From 5d9f4a33429788cabe33725008f4857d8899df18 Mon Sep 17 00:00:00 2001 From: Paolo Matarazzo <74918781+paolomatarazzo@users.noreply.github.com> Date: Wed, 16 Aug 2023 15:24:36 -0400 Subject: [PATCH] updates --- ...redential-guard-with-remote-admin-mode.png | Bin 26878 -> 0 bytes .../remote-credential-guard.md | 146 ++++++++++++------ 2 files changed, 101 insertions(+), 45 deletions(-) delete mode 100644 windows/security/identity-protection/images/windows-defender-remote-credential-guard-with-remote-admin-mode.png diff --git a/windows/security/identity-protection/images/windows-defender-remote-credential-guard-with-remote-admin-mode.png b/windows/security/identity-protection/images/windows-defender-remote-credential-guard-with-remote-admin-mode.png deleted file mode 100644 index 56021d820eb2160a81f3405d3d5ce0efc4ccddab..0000000000000000000000000000000000000000 GIT binary patch literal 0 HcmV?d00001 literal 26878 zcmcG$2UJu`*EZOQh={@^iGYBTgMehoDnWweoIyY&G&x5V$sjo=iA~Nll5O5h(HJ85l45D2gH<_9B=6^{bw#CDRAm&9JYPen{|uODQ+@pqS` zmeU(&r%$#Hpn}ptX`t(&6VN4L=4j$zVdrFFYXc&}c}@%TKe*`^x3zP3urUAR1S-ZK z6a;$l{_b@!Grk%6%*g_52I4)&#{sV3++0z${pjRs>|h4cx4XU>j{En+EgVg(je(&K zpxV~z2%!7^O}D18gN=oaIjEIlH4x~-{^x#Y2NN^U;k6&~c9^&=7;I+a1UedwZvp!5 z-3(K+aI!W7<)g+JK_Co}jKmu?x74k9_s>tw(oU{N#zl_lVv( z{lKpwG$_KmBZxv|#ZRAv!`5;X3yZ0^6mfP4Tj@r;35BD@jpM?f1V-MpYpX2bFPGh6{X8FA3DDT;ZDP`4i%lZ)SJIB z?UV;AFg}-j&69^BqGg$p@oE(+7a!zvg*F;p+Mv-Nh@=%m-$=ca&BA?iX`zMaj9wQ7 zeWO{HtY6l2k;%C)pdx#^o(HR6{%&mClyW6C?NUZ_@%jvz)*={MehyNi3-OM+59y@8 z#iDdMI)E6?Tus2-1ficDQt_(#dNy7TQze|o{;WjI10K_1y#9hjhi6nA{665hOqt(E zG>3<5e}^679ka2Q2vux1sEQP9L+4#ts87nZtd3ms`S68I+~y%tPji(%31-uwly zBYKGUJmL*}q3&R!z{2VYv}^F1J(Zl7tbXj0l;HE|i$O_2h(xE|J2*rkq6+my8tGob zXmxt=NRE9RKb>Vni_ZbUe@wu==={@x%o2eSSUH@ygdHrv2FlH!Cf!J#zVe*17;9gd zTs~0jR#Q3?L!}MBcRjfbupRbm@$#uGDpIcy_)|JZ3u1AytJ(35tz>JHl7zYw}TqFGn-_Q2iJy=;_q`JK9#e)trDNSSaYx47H3;LGgz+$+*&t&1 zimm+Z-Ypiq$rWB7(S_iL8xX_993kl3z|X*BPxpOq$AXyxK4j9YyN6@irVRQusyTbg{gtn|Wy%E6 z@3$&f3SLK?=}_IT-n3|*iPh)sXKHSOR`8XA2m?FWSD#gghpl7!I0~)#Jw)(Un0aw5 z(?)Z1ATIm-FGM{y8ysT1codUzr=SipAH49BTj&^&_ua_H<|ybL?2q3!vC ziQSIZHniLq(}9NpiX{5@pOs`wPKPwq>l9s{+`QY4+hIu#ie&ufY5!={b{a~lD6JPT zIGmM+mzOs#F3va*6U4+h$Y)#~)b$}PEiKp~>G3TV;(s@NeSJ(!OyhTVfpIzVPuQaO z-+PK34T)r&Q4?$+k+?!Mpx43A!R_l=1FS@5B*yPBKuj{J@Nc78d3kw7MOK>}rShUB zrKNcMRG`;=z`#$++S=NhnhAO-MWv+-0N`$tv)`0+3U3|D^9{ z20Q54>;L0|{*#HgP?8NV4|u?k{Z4YSE$e}lM6Ajie>H1;Rw{q8r1EaDU6(o=qL=kK zzQLbL#BrWA&4)oUcPYiS+8QE^H!V2Bz|S5tC*5Kp+dVo!SN?11n81-8>|Ww)dchXB zfLkV=@>x0OzH0n0%qMLjVC&HBD)X#QCRAj;1CrCB#lTgS=!*nxB~{uDN5TzWq04iQ z8j)-&IC^99<3#FcybKWv%NowLmCQ@mL9pADZQL^Uu6xBUdNaG`bIm=-XjS;o3V7&j zx~a;+6r|rhJ-o3KrN}#RY4pBUFEjlOF>o$R4dcj`m@g-Ly2@C%(7pj5r%d>m~&!hVPW|=m{{Sq_or$^RA@`<^KbV{1G#I6dHJLVi*2Q?=v7^k zTn$v*TvvCqoOt3(&r1q!W|MP7-Me*NCH*QJrzCWrjtrBD%0u4)Q9+wmV#|jkbLFn- z#0LpZ_+l5kY_)SYQ;zi~NzgqG1urz7!VyfKx9e!e03$z{fxTbC*>RA!J@90nu5Hml>|#z9td~rW9%=EuS{#nmsN@1KX?i zL%VClSMmoj0mXhl+S3nZ(0f#5-*umL=nBUX|G+7WyE~TON9|BCXlysb+`;3DtLRNdqzF)Wli~@%N z-K_hOEmC>BbpitN)8iAo?0cTQra6`0_kC&)IruhmhgCasPIbUpaS zFpu|t29FUAFtO$0re5+)xgqWAIR~}(Eji;j8)7diF!XiH`u82ADO6F8%9V|c!qd`9 zZWUU^RaM-lKZ}Y0T~P|?hq=hN#wm8D^B?9>2h$eWi_IH|lz>Ndjhkgwt6dk{pBh42 z{A%4_iZ0;oYqKBcSHe~g3K!vPHC6%Oq$%r#>Vf9fF1-iDBZ$g#YKLb8^%K@txr^fV zIr2JkQ(ro(t`pq6{W}9EJC`PA65g$*k-BJ&%}|sTD3SQYu$`0}nof?}2 zM&I=H?XXm5ZLR0dPpO(u7t^pChzLfny+&iJRww*P`aV^C7)M=uT5j`;UBOzpArdst zX@dKcCCqAwy_oNUUfv;oGt0x1Z+HRD@m9=gmPzweHyw0q@~JEKl)5_lmd+(d$;GQTsDYH4NFP+y;SxwYR10Zamh z#&^5$2|Bl&BU~nZV~D&C^1FAi^MJZKczMifqFR6^i-9WPuUwc|%=Cc+&#!8Wo-bD& zm%+=$ekz4Uu1tJ6j4<=`+G@yWETW}bEZB}VkJ1f&d={pYE62^_!%LVw4@R&tA7Y{` z$&>j|NL*pZ!s6oMq9Qr=Np;PehON#GGKyvTT5T~EkRRQ7Fdi)s6C@385Zw zsYP~dTW+2F&^g~&YM6p{ZWa;JjE!;=GnbL1{T1hK1QX26wVt%nS0z=Lo9Fx4;`p=F zg(?3@WSk0Do&~JiTNiUA6|gq1GH^h@b=NIa-`1kkShA88URjO!nf)$@?KBsZ!9i8nDdZ}vgiA6C9 z@I;#Z)A$}8$s+kmh&%@RB@`R6wrOs$Xn2Sp9K@81?U8$3{ykm>ZZqlhL8(OFXE?|F z3bt1Sf!8R!FPRc+Jp1`2v9u)QBQYEydJ;@+ldP5TKBd2qb)q_0{k)0)_}WHakXZ39 z!3mQ?evu{%xddJ0AT#yxI2I^OCo@mJqvFI55hs#Dq*J6nVESugSq-;Qz zwEq|)xWH?&b=vbiO<7afkgSAVH53K^v#{z9;cvX^@s^e3xCre2M5kg^`+?icYsJi5 z@dN<6RL~b4--KzVeA8*SU z9x7IUh&{n$T&D=-SLv8GohzU4!$;HL7K_3B^N9kY)v#k1RM%Em6 zP)=sMA5O|K+8%I&$11)I%8xoQvnI4PXY+Lj(nUp9FRg446(zh#^y;P)TRUQ*&uFUN zI7l*q*@zWOvQ~_w#Hxgn${RHHzQeu$G)dLyYkdTXtQtx{wJ>191RmZV_=r|*dW|pF zN*KD;lrd#Oamb2~Y!Ti%z;@}|GimX*QB_YGFpd;yh!2OrJp^eh1>bsXvz3;4D+gtZuJ4#|)6s>zR?_h$|+Dvj5A z;;6}G(|>%tnA4o{vDHHc3b2^9slpSCkd@u+epcH3;RI&J{8nLZlW8Rf4rfwqxQDk|LxX0ZvovvuU;GhF) zpQSdt_W>`Et~7DVhx3y1B+A#=VGXqh-Hp_CfrMupkc^{wCZ+mRyrgFQTw_YVCa9H) z0YshwYpm=*_5rt&Xn-W;Vl%;$f)KMPg`-D6nEJ1n9skkhBaVDk4z)+}XSRxk3&Y=5 zc24~q$-k4SM#-_Zz+u;O&2P%wHQmokD;cSWa`o@NIo^T`))su^;TW@Mh|A7WallsC z|NICWk(0Qij6TEY?ZIX+nH@BveM#e=%ttA5S}Y-_7#Nm9C$bGSWF@8K?=}?TU5Tn& zVpRke8%(IpE0J6t88+(s6;#$|UHx1#@Z9G0Eup=?{N9!cZK4ttXuiU11QrnKHLTE+ z>U(()u|m%_6HVwP{>2NI8?0hNPNx&!*qIB{Id&;v^nD)3TW`|RxfFfDpQNI~&3?*V zZ-RUeNmj7VPlYQ9xW1iC-Bai8QGZ`}>d7BSH0BJS5xd1g;K?zux#YEynQse3|1Tzo zJflwo0(Jfw6i7$5z*hMP6`&>*oy{12V-FJo-G|MOm3e}&kxCyhGmP^o2iImF|B>&I`Ac# zF4yc>{CNF5rX$O5=Ql&S!NeUnPpmkP70gP0(FKGNK(CxykvYlZoi&}+hFdH=0u-LC@hu+gF}h4@ zN~O3QHhShQNirGG$7rd?Q7begK^J)e%EX@w}SVLaE1q(dz$m58a&L;PoOek-z=9)^Yn{03DuRFy>f zy+Ab_TE$+-x1!mz^*F;(Ur&{?(-=zxYw*vYPXq;IjEw2Ij~m~~3yP|{xw;P0gU^mv zJQqYvw&JRgJ6f*mN6yzuX}z zqSi?p{ojeWQIrEwh(_Kxjzk7z4oug@W+>n5rRx{y5BcZ_n9WzQCRX z!TDrLw#*6{;h6XW%X}y)9+GVJw;%TXa)bBA57QPE0D(-Int&z$!SO~|r6mj(BdKAU z9PrDd4HE=!b}4#Ycc|tNzr~~cdg>P@)-4vANFls~uA_s8LhAmb*_D-*rKRk3e40QI zudh$(BJtX#%O%_oWb2>_#KA27WT{FEUsZe&a$I29vrDKAfq;q1q2bZ-rG=-fyPA4} zB%uyo&mR%-;GglOZ70Jht!d+|AT{-y=1(d4sTiRl+T0?wTU&<%X`SOBNb=B8yF}Yp zpg#m5j(K61H7iT_bce4F!a5P>T`P=padxw@)p<3(@~r$}m`Zm-wx6kG9fz^bmWOWh zd0jc=Wo^DCc)$iOgx7Hu=QS0sFWzHjdW^vyH4RIR-D^skP4u#+5Jw|JQJwgl0y{qU&ksWu%>F1!Uf@~~Zcd1Px>lM*gUB7vu z7l-s#Lk#i|MQ&4JJUVILI~&QWRvPKRIm$oh;1vfW<%@s0gZZ`G&wAYpVedAr(QJ!{ zWyMdL$sE*v&Eyr8))&^-pH=iwS%JZ9rVU>{Sz78ey6xS>)a96M>nj#*?F9h`5C%lB z0QA$7IAd1-U`Emc%(`>2OWZ!h53-MwZ|D)}oA$}|Os(&wp2@qF&~?7yn=!ll{+YYV zx?>7^!&c=0d&7$a@(&f$*kUJbT7z)K<%J_?t-j+BZ(TJmv0poNz|hp}gK=5oKYMSe zy&tHlM0IYM{6cdsM(ub!csY^TNhY1`uER`WjBCdryS2(fqoS3L*b=9%Wu&wP6S z-eE^=bMFi(NM*F83`K0i?YRMk$2>UF2aq)96{|g#Jf8 zPi>n^g`2YnYnpfiK_wp;Fxumt-M+2bmWo`*&|D6V9Weo|FcP5+7^>%YxkFi_OYU$16$u9BYY z!jfSUio#|)W;1x#?M(`t@mjmOPulT(-PB=^^8}CD#a8BhU=TMQi=S$%xU}lm>GqnI zZ+9$!?V9Kj%GyRLNE~g$*9yFZsdm=adsSb8@!lWYVgY1iVgWT{akx3j(Q;8a)kNjB z+var_6G+HJjA`XiJb5zR;JO3ce~nIPDb}i>p^ES(xIG>aTox3si0G?0%^cF?)i=aO3oV1*yJg(10UlrJYNQZ}Hn!LKj z0_&<2FgzUrj{@;138Qd`7zWctJlntF)R8vtG@t8{H*FRcIfRmfl$_8>d=><`gfy}e z%rzDr-Ja>bzegFVe0uzM=)iB=tY<3C06YtHEe{S4w-=f`7aHC7SBC~FUV@CO`wVAu zY6uBPMrmZBw)0nh*uK@y!)=9qCgww_QMFQEvYlL9N)4KHBvyyhJTLZoLVHW~84XT|EwL9?({YQW$3{s&27x z-7J8F^ybN@SmV~VY{j$Bxo{Nunm^A7X&AwXen)*!miovrvu4 zrDB@RXO@PJIb7sLVfY7lg4;3aps0t>U4eb1iB2__O%ia-3#zWEnR$$QwUh5D;L7e* z76dGKmHR#DwZ(ldAO&SLiX#&wjpnf!Qb&M*^R68sUi?C@IsmSII zb6|Ld_AJp5hD()jXp0&3wG-B8*ZC~bgId=gf11sSB@C7})py(%j}ReNwtU5R&?*;! z65TU8SJL!)XMK_mMRFK&nP|j2rT~tQO1~gMT(dGI!Gyt}bNItP>bC9a3cCAt#J5<` zdYj0}$!*eGE!uO4MK@R2OsYctfu$=&LcYC|xOZ-X&*pt{iqh0*s&`mSS(qCetE8#0 zNvQ62?dlfE+_}CQ^T#C(LB5Cv568|$U#UoOB9DqaXGA~7TYXCsazz0Wl9G}_8zt=k zF3rs~8%pM-aTt?foOx_>(LqVbCRaK%S>j`NBV4mAt!IW{m= zpzZ#KLj-Jkt^V}~cUBi@660>M02v(s z+qC&=qQYeDJBdDpsj>RuV7;M;&&XG-ef&qYM_0{<6bWALqgj$V62XMW8w?GDeTGy^ zCS?<;F*{Pq*1(kffE>%G@YU4RSd=inPqYKpDvtG;?M3mLD+XsZ|bS}!j-M1so}SLngrk7GG93Yz-;xi6E zy{5;PgP2qJBBK;`^nQ+Xt* zlPn$9s$V8Vb^a9N<@i_$xM9zjf29;Ll}IpFtH}CZh8k|4l!<%ZJJNSvIS15bKa(wx z*=EvslP9l}mE|l^4a>@kqW0Mj#Ju#5l9sS4iCy%%$z?@706a1Sd6n0rJ=m z2DlEbL4RFD%zDJL!LR)}v}$**Bd*sCD`<9Cf!BUO`@5PM3f6`5PB|gG97l*0b8N*L zoh+uLYf3#L&E2}basjjjm>Zzp1`JJO5y6_OwQi1{Nu1=fK;u}a}M^* z0muVCgpcPOzZlfY&vIhDYt_~n1J=D~0jsUFw zQ3(y3FnxQ;`IbxFy57j%a_Kthj+&|OO$RC+^WGzbxh~6j4j@njOc@yck6b*nbC*ex zFufpc{>%1LP>_Tqp}hQ(*!8I}FF=4$dU7h8Qoqw;C@4rsgA;Xfbvb{$fV4P%%9xsH z3BdDZKyKFQWHAule31K1T8)k-t6KCRm%~gC#O+F!KnG0HTl8Z*Z*lP`rOUW`bqv4_>)UV?rjKH1&#@F`>{+oaC`VF9|c=bHN z%asG&Argg!43}q9k1|dq9L`UCFQMv<<~~ppDLDU ze4p~NTG!dbsi_w_u~#aWfns{1X0q@hetw@N3JmCd0L_;e2)*1t--zE-zs@oiQu45^N1LSCXeWZBcK+${?5 zWt8gC32mQbR^(G;$=gG8jqgrNOKU{yA)h-LmcB5ksMOhSdy|&^i$_7Mq zEBTTQQk*@{{GNJ78I0xN!t~J-Z;thg+3tXp-U1t24byRYOGrb5?q*ThpLHIoZn^O2 z`2L*iyGwsw9EB^&Vo$9^h2>I|1*JQt8d&Vv7qyWw(S5)LJD|79-k@;YNRZ1{AMq+5X{d*1G>)x<4WHgtZ%3pRda~k{EBv<8n9XX z>lTY>8II!joBV^zmEAEle(b;*kJ8vzVR~U2u4!t|Pa7R0t}T_DlX19+gVp%>c#>e} zh8*5zRz4Jt_w{iCyWUSFy@*)PnHYG}?~^vthel0Otg`ES0vFnub=cTcbyax!sd?e_Y9G4V{@G2W@jR z;i2*A%3+<;#2$2$r={eetD`76o2l*_=f6OoqyI9Uov_b0=^3VEt>^1)FWgLWZt=KC z$HHBuCb!wX^hWZtpQ5uQL#u-b=~3hIk2kO#kc8>u@nI0CF4yMBE9Rc$4l`?4=D|K9 zfE4wQTs&24@tW8XDts-NxReM0G5A%u)}l=tm+JhqV=8TT<|=nv@Nt=kt;s-`_<6>R zvqgvG6kDCb!p~=4rWJUD=au;`PrxE|`8uq*e1a;E5(xR71)^yH12mJ~X20 z-cq(7!wtw;03?5OG$++K>Q?0pJ;!S*APsmMs3|Bo9a?t<-MQjv)c`(_w*;oMH%5?P zbjsVNZ*BDg`D=U|Q_*Q|x6f9=Cb|6^5Fju)e_7Czw4fKvj8i#78eUlT_)^Ytm+us^ zA|R5X8tq*GW8pP3F5uJ=l9bS9)jTE%zt~L?d%C_8DnX-Tm0KOjj{*9u^4L^EUWWD- zi`m%5gUqLW5m{!Vvz#UodRVHxH~Ly;U`^lI8Qr3W_KlN%!B>4zXYO-U1V1}FLr=2< z*QxG$*r?vijkzXZlP!Q2T?_=S4b63}1=O^xP<1Lsf$$_!TszUh6}U#T(8}0KE|TNDEbTmVEH?HC2JP zo7;L6BeiGscAv8eA2n*DluXmptrZ?D-#16^ea5(CFC}9|29Yi9()&=JMk9p)p74)c ze66%`N-n4b4;Qo-?=2IiK>7hdWy`DNbtEL|DjUp>GYqe)2uUJ(riyjVwIN@v2TZLe-q~Q9JB&pr#H72K%}ICG(>Dc#troxe zxSb3RSmx#9Vg!LMaL}>4LHW(71&Dzb6#Wa~vIBRXt2SXRV)fl0!)#En1hm_;N;ZQA z8i%euO@niPq#lb5;A+YWb{L`LH%6YJp#W7iJq5ypuZo@P~zN^`CZ*g z({=++t*?~5xzwV2JiRr&bz~7Jq=6D~hac?t90Y_SPLF7(?8Y!k@pT}{5Blo2)P-@4 zyNCdaBJFFVIypLW?;Xzt&vV~}BiLeaouGHuR~rUT%Gi;o9iB;7y*57M+Qy=u&kIFg_1`1OhEHwK}E{uB@z>r~9mG1|%FH z=8v~l<0fs%;Iob3i~3Ct12lDlp}VAxOl@PEX?6sgLZ~5w`U+uyDuz1gm-JgK_T5qq z&=a@{4tD@y{xZbJeA&HsGI(n4bBeZFJ5Fs}>zgt)yEY#_?F=kCvr{SoB=Q^mPu#zl z2y%&ZB$gW;htJz3uldXe4)D`XVO&;m^e_d=B_sN_T6e6NDcLpt~a$iYyB`>X!An&4=F`U~<>_OpPw=Wy5VO zz(P;dZtN^p%!uch1%Wb-vd%w|ati8tk5ci%_MNUL6$Rie_eMM`BlO`Zi3`dPdaPXO zjXa_jKFKa|#M6+c60%wiYvk2wywidAVD^EPtl+w?(GV5Tk^zY8J;6xN@+Rio0VHg(+`%m8}zyFIr#T z0flJ%hv>C_`(qs|+a1lfL;_t;EjfGcfqDabm=tP1YFxc zVI4RDRYn?Y$eZ%4QDu6H2kg9+5=Uh(R&ydh3q8t)xL|;CS$kF6X=(f}D+1$1FT9Rf ziwyMZcI9ntEG)F6v})yamKr`RrT;qi_1yqWXcw=X45bkl-Wb%3Zd7j2Uf1^e_Z7OQuj5nm&Jt6y=3JwWT2nt$9 ziq6=4a%WU;F{M^RoIs_%)Svf)zgH#$KI~w#@Ds1|B`!YS`>Q zwiwM)r&72HUYJsW4}?v5R1mQ5%A>vbEvFq{u9~IkvT8JB*OpA}0QK<|=O(fx*8blk z+Y-PpX$^{O@f-uD31j;In+;x#vv)Oga*M_PH23`fo&t)NWX_Fcffj~z_96*DMm$Wc zUNO)fxf16um`tXj3Y^PA4}C?3$aRgsVgnxn@qo4JGe`WkVdIyy0I*~JFX6GVqRPs@ zx9AQ8q9^E-xVQ%lg#}>N6chz?AfpK&ZPL$jxtnUg3-xBM;q*3R5qVQ#Q?0RXkm9KZ zJv>=eQ#HJyKT@fL6Rv?2edYcD2lN?4GC-pr5XKyS0Ac4K zgRP4uP`OFak@7EMA3VaoN!am3k5~J z;xZ2%yaAo=Cbs?P)k9OW>BxvxVKdD?jRqSkRS|7CcEESr8?&p3<0{BDYqrO9s=_oy zaNqK9NU(#ae;g|>0R-yexKM3R^HGX-)}W0OCgECq0`8OFoR<+9G8A_&Bm<5Nh`VUg z*dW|KX#4xF$#>txzWH|!kt?EKRpjiGK!BR?oC%-TWbQ){Xz_tBROSVd0@;9_21AQ0 z_xr+!aM@LUcKRyV5@F&LiZoI54E+dYW?e=bdHxFnr1UVv3EIb3TkhR=v}W53cPJb3 zmP17?XBU38H#8YCGXfS&_4ImlAaN?e!Fm9>IA`Txq&1y8tCue5zbsVJH~t&& z(&>N)0Y1o&>Hp3d{vWEJ_zZexdn*^W9Ozd3+==^EOb1f$f;NIDm4K4GFO+B6%M%stCx(cbh~PVf`k zPK_)3;gjzv?#7T0+Sqe~<*2<^hfG$|WF|-p!wQot7t>4YpTv%*(?27iH7)GMT4LL| zR|#0GV+=n`bDF2_WY9YZKF$+!7L=-oya3Ge_l8yDpVmBE2`vjrPW??EV-{wbm!0lc zV|>(Yyv1UEO0YaVojhQ<^SC*{Hc+m9RVA}8CB?Z~ev{wUqw~Tn{9`I1Uh94f$D@I@ zf?2PsfJNd&$Y<||Is|yqmgyb4uTwlpqj~QhMh!6icCKy;XfuTMc32ZBaaESO-t7{c zC$x4)sJl~Qz|mJ(yfXu;Ll}6;5e#>pCe0l`f(GA__yZ3*9UvdNp%SYka@3Sxu_2pP z;uqpilfTw9MtqXLv#;Zbu^@ZQaEFYn1L|OY^7zSP+yUvc0rDEH984+PG#7G<=$$3m zW_;;I1<#+|5AluPt2 z7lPl)uyc$up|-Uk@jQis*lLg+Yb=yx-|+DbDSEVP*~>hJ`$tu}oRu4@M3oaBM|&*M znM;_^`aY|lJQ1?{(1e?e{#a0?D`rUwaZY|DIk<2KqFLo5+$ic2@vHpv)Z;2>bVSPw zQ==&02=f12P6TkzqpSg%iZQSEqCaWCBoFABV&bh#-&7z;3Wm{KUS4{8d()@@X>nCm zB9~X7&xF9PNQG*>a5>psbQ7kE=<)RMxOeYf`}g};?Qv22biS^ptLnkGa&gRRTH_`B z8^;2;$25JS{$&4L^kQ;iTv<97hx48y+^C7PgaK;JOL^hYHA4T1hc zMPkrX(d~=$agM*DGBYzHF&~JdH9jzV)kW}SAAR_RwSJOM2_Fq`OnIpj8yDC0p(1%o zlb)qWG6x{VZUtS~)vv`aHY*(KmN#)|RW=@eR0mR#n^D<2ZgF1L+d38@n z24ti-71R1(p;mo5hjak$SdJK;sgd_qoU?S-b6>8l8r4)3wHqX&LiO7d&fCeB_LiCD zfvSYuL_U)Aam|(;@wZw%gk{^wv5J(Geu7dT>9FfG*9*Gd!jy!W{rPkYhdF<@im}`$ z0Jb4&_U~4ny*uKvlAj+t*Qc_IL4nsS!->dVKE(X%4>m)q;#Y{l^7KmdIVgMg?=Pwv zNA+K9E;uhOb(aGfea928goJEHqYzV_QB@8vCjk?~R;-qrFA3=(v3Ly@X}{t%{5HT| z7h$(KmzK4unND2MRRLIwe`5A6Ozm&fBqukr#D#*SJg0S(^$CXC3^qBy&$yvlid*uC zbl#VcI|if^ddbq9sh=wzJMO5#9>{;_eX@9vf#(KpC(k@|+A1bFLuRWsXb1A7$t0u& z3|LLG8xvo92zt?i??{nC5Lc%2i9Wv^SUxttFw^2fD);12m0_gV9@N^xxELbjU0kVM zAo+8?*a-uzXYhe>_~Me|3NMH{`%4rc{-E7pGtwu2vbjFIgx>|7H2ioB{z4E8xGrAg z1^LFw`W1bTMY zKOL+CwVnx|Cgvc!#e#p~Cy@92FZ_Ifvfut4i2T0&07?dEBZO6cKgM*uzB~@31l*ka zZ!$?YTu^gK9&@6{f9}+#AAE6CZ1}U~zM?!HYtNMKw(cM2dvT~3qj%P<5GyDO&_l3xuMlQv0xBeur zojXQq_H~sm<#B83Txie|qj~#%RUV5NSpEKIAJp{$bdpP$F1)9JzlEP`=fciUr=f)0 zMpO0{i+8btU@7oVV-WLc!)V+%30{foR%Q5e=b!RTrfjPYQ+OR3oetxi5W(>!nX(>> zhVlERv936S!7X2go+w)J>mLDJ(3d_5lugYW?0&XdDG{ai8wz)ew8j|bCzDU+A4MIB z+>pyDr&$!QXhz{=0?4M!PHvvmpDR)N;Q77E%3jr?*{e(H2weJy&-BmObo@j>KN+bD zwo&_kZFmNY>zIty%dw^l+K3o62)ih5q@t!)neQd6S~pm8-G|1AGlYLEX89O9m_Kgz zuFSUn+~{M;kk!=OyL-Etug3B+-(3E&rQP-&UEfXKSIyde+QqR+18!qpeuW8YFmzehhn42F~>^aKEEf(V)m6CUpz(v z1c0dIOc-7W z8_w)|MB;E@xE?U?$4IHF{8(LQAhB>gWUAgT9D_an;v$$r?D9Ln#s{h;W@eJS<|hAU ztE;P%SQDMbSA1J61L!f@5$tuf|DwnAP$!%|fw#MF2SqftjSqgndG7zVJcJgk^SU7D zRxW1iM9G8c^3t9r37&_C*Bo-~G~O`W@lX?i@X6^t48EUdhp0=+J^m50aeF}gS8Yg` z;nfX_->+PPV%1T?zYzS1O0v*x>Q7HKsf<8&{C`oLjleU`h8a2V_#9=2xwlUfcIa5F zZir=o!J|*$lX9*AKQ|o{Yo)}QF=N96%ko9 zV~7$@K{_3V5}}D$ZRk1QWPFBjCR(3+Q=zylRiKoHT$xm)oY!iW$6inJavHrlzlWCo zprLx0#0b+K(6dM7=u(4crbM-rslXQ7z6f_!lo#__X}gx>p%#vyV_`wT#^z@7S*TTv zB2a*WS>R%7CurPthRo5^NZ|63jPnU-FlJ?^2YVWyBU#|v?2xT#m$veA*uM3cqC50a zt5+_U`YRJdh?IVJziR07ReA;67}akI;ut57U4Z(HNVgNuN^{4zRy9`QAEpAr&aFZu zZ?TxF2@<|ek#JWxMG0)ckt{Tfd}=;RZ1Mn2*bS`8?0mFUAAWvLZgpl(ZRKnKW&Gp! zx{J9!M3ZkV;pNe3_*w?c4l?yIG6fLV{{DV|rg?ScLr?&a0lP@*pK9Yj(H?0%tR2nO zfhV9Rs#Q;)>hdthpSRY#(pjl7Q1T00&mM_5AU-XGEdE$2u=*_a93p>a6uM=pa4FXd z4cipWcP);qt}dv5fxg`TuFV4uYmr*QX(}^W$6TAxhz*~qtla^)_25wbN~3lx2rpf= z0{i6YE^Op_4Dnt10Z{KzSV-7bEmCfnj%M%MngHB*r{NhB$)rh)c~BXAc(Tf zW+A~OyVrk507BCU6es?0B2k{D(?K?O*e-K*_;HzPw-D8>zsgwS4wjZwzM^oI!x$QJ&2Syk|BpcNU8~abj|SNLOh}!x?bmVTHEc z%Eg&bM6H;&(1zWM1-_T5&AA28;yht;b;}RVPA=jr7DPoovF~iOYg*cu{w$xIZ7SG$ zK63*W8n~Hqb)KMjiL#>3XWDm97X_+RZeEoJFj|55eLsW8ym#}r-=QI7OHX%bA1khp z2v?bVscU=sUYyvIjCaRgc64rzGiZ!Z8VW#Zk`1z#aOMZ;h`&VOW8x7*%6(-t#UzJB7|BJr+u3$xYJAlrjBeWggpz{lYN?(8ufQhLcuTIfmXkl(TGnjM)FK zL)Xg#boleNH-$Y;rU&w%rLxTSWhv{pO+&-#YlNoZ%yrjk413bvu~~I8y0>X3 z*=HNq^ZIf|1o6tVpPn0FDUCOHJQyvaJ+e7*e4awVsgi(0Z{Gj=+{aG4NWN@*gU*iP=mvY!_1p6Jcty2W}vi3x^VQgg1XSm(D=g{Xe(Aw7Ad+;78CnnR|MTk5NjTwn$ zo7w2;PW(|*Jw(4NFgH(O6C&-ry0Z%KnupLLVhx{k&>L3^i;5iZ{WgI^&7sl}CbIDS zl;Mmszc}oc3-r}naw<&<@aP`Qxj;{uNXke z{$D=0m$N{#q_L7tL2ar_s5?9Yom$~7w0{W@+&0g|is6o%pAvXirnRW``$2$bqWn892zzs`I$sD!8a8@*f=)zwN3 zUv=f~E^1wHoO=Y;c$rHUeG*x|5Emwn`{9tcGLV2x60Ldq^R;_-eOwFqSjIgEmTEA4 zT_Cy9OaC?IFq&Yp&%tAIDH1upul9;okNRrN<|{g9j%|{Z4fjSIDL#f3B?{(wZ6>0@ z`e_#-fG_<|JW>&ln(jXOvUYsX=wYX1rB4<-5i2=+cFL>QXO!M2gHid{KDXQ4z;r2W zMK@~jkK2Q6=@0jevVf{k0R_oeKjDLOliNeCMd)bhzQ8u)7?84 zG5kYl%*+uQ&F!Dx8a&)Bg#g-+iP!Mz*Xi>6=du~# zXluvkWd8KvXl4^vh?!7K9~&f+Yt!jL_w2U;@+=4{MFMFM3~2|w<$pWI5JtC_Axf*r z+w-AfVZnf)0BFTdjmjg^W+^mUh7M;l$*StmK==J{)ED>pDMKQLxSt7}4{5FF7 zi}Ab_6&%n>>&EHElSkj^zm1zf zXtg!4C}?5=<_1pg^R_OWmWJRzN0-p~suPDxDTXD?BJ0wyV>!WVOIcWBt358eTXD|^oy#9Fj zqNHznojBzjzD(r@dc)K=!$1%$As@gY=T7r?P6y0Kx zA5-B8WAOU6sp1H0SC}9C2`_aHHJ*ma>YodcW zlJF-e?lCrV6Gp;@+qT|tOEFDFjdQ0M^%iyKmXG=1t&m44vWRNacG{o3x(qaP<>;zj z>tf3^tS}EAYu;|yDE*rx6r^tHgElG?)ZOXf?B}$;QEAWQ#!S7f<%!k|U*K0Ln@3mZjWohF0>y`_;-~PkZ#<9i; zHgoMBMwAonk^*(drcxjRPAAA*thB&&>RB9JV?iln3Y!gk^$+y5pL(p{CU^1ZV-dL& zp&6$RhJsslv$L}>7!1f+#l*zC;Bc_D^_dGIP**D|ECd+DvX=WxT?Ntap-xCD9YZp( z%Zov0(E()ga8?DVEiVIHZ4GTsUkv=97K{Ku$%_<*S?wPKJ_5!zr zEHLR$TT?HUH-`U=u1P#e37jG5<5WAc{QadzfXcLJ6)+j{T3D<$PuQx7v)%>ZQdz*Znn^S@abfm?=HGmaU_ z0BWoyIwnIHdqMzA6kZn>?}Y z1fj%5<;`?nX9^>bKi60&8SXos$-BwE@u}Da$aV2}206;Gp2T}4vg~j5BenIz&z2pw zrzO#U^2TlBDycVh${njeTKtsxw#k+c5Ci|HNH%CX_ z&8LAM0rfXj&{li=t?B36ygVtjy6|K3X`(LzXnfLF}0K1)pLF@?=1?%f8F$X|&h7ywAy=yny zR1b$A?asGZbi~-(*+IoUAX-{U@FhRY40>o)OUEe5XDNt|o*pXUgKD>Z>q-r06id$J6R;6<_CQfxs@ygND9uyrOzQ#;eJ!V)T0i+)G3=D)|E8d zIKeg^wX`7IdiACEvP`5!>TN0kB1e|e()0BD9<%aYYnz*f&ED{^-VAZfXA0GOalphS zEG%4Rg79DX9S+DWlz66xhY!XOI5$tvIv?DWIJa+r-TodGf%{*?$)7qMe}waL_s!Sk z|E(bc46L&=Z(E8{Jr<1KQ_zbw!e{pD);r_P?=d|D#tdTO4;V~N&vJ}var61%oVE?Z z)zL4dCH(1845(k7p!wl`gv zhdjI(KxQ~k<-W}@aB)LIL&a&hW&=jzmy&UdYHQNC#Q6#eR*547oiN0(&e1GO9H>RJ z2KAjmohJ)OQMkESl+$(xB8U zhh(EELndyMkj4~v;1+da_R{I=`x~|Z!-X;q(5ytY0&X2lL%2~=E4v+$9m1)cbNJ@< zxY!2))bsLc_Q!XqqK)0!lRN^>jwkcUv7!GM)6LfVtgYChj(2p7PI2G#Z+u)xq}Tvg z|BM5o136P04S`b)vB4dGOk)5x)#R@P)lNXxRxeDW#dj-!U<7|oYoErY(S1t^H9j;H z@6B%H+*gWg4}D$}d)~8S-*ZKrpHuAv?!r-h7T1M^NNyae$N^ygeP#4tUg5K_)mwk1 z`)&YMlK24vnXPkLocq_dQHE%F*Y|)-bS)>LIQaYE>gRl%N4KA__Li3lF|qdcl-Sy@ z^aq!Yq3R#{p`vDoKw(lAuL+`|Ssi0NNXDYi?LQ^1josrRUZjg3`<2Mt_pyKR8jH)D zltcfMz#zd3Tkf=o?8}r67%9{`;*rq3Z2eTQrBuK_AmMUxvR9+B+b9a6mBdp{kH>Jv zF<-JVQ9PiNTZ(Qh4pYLJmV9qsyxeZw!0w#S~Cz=c~{=B9h_Koy8l_$-i=LhEtg5QqSvNL1FeuM`k)37k8NJFaCb zyKzN&DX;E=QNQJQ46MY|(}nDs(5D0s{TAju3{O;tSSfpR6ce783eIKM)VSj=PFYzZ z55(r=%sXNj#!LdRwq?!9zGn+ITFbH5SVZywO(U>}`O?@dQY+jWGLRD37$6e;52UBN z7)gHafs7_s4WwYEox{WTK1L4Q$HbIFfEiS2^YP?Nqemq839!^;YHMo)ESjWod$G)M zoj|-6RDKg5l)3K>ha4eKU+ZHqN3+<&X7QEUvQ0e-vJxi$Nfje-I48%A_RX3p$W+z) z*f2xS`QTcV|9LZJ_B@xzkKHT!XvzWM*OSa;MsOP>wJc~q6yKZ9wBGNtbLO&KRCX+= z!12AJ`{aegu}}GVONAmbW;%}MX%3e`%`=0V*S3DRQ#8u4jhHRdcOQTrx0Z=pLtm5| zTw}or$PEM@FwoMT%|#O1#|#%OG!G$qP{1No;UCU1AyGF5_?>j?5Loy^x?P+S#F4h z3~AHh>NW*w4XInZ2Qp;GrV+Q#!vD@nw013e(i!GxUU=te`O(H$WG65bR3-L)N2T;j zVhl^%09~&09a12K|M~wG`(PDOm)Kk)8g9zx_f4NDJs~F`eMlK+5hKd_AR4*2_g8t) zdgbL^AUyc@dc<}8Z$VeU5WR%wm!43(r*b#)RSaq%r?VL-2Whu*ukM=UPvZXWJ6q~h z6TiAdwXGA2sxtj`@gLq3lEuWh z+BzlubDn;^p+3#UqD`y*JYEJ-{m6@3>SG-uGP- z*#We$QM|fa%3Y7q|FEMR>an96DgI^0Mihm!Q{(Dh)|ZU#Mw5<%Zpx)!g@%H! zu}EMR*6k7-NrZu{p2)1I8FBmy6Zn_xgm&bi&n91+bOS&ZHE)lIrW1yFuNS<8&z>Od z@5su&QdD?8^sV*1T#Lb7N#}2$@u5QP@Y2EpW9Pnf2Evh?Bx(14sAo2;Cy38tRKPxu&h0eIDT z909~;iA4DqTjg^Sc@4dk_Fbn1VL@MGzFO3y}-dos}w|u+SwHPimPc+*I2OU zB5>_x?iXWOk~hyw8}|M5tF7f`@uMCp74Z1)MWz^g7lavlEhlB3_P(!y%zTI!&1KBj za5nLGPK)b)YSCDxtku=gMc>K}PT{?){BG+%UkG_f4zS6fLN?(Mqhy2nkrDF#Cw+`0 zhZs2~vJ$v@ukelU!Rm!sS@TT?{mN1$MMdH}O$S%)S2_d|n3ief4t&Emu#aImNK9N( z=kg+#&kr2VTVi2d2K!TTMUKWWaN3}SLA1oxqd;+;fq?;7{C05>kkH>2e&Y1CgRtD! ztdL`0J}9na)gMb_YDr5=TX!^S;Lx;(1n%WlA|61*k`RIxx>Z*!;Tm*}1vtfm<)z9G zk&>G$bQG^%%z@LDjGb9yIiGzSw=MxxbEJ$?h9)Km$V|f_XGr5gZ6$Rl&)R;*uw@D2 zC)*t-Rq{ElxA`i!T6#SmrxO)&m41$4%1Q*{&E9bl0fFjweQ8J}ve^ftFZ~0kYQBWS zoK)lOIZP!T*!7+*(wNo68WqAv9k`Nl@jfe-`v(H~{qOKi$4%NgXJqi?Nv}LlVF9?) zU)qyZc6tMhINoIf>CW+%OKF_Nbf}bOvuTixBeSqQp%ObX>Yn|0`QreZTiC%^|HCO1 zPRJ{1mvU<2O|GV&AJ)iYMi5ZNN!-$i_bu`%rV#X2f@9_yi@3RZG>pH2 z56V_yKQ&oepLf2J?gR5=@;jf;Rc?gTTcJ9nA5PWu<-jaoeR1Nh7h~F>X7sVzwB@px zwf43j-7*(dnDyWpQciRI)u0R$TWyJi%SC}AX?Pw=`}-o#i{Lfyj+F{}co0zNoflnq zMC{j_(6Eg68G?VOi>o1*-8zSJrp`W1`T5wh4Q8hBqYZ<8$=Z#Ub6?HU#32RCnRu9( z<&1L7g{=sjuQ^K4uWQo!3~6|_JVa#Mdp}yt?Q!$|g&S`N-%Iv1F}HOf$~+1Q`6s1U zBvshNeZq?Ie7uA3J{<_3X|B4!e5H3ak)15=E7-0*;y4|m1lg&ZVq|}Ljl~}Fq)>~G zjD`HZbjwBE;`GK_g;7{B!BMdt+NRh_VkFhg!}fc@(xZ`E%T_P@a%i+!kLcbx>n(Oo zzDzOVRR>~^%NX%(Pqa8n&&a4`v-d0CqOHmKWIT&<#4c+~mPIhhQ~zI?Qvyu^m$3H8 zP-A~D-JGVZ`EjkHCvnz#<)%Nre>cpzfV$*K?Y@{uWY=r06ra`~CQ0C0qk2dGx5VK2 zijLv>Ym}rd?Rw|O?`Bw-_q=B8ma?Ak%J)y(8Lu8MA5G`E`e3$=fJqHd*#gvsg*{Ju z`>n&Z;Q^7wC=J}@@wSv$_j>=$lO3r6%jb%$H{xG_U*FcQz85!BNFXPyTf=dU#S8n9 zwuP1}?Ki6BNL9{=eNswJK8lj#f_tws`{Tv`+J1Ow@1i6Q2qM zeQrX$UODpG#_{pS3`|X@PAk4!#W1fsqNOmHMm4;H9>3Whri7ebOKX`GrqxkdCw}4h3kbeV|fM{1H5a@ZXRmL=+*~^8)?TKhY1XKc+sZ?{w3b@C{O)e)T zoy@!2kO5!PN#`fvwEnge=CmkB^_cn){%Ud8WWh2@q?#xvI|coM)D6&spW&R>Sb#cT z?3d+4a->NkR<|2n!dhj?vgxz=dQxa+T@yNMR@5d=1{~T%+wU023h^~9Pxn>M(Es&P z?@y2HZIy@t7bcfcuqL$P%UxM;c5<(Aq=)@DQIH-&M!gNwWNL0|06J~%})Wc}e8Jya*kU)UZ2l^s6 z^hQXI$q2}Qc~99xU1;7yR8+PT**W53#6*;hL;wrMo>^5@Q_){`xdv$5?LoNyn|g*CXPz6E(HAyx+X0yP-Xi z9iA@oV$7gGN=5E;6dsvaW6KR6^ zzAfE=>@whZ^Q2ZDXtw`kj{y$PC6#*mTy^t^*SA+(!srQu=-mo;C(kg#7xEK6)tIal z{fNlv9&{`gnUk%idRGeZ-R-C+p#HMawcS!v74*e#DU*B~CQ$HFJ7WGC3-1mRnLbJ_ zN9@ta(UE9U64T;uNV14sEJar@J*YA<@1OzGz?|0N3Yj=8i|v1#WP|p(w0H^cUacs} zKf~U4wE^4Mtcg*e~a;5})2TWW`*h+xl1nWanHprm8DmCkv{R=xy;rA0`c3K{mX zp;dIbQ2&sPNjd86qh7a+u&3l6x4@5z30lQ8re|)-G;=?>shmuv1`w9HqOB#>Nn?KeoYg8+G0L-FL!chxJNFbxWsz&qkCy(JO_I6UW<;B(p@iEH7QWnfe?Y zw_N3x;Ul&bqJBsAGgD3@q3=r*|59>n>4I#_w|>QWiC552su3^zeo?0xMt5o4WVjYe zT>7l9zOzGCD3)=QxAL)Gg`Vm)7Rlh- zdnBMQHbZ(sa$~6?Y{3j?CyQfCLdTSKt;3{5&lIn* zV54cD+5%9h-q{PMKZxl(`+pUt?@mTxO>u!hP+VI$%5s7 z9x-*~dP;I5DNO=hN-4-JBF5ULxsUr0_xWwtSLp>`K9=(EUMp&x6vX!4SA7fB&>cPk zn<{DP=^w-@9xn)n(=>{bT8VtU4Ri=H@%z40aN=mq@RWO#*Ko9pa)k2n=EQ+nKbrz! z+SA{@jIOaC=195ye`FUj{d!}L2Ic-S_t;go{E?MoHuh42v9UHj?G~VbV1$#q_YyhQ zPNZj9rr9UPw=2&gc5dJ@kGsDiWj+i*o|&| zF;$6k_W^}W(!ZKCu+4phpXu%b$3SI3u_onIt8z{VZ>CP7^IqJx5Bt2a3J6V}YNg@g za?pl2_38-zq>_{`bx@6S#}MUuv2;Wjq@Nc2lJ+p!9URxmEaK$kVOE8%JtOv*#LolA z{5RhTs`vIY%b;K{%x(~kJUnYw$GE<|H3;|-3Xy*zC6K&@yXhhRA zzRr9&FEqhYk3V(5Ai|yBkox`Uq?zu)$qHo8K~Gz?E{fz4T}4Pph;3=Te77zEDZQbV z&!tZ(cAirUE|NlWlJDo#(()+aGV4>lTb2&vgoMj+@u~`sXqFuw?G3=4g@cnqvcURh z8Q1CZe7`@o$^6J5z@Q0u;;g}T&jK>Zo6A+{(Mv?~B5cSXkH&%{DNMftZWAMa|3wnjMjK19{xP*4Ge%Y=nbsm3Czt2tO*-=Q;cf37kwd`bn- zg|2+@E{}4O2O?4zY{-U#C(b03zIOP06$_tj{b*U{_TI_zoi!tbHv7%A#%>53)QBXx zY&j%MMMFF6bx~%BnJ^ycMP8f_iZw|@N5mgIv|>I8}icPWzGoO6 zUtWBF7+FP73$E#-ua*{8>N2F(Sj4GoZN)T_{Ox&71|fsaKY{^dRK$FS7pY7nL{ILV z|MuXg-?&uzZyx+!lpr#5(VVuA`?INa9BhRo`F+=2t4enZq_Rlg=lS@)Hxd+WoeSd9 zW_T+M5NpM)NPxpX0p8!@4p01r`!zP}i!B|&(4SaKli3$folN}J=wMXyNL4;_wO7rTy7w%) z$?arjcOYQM&Ei`X+7*?TOi+q&7|b>Z7jcq*t#&Z63NoF~j^tJk*@F3bvClGo!Ruv5S7b^1?%-xFfd-q z3`Ub)EZqnPaxx%LNanOgt0-EQu;gsd&lckObYK2*E|eiD6e)F9r6B3$1x#wdX?LXy z*t+>tWyL;Lhyz04f8Qf)$P [!NOTE] -> Remote Desktop client devices running earlier versions, at minimum Windows 10 version 1607, only support signed-in credentials, so the client device must also be joined to an Active Directory domain. Both Remote Desktop client and server must either be joined to the same domain, or the Remote Desktop server can be joined to a domain that has a trust relationship to the client device's domain. -> -> GPO [Remote host allows delegation of non-exportable credentials](/windows/client-management/mdm/policy-csp-credentialsdelegation) should be enabled for delegation of non-exportable credentials. +> Remote Desktop client devices running earlier versions than Windows 10, version 1607, only support signed-in credentials. Therefore, the client device must also be joined to an Active Directory domain. Both Remote Desktop client and server must either be joined to the same domain, or the Remote Desktop server can be joined to a domain that has a trust relationship to the client device's domain. [!INCLUDE [windows-defender-remote-credential-guard](../../../includes/licensing/windows-defender-remote-credential-guard.md)] -## Enable Remote Credential Guard +## Enable Remote Credential Guard on the remote host -You must enable Restricted Admin or Remote Credential Guard on the remote host by using the Registry. -1. Open Registry Editor on the remote host -1. Enable Restricted Admin and Remote Credential Guard: +To enable Remote Credential Guard on the remote host, you can use: - - Go to `HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Lsa` - - Add a new DWORD value named **DisableRestrictedAdmin** - - To turn on Restricted Admin and Remote Credential Guard, set the value of this registry setting to 0 +- Microsoft Intune/MDM +- Group policy +- Registry -1. Close Registry Editor +[!INCLUDE [tab-intro](../../../includes/configure/tab-intro.md)] + + +> GPO [Remote host allows delegation of non-exportable credentials](/windows/client-management/mdm/policy-csp-credentialsdelegation) should be enabled for delegation of non-exportable credentials. + + + + +To enable Remote Credential Guard on the remote host, you can use: + +- Microsoft Intune/MDM +- Group policy +- Registry + +[!INCLUDE [tab-intro](../../../includes/configure/tab-intro.md)] + +#### [:::image type="icon" source="../images/icons/intune.svg" border="false"::: **Intune/MDM**](#tab/intune) + +### Configure Remote Credential Guard with Intune + +[!INCLUDE [intune-settings-catalog-1](../../../includes/configure/intune-settings-catalog-1.md)] + +| Category | Setting name | Value | +|--|--|--| +| Administrative Templates > System > Credentials Delegation | Restrict delegation of credentials to remote servers | Select **Enabled** and in the dropdown, select one of the options:
 - **Restrict Credential Delegation**
 - **Require Remote Credential Guard**
 - **Require Restricted Admin**| + +When running in *Restricted Admin* or *Remote Credential Guard* mode, participating apps do not expose signed in or supplied credentials to a remote host: + +- Restricted Admin limits access to resources located on other servers or networks from the remote host because credentials are not delegated +- Remote Credential Guard does not limit access to resources because it redirects all requests back to the client device +- Restrict credential delegation: Participating applications must use Restricted Admin or Remote Credential Guard to connect to remote hosts +- Require Remote Credential Guard: Participating applications must use Remote Credential Guard to connect to remote hosts +- Require Restricted Admin: Participating applications must use Restricted Admin to connect to remote hosts + +[!INCLUDE [intune-settings-catalog-2](../../../includes/configure/intune-settings-catalog-2.md)] + +Alternatively, you can configure devices using a [custom policy][INT-1] with the [DeviceGuard Policy CSP][CSP-1].\ +The policy settings are located under: `./Device/Vendor/MSFT/Policy/Config/DeviceGuard/`. + +| Setting | +|--| +| **Setting name**: Turn On Virtualization Based Security
**Policy CSP name**: `EnableVirtualizationBasedSecurity` | +| **Setting name**: Restrict delegation of credentials to remote servers
**Policy CSP name**: `LsaCfgFlags` | + +#### [:::image type="icon" source="../images/icons/group-policy.svg" border="false"::: **Group policy**](#tab/gpo) + +### Configure Remote Credential Guard with group policy + +[!INCLUDE [gpo-settings-1](../../../includes/configure/gpo-settings-1.md)] `Computer Configuration\Administrative Templates\System\Credentials Delegation`: + +| Group policy setting | Value | +| - | - | +| Restrict delegation of credentials to remote servers| **Enabled** and in the dropdown, select one of the options:
 - **Restrict Credential Delegation**
 - **Require Remote Credential Guard**
 - **Require Restricted Admin**| + +[!INCLUDE [gpo-settings-2](../../../includes/configure/gpo-settings-2.md)] + +- If you want to require either [Restricted Admin mode](https://social.technet.microsoft.com/wiki/contents/articles/32905.remote-desktop-services-enable-restricted-admin-mode.aspx) or Remote Credential Guard, choose **Restrict Credential Delegation**. In this configuration, Remote Credential Guard is preferred, but it will use Restricted Admin mode (if supported) when Remote Credential Guard cannot be used + > [!NOTE] + > Neither Remote Credential Guard nor Restricted Admin mode will send credentials in clear text to the Remote Desktop server. + > When **Restrict Credential Delegation** is enabled, the /restrictedAdmin switch will be ignored. Windows will enforce the policy configuration instead and will use Remote Credential Guard. + +- If you want to require Remote Credential Guard, choose **Require Remote Credential Guard**. With this setting, a Remote Desktop connection will succeed only if the remote computer meets the [requirements](#remote-credential-guard-requirements) listed earlier in this topic. +- If you want to require Restricted Admin mode, choose **Require Restricted Admin**. For information about Restricted Admin mode, see the table in [Comparing Remote Credential Guard with other Remote Desktop connection options](#comparing-windows-defender-remote-credential-guard-with-other-remote-desktop-connection-options), earlier in this topic. + +#### [:::image type="icon" source="../images/icons/windows-os.svg" border="false"::: **Registry**](#tab/reg) + +### Configure Remote Credential Guard with registry settings + +To configure devices using the registry, use the following settings: + +| Setting | +|--| +| **Key path:** `HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa`
**Key name:** `DisableRestrictedAdmin`
**Type:** `REG_DWORD`
**Value:**
 `0` (to turn on Restricted Admin and Remote Credential Guard)
 `` (to )| You can add this by running the following command from an elevated command prompt: @@ -112,31 +184,13 @@ You can add this by running the following command from an elevated command promp reg.exe add HKLM\SYSTEM\CurrentControlSet\Control\Lsa /v DisableRestrictedAdmin /d 0 /t REG_DWORD ``` +--- + ## Use Remote Credential Guard -You can enable Remote Credential Guard on the client device either by using Group Policy or by using a parameter with the Remote Desktop Connection. - -### Turn on Remote Credential Guard by using Group Policy - -1. From the Group Policy Management Console, go to **Computer Configuration > Administrative Templates > System > Credentials Delegation > Restrict delegation of credentials to remote servers** - ![Remote Credential Guard Group Policy.](images/remote-credential-guard-gp.png) -1. Under **Use the following restricted mode**: - - If you want to require either [Restricted Admin mode](https://social.technet.microsoft.com/wiki/contents/articles/32905.remote-desktop-services-enable-restricted-admin-mode.aspx) or Remote Credential Guard, choose **Restrict Credential Delegation**. In this configuration, Remote Credential Guard is preferred, but it will use Restricted Admin mode (if supported) when Remote Credential Guard cannot be used - - > [!NOTE] - > Neither Remote Credential Guard nor Restricted Admin mode will send credentials in clear text to the Remote Desktop server. - > When **Restrict Credential Delegation** is enabled, the /restrictedAdmin switch will be ignored. Windows will enforce the policy configuration instead and will use Remote Credential Guard. - - - If you want to require Remote Credential Guard, choose **Require Remote Credential Guard**. With this setting, a Remote Desktop connection will succeed only if the remote computer meets the [requirements](#remote-credential-guard-requirements) listed earlier in this topic. - - If you want to require Restricted Admin mode, choose **Require Restricted Admin**. For information about Restricted Admin mode, see the table in [Comparing Remote Credential Guard with other Remote Desktop connection options](#comparing-windows-defender-remote-credential-guard-with-other-remote-desktop-connection-options), earlier in this topic. - -1. Select **OK** -1. Close the Group Policy Management Console -1. From a command prompt, run `gpupdate.exe /force` to ensure that the Group Policy object is applied - ### Use Remote Credential Guard with a parameter to Remote Desktop Connection -If you don't use Group Policy in your organization, or if not all your remote hosts support Remote Credential Guard, you can add the remoteGuard parameter when you start Remote Desktop Connection to turn on Remote Credential Guard for that connection. +If you don't use Group Policy in your organization, you can add the `remoteGuard` parameter when you start Remote Desktop Connection to turn on Remote Credential Guard for that connection: ```cmd mstsc.exe /remoteGuard @@ -145,10 +199,12 @@ mstsc.exe /remoteGuard > [!NOTE] > The user must be authorized to connect to the remote server using Remote Desktop Protocol, for example by being a member of the Remote Desktop Users local group on the remote computer. -## Considerations when using Remote Credential Guard +## Additional considerations -- Remote Credential Guard does not support compound authentication. For example, if you're trying to access a file server from a remote host that requires a device claim, access will be denied -- Remote Credential Guard can be used only when connecting to a device that is joined to a Windows Server Active Directory domain, including AD domain-joined servers that run as Azure virtual machines (VMs). Remote Credential Guard cannot be used when connecting to remote devices joined to Azure Active Directory -- Remote Desktop Credential Guard only works with the RDP protocol +Here are some additional considerations for Remote Credential Guard: + +- Remote Credential Guard doesn't support compound authentication. For example, if you're trying to access a file server from a remote host that requires a device claim, access will be denied +- Remote Credential Guard can be used only when connecting to a device that is joined to an Active Directory domain. It can't be used when connecting to remote devices joined to Azure Active Directory +- Remote Credential Guard only works with the RDP protocol - No credentials are sent to the target device, but the target device still acquires Kerberos Service Tickets on its own - The server and client must authenticate using Kerberos