Enabling RDP when applying a CIS Windows Build Kit
Product Name
CIS Windows Build Kit
Product Version
n/a
Date
Jul 9, 2020
Ā
Problem
I am using a CIS BuildKit (Remediation_Kit) to harden a Windows server. Everything works great except I need to enable RDP (Remote Desktop Services). Which settings do I need to change?
Solution
Ā
We have this information from a member was able to enable RDP by making the below changes.
Also please reference this post in the Workbench Community which may also provide some useful information
Modifying RDP Policies (Part-1) | Open āgpedit.mscā and navigate to āLocal Computer Policy\Computer Configuration\Administrative templates\Windows Components\Remote Desktop Services\Remote Desktop Session Hostā* Modify the āenabled/disabledā policies to āNot Configuredā for every section. |
Modifying āUser Rights Assignmentā Policies (if you are using Local Accounts) | Open āgpedit.mscā and navigate to āLocal Computer Policy\Computer Configuration\Security Settings\User Rights Assignmentā* Remove āLocal Accountsā from below 2 policies. Only āGuestsā should be Denied. * Deny log on through Remote Desktop Services* Deny access to this computer from the network |
Start the RDP services | Open āServices.mscā* Start the below 3 services and with startup type āAutomaticā * Remote Desktop Services* Remote Desktop Configuration* Remote Desktop Service UserMode Port Redirector |
Modifying āSystem Propertiesā | Right click on āThis PCā and choose properties.* Choose āRemote Settingsā in the left pane.* Under āRemote Desktopā, choose the radio button āAllow remote connections to this computerā. And also choose checkbox to have āNetwork Level Authenticationā. |
Adding Inbound Firewall Rules to allow RDP traffic | Open āgpedit.mscā and navigate to āLocal Computer Policy\Computer Configuration\Security Settings\Windows Defender Firewall with Advanced Securityā* Breakdown the hierarchy and right click on āInbound Rulesā to add āNew Ruleā.* In the next dialogue box, choose the radio button āPredefinedā and select āRemote Desktopā in the drop down list. * Select all 3 rules and set the action āAllow the connectionā to add. |
Ā
Copyright Ā© 2020
Center for Internet SecurityĀ®
Ā
Ā