Information
This policy setting allows you to specify whether Remote Desktop Services requires secure Remote Procedure Call (RPC) communication with all clients or allows unsecured communication.
You can use this policy setting to strengthen the security of RPC communication with clients by allowing only authenticated and encrypted requests.
The recommended state for this setting is: Enabled
Allowing unsecure RPC communication can exposes the server to man in the middle attacks and data disclosure attacks.
Solution
To establish the recommended configuration via configuration profiles, set the following Settings Catalog path to Enabled
Administrative Templates\Windows Components\Remote Desktop Services\Remote Desktop Session Host\Security\Require secure RPC communication
Impact:
Remote Desktop Services accepts requests from RPC clients that support secure requests, and does not allow unsecured communication with untrusted clients.