Disable NLA Network Level Authentication

Anonymous
2023-11-16T17:00:10+00:00

Dear Microsoft Support Team,

I am trying to disable NLA and I have it disabled from:

local group policie/administrative template/Windows Components/Remote Desktop Services/Remote Desktop Session Host/Security

But when I go to Control Panel/System and Security/System/Remote settings/System Properties/Remote/Remote Desktop

I can't uncheck the Allow connections only from computers running Remote Desktop with NLA because it is blocked.

Thank you for your time and support. I look forward to your prompt response.

Best regards,

Windows Server Identity and access Deploy group policy objects

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question. To protect privacy, user profiles for migrated questions are anonymized.

0 comments No comments
{count} votes

31 answers

Sort by: Most helpful
  1. Anonymous
    2023-11-21T13:26:29+00:00

    Hi Daysi

    This machine is de domain controller.

    I did this Allow connections only from Remote Desktop computers with NLA in both local group policy and domain group policy to affect both the local computer and the domain.

    Run rsop.msc to view the enabled policies. And it does not appear

    I also ran a GPReport with these results.

    Best Regards

    Alberto

    0 comments No comments
  2. Anonymous
    2023-11-22T01:03:54+00:00

    Hello Albertosd77,

    Thank you for your reply.

    Please change "Require user authentication for remote connection by using NLA" to "Not Configured" via Domain GPO, and run command “gpupdate /force” on this machine.

    Best Regards,
    Daisy Zhou

    0 comments No comments
  3. Anonymous
    2023-11-23T13:30:10+00:00

    Hi Daisy

    Thank you for your reply

    I currently have "Not Configured" from both the local computer and the domain GPO.

    "Require user authentication for remote connection by using NLA"

    Local

    GPO in beta policy

    in the gp report it does not appear because there are only the enabled and disabled ones and if it is not configured it does not appear. As it is currently

    Previously it was disable and appeared like this.

    Thank your for your help.

    Alberto

    0 comments No comments
  4. Anonymous
    2023-11-24T01:49:48+00:00

    Hello Albertosd77,

    Good day!

    So you have configured in different GPO before (such as ISD AD Domain Controllers Beta Findings and Beta policy), maybe any other GPO?

    There must be one setting control it. I suggest you can double check the setting "Require user authentication for remote connection by using NLA" by viewing settings within GPO "ISD AD Domain Controllers Beta Findings and Beta policy" **and maybe other GPO on your DC.**Best Regards,
    Daisy Zhou

    0 comments No comments
  5. Anonymous
    2023-11-24T12:25:10+00:00

    Hello Daisy

    I have checked the computer GPOs and they are set to not configured.

    In the GP report it does not appear because only the enabled and disabled are there and if it is not configured it does not appear. As it is currently

    I ran rsop.msc to see the enabled policies. And it does not appear.

    Regards

    Alberto

    0 comments No comments