1.131 WN19-CC-000380

Information

Windows Server 2019 Remote Desktop Services must be configured with the client connection encryption set to High Level.

GROUP ID:V-205637
RULE ID:SV-205637r958408

Remote connections must be encrypted to prevent interception of data or sensitive information. Selecting 'High Level' will ensure encryption of Remote Desktop Services sessions in both directions.

Satisfies: SRG-OS-000033-GPOS-00014, SRG-OS-000250-GPOS-00093

Solution

Configure the policy value for

Computer Configuration >> Administrative Templates >> Windows Components >> Remote Desktop Services >> Remote Desktop Session Host >> Security >> 'Set client connection encryption level' to 'Enabled' with 'High Level' selected.

See Also

https://workbench.cisecurity.org/benchmarks/22176