RDS (Remote Desktop Services) and Protect Remote Desktop credentials with Windows Defender Remote Credential Guard?

_KUL 286 Reputation points
2021-04-06T02:44:53.827+00:00

We use SSO Protect Remote Desktop credentials with Windows Defender Remote Credential Guard on "Windows Server 2016" and "Windows Server 2019" servers. There are no problems. We have many users with "Windows Hello for Business + Key Trust" technology and there is an RDS farm (Broker + TS's) on "Windows Server 2016". We have configured the registry on all servers of the RDS farm. But use the connection "mstsc.exe /remoteGuard" fails.

All the latest updates are installed on the servers, and the check was performed through the Microsoft servers.
WindowsProductName : Windows Server 2016 Standard
WindowsCurrentVersion : 6.3
OsVersion : 10.0.14393
OsBuildNumber : 14393

Using the command mstsc.exe /remoteGuard:
An error occurs when trying to connect to a shared name - "An authentication error has occured. \r\n The function requested is not supported \r\n Remote computer: xxx \r\n This could be due to CredSSP encryption oracle remediation."
When trying to connect directly to the TS server, RDP opens, the session starts, and an error occurs inside the RDP screen - "The requested session access is denied." But if add a user to the Administrators group, everything works - but it's not right! On the server, an entry is recorded in the event log - "Session 5 has been disconnected, reason code 12".

Questions:

  1. Will it work - "RDS and Protect Remote Desktop credentials with Windows Defender Remote Credential Guard" ?
  2. What update should I install for Windows Server 2016 to fix the problem with Administrators / Remote Desktop Users groups (perhaps some update is missing) ?
Windows Server 2016
Windows Server 2016
A Microsoft server operating system that supports enterprise-level management updated to data storage.
2,391 questions
Remote Desktop
Remote Desktop
A Microsoft app that connects remotely to computers and to virtual apps and desktops.
4,269 questions
Windows 10 Security
Windows 10 Security
Windows 10: A Microsoft operating system that runs on personal computers and tablets.Security: The precautions taken to guard against crime, attack, sabotage, espionage, or another threat.
2,770 questions
0 comments No comments
{count} votes

5 answers

Sort by: Most helpful
  1. Leila Kong 3,691 Reputation points
    2021-04-29T08:10:55.893+00:00

    Hello @_KUL ,

    How is everything going on your side?

    It is from our internal document that:
    Update October 2018 : Dev team has modified documentation to state that /remoteguard can only be used by administrators :

    Use Windows Defender Remote Credential Guard with a parameter to Remote Desktop Connection
    If you don't use Group Policy in your organization, or if not all your remote hosts support Remote Credential Guard, you can add the remoteGuard parameter when you start Remote Desktop Connection to turn on Windows Defender Remote Credential Guard for that connection.

    mstsc.exe /remoteGuard
    Note
    The user must be part of administrators group.

    1 person found this answer helpful.
    0 comments No comments

  2. Leila Kong 3,691 Reputation points
    2021-04-06T09:18:15.153+00:00

    Hello KUL,

    Please try to use the group policy settings to roll back the changes to ‘Vulnerable’ state to allow RDP access.

    1.type "gpedit.msc" in search bar and open Group Policy Editor, navigate to Computer Configuration -> Administrative Templates -> System -> Credentials Delegation -> Encryption Oracle Remediation, then select Enabled and change Production Level to Vulnerable, finally run the command gpupdate /force to apply group policy settings.

    84833-gpo.png

    84826-encryption-oracle-remediation.png

    2.type "winver" in search bar and check the detailed OS build No. of 14393:

    84827-winver.png


  3. Leila Kong 3,691 Reputation points
    2021-04-23T08:54:31.357+00:00

    Hello @_KUL ,

    Mstsc.exe /remoteguard only works with administrators.

    Normal users should only use mstsc.exe without the “/remoteguard” parameter and you should ensure they have the correct GPO set for remote guard to be used for them.

    Setup the remote guard GPO for normal user to use remoteguard:
    https://learn.microsoft.com/en-us/windows/security/identity-protection/remote-credential-guard

    Can you uninstall the yellow update of problem server and install the yellow update of regular server as shown in below picture?
    90677-ms-update-catalog.png

    You may download here: https://www.catalog.update.microsoft.com/Home.aspx


  4. Leila Kong 3,691 Reputation points
    2021-05-11T06:37:40.517+00:00

    Hello @_KUL ,

    How are things going there on this issue?
    Please let me know if you would like further assistance.

    0 comments No comments

  5. Leila Kong 3,691 Reputation points
    2021-05-18T09:36:58.313+00:00

    Hello @_KUL ,

    Just checking in to see if the information provided was helpful.
    Please post back at your convenience if we can assist further.