Set client connection encryption level
This policy setting specifies whether to require the use of a specific encryption level to secure communications between client computerss and RD Session Host servers during Remote Desktop Protocol (RDP) connections. If you enable this policy setting all communications between clients and RD Session Host servers during remote connections must use the encryption method specified in this setting. By default the encryption level is set to High. The following encryption methods are available:* High: The High setting encrypts data sent from the client to the server and from the server to the client by using strong 128-bit encryption. Use this encryption level in environments that contain only 128-bit clients (for example clients that run Remote Desktop Connection). Clients that do not support this encryption level cannot connect to RD Session Host servers. * Client Compatible: The Client Compatible setting encrypts data sent between the client and the server at the maximum key strength supported by the client. Use this encryption level in environments that include clients that do not support 128-bit encryption. * Low: The Low setting encrypts only data sent from the client to the server by using 56-bit encryption. If you disable or do not configure this setting the encryption level to be used for remote connections to RD Session Host servers is not enforced through Group Policy. ImportantFIPS compliance can be configured through the System cryptography. Use FIPS compliant algorithms for encryption hashing and signing settings in Group Policy (under Computer Configuration -> Windows Settings -> Security Settings -> Local Policies -> Security Options. ) The FIPS compliant setting encrypts and decrypts data sent from the client to the server and from the server to the client with the Federal Information Processing Standard (FIPS) 140 encryption algorithms by using Microsoft cryptographic modules. Use this encryption level when communications between clients and RD Session Host servers requires the highest level of encryption.
Do not allow passwords to be saved
Controls whether passwords can be saved on this computer from Remote Desktop Connection. If you enable this setting the password saving checkbox in Remote Desktop Connection will be disabled and users will no longer be able to save passwords. When a user opens an RDP file using Remote Desktop Connection and saves his settings any password that previously existed in the RDP file will be deleted. If you disable this setting or leave it not configured the user will be able to save passwords using Remote Desktop Connection.
Do not allow passwords to be saved
Controls whether a user can save passwords using Remote Desktop Connection. If you enable this setting the credential saving checkbox in Remote Desktop Connection will be disabled and users will no longer be able to save passwords. When a user opens an RDP file using Remote Desktop Connection and saves his settings any password that previously existed in the RDP file will be deleted. If you disable this setting or leave it not configured the user will be able to save passwords using Remote Desktop Connection
Turn Off UDP On Client
This policy setting specifies whether the UDP protocol will be used to access servers via Remote Desktop Protocol. If you enable this policy setting Remote Desktop Protocol traffic will only use the TCP protocol. If you disable or do not configure this policy setting Remote Desktop Protocol traffic will attempt to use both TCP and UDP protocols.
Select RDP transport protocols
This policy setting allows you to specify which protocols can be used for Remote Desktop Protocol (RDP) access to this server. If you enable this policy setting you must specify if you would like RDP to use UDP. You can select one of the following options: “Use both UDP and TCP (default)” “Use only TCP” or “Use either UDP or TCP”If you select “Use either UDP or TCP” and the UDP connection is successful most of the RDP traffic will use UDP. If the UDP connection is not successful or if you select “Use only TCP” all of the RDP traffic will use TCP. If you disable or do not configure this policy setting RDP will choose the optimal protocols for delivering the best user experience.
Select network detection on the server
This policy setting allows you to specify how the Remote Desktop Protocol will try to detect the network quality (bandwidth and latency). You can choose to disable Connect Time Detect Continuous Network Detect or both Connect Time Detect and Continuous Network Detect. If you disable Connect Time Detect Remote Desktop Protocol will not determine the network quality at the connect time and it will assume that all traffic to this server originates from a low-speed connection. If you disable Continuous Network Detect Remote Desktop Protocol will not try to adapt the remote user experience to varying network quality. If you disable Connect Time Detect and Continuous Network Detect Remote Desktop Protocol will not try to determine the network quality at the connect time; instead it will assume that all traffic to this server originates from a low-speed connection and it will not try to adapt the user experience to varying network quality. If you disable or do not configure this policy setting Remote Desktop Protocol will spend up to a few seconds trying to determine the network quality prior to the connection and it will continuously try to adapt the user experience to varying network quality.
Enable Remote Desktop Protocol 8.0
This policy setting allows you to enable Remote Desktop Protocol (RDP) 8. 0 on this computer. Please read the following KB article before enabling this Group Policy. http://go. microsoft. com/fwlink/?LinkID=251814If you enable this policy setting connections from RDP 8. 0-compatible client computers to this computer will use RDP 8. 0. Computers that are not compatible with RDP 8. 0 will use a compatible earlier version of RDP. If the policy setting is enabled the following functionality will not be available:1. Administrator shadow which allows remote monitoring of users’ sessions2. Desktop Composition and Aero experience unless this computer is configured to use a RemoteFX VGPUFor more information see http://go. microsoft. com/fwlink/?LinkID=251814. If you disable or do not configure this policy setting client computers including computers that are compatible with RDP 8. 0 will only use RDP 7. 1 or an earlier version of RDP. Note: This policy setting does not apply to connections that use RemoteFX VGPU. Connections that use RemoteFX VGPU will continue to use RDP 7. 1. For this change to take effect you must restart Windows.
Configure RemoteFX Adaptive Graphics
This policy setting allows the administrator to configure the RemoteFX experience for Remote Desktop Session Host or Remote Desktop Virtualization Host servers. By default the system will choose the best experience based on available nework bandwidth. If you enable this policy setting the RemoteFX experience could be set to one of the following options:1. Let the system choose the experience for the network condition2. Optimize for server scalability3. Optimize for minimum bandwidth usageIf you disable or do not configure this policy setting the RemoteFX experience will change dynamically based on the network condition. ”
Configure image quality for RemoteFX Adaptive Graphics
This policy setting allows you to specify the visual quality for remote users when connecting to this computer by using Remote Desktop Connection. You can use this policy setting to balance the network bandwidth usage with the visual quality that is delivered. If you enable this policy setting and set quality to Medium RemoteFX Adaptive Graphics uses an encoding mechanism that results in medium quality images. This mode consumes the lowest amount of network bandwidth of the quality modes. If you enable this policy setting and set quality to High RemoteFX Adaptive Graphics uses an encoding mechanism that results in high quality images and consumes moderate network bandwidth. If you enable this policy setting and set quality to Lossless RemoteFX Adaptive Graphics uses lossless encoding. In this mode the color integrity of the graphics data is not impacted. However this setting results in a significant increase in network bandwidth consumption. We recommend that you set this for very specific cases only. If you disable or do not configure this policy setting RemoteFX Adaptive Graphics uses an encoding mechanism that results in medium quality images.
Use the hardware default graphics adapter for all Remote Desktop Services sessions
This policy setting enables system administrators to change the graphics rendering for all Remote Desktop Services sessions on a Remote Desktop Session Host (RD Session Host) server. If you enable this policy setting all Remote Desktop Services sessions on the RD Session Host server use the hardware graphics renderer instead of the Microsoft Basic Render Driver as the default adapter. If you disable or do not configure this policy setting all Remote Desktop Services sessions on the RD Session Host server use the Microsoft Basic Render Driver as the default adapter. NOTE: The policy setting affects only the default graphics processing unit (GPU) on a computer with more than one GPU installed. All additional GPUs are considered secondary adapters and used as hardware renderers. The GPU configuration of the local session is not affected by this policy setting.