Information
Windows Server 2019 Remote Desktop Services must be configured with the client connection encryption set to High Level.
GROUP ID:V-205637
RULE ID:SV-205637r958408
Remote connections must be encrypted to prevent interception of data or sensitive information. Selecting 'High Level' will ensure encryption of Remote Desktop Services sessions in both directions.
Satisfies: SRG-OS-000033-GPOS-00014, SRG-OS-000250-GPOS-00093
Solution
Configure the policy value for
Computer Configuration >> Administrative Templates >> Windows Components >> Remote Desktop Services >> Remote Desktop Session Host >> Security >> 'Set client connection encryption level' to 'Enabled' with 'High Level' selected.