Endpoint configuration · GraphQL enum

AllowEncryptionOracle enum

CredSSP Encryption Oracle Remediation — controls whether the RDP client/server allows connections when either side lacks the CVE-2018-0886 CredSSP security patch. Registry: HKLM\SOFTWARE\Policies\Microsoft\Cryptography\Configuration\SSL\00010002:AllowEncryptionOracle (REG_DWORD). Reference: CredSSP encryption oracle remediation

Values

Enum Value Description

FORCE

Force updated clients (registry value 0). Most secure setting. Blocks RDP connections whenever either the client or server lacks the CVE-2018-0886 CredSSP patch. Both sides must be patched for a session to succeed.

SECURE

Mitigated (registry value 1). Intermediate setting. An updated client cannot connect to an unpatched server, but an unpatched client can still connect to a patched server. Use when you need to allow legacy clients temporarily while the server is already patched.

ALLOW

Vulnerable (registry value 2). Least secure setting. Allows all RDP connections regardless of CredSSP patch status on either side. Exposes the host to CVE-2018-0886. Use only as a temporary workaround while applying the CredSSP patch.

Used by

Example

Example

"FORCE"