked IP addresses interface. :chatgpt-content-reference{index="8"}
- Confirm that the required subscription is active.
- Check that automatic synchronization is enabled.
- Run a manual refresh if needed and check for errors.
- Investigate any legitimate connection reported as blocked before creating an exception.
Verification: Confirm that refreshing succeeds. Do not visit malicious infrastructure to test the feature.
Step 8: Configure Ransomware Protection
Complete this step when your license includes Ransomware Protection.
- Confirm that the server is suitable for establishing a trusted application baseline.
- Open Ransomware Protection and select Enable Ransomware Protection.
- Review the learning period. TSplus recommends an initial five-day period.
- Run representative approved workloads, including scheduled business tasks.
- Review learned program exceptions and investigate unfamiliar entries.
- After learning completes, verify that protection is enabled and is no longer learning.
TSplus documents that stopping the learning period disables Ransomware Protection. Do not assume that pressing a stop control immediately switches the feature into enforcement. Check the resulting status. :chatgpt-content-reference{index="9"}
Review snapshot storage and retention under the advanced ransomware settings. These snapshots have configurable capacity and retention limits and should not replace independent backups. Avoid broad script or application exceptions. :chatgpt-content-reference{index="10"}
Verification: Confirm the protection state, review exceptions, and run normal business operations. Do not test with live ransomware on a production server.
Step 9: Restrict Working Hours
- Open Restrict Working Hours.
- Select a pilot user or group.
- Choose access during specified time ranges.
- Define permitted days and hours, checking the applicable timezone.
- Configure the advance warning under Settings > Advanced > Working Hours.
- Test before applying the schedule to additional users.
Direct user rules take priority. Without a direct user rule, TSplus combines group rules using the more permissive result. Check all relevant group memberships when access extends beyond the intended schedule. Enforcement relies on server time, so verify the server clock and configured timezone. :chatgpt-content-reference{index="11"}
Verification: Check a pilot user's new login inside and outside the permitted period, along with the warning and session behavior at the boundary.
Step 10: Configure Additional User Restrictions
Trusted Devices
- Open Trusted Devices and select a pilot user.
- Review the recorded client device name and independently confirm it belongs to an approved workstation.
- Add the required device names and enable the restriction.
- Test both an approved and an unapproved client.
Trusted Devices checks client names. TSplus documents incompatibility with HTML5 sessions and limitations with iOS and Android devices. A client-provided hostname is not cryptographic proof of device identity. Allowing Web Portal connections through the advanced exception does not provide equivalent device verification. :chatgpt-content-reference{index="12"}
Permissions
Use Permissions to review access to local filesystems, printers, and registry keys. Begin with a pilot user and a limited business resource. Record existing permissions, apply only the access required, and verify both permitted and denied operations using the pilot account. :chatgpt-content-reference{index="13"}
Secure Sessions
Where available, use Secure Sessions to configure Windows, secured-session, or kiosk behavior for a pilot user. Review desktop, disk, and application interface restrictions, then test a fresh session.
TSplus warns that these settings can conflict with Active Directory policies. The feature primarily customizes the user interface; hiding a drive or control does not replace access permissions. Coordinate changes with existing domain policies. :chatgpt-content-reference{index="14"}
Step 11: Configure Alerts and Save Your Configuration
- Open Alerts and select the security events that require attention.
- Configure the email notification channel using your approved SMTP service. SMTP is the protocol used to send email.
- Enter the required server, port, authentication, sender, and recipient details.
- Send the provided test notification and confirm delivery to the intended mailbox.
Use the encryption and connection requirements specified by your mail provider. Protect notification credentials and any webhook secrets. :chatgpt-content-reference{index="15"}
Next, open Backup / Restore and create an Advanced Security configuration backup. Confirm that the backup exists and copy it to a protected location outside the server. This backup covers the product's data and settings; it is separate from business-data and system recovery backups. :chatgpt-content-reference{index="16"}
Step 12: Verify the Deployment
| Check | Expected result | If it fails |
|---|---|---|
| New administrator connection | The approved management path works. | Use console access and inspect the observed source IP and blocking reason. |
| Standard user access | A pilot user can sign in and use required applications. | Review country, schedule, device, and permission restrictions. |
| Bruteforce monitoring | Applicable monitoring and service indicators are healthy. | Investigate the reported component before declaring protection operational. |
| Geographic rules | Required locations work through the intended connection path. | Check source IP classification and monitored ports or processes. |
| Ransomware protection | Protection is enabled after learning, with reviewed exceptions. | Check whether learning remains active or protection was disabled. |
| Working hours | Pilot access follows the intended schedule. | Check server time, timezone, direct user rules, and group membership. |
| Notifications | The test notification reaches its destination. | Check mail settings, authentication, delivery filtering, and outbound connectivity. |
| Configuration backup | A recent backup exists in a protected secondary location. | Repeat the backup and verify the destination. |
Document the tested version, policies, exceptions, recovery route, and results. Expand deployment only after the pilot succeeds.
Troubleshooting and Recovery
A Legitimate User Cannot Connect
- Record the failure time, username, client type, and source IP without collecting passwords.
- Use the server console or another approved working management path.
- Review Advanced Security events and the blocked IP list.
- Correct the specific cause: an omitted country, incorrect schedule, unapproved device, or failed-logon block.
- If appropriate, remove the individual block after correcting its cause.
- Test a fresh connection.
Unblocking an address alone may be temporary if the policy that caused the block remains unchanged. A narrowly scoped whitelist exception should be deliberate and documented.
The Policy Appears Ineffective
- Check whether the test IP is whitelisted.
- Check whether the test user appears in the Users Allow List.
- Confirm that the relevant feature is licensed and enabled.
- Check group membership and direct user overrides.
- Confirm that you tested a new session and the intended protocol or port.
TSplus documents that users in its Users Allow List are excluded from applicable restrictions. Use an ordinary pilot account when testing user policies. :chatgpt-content-reference{index="17"}
A Business Application Is Flagged
Inspect the detection and verify the application's origin and behavior before allowing or restoring it. Prefer the smallest justified exception. Do not whitelist a whole writable folder to resolve one application alert. If malicious activity is suspected, follow your incident response process before restoring quarantined items.
Restore an Earlier Configuration
- Connect through the recovery console.
- Preserve relevant incident or troubleshooting records.
- Open Backup / Restore and select the known-good backup.
- Choose Restore Settings Only or the full restore option according to the recovery requirement.
- Allow the settings to reload, then repeat access and protection checks.
Restoring product settings does not automatically reverse every external change. Restore separately recorded Windows permissions or firewall configuration when those changes require independent recovery. :chatgpt-content-reference{index="18"}
Uninstall Only When Necessary
Use the documented TSplus uninstaller when removal is required. Review its Unblock IP addresses option: removing the application alone should not be assumed to remove previously created Windows Firewall blocks. Removing those blocks also removes their protection, so plan replacement controls first. Do not reset the entire Windows Firewall policy to fix a single TSplus rule. :chatgpt-content-reference{index="19"}
Maintenance
- Review security events and investigate unexpected administrator or application blocks.
- Remove obsolete IP, user, program, and device exceptions.
- Review access schedules when staffing or support arrangements change.
- Monitor license and support entitlements.
- Back up the configuration before significant changes.
- Install updates in a maintenance window and repeat the pilot checks afterward.
TSplus provides updating through the homepage update tile and documents an automatic settings-and-data backup before updates. Keep an independently retained backup as part of your change procedure. :chatgpt-content-reference{index="20"}
Frequently Asked Questions
Does installing Advanced Security automatically complete the configuration?
No. You must check protection status, define access policies, review exclusions, confirm licensing, and test legitimate access. Ransomware learning also requires review before relying on enforcement.
Should every office IP address be whitelisted?
Only where the exception is justified. An allowlisted shared office address can exempt traffic from multiple devices. Use narrow management exceptions and test normal users without those exemptions.
Can country filtering replace strong authentication?
No. A connection from an allowed country can still be unauthorized. Maintain strong authentication, account permissions, patching, and an appropriately restricted remote access architecture.
Can I apply the same configuration to every server?
Use a common baseline, then validate each server's applications, connection paths, source addresses, schedules, and recovery arrangements. Copying restrictions without checking those differences can disrupt access.
Does a successful ransomware learning period prove that all ransomware will be blocked?
No. Learning establishes exceptions for observed activity. Review those exceptions, confirm enforcement, retain other security controls, and test independent backup recovery.
Sources
- TSplus Documentation: Prerequisites
- TSplus Documentation: Installation and Uninstallation
- TSplus: Advanced Security Editions and Licensing
- TSplus Documentation: License Activation
- TSplus Documentation: Firewall and IP Lists
- TSplus Documentation: Advanced Firewall Settings
- TSplus Documentation: Bruteforce Protection
- TSplus Documentation: Geographic Protection
- TSplus Documentation: Hacker IP Protection
- TSplus Documentation: Ransomware Protection
- TSplus Documentation: Ransomware Snapshot Settings
- TSplus Documentation: Working Hours Restrictions
- TSplus Documentation: Working Hours Warnings and Timezone
- TSplus Documentation: Trusted Devices
- TSplus Documentation: Trusted Devices Limitations
- TSplus Documentation: Secure Sessions
- TSplus Documentation: Users Allow List
- TSplus Documentation: Alerts
- TSplus Documentation: Backup and Restore
- TSplus Documentation: Updating Advanced Security
Was this guide useful?
Your answer helps us keep BISONKB accurate and practical.