GPO policy: "Set client connection encryption level" under Computer Configuration > Administrative Templates > Windows Components > Remote Desktop Services > Remote Desktop Session Host > Security. Controls the minimum encryption level for RDP sessions. Only applies when SecurityLayer is set to RDP or Negotiate; SSL/TLS manages its own cipher strength. Registry: HKLM\SOFTWARE\Policies\Microsoft\Windows NT\Terminal Services:MinEncryptionLevel (REG_DWORD). CIS Benchmark (L1) recommends High (value 3) when RDP encryption is used. Reference: Policy CSP - ADMX_TerminalServer
Values
| Enum Value | Description |
|---|---|
|
|
Low encryption (registry value 1). Data sent from the client to the server is encrypted using 56-bit keys. Data sent from the server to the client may be unencrypted. Least secure. |
|
|
Client-compatible encryption (registry value 2). All data is encrypted using the maximum key strength supported by the client. |
|
|
High encryption (registry value 3). All data — in both directions — is encrypted using 128-bit keys. Clients that do not support 128-bit encryption cannot connect. CIS L1 recommended value. |
Used by
ComputerAdministrativeTemplatestype: Computer-specific Administrative Templates (ADMX) settings on an Endpoint.
Example
Example
"LOW"