---
title: AllowEncryptionOracle enum | Wartiva GraphQL API
description: CredSSP Encryption Oracle Remediation — controls whether the RDP client/server allows connections when either side lacks the CVE-2018-0886 CredSSP security.
url: https://wartiva.com/api-docs/types/allow-encryption-oracle.html
updated: 2026-10-07
---

Endpoint configuration · GraphQL enum

# `AllowEncryptionOracle` enum

CredSSP Encryption Oracle Remediation — controls whether the RDP client/server allows connections when either side lacks the CVE-2018-0886 CredSSP security patch. Registry: HKLM\SOFTWARE\Policies\Microsoft\Cryptography\Configuration\SSL\00010002:AllowEncryptionOracle (REG_DWORD). Reference: [CredSSP encryption oracle remediation](https://learn.microsoft.com/en-us/troubleshoot/azure/virtual-machines/windows/credssp-encryption-oracle-remediation)

## Values

| Enum Value | Description |
|---|---|
| `FORCE` | Force updated clients (registry value 0). Most secure setting. Blocks RDP connections whenever either the client or server lacks the CVE-2018-0886 CredSSP patch. Both sides must be patched for a session to succeed. |
| `SECURE` | Mitigated (registry value 1). Intermediate setting. An updated client cannot connect to an unpatched server, but an unpatched client can still connect to a patched server. Use when you need to allow legacy clients temporarily while the server is already patched. |
| `ALLOW` | Vulnerable (registry value 2). Least secure setting. Allows all RDP connections regardless of CredSSP patch status on either side. Exposes the host to CVE-2018-0886. Use only as a temporary workaround while applying the CredSSP patch. |

## Used by

- [`ComputerAdministrativeTemplates`](https://wartiva.com/api-docs/types/computer-administrative-templates.html) type: Computer-specific Administrative Templates (ADMX) settings on an Endpoint.

## Example

### Example

```json
"FORCE"

```

---

Wartiva is in early access. Request access: https://wartiva.com/early-access.html  
All pages: https://wartiva.com/llms.txt
