Does your RDP send your credentials to the target computer?

๐——๐—ฒ๐—ณ๐—ฎ๐˜‚๐—น๐˜ โ†’ ๐—›๐—ฎ๐—ฟ๐—ฑ๐—ฒ๐—ป๐—ฒ๐—ฑ

Real configs. Real fixes. Windows & AD security.

๐——๐—ผ๐—ฒ๐˜€ ๐˜†๐—ผ๐˜‚๐—ฟ ๐—ฅ๐——๐—ฃ ๐˜€๐—ฒ๐—ป๐—ฑ ๐˜†๐—ผ๐˜‚๐—ฟ ๐—ฐ๐—ฟ๐—ฒ๐—ฑ๐—ฒ๐—ป๐˜๐—ถ๐—ฎ๐—น๐˜€ ๐˜๐—ผ ๐˜๐—ต๐—ฒ ๐˜๐—ฎ๐—ฟ๐—ด๐—ฒ๐˜ ๐—ฐ๐—ผ๐—บ๐—ฝ๐˜‚๐˜๐—ฒ๐—ฟ?

โš ๏ธ By default, yes. When you authenticate using a standard RDP session, your credentials are sent to the target machine. If that machine is compromised, an attacker can potentially recover them from LSASS.

โœ… A better option for administrative access is ๐—ฅ๐—ฒ๐˜€๐˜๐—ฟ๐—ถ๐—ฐ๐˜๐—ฒ๐—ฑ ๐—”๐—ฑ๐—บ๐—ถ๐—ป ๐—บ๐—ผ๐—ฑ๐—ฒ.

With Restricted Admin enabled, your credentials are not sent to the target computer. Instead, RDP reuses your existing authenticated session from the source device. The account you’re already signed in with must have administrative privileges on the target host, but there is no additional credential exchange during the connection.

๐—ง๐—ต๐—ถ๐˜€ ๐—ด๐—ถ๐˜ƒ๐—ฒ๐˜€ ๐˜†๐—ผ๐˜‚ ๐˜๐˜„๐—ผ ๐—ฏ๐—ฒ๐—ป๐—ฒ๐—ณ๐—ถ๐˜๐˜€:

โ–ช๏ธ Your credentials are not available in LSASS on the target machine.

โ–ช๏ธ It feels almost like Single Sign-On because you don’t have to enter your credentials again.

โžก๏ธ I find this especially useful in environments implementing a Tiering Model with Privileged Access Workstations (๐—ฃ๐—”๐—ช๐˜€) or jump servers. You’re already signed in with the correct administrative account, so Restricted Admin simply reuses it.

If you want to implement it, ๐—œ ๐—ฎ๐—น๐˜€๐—ผ ๐—ฐ๐—ฟ๐—ฒ๐—ฎ๐˜๐—ฒ๐—ฑ ๐—ฎ ๐—ณ๐—ฟ๐—ฒ๐—ฒ ๐—ด๐˜‚๐—ถ๐—ฑ๐—ฒ called “Protecting credentials over RDP.pdf”, available in my Windows Security Guides:

๐Ÿ”— https://academy.horizon-secured.com/p/windows-infrastructure-security-guides

Do you use Restricted Admin for administrative RDP connections?