2x server and client have been set up to allow client to use/see one software on the server. How do you lock the client down so they can't use the same credentials to remote desktop and see the entire server?
You can lock down the client using the "Client Policies" but that currently works only on Windows Clients. However what you want to achieve seems to be to block standard RDP connections and only allow 2X published applications. To do so you will need: To put the RDP servers you want to protect behind a firewall such that only connections from the 2X Gateway are allowed Force all published applications to work in gateway mode
You can block RDP access form clients to Terminal Servers by a windows firewall rule. Only 2X Gateway must allowed to the RDP service on Terminal Servers.