Disable TLS 1.0 for RDP Protocol using GPO

Federico Coppola 1,181 Reputation points
2020-11-26T14:45:11.99+00:00

Hi all,
Inside company we have completed a vulnerability assessment.
I have this vulnerability:

"TLS Version 1.0 Protocol Detection"

All physical servers and virtual machine inside company are Windows Server 2016 DataCenter and they has got the last Windows Updates.

How can I solve it about RDP?
Is it possible disable TLS 1.0 for RDP using GPO?

I would improve security on company servers.

Thanks so much

Best regards
Federico

Windows Server 2016
Windows Server 2016
A Microsoft server operating system that supports enterprise-level management updated to data storage.
2,402 questions
Remote Desktop
Remote Desktop
A Microsoft app that connects remotely to computers and to virtual apps and desktops.
4,298 questions
Windows Server Security
Windows Server Security
Windows Server: A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.Security: The precautions taken to guard against crime, attack, sabotage, espionage, or another threat.
1,746 questions
0 comments No comments
{count} votes

7 answers

Sort by: Newest
  1. Federico Coppola 1,181 Reputation points
    2020-12-13T21:58:24.15+00:00

    Any suggestions?

    I have followed this video to increase security of terminal server:
    https://www.youtube.com/watch?v=nyBOJwvUaKQ

    Thanks

    0 comments No comments

  2. Federico Coppola 6 Reputation points
    2020-12-03T16:50:09.347+00:00

    Dear @Vicky Wang ,
    Thanks for your answare.

    Sorry but I did not found tsconfig.msc on my Windows Server 2016 Terminal Server.
    Is it normal?

    Best regards


  3. Vicky Wang 2,646 Reputation points
    2020-12-03T09:21:50.59+00:00

    Hi,
    According to my knowledge, there is no GPO that can disable the terminal server
    Best wishes
    Vicky

    0 comments No comments

  4. Federico Coppola 1,181 Reputation points
    2020-12-02T20:07:38.68+00:00

    Can anyone suggest me properly GPO to set to disable TLS 1.0 on different servers?
    Not servers are Terminal Server (just one at the moment).

    Thanks
    Federico

    0 comments No comments

  5. Federico Coppola 1,181 Reputation points
    2020-11-29T21:18:10.817+00:00

    Hi,
    thanks for you reply.

    @Thameur-BOURBITA Ok, so I will disable TLS 1.0 for all system and not just for RDP.

    @Vicky Wang Sorry but I did not understood which is the right option about "Remote Desktop Session Host Configuration"

    I would generally disable TLS 1.0 to improve security in my LAN where there are differente Windows Server 2016 VM (Domain Controllers, File Server, Print server...)

    Can I create a group policy to disable it on different machines?

    Thanks so much
    Federico

    0 comments No comments