You're correct that you would want to use a VPN instead of exposing RDP to the internet. Your high-level process would be: 1. Authenticate and connect to the on-premise environment over VPN 2. RDP to your Windows 11 computer You can use either the Meraki L2TP Client VPN, or use Cisco Anyconnect (additional licensing is technically required). Client VPN Overview - Cisco Meraki AnyConnect on the MX Appliance - Cisco Meraki If you only want to be able to access the windows 11 jumphost, you can restrict VPN users to only access this host - Restricting Client VPN access using Layer 3 firewall rules - Cisco Meraki
... View more