Enabling RDP when applying a CIS Windows Build Kit


Product Name

CIS Windows Build Kit

Product Version

n/a

Date

Jul 9, 2020



Ā 

Problem

I am using a CIS BuildKit (Remediation_Kit) to harden a Windows server. Everything works great except I need to enable RDP (Remote Desktop Services). Which settings do I need to change?

Solution

Ā 

We have this information from a member was able to enable RDP by making the below changes.

Also please reference this post in the Workbench Community which may also provide some useful information

Modifying RDP Policies (Part-1)

Open ā€œgpedit.mscā€ and navigate to ā€œLocal Computer Policy\Computer Configuration\Administrative templates\Windows Components\Remote Desktop Services\Remote Desktop Session Hostā€* Modify the ā€œenabled/disabledā€ policies to ā€œNot Configuredā€ for every section.

Modifying ā€œUser Rights Assignmentā€ Policies (if you are using Local Accounts)

Open ā€œgpedit.mscā€ and navigate to ā€œLocal Computer Policy\Computer Configuration\Security Settings\User Rights Assignmentā€* Remove ā€œLocal Accountsā€ from below 2 policies. Only ā€œGuestsā€ should be Denied. * Deny log on through Remote Desktop Services* Deny access to this computer from the network

Start the RDP services

Open ā€œServices.mscā€* Start the below 3 services and with startup type ā€œAutomaticā€ * Remote Desktop Services* Remote Desktop Configuration* Remote Desktop Service UserMode Port Redirector

Modifying ā€œSystem Propertiesā€

Right click on ā€œThis PCā€ and choose properties.* Choose ā€œRemote Settingsā€ in the left pane.* Under ā€œRemote Desktopā€, choose the radio button ā€œAllow remote connections to this computerā€. And also choose checkbox to have ā€œNetwork Level Authenticationā€.

Adding Inbound Firewall Rules to allow RDP traffic

Open ā€œgpedit.mscā€ and navigate to ā€œLocal Computer Policy\Computer Configuration\Security Settings\Windows Defender Firewall with Advanced Securityā€* Breakdown the hierarchy and right click on ā€œInbound Rulesā€ to add ā€œNew Ruleā€.* In the next dialogue box, choose the radio button ā€œPredefinedā€ and select ā€œRemote Desktopā€ in the drop down list. * Select all 3 rules and set the action ā€œAllow the connectionā€ to add.

Ā 


Copyright Ā© 2020

Center for Internet SecurityĀ®


Ā 

Ā