Endpoint configuration · GraphQL enum

SecurityLayer enum

GPO policy: "Require use of specific security layer for remote (RDP) connections" under Computer Configuration > Administrative Templates > Windows Components > Remote Desktop Services > Remote Desktop Session Host > Security. Controls the security/transport layer used for RDP client connections. Registry: HKLM\SOFTWARE\Policies\Microsoft\Windows NT\Terminal Services:SecurityLayer (REG_DWORD). CIS Benchmark (L1) recommends SSL/TLS (value 2) for strong server authentication. If SSL is selected, NLA can be enforced separately via the "Require NLA" policy. Reference: Policy CSP - ADMX_TerminalServer

Values

Enum Value Description

RDP

RDP Security Layer (registry value 0). Native RDP encryption is used for the session; no SSL/TLS server authentication. Provides minimal protection; not recommended.

NEGOTIATE

Negotiate (registry value 1). The most secure layer supported by the client is negotiated; SSL/TLS is preferred if the client supports it, otherwise RDP encryption is used.

SSL_TLS

SSL/TLS (registry value 2). SSL (TLS 1.0 or higher) is required for server authentication and to encrypt all data transferred during the session. CIS L1 recommended value.

Used by

Example

Example

"RDP"