๐๐ฒ๐ณ๐ฎ๐๐น๐ โ ๐๐ฎ๐ฟ๐ฑ๐ฒ๐ป๐ฒ๐ฑ
Real configs. Real fixes. Windows & AD security.
๐๐ผ๐ฒ๐ ๐๐ผ๐๐ฟ ๐ฅ๐๐ฃ ๐๐ฒ๐ป๐ฑ ๐๐ผ๐๐ฟ ๐ฐ๐ฟ๐ฒ๐ฑ๐ฒ๐ป๐๐ถ๐ฎ๐น๐ ๐๐ผ ๐๐ต๐ฒ ๐๐ฎ๐ฟ๐ด๐ฒ๐ ๐ฐ๐ผ๐บ๐ฝ๐๐๐ฒ๐ฟ?
โ ๏ธ By default, yes. When you authenticate using a standard RDP session, your credentials are sent to the target machine. If that machine is compromised, an attacker can potentially recover them from LSASS.
โ A better option for administrative access is ๐ฅ๐ฒ๐๐๐ฟ๐ถ๐ฐ๐๐ฒ๐ฑ ๐๐ฑ๐บ๐ถ๐ป ๐บ๐ผ๐ฑ๐ฒ.
With Restricted Admin enabled, your credentials are not sent to the target computer. Instead, RDP reuses your existing authenticated session from the source device. The account you’re already signed in with must have administrative privileges on the target host, but there is no additional credential exchange during the connection.
๐ง๐ต๐ถ๐ ๐ด๐ถ๐๐ฒ๐ ๐๐ผ๐ ๐๐๐ผ ๐ฏ๐ฒ๐ป๐ฒ๐ณ๐ถ๐๐:
โช๏ธ Your credentials are not available in LSASS on the target machine.
โช๏ธ It feels almost like Single Sign-On because you don’t have to enter your credentials again.
โก๏ธ I find this especially useful in environments implementing a Tiering Model with Privileged Access Workstations (๐ฃ๐๐ช๐) or jump servers. You’re already signed in with the correct administrative account, so Restricted Admin simply reuses it.
If you want to implement it, ๐ ๐ฎ๐น๐๐ผ ๐ฐ๐ฟ๐ฒ๐ฎ๐๐ฒ๐ฑ ๐ฎ ๐ณ๐ฟ๐ฒ๐ฒ ๐ด๐๐ถ๐ฑ๐ฒ called “Protecting credentials over RDP.pdf”, available in my Windows Security Guides:
๐ https://academy.horizon-secured.com/p/windows-infrastructure-security-guides
Do you use Restricted Admin for administrative RDP connections?
