By Keren Pollack, on January 13th, 2020

 

COM port is the name of the serial port interface on IBM PC-compatible computers. It can refer not only to physical ports but also to emulated ports, such as ports created by Bluetooth or USB-to-serial adapters.

 

POLICY DESCRIPTION:

This policy setting will determine whether the redirection of data to client COM ports from the remote computer will be allowed in the RDS session. By default, RDS allows COM port redirection. It can be used, for example, to use a USB dongle in an RDS session.

 

POTENTIAL VULNERABILITY:

When not enabled, users can redirect data to COM port peripherals or map the local COM ports while using the Remote Desktop Service session.

RDS Configuration Hardening Guide

COUNTERMEASURES:

Enable this object wherever’s possible.

If the status is set to Disabled, Remote Desktop Services always allows COM port redirection. If the status is set to Not Configured, COM port redirection is not specified at the Group Policy level. However, an administrator can still disable COM port redirection using the Remote Desktop Session Host Configuration tool.

 

POTENTIAL IMPACT:

RDS users won’t be able to access a client’s COM port peripherals such as USB dongles and Bluetooth.

 

CALCOM’S RECOMMENDED VALUE:

Enable

 

RDS: Require user authentication for remote connections by using Network Level Authentication (NLA)- The policy expert

HOW TO CONFIGURE:

1. Press Windows Logo+R, type gpedit.msc, and press Enter.

 

2. Click the arrow next to Computer Configuration under Local Computer Policy to expand it.

 

3. Click the arrow next to Administrative Templates to expand it.

 

4. Click All Settings to show all group policy settings.

 

5. Scroll down to Do not allow COM port redirection and double-click on it to view the setting.

 

6. Ensure the policy isn’t Disabled and click OK. (Enabled must be selected).

AUTOMATE YOUR SERVER HARDENING:

Server hardening can be a painful procedure. If you’re reading this article, you probably already know it. Endless hours, labor and money are invested in this process, which can often result in production breakdown despite the effort to prevent it. CSH by CalCom is automating the entire server hardening process. CHS’s unique ability to ‘learn’ your network abolishes the need to perform lab testing while ensuring zero outages to your production environment. CHS will allow you to implement your policy directly on your production hassle-free. want to know more?

Click here and get the datasheet.