---
title: MinEncryptionLevel enum | Wartiva GraphQL API
description: GPO policy: "Set client connection encryption level" under Computer Configuration > Administrative Templates > Windows Components > Remote Desktop Services.
url: https://wartiva.com/api-docs/types/min-encryption-level.html
updated: 2026-10-07
---

Endpoint configuration · GraphQL enum

# `MinEncryptionLevel` enum

GPO policy: "Set client connection encryption level" under Computer Configuration > Administrative Templates > Windows Components > Remote Desktop Services > Remote Desktop Session Host > Security. Controls the minimum encryption level for RDP sessions. Only applies when SecurityLayer is set to RDP or Negotiate; SSL/TLS manages its own cipher strength. Registry: HKLM\SOFTWARE\Policies\Microsoft\Windows NT\Terminal Services:MinEncryptionLevel (REG_DWORD). CIS Benchmark (L1) recommends High (value 3) when RDP encryption is used. Reference: [Policy CSP - ADMX_TerminalServer](https://learn.microsoft.com/en-us/windows/client-management/mdm/policy-csp-admx-terminalserver)

## Values

| Enum Value | Description |
|---|---|
| `LOW` | Low encryption (registry value 1). Data sent from the client to the server is encrypted using 56-bit keys. Data sent from the server to the client may be unencrypted. Least secure. |
| `CLIENT_COMPATIBLE` | Client-compatible encryption (registry value 2). All data is encrypted using the maximum key strength supported by the client. |
| `HIGH` | High encryption (registry value 3). All data — in both directions — is encrypted using 128-bit keys. Clients that do not support 128-bit encryption cannot connect. CIS L1 recommended value. |

## Used by

- [`ComputerAdministrativeTemplates`](https://wartiva.com/api-docs/types/computer-administrative-templates.html) type: Computer-specific Administrative Templates (ADMX) settings on an Endpoint.

## Example

### Example

```json
"LOW"

```

---

Wartiva is in early access. Request access: https://wartiva.com/early-access.html  
All pages: https://wartiva.com/llms.txt
