Disabling TLS 1.0 for Remote Desktop | ANS Documentation (2024)

  • TLS 1.0 is no longer considered to be a secure version of the TLS protocol, and as such, many compliance standards require that it is disabled in favour of more secure versions such as TLS 1.1.

  • It is advised that before carrying out this guide, that you review any other services such as IIS and MSSQL to ensure that they too are configured to operate with TLS 1.0 disabled. Failing to do so may result in loss of reachability, until resolved.

Windows Server 2008 R2 Considerations

Remote Desktop Services (RDS) on Windows server 2008 R2 does not support TLS 1.1 out of the box. However, there is a hotfix which Microsoft have written to add support for TLS 1.1 and TLS 1.2. This must be installed before disabling TLS 1.0 otherwise you will lose access to Remote Desktop Services until rectified.The hotfix can be obtained from the link below

Remote Desktop Services TLS 1.1 and TLS 1.2 Support patch (KB3080079)

Windows Server 2012 & 2012 R2 Considerations

Windows server 2012 & 2012 R2 support TLS 1.1 and TLS 1.2 for Remote Desktop Services out of the box.Once the you have disabled TLS 1.0, any new connections will automatically be formed with the next version available.

Windows Server 2016 Considerations

Window server 2016, as with Windows server 2012 & 2012 R2, supports TLS 1.1 and TLS 1.2 for Remote Desktop Services out of the box.Again, once TLS 1.0 has been disabled, any new connections will automatically be formed with the next version available.

How To Disable the TLS 1.0 Protocol

  • This process is identical on Windows Server 200R 2, Windows Server 2012 & 2012 R2, and Windows Server 2016.

Select Start, type regedit, and select the regedit.exe icon which is presented as below

Disabling TLS 1.0 for Remote Desktop | ANS Documentation (1)

You will now be presented with the regedit window as below

Disabling TLS 1.0 for Remote Desktop | ANS Documentation (2)

Starting at HKEY_LOCAL_MACHINE on the left hand side of the window, please navigate through the hive to the location \SYSTEM\CurrentcontrolSet\Control\SecurityProviders\SCHANNEL\Protocols\TLS 1.0 in the registry, as below

Disabling TLS 1.0 for Remote Desktop | ANS Documentation (3)

  • If the TLS 1.0 key is not present, you will need to create it. To do so, please follow the below numbered steps

  1. Right click on the “Protocols” key, and select New then select Key

  2. Name the new key TLS 1.0

  3. Right click the TLS 1.0 key, select New then select Key

  4. Name the new key Server

  5. Right click the TLS 1.0 key, select New then select Key

  6. Name the new key Client

  • The above steps will create the structure as depicted in this guide.

Select the Server key, right click and select New, then select DWORD (32-bit) Value. A new value will now be created in the main field of the regedit window. In the Name field, type Enabled and click away from the key.

Now right click the Enabled value, and select Modify.... The Edit DWORD pane will now be displayed. Select Decimal from the Base selector, and in the Value data field, enter 0, then select OK

You should now be able to see your new key as below

Disabling TLS 1.0 for Remote Desktop | ANS Documentation (4)

  • We now need to carry out the same steps for the Client key, as follows:

Select the Client key, right click and select New, then select DWORD (32-bit) Value. As before, a new value will be created in the main field of the regedit window. In the Name field, please type Enabled and click away from the key.

Now right click the Enabled value, select Modify..., the Edit DWORD panel will now be displayed. Select Decimal from the Base selector, and in the Value data field, enter 0, then select OK

You should now be able to see your new Client key as below

Disabling TLS 1.0 for Remote Desktop | ANS Documentation (5)

  • The keys to disable TLS 1.0 from the server side and also to refuse client connections using TLS 1.0 are now set. In order for the keys to take effect, your server must now be restarted.

Next Article > KB4103716: CredSSP Updates - An authentication error has occurred

Disabling TLS 1.0 for Remote Desktop | ANS Documentation (2024)
Top Articles
5 Ways to Optimize Your Asset Management Process - Camcode
Fixed Costs vs. Variable Costs in Commercial Real Estate | FNRP
Somboun Asian Market
Devon Lannigan Obituary
Craigslist Cars And Trucks For Sale By Owner Indianapolis
Jonathon Kinchen Net Worth
South Park Season 26 Kisscartoon
Wild Smile Stapleton
Noaa Swell Forecast
Elden Ring Dex/Int Build
Magic Mike's Last Dance Showtimes Near Marcus Cedar Creek Cinema
Grand Park Baseball Tournaments
Tiraj Bòlèt Florida Soir
shopping.drugsourceinc.com/imperial | Imperial Health TX AZ
Cranberry sauce, canned, sweetened, 1 slice (1/2" thick, approx 8 slices per can) - Health Encyclopedia
Bjork & Zhulkie Funeral Home Obituaries
Busted Newspaper S Randolph County Dirt The Press As Pawns
Funny Marco Birth Chart
Craigslist Panama City Fl
Troy Bilt Mower Carburetor Diagram
List of all the Castle's Secret Stars - Super Mario 64 Guide - IGN
Prestige Home Designs By American Furniture Galleries
Jalapeno Grill Ponca City Menu
Weepinbell Gen 3 Learnset
Walgreens Alma School And Dynamite
Boscov's Bus Trips
Xsensual Portland
Encore Atlanta Cheer Competition
Where to eat: the 50 best restaurants in Freiburg im Breisgau
How to Watch Every NFL Football Game on a Streaming Service
HP PARTSURFER - spare part search portal
His Only Son Showtimes Near Marquee Cinemas - Wakefield 12
Shia Prayer Times Houston
What is Software Defined Networking (SDN)? - GeeksforGeeks
How To Improve Your Pilates C-Curve
Gncc Live Timing And Scoring
Dubois County Barter Page
NIST Special Publication (SP) 800-37 Rev. 2 (Withdrawn), Risk Management Framework for Information Systems and Organizations: A System Life Cycle Approach for Security and Privacy
Nail Salon Open On Monday Near Me
Viewfinder Mangabuddy
Bismarck Mandan Mugshots
Dying Light Nexus
Janaki Kalaganaledu Serial Today Episode Written Update
Pekin Soccer Tournament
The power of the NFL, its data, and the shift to CTV
Unblocked Games - Gun Mayhem
Advance Auto.parts Near Me
Quest Diagnostics Mt Morris Appointment
Peugeot-dealer Hedin Automotive: alles onder één dak | Hedin
Lux Nails & Spa
Heisenberg Breaking Bad Wiki
Latest Posts
Article information

Author: Amb. Frankie Simonis

Last Updated:

Views: 6206

Rating: 4.6 / 5 (76 voted)

Reviews: 91% of readers found this page helpful

Author information

Name: Amb. Frankie Simonis

Birthday: 1998-02-19

Address: 64841 Delmar Isle, North Wiley, OR 74073

Phone: +17844167847676

Job: Forward IT Agent

Hobby: LARPing, Kitesurfing, Sewing, Digital arts, Sand art, Gardening, Dance

Introduction: My name is Amb. Frankie Simonis, I am a hilarious, enchanting, energetic, cooperative, innocent, cute, joyous person who loves writing and wants to share my knowledge and understanding with you.