mirror of
https://github.com/MicrosoftDocs/windows-itpro-docs.git
synced 2025-06-19 20:33:42 +00:00
Merge branch 'main' into frankroj-patch-1
This commit is contained in:
@ -156,14 +156,16 @@ Supported values:
|
|||||||
|
|
||||||
### Protected client
|
### Protected client
|
||||||
|
|
||||||
Applies more security settings to the sandbox Remote Desktop client, decreasing its attack surface.
|
When Protected Client mode is enabled, Sandbox adds a new layer of security boundary by running inside an [AppContainer Isolation](/windows/win32/secauthz/appcontainer-isolation) execution environment.
|
||||||
|
|
||||||
|
AppContainer Isolation provides Credential, Device, File, Network, Process, and Window isolation.
|
||||||
|
|
||||||
`<ProtectedClient>value</ProtectedClient>`
|
`<ProtectedClient>value</ProtectedClient>`
|
||||||
|
|
||||||
Supported values:
|
Supported values:
|
||||||
|
|
||||||
- *Enable*: Runs Windows sandbox in Protected Client mode. If this value is set, the sandbox runs with extra security mitigations enabled.
|
- *Enable*: Runs Windows sandbox in Protected Client mode. If this value is set, the Sandbox runs in AppContainer Isolation.
|
||||||
- *Disable*: Runs the sandbox in standard mode without extra security mitigations.
|
- *Disable*: Runs the Sandbox in the standard mode without extra security mitigations.
|
||||||
- *Default*: This value is the default value for Protected Client mode. Currently, this default value denotes that the sandbox doesn't run in Protected Client mode.
|
- *Default*: This value is the default value for Protected Client mode. Currently, this default value denotes that the sandbox doesn't run in Protected Client mode.
|
||||||
|
|
||||||
> [!NOTE]
|
> [!NOTE]
|
||||||
|
Reference in New Issue
Block a user