Policy Expert

RDS: Do not allow supported Plug and Play device redirection- The policy expert

Reading time: 2 Minutes Read
Ben Balkin
Published on: August 29, 2019
RDS: Do not allow supported Plug and Play device redirection- The policy expert

Server hardening can be a painful procedure. If you’re reading this article, you probably already know it. Endless hours, labor and money are invested in this process, which can often result in production breakdown despite the effort to prevent it. CSH by CalCom is automating the entire server hardening process. CHS’s unique ability to ‘learn’ your network abolishes the need to perform lab testing while ensuring zero outages to your production environment. CHS will allow you to implement your policy directly on your production hassle-free. want to know more? Click here and get the datasheet. 

This blog post will cover:

  1. Plug and play device policy description.
  2. The potential vulnerability in plug and play devices.
  3. Countermeasures.
  4. The potential impact of policy change on your production.
  5. The recommended value for this setting.
  6. How to configure plug and play devices setting.

POLICY DESCRIPTION:

This policy setting allows you to control the redirection of supported Plug and Play devices, such as Windows Portable Devices, to the remote computer in a Remote Desktop Services session. By default, Remote Desktop Services allows redirection of supported Plug and Play devices. Users can use the “More” option on the Local Resources tab of Remote Desktop Connection to choose the supported Plug and Play devices to redirect to the remote computer. If you enable this policy setting, users cannot redirect their supported Plug and Play devices to the remote computer. If you disable this policy setting or do not configure this policy setting, users can redirect their supported Plug and Play devices to the remote computer. Note: You can also disallow redirection of supported Plug and Play devices on the Client Settings tab in the Remote Desktop Session Host Configuration tool. You can disallow redirection of specific types of supported Plug and Play devices by using the “Computer ConfigurationAdministrative TemplatesSystemDevice InstallationDevice Installation Restrictions” policy settings.

POTENTIAL VULNERABILITY:

RemoteFX USB device redirection goal is to enable the user to use any device he wants. But, leaving Plug and Play device redirection enabled or unconfigured can be leveraged for RemoteFX redirection attacks, in which a rogue USB can harm an RDP server. In order to mitigate unwanted RemotetFX USB redirection, ‘Do not allow supported Plug and Play device redirection’ in the RDP needs to be configured to enable.

RDP Hardening and Hardening RDS Essential Guide

COUNTERMEASURES:

Enable ‘Do not allow supported Plug and Play device redirection’.

POTENTIAL IMPACT:

Users won’t be able to use remote devices. That may lead to damage in production for applications that rely on this ability.

CALCOM’S RECOMMENDED VALUE:

Enable

HOW TO CONFIGURE:

Configure the policy value for Computer Configuration -> Administrative Templates -> Windows Components -> Remote Desktop Services -> Remote Desktop Session Host -> Device and Resource Redirection “Do not allow supported Plug and Play device redirection” to “Enabled”.

 

Ben Balkin
Ben Balkin is a professional writer and blogger specializing in technology and innovation. As a contributor to the Calcom blog, Ben shares practical insights, useful tips, and engaging articles designed to simplify complex processes and make advanced technological solutions accessible to everyone. His writing style is clear, insightful, and inspiring, reflecting his strong belief in technology's power to enhance quality of life and empower businesses.

Related Articles

About Us

Established in 2001, CalCom is the leading provider of server hardening solutions that help organizations address the rapidly changing security landscape, threats, and regulations. CalCom Hardening Suite (CHS) is a security baseline hardening solution that eliminates outages, reduces operational costs, and ensures a resilient, constantly hardened, and monitored server environment.

More about us
Background Shape
About Us

Stay Ahead with Our Newsletter

Get the latest insights, security tips, and exclusive resources straight to your inbox every month.

    Ready to simplify compliance?

    See automated compliance in action—book your demo today!