Configuring Remote Desktop Features

Table Of Contents
Table 521. RDS Security Group Policy Settings (Continued)
Setting Description
If you disable or do not congure this seing, the encryption
level to be used for remote connections to RDS host is not
enforced through Group Policy. However, you can congure a
required encryption level for these connections by using the
Remote Desktop Session Host Conguration tool.
I FIPS compliance can be congured through the
"System cryptography: Use FIPS compliant algorithms for
encryption, hashing, and signing" policy seing in the
Computer  > Windows  > Security
 > Local Policies > Security Options folder or,
through the "FIPS Compliant" seing in Remote Desktop
Session Host Conguration. The FIPS Compliant seing
encrypts and decrypts data sent from the client to the server
and from the server to the client, with the Federal Information
Processing Standard (FIPS) 140-1 encryption algorithms, using
Microsoft cryptographic modules. Use this encryption level
when communications between clients and RDS hosts require
the highest level of encryption. If FIPS compliance is already
enabled through the Group Policy "System cryptography: Use
FIPS compliant algorithms for encryption, hashing, and
signing" seing, that seing overrides the encryption level
specied in this Group Policy seing or in the Remote
Desktop Session Host Conguration tool.
Always prompt for password upon connection
Species whether Remote Desktop Services always prompts
the client for a password upon connection.
You can use this seing to enforce a password prompt for
users logging on to Remote Desktop Services, even if they
already provided the password in the Remote Desktop
Connection client.
By default, Remote Desktop Services allows users to
automatically log on by entering a password in the Remote
Desktop Connection client.
If you enable this seing, users cannot automatically log on to
Remote Desktop Services by supplying their passwords in the
Remote Desktop Connection client. They are prompted for a
password to log on.
If you disable this seing, users can always log on to Remote
Desktop Services automatically by supplying their passwords
in the Remote Desktop Connection client.
If you do not congure this seing, automatic logon is not
specied at the Group Policy level. However, an administrator
can still enforce password prompting by using the Remote
Desktop Session Host Conguration tool.
Chapter 5 Configuring Policies for Desktop and Application Pools
VMware, Inc. 157