1.2.3.4.2.3.1 Configure 'Set client connection encryption level'

Information

This policy setting specifies whether the computer that is about to host the remote connection will enforce an encryption level for all data sent between it and the client computer for the remote session. If Terminal Server client connections are allowed that use low level encryption, it is more likely that an attacker will be able to decrypt any captured Terminal Services network traffic.

Solution

Configure the following Group Policy setting in a manner that is consistent with the security and operational requirements of your organization-

Computer Configuration\Administrative Templates\Windows Components\Remote Desktop Services\Remote Desktop Session Host\Security\Set client connection encryption level

Impact- Clients that do not support 128-bit encryption will be unable to establish Terminal Server sessions.

See Also

https://workbench.cisecurity.org/files/42

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-17(2), CCE|CCE-3812-5

Plugin: Windows

Control ID: 624b36c9b902d904f893a072bb3e09c08e530655ea832a6bf76853bf063f3ac0