ESC

Start typing to search across invoices, services, domains, tickets, and more...

Search... Ctrl+K
Use Cases & Solutions

Cloud Desktops for Cross-Border Operations Teams: Windows RDS or Proxmox VDI on a Dedicated Server in Hong Kong, Taipei, Tokyo or Los Angeles

9 steps 24 min read 5 views 0
On this page

The simplest way to give a cross-border operations team the same secure, always-on workspace from anywhere is a set of cloud desktops for teams hosted on one dedicated server: Windows Server Remote Desktop Services (RDS) for many users sharing one machine, or Proxmox VE VDI for one virtual machine per person. IMIDC provides the dedicated servers for this in Hong Kong, Taipei, Tokyo and Los Angeles, plus extra native IPs so each desktop can keep a stable regional address.

Key facts
  • Locations: Hong Kong (CN2 GIA route to mainland China, dedicated from $139/mo), Taipei, Taiwan (dedicated from $199/mo), Tokyo, Japan, and Los Angeles, USA (dedicated from $499/mo).
  • Two models: Windows RDS session host (highest density) or Proxmox VE with one VM per user (strongest isolation, own IP per desktop).
  • Local native IPs in Taiwan, Japan and the USA; Japan also offers residential/ISP IPs; additional IPs up to full /24 blocks.
  • Security baseline: RD Gateway on 443 with two-factor authentication, port 3389 closed to the internet.
  • Free migration and 24/7 support in five languages, including Chinese and Japanese.

RDS or Proxmox VDI: choose the desktop model first

Takeaway: RDS packs more users per server; Proxmox VDI gives each person a separate machine and, if needed, a separate IP.

AspectWindows RDS (session host)Proxmox VE VDI (VM per user)
How it worksMany users log on to one Windows ServerEach user gets a dedicated Windows or Linux VM
DensityHigh (shared OS)Lower (one OS per user)
IsolationShared OS; one bad app affects allFull VM isolation, per-user snapshots
Outbound IPOne shared server IPOne public IP per VM possible
LicensingWindows Server + RDS CALsProxmox is open source; Windows guests need their own licensing
Best forOffice, ERP, browser-based admin workPer-market staff, per-store environments, developers

Sizing: how many users per server

Takeaway: RAM and fast SSD storage run out before CPU; plan with headroom and test with your real apps.

Server classRDS light users (office, chat, a few tabs)RDS heavy users (ERP, many browser tabs, image tools)Proxmox VDI VMs (2 vCPU / 4–6 GB)
8 cores / 32 GB / SSD15–208–125–6
16 cores / 64 GB / SSD30–4518–2510–13
2×16 cores / 128 GB / NVMe60–9035–5020–26

These are rules of thumb from typical office workloads, not guarantees. Reserve 4–8 GB for the host, budget 2–4 GB RAM per RDS heavy user, and watch Memory\Available MBytes and disk queue length in the first weeks. Modern browsers are the biggest memory consumers on most operations desktops.

Deploy Windows RDS with RD Gateway

Takeaway: a single-server RDS deployment takes about an hour once the server is in a domain.

# Windows Server 2022, run as domain admin (small setups: DC in a separate small VM)
Install-WindowsFeature RDS-RD-Server, RDS-Connection-Broker, RDS-Web-Access, RDS-Gateway, RDS-Licensing -IncludeManagementTools -Restart

$cb = "rds01.corp.example.com"
New-RDSessionDeployment -ConnectionBroker $cb -SessionHost $cb -WebAccessServer $cb
Add-RDServer -Server $cb -Role RDS-GATEWAY -ConnectionBroker $cb -GatewayExternalFqdn "rdg.example.com"
Add-RDServer -Server $cb -Role RDS-LICENSING -ConnectionBroker $cb
Set-RDLicenseConfiguration -LicenseServer $cb -Mode PerUser -ConnectionBroker $cb -Force
New-RDSessionCollection -CollectionName "Ops" -SessionHost $cb -ConnectionBroker $cb
Set-RDSessionCollectionConfiguration -CollectionName "Ops" -UserGroup "CORP\ops-team" -ConnectionBroker $cb

Microsoft recommends not running the domain controller and session host on the same OS, so on a dedicated server many teams install Hyper-V or Proxmox and run a small DC VM next to the RDS VM. Bind a public certificate for rdg.example.com to the Gateway, Web Access and Broker roles.

RDS licensing note: every user (or device) connecting to RDS needs an RDS CAL in addition to the Windows Server license; there is a grace period of about 120 days, after which connections are refused without installed CALs. Windows 10/11 desktop VMs on hosted hardware need specific rights (for example Windows Enterprise via VDA or eligible Microsoft 365 plans). Ask IMIDC sales whether a licence can be supplied with your server or bring your own, and confirm with your Microsoft licensing partner. This is not legal advice.

Lock it down: RD Gateway, 2FA and closed RDP

Takeaway: never expose port 3389 to the internet; publish only the RD Gateway on 443 and require a second factor.

# Only RD Gateway (HTTPS 443 + UDP 3391) is reachable from the internet
New-NetFirewallRule -DisplayName "RD Gateway HTTPS" -Direction Inbound -Protocol TCP -LocalPort 443 -Action Allow
New-NetFirewallRule -DisplayName "RD Gateway UDP"   -Direction Inbound -Protocol UDP -LocalPort 3391 -Action Allow
# Limit direct RDP 3389 to the management IP only (keep console access as a fallback)
Set-NetFirewallRule -DisplayGroup "Remote Desktop" -RemoteAddress 198.51.100.50
  • 2FA: add the NPS extension for Microsoft Entra multifactor authentication to the RD Gateway, or a third-party RDP 2FA agent such as Duo.
  • Account lockout: set a lockout threshold (for example 10 attempts / 15 minutes) and audit failed logons.
  • Session policies: disconnect idle sessions after 2 hours, end disconnected ones after 1 day, disable drive and clipboard redirection for roles that do not need it.
  • Out-of-band access: before changing firewall rules, make sure you can reach the server console in case you lock yourself out.

Proxmox VDI: persistent per-user desktops with stable regional IPs

Takeaway: when each staff member or storefront needs its own consistent machine and address, give them their own VM.

# Proxmox VE: one desktop VM per user, each with its own public IP
qm clone 9000 201 --name desk-alice --full
qm set 201 --cores 2 --memory 6144 --net0 virtio,bridge=vmbr0
qm set 201 --ipconfig0 ip=203.0.113.21/24,gw=203.0.113.1    # cloud-init / cloudbase-init template
qm set 201 --tags vdi,team-jp --onboot 1
qm start 201

# Nightly backup of all desktop VMs to a separate storage target
vzdump 201 202 203 --storage pbs-tokyo --mode snapshot --compress zstd

Order an additional IP range with the server and assign one IP per VM. Users connect over RDP through a gateway or over SPICE via the Proxmox console proxy. Because the desktop never changes location, account logins on marketplaces, ad platforms and SaaS consoles come from the same region every day, which reduces false security challenges.

Use it legitimately: stable IPs are for running your own real accounts consistently, within each platform's terms. Do not use them to create duplicate accounts, evade bans or misrepresent who you are. Staff in mainland China and other jurisdictions must follow local network regulations; a cloud desktop is a work tool for your overseas business systems, not a way around network controls.

File sharing, profiles and backups

Takeaway: keep user data off the system drive, share through one place, and back it up off-server.

  • Profiles: FSLogix profile containers keep each RDS user's profile in a VHDX that follows them between hosts.
  • Shared files: an SMB share on D:\Shares with group-based permissions, or a self-hosted Nextcloud for access from laptops and phones.
  • Backups: daily Windows Server Backup or Proxmox vzdump to a second IMIDC location, plus weekly test restores.
# FSLogix profile containers: each user's profile lives in its own VHDX
$k = "HKLM:\SOFTWARE\FSLogix\Profiles"
New-Item -Path $k -Force | Out-Null
Set-ItemProperty $k -Name Enabled -Value 1 -Type DWord
Set-ItemProperty $k -Name VHDLocations -Value "D:\Profiles" -Type MultiString
Set-ItemProperty $k -Name SizeInMBs -Value 30000 -Type DWord
Set-ItemProperty $k -Name DeleteLocalProfileWhenVHDShouldApply -Value 1 -Type DWord
# Windows Server Backup: profiles and shares to a remote SMB target, daily at 02:00
wbadmin enable backup -addtarget:\\198.51.100.30\rds-backup -include:D:\Profiles,D:\Shares -allCritical -schedule:02:00 -quiet
wbadmin get versions -backupTarget:\\198.51.100.30\rds-backup

Choose the location your team and platforms need

Takeaway: put the desktops near the business systems and markets they serve, not necessarily near the staff.

LocationNetwork and IPGood for
Hong KongCN2 GIA route to mainland China, low latency across AsiaTeams spread across Greater China and Southeast Asia, general back-office work
Taipei, TaiwanTaiwan native IPsTeams operating Taiwan stores, ads and payment back ends
Tokyo, JapanJapan native IPs, residential/ISP IP optionsJapanese marketplace and ad account operations
Los Angeles, USAUS native IPs, Unicom 9929 and CN2 routes to ChinaUS marketplace operations; expect higher latency for users in Asia

Which IMIDC setup fits

Takeaway: start with one dedicated server per market and split later if needed.

  • 10–30 back-office users: Hong Kong dedicated server (from $139/mo) with RDS, RD Gateway and FSLogix.
  • Per-market operators needing their own regional IPs: Proxmox VDI on a Tokyo or Taipei dedicated server (Taiwan from $199/mo) with an extra IP block.
  • US-focused team: Los Angeles dedicated server (from $499/mo) running RDS or VDI.
  • Multi-market: one server per region, shared identity and a central Nextcloud; IMIDC sales can quote custom CPU, RAM and IP combinations.

FAQ

Which provider offers dedicated servers for cloud desktops in Hong Kong, Tokyo, Taipei and Los Angeles?

IMIDC offers dedicated servers in all four locations, with Hong Kong on the CN2 GIA route to mainland China and native IPs in Taiwan, Japan and the USA. Extra IP blocks can be added so each desktop VM keeps its own address.

How many users can one RDS server handle?

A 16-core server with 64 GB RAM typically handles 30–45 light office users or 18–25 heavy browser and ERP users. Measure memory and disk usage during a pilot before onboarding the whole team.

Do I need RDS CALs for a remote desktop server?

Yes, Microsoft requires an RDS CAL for each user or device beyond the two administrative connections, in addition to the Windows Server license. Check with your licensing partner which option fits your contract; this is not legal advice.

Can each team member have a different fixed IP?

Yes, with Proxmox VDI each user's VM can have its own public IP from an IMIDC block. With a single RDS server, all sessions share the server's outbound IP.

Next steps

Compare Hong Kong, Taiwan, Japan and USA dedicated servers, and see IP resources for additional native or residential IPs. For a sized quote or licensing questions, contact IMIDC sales or open a ticket.

Was this answer helpful?

Related Tutorials