1. 登录认证:设置RDP-tcp安全层为0x0,记录登录源IP。(镜像系统默认为0x1)
查询:
reg query "HKLM\System\CurrentControlSet\Control\Terminal Server\WinStations\RDP-Tcp" /v SecurityLayer
设置:
reg add "HKLM\System\CurrentControlSet\Control\Terminal Server\WinStations\RDP-Tcp" /v SecurityLayer /t REG_DWORD /d 0x0 /f
2. 登录认证:设置UserAuthentication为0x0,记录登录源IP。(镜像系统默认为0x1)
查询:
reg query "HKLM\System\CurrentControlSet\Control\Terminal Server\WinStations\RDP-Tcp" /v UserAuthentication
设置:
reg add "HKLM\System\CurrentControlSet\Control\Terminal Server\WinStations\RDP-Tcp" /v UserAuthentication /t REG_DWORD /d 0x0 /f
3. 登录审计:开启登录成功和失败审核策略。