RDP "internal error has occurred"

Mountain Pond 1,101 Reputation points
2021-09-19T12:41:48.537+00:00

Hello,

all of a sudden, all computers in the domain began to issue an "internal error has occurred" error.
We cannot find the reason why this error started to occur, but more than 500 workstations became unavailable immediately after rebooting the system.

We found out that if you enable inheritance for the "C: \ ProgramData \ Microsoft \ Crypto \ RSA \ MachineKeys" directory, the problem is outdated instantly. Without restarting the terinals service or rebooting the system.
133287-mstsc-h4ifniheoo.png

We found out that inheritance is not enabled by default for computers that are not included in the domain and this problem is not observed.

We ran the script to enable inheritance and that fixed the problem.

The day before the incident, we disabled support for TSL 1.0 and 1.1 in the registry. However, we tried to retry by disabling TSL on computers in a different domain. But failed to get the same error. We cannot understand what it was. What caused the incident. The problem arose on all computers, this is not like updating the system, installing some kind of software, because computer service is separate.

Thank you.

Windows Server
Windows Server
A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.
12,083 questions
Remote Desktop
Remote Desktop
A Microsoft app that connects remotely to computers and to virtual apps and desktops.
4,226 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Limitless Technology 39,336 Reputation points
    2021-09-20T14:40:03.093+00:00

    Hello,

    Thank you for your question.

    I would like to suggest you to check below Troubleshooting steps.

    1. Please check if the AD replication health is good in your environment , you can download Active Directory Replication Status Tool
      https://www.microsoft.com/en-in/download/details.aspx?id=30005
    2. Please try to Disable firewall and Antivirus for temporary purpose.
    3. for TLS 1.0 and 1.1 please download the tool call IISCrypto to see which Protocols and ciphers you have disabled , then you can enable it.
    4. Please check what Microsoft updates or any other software updates have been applied of these affected computers.

    If the reply was helpful, please don’t forget to upvote or accept as answer.