Restrict delegation of credentials to remote servers

When running in restricted mode, participating apps do not expose credentials to remote computers (regardless of the delegation method). Restricted mode may limit access to resources located on other servers or networks beyond the target computer because credentials are not delegated.

Participating apps:
Remote Desktop Client

If you enable this policy setting, restricted mode is enforced and participating apps will not delegate credentials to remote computers.

If you disable or do not configure this policy setting, restricted mode is not enforced and participating apps can delegate credentials to remote computers.

Note: To disable most credential delegation, it may be sufficient to deny delegation in Credential Security Support Provider (CredSSP) by modifying Administrative template settings (located at Computer Configuration\Administrative Templates\System\Credentials Delegation).

Supported on: At least Windows Server 2012 R2, Windows 8.1 or Windows RT 8.1

Registry HiveHKEY_LOCAL_MACHINE
Registry PathSoftware\Policies\Microsoft\Windows\CredentialsDelegation
Value NameRestrictedRemoteAdministration
Value TypeREG_DWORD
Enabled Value1
Disabled Value0

credssp.admx

Administrative Templates (Computers)

Administrative Templates (Users)