CredSSP Encryption Oracle Remediation RDP Error: Patch and Check Policy
Remote Desktop fails with “An authentication error has occurred… This could be due to CredSSP encryption oracle remediation.” A security update and the effective CredSSP policy can prevent an unsafe connection when one endpoint is unpatched.
Fix 1: Patch both endpoints
Install the applicable current security updates on the client and server, and restart each after saving work. If RDP is unavailable, use an approved local/hypervisor console, another secure management channel or your cloud provider’s recovery console to patch the server. Check the effective policy if the error remains after both ends are updated.
Fix 2: Understand which policy controls the connection
Encryption Oracle Remediation is under Computer Configuration → Administrative Templates → System → Credentials Delegation. On a managed machine, have the policy owner review it rather than creating a conflicting local setting.
| Connection | Force Updated Clients | Mitigated | Vulnerable |
|---|---|---|---|
| Patched client connecting to an unpatched server | Blocked | Blocked | Allowed using an insecure fallback |
| Unpatched client connecting to a patched server | Blocked | Allowed | Allowed |
| Both endpoints patched | Allowed | Allowed | Allowed |
Mitigated on a client does not allow it to connect to an unpatched server. The previous workaround of choosing that value for this scenario cannot work. The server-side behavior toward unpatched clients is a different case.
Fix 3: Recover access without weakening authentication
Patch the unpatched endpoint through a console or another approved management route. Setting a client to Vulnerable permits the insecure fallback and exposes the connection to the vulnerability; it is not a safe general repair. If an organization has an exceptional recovery procedure involving it, the security owner must assess the exposure, keep the exception temporary and restore the secure policy after patching.
FAQ
Is the problem always on the server? No. An unpatched server can be rejected by a patched client; a server configured to force updated clients can also reject an unpatched client. Check both endpoints and the policy direction.
Should I use Force Updated Clients? It requires patched clients and servers. Follow your organization’s policy after updating all affected systems.
Sources: Microsoft Learn — CredSSP connection compatibility table, Microsoft Learn — CredSSP policy