RBAC (Role-Based Access Control) defines who can access which systems, and what they can do once inside. In remote desktop environments, this means mapping user roles to specific machine rights—connect, view, edit, or administer. Every action is tied to a policy, not to a person’s name, making auditing