Restricted Admin Mode

Mikhail Firsov 1,881 Reputation points
2021-05-27T09:52:10.407+00:00

Hello!

Have anyone spotted any difference in how Restricted Admin Mode works in Windows Server 2019?

I'm asking that question because after deploying exactly the same remote access configuration as in my Windows Server 2016 environment in the new network with Windows Server 2019 machines I can't seem to make RDP with Restricted Admin Mode work.

I've doubled-checked that

1) all respective machines (both servers and workstations) have the following GPO settings applied:

a) Require Restricted Admin Mode  
b) Restrict Delegation of credential to remote servers -enabled  

2) I'm trying to RDP with the user account that is a member of the local Administrators group on the target server

In the Windows Server 2016 environment it works as expected:
100186-q0.png

In the Windows Server 2019 environment the error arises as if the Restricted Admin mode were not enabled (I had no problems connecting to the Win2019 server prior to applying the gpo with the RDP-related settings):
100196-q01.png

Thank you in advance,
Michael

Windows Server 2019
Windows Server 2019
A Microsoft server operating system that supports enterprise-level management updated to data storage.
3,754 questions
{count} votes

4 answers

Sort by: Most helpful
  1. Karlie Weng 18,281 Reputation points Microsoft Vendor
    2021-05-28T06:22:24.377+00:00

    Hello @Mikhail Firsov

    Please check if below article helps:

    Pass-The-Hash with RDP in 2019
    Restrict delegation of credentials to remote servers

    Best Regards
    Karlie

    ----------

    If the Answer is helpful, please click "Accept Answer" and upvote it.


  2. Mikhail Firsov 1,881 Reputation points
    2021-05-31T10:24:16.357+00:00

    "Have you tried this on another server2019 ?" - yes, I have, and it clarifies nothing: I installed another Windows Server 2019 VM - Srv4 - alongside with the first one - Srv1, and it did work... I have no explanation for that. Here's my test lab:

    1) Both servers 2019 are hosted on the same host machine (Host1) and were deployed using the same ISO:

    101056-18.png

    2) Both of them are just standalone servers - no policies have been applied to them, the single setting applied was DisableRestrictedAdmin set to 0 (I also created one more local admin account - Admin):

    101081-15.png

    101048-14.png

    3) Now if I connect to Srv4 from ANY other computer (server or workstation, domain-joined or not) - I will succeed:

    101010-17.png
    101049-17-2.png

    4) Connecting to Srv1 would fail for any client and for any user (Administrator or Admin):

    101091-16.png
    101101-16-2.png

    In fact this newly-installed Srv4 is the only Windows Server 2019 machine that I can connect to - all other Win2019 servers produce the same error.

    I re-deployed some of my Windows Server 2016 machines and tested them again - all of them are working flawlessly.

    Regards,
    Michael


  3. Mikhail Firsov 1,881 Reputation points
    2021-06-01T07:23:12.457+00:00

    Have you added the DisableRestrictedAdmin regestry key as on my screenshot above?


  4. Mikhail Firsov 1,881 Reputation points
    2021-06-02T07:51:30.623+00:00

    Then it's even more weird...

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.