Workgroup Computers - Remove option to Save RDP Credentials

George Freeman
George Freeman used Ask the Experts™
on
Hello,

We have  a workgroup environment that uses the RDWeb to access company resources.  When the user logs into RDWeb and clicks the resource (RDP), it prompts them for their Username and Password and Provides the option to save those credentials.  Is there a way, without modifying the local policy of the workgroup computer, to disable / remove that option from server side (Windows Server 2012 R2)?

Thank you.
Comment
Watch Question

Do more with

Expert Office
EXPERT OFFICE® is a registered trademark of EXPERTS EXCHANGE®

Commented:
type gpedit
User Configuration | Administrative Templates | Windows Components | Remote Desktop Services
Select the Remote Desktop Connection Client item under Remote Desktop Services. In the Setting list on the right, double-click on the Do not allow passwords to be saved setting.
On the dialog box that displays, select the Enabled radio button.
Qlemo"Batchelor", Developer and EE Topic Advisor
Top Expert 2015

Commented:
Note: Doing that on the target machine will not prevent the option to be available, but passwords will not be used when connecting​, with an according message telling about that.

Commented:
On the RD Session Host server, open Remote Desktop Session Host Configuration. To open Remote Desktop Session Host Configuration, click Start, point to Administrative Tools, point to Remote Desktop Services, and then click Remote Desktop Session Host Configuration.
Under Connections, right-click the name of the connection, and then click Properties.
In the Properties dialog box for the connection, on the Log on Settings tab, configure the logon settings as appropriate for your environment, and then click OK.
https://technet.microsoft.com/en-us/library/cc730945.aspx?f=255&MSPPError=-2147217396
CompTIA Cloud+

The CompTIA Cloud+ Basic training course will teach you about cloud concepts and models, data storage, networking, and network infrastructure.

Author

Commented:
Thank you for your replies.

@dj 3094,
In reference are end user computers and public computers.  We do not want to allow the ability to save their credentials to the rdp session.  Will your solution work for this type of scenario?  Also, the Remote Desktop Session Host Configuration isn't available on the Server 2012 R2.  Do you know where I would go set said settings or point me in another direction if that is required?

Thanks again.

Commented:
I have not tried but will try on monday and let you know

We can access

Click Start, click Run, type mmc and then press ENTER.
On the File menu, click Add/Remove Snap-in.
Under Available snap-ins, click Remote Desktop Session Host Configuration, and then click Add.
In the Select Computer dialog box, select whether you want to connect to the local computer or to another computer. If you select Another computer, either type in the name of the computer or use Browse to search for the computer.
Click OK.
In the Add or Remove Snap-ins dialog box, click OK

https://technet.microsoft.com/en-us/library/cc731617%28v=ws.11%29.aspx?f=255&MSPPError=-2147217396

Author

Commented:
Thank you, I look forward to your response.  I re-read my comment and I believe it doesn't make perfect sense.  What I mean to say is the users will be using public computers in which I will have zero access to.  The changes will need to be made server side.  Thank you again!
Qlemo"Batchelor", Developer and EE Topic Advisor
Top Expert 2015

Commented:
As said, you can set the server side up to always ask for the password, but that does not prevent saving it on the local machine, it just hasn't any effect to do so. The password is stored in the machines encrypted and protected part of the registry.

To be secure you would need to have control over the clients, which you do not. Public computers need to be closed down to only allow a very restricted set of operations anyway.

Author

Commented:
Since this is RDWeb access and will be access from various machines completely outside our organization / control what would you recommend?  I am guessing some form of TFA that requires a token refresh or the like every login?  Your continued help is appreciated.  I can't believe we are the first people to use RDWeb and want it secured from people using their personal systems to 'always remember' all of their logins.
Qlemo"Batchelor", Developer and EE Topic Advisor
Top Expert 2015

Commented:
I can't remember exactly, but I think the RDP password is only saved if the login was successful. If true, inhibiting the usage of a stored password should prevent storing it already.
Thank you for all the replies.  We have decided to go the route of Multi-authentication.

Author

Commented:
We have decided to go a different route and implement multi-authentication.

Do more with

Expert Office
Submit tech questions to Ask the Experts™ at any time to receive solutions, advice, and new ideas from leading industry professionals.

Start 7-Day Free Trial