Security Setting : Restrict delegation of credentials to remote servers

DMH Cyber Security 1 Reputation point
2020-11-10T08:04:16.267+00:00

Working with a Client at the moment who have added the above security setting and recently added some 2016 machines. The GPO setting is using option 3 in this list however when attempting to initiate a connection using MSTSC I receive a CredSSP encryption Oracle remediation error message.

Restrict Credential Delegation
Registry Hive

HKEY_LOCAL_MACHINE

Registry Path

Software\Policies\Microsoft\Windows\CredentialsDelegation

Value Name

RestrictedRemoteAdministrationType

Value Type

REG_DWORD

Value

3

Require Remote Credential Guard
Registry Hive

HKEY_LOCAL_MACHINE

Registry Path

Software\Policies\Microsoft\Windows\CredentialsDelegation

Value Name

RestrictedRemoteAdministrationType

Value Type

REG_DWORD

Value

2

Require Restricted Admin
Registry Hive

HKEY_LOCAL_MACHINE

Registry Path

Software\Policies\Microsoft\Windows\CredentialsDelegation

Value Name

RestrictedRemoteAdministrationType

Value Type

REG_DWORD

Value

1

I have added the registry key to the destination and host :

DWORD = DisableRestrictedAdmin but cannot connect due to the CredSSH error, on a 2016 machine I can change the sub setting in PreProd to 'Require Restricted Admin' and the connection completes however in production this setting is set by GPO that I do not have access to see or change so was wondering if there are any other Admin's out there that are having this issue and if there is a resolution that does not reduce the security.

Windows for business | Windows Client for IT Pros | User experience | Other
0 comments No comments
{count} votes

4 answers

Sort by: Most helpful
  1. Vicky Wang 2,741 Reputation points
    2020-11-11T09:44:01.403+00:00
    1. AD team can only help to see whether the GPO is applied. If the registry key pushed by the GPO has been applied, AD team cannot answer why the registry is not effective.

    Related GPO references are as follows;

    https://getadmx.com/?Category=Windows_10_2016&Policy=Microsoft.Policies.CredentialsSSP::AllowSavedCredentials

    Best Regards,

    Vicky

    0 comments No comments

  2. Vicky Wang 2,741 Reputation points
    2020-11-16T06:56:04.377+00:00

    Hi,

    Just checking in to see if the information provided was helpful.

    Please let us know if you would like further assistance.

    Best Regards,
    Vicky

    0 comments No comments

  3. DMH Cyber Security 1 Reputation point
    2020-11-16T13:46:44.93+00:00

    Hi Vicky

    Unfortunately no we are looking into this further, it seems to stem from the Different OS levels and how the options are configured in the registry keys. I am going to be working with the AD team and GPO owners in an effort to understand what setting they can use to allow a secure options to this.

    Thanks

    Darren


  4. Vicky Wang 2,741 Reputation points
    2020-11-27T08:03:34.203+00:00

    Hi,

    Just checking in to see if the information provided was helpful.

    Please let us know if you would like further assistance.

    Best Regards,

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.