I would like to upvote this question.
When I remove the credentials in RDCMan, it seems to use my local AD credentials automatically. As a result I can automatically login to our production servers, i.e. not asking for a password.
That is against our company policy (which is based on ISO 27001): logging in to a test/staging/production server must always ask for a password.
The only "workaround" I found is setting the default credentials with an invalid password. That way it will show an "credentials were invalid" login screen. However, this will also log an invalid login attempt.
So it should NOT use local AD credentials to login to remote servers. Maybe opt-in and if so, that should also be password protected. Else it's just too easy to abuse the AD credentials. This is not secure.