Is there a best practice regarding putting an RDS domain-joined gateway in an existing DMZ with other systems or creating a new isolated DMZ for it?
Thought process is that if a system in the DMZ is compromised it could more readily lead to a compromise of the gateway and then straight to a domain controller.