Configuring Remote Desktop Features

Table Of Contents
Table 522. RDS Security Group Policy Settings (Continued)
Setting Description
Require user authentication for remote
connections by using Network
Use this policy setting to specify whether to require user
authentication for remote connections to the RDS host by using
Network Level Authentication. This policy setting enhances security
by requiring that user authentication occur earlier in the remote
connection process.
If you enable this policy setting, only client computers that support
Network Level Authentication can connect to the RDS host.
To determine whether a client computer supports Network Level
Authentication, start Remote Desktop Connection on the client
computer, click the icon in the upper-left corner of the Remote
Desktop Connection dialog box, and then click About. In the About
Remote Desktop Connection dialog box, look for the phrase
"Network Level Authentication supported."
If you disable or do not configure this policy setting, Network Level
Authentication is not required for user authentication before
allowing remote connections to the RDS host.
You can specify that Network Level Authentication be required for
user authentication by using Remote Desktop Session Host
Configuration tool or the Remote tab in System Properties.
Important Disabling or not configuring this policy setting provides
less security because user authentication will occur later in the
remote connection process.
Do not allow local administrators to customize
permissions
Specifies whether to disable the administrator rights to customize
security permissions in the Remote Desktop Session Host
Configuration tool.
You can use this setting to prevent administrators from making
changes to the user groups on the Permissions tab in the Remote
Desktop Session Host Configuration tool. By default, administrators
are able to make such changes.
If the status is set to Enabled, the Permissions tab in the Remote
Desktop Session Host Configuration tool cannot be used to
customize per-connection security descriptors or to change the
default security descriptors for an existing group. All of the security
descriptors are Read Only.
If the status is set to Disabled or Not Configured, server
administrators have full Read/Write privileges to the user security
descriptors on the Permissions tab in the Remote Desktop Session
Host Configuration tool.
Note The preferred method of managing user access is by adding
a user to the Remote Desktop Users group.
Configuring Remote Desktop Features in Horizon 7
VMware, Inc. 187