RDP Security Features

๐Ÿ”’ย Secure Bits ๐Ÿ’ก
๐——๐—ผ ๐˜†๐—ผ๐˜‚ ๐˜‚๐˜€๐—ฒ ๐—ฅ๐——๐—ฃ ๐—ฟ๐—ฒ๐—ด๐˜‚๐—น๐—ฎ๐—ฟ๐—น๐˜† ๐—ถ๐—ป ๐˜†๐—ผ๐˜‚๐—ฟ ๐—ฒ๐—ป๐˜ƒ๐—ถ๐—ฟ๐—ผ๐—ป๐—บ๐—ฒ๐—ป๐˜? Then you should know there are more secure ways to do it.

๐—•๐˜† ๐—ฑ๐—ฒ๐—ณ๐—ฎ๐˜‚๐—น๐˜, your credentials are sent to the remote host during an RDP session โ€” which means if the machine is compromised, attackers can steal and reuse them.

๐—•๐˜‚๐˜ ๐˜๐—ต๐—ฒ๐—ฟ๐—ฒโ€™๐˜€ ๐—ด๐—ผ๐—ผ๐—ฑ ๐—ป๐—ฒ๐˜„๐˜€ โ€” Microsoft gives us secure modes likeย Restricted Adminย andย Remote Credential Guard, which prevent that.

๐Ÿ“„ ๐—œโ€™๐˜ƒ๐—ฒ ๐—ฝ๐˜‚๐˜ ๐˜๐—ผ๐—ด๐—ฒ๐˜๐—ต๐—ฒ๐—ฟ ๐—ฎ ๐˜€๐˜๐—ฒ๐—ฝ-๐—ฏ๐˜†-๐˜€๐˜๐—ฒ๐—ฝ ๐—ด๐˜‚๐—ถ๐—ฑ๐—ฒ on how to enable these protections properly. Whether youโ€™re securing privileged access via PAW or regular RDP user access, this is something every admin should know.
Protecting credentials over RDP

๐Ÿ‘‰ You can download the full PDF (and other guides) and follow it carefully to avoid mistakes:
https://academy.horizon-secured.com/p/windows-infrastructure-security-guides