Endpoint configuration · GraphQL enum

RestrictRemoteClients enum

GPO policy: "Restrict Unauthenticated RPC clients" under Computer Configuration > Administrative Templates > System > Remote Procedure Call. Controls whether the RPC runtime on a server restricts unauthenticated RPC clients connecting to that server. Helps prevent anonymous access to RPC-exposed services. Registry: HKLM\SOFTWARE\Policies\Microsoft\Windows NT\Rpc:RestrictRemoteClients (REG_DWORD). CIS Benchmark recommends value 1 (Authenticated) for most environments. Reference: Policy CSP - RemoteProcedureCall

Values

Enum Value Description

NONE

None (registry value 0). No restrictions on remote RPC clients; anonymous connections are allowed. Default on Windows Server 2003 SP1 and older.

AUTHENTICATED

Authenticated (registry value 1). Only authenticated remote RPC clients are allowed; anonymous calls are rejected except those arriving over named pipes (ncacn_np). Default on Windows Vista and later. CIS L1 recommended value.

AUTHENTICATED_WITHOUT_EXCEPTIONS

Authenticated without exceptions (registry value 2). All anonymous remote RPC calls are rejected with no exceptions — including calls that would otherwise be allowed over named pipes. Most restrictive.

Used by

Example

Example

"NONE"