Windows Server

CredSSP Encryption Oracle Remediation RDP Error: Patch and Check Policy

Updated Sources linked 2 min read October 3, 2026 · by Ryan Bennett

Remote Desktop fails with “An authentication error has occurred… This could be due to CredSSP encryption oracle remediation.” A security update and the effective CredSSP policy can prevent an unsafe connection when one endpoint is unpatched.

Fix 1: Patch both endpoints

Install the applicable current security updates on the client and server, and restart each after saving work. If RDP is unavailable, use an approved local/hypervisor console, another secure management channel or your cloud provider’s recovery console to patch the server. Check the effective policy if the error remains after both ends are updated.

Fix 2: Understand which policy controls the connection

Encryption Oracle Remediation is under Computer Configuration → Administrative Templates → System → Credentials Delegation. On a managed machine, have the policy owner review it rather than creating a conflicting local setting.

Connection Force Updated Clients Mitigated Vulnerable
Patched client connecting to an unpatched server Blocked Blocked Allowed using an insecure fallback
Unpatched client connecting to a patched server Blocked Allowed Allowed
Both endpoints patched Allowed Allowed Allowed

Mitigated on a client does not allow it to connect to an unpatched server. The previous workaround of choosing that value for this scenario cannot work. The server-side behavior toward unpatched clients is a different case.

Fix 3: Recover access without weakening authentication

Patch the unpatched endpoint through a console or another approved management route. Setting a client to Vulnerable permits the insecure fallback and exposes the connection to the vulnerability; it is not a safe general repair. If an organization has an exceptional recovery procedure involving it, the security owner must assess the exposure, keep the exception temporary and restore the secure policy after patching.

FAQ

Is the problem always on the server? No. An unpatched server can be rejected by a patched client; a server configured to force updated clients can also reject an unpatched client. Check both endpoints and the policy direction.

Should I use Force Updated Clients? It requires patched clients and servers. Follow your organization’s policy after updating all affected systems.

Sources: Microsoft Learn — CredSSP connection compatibility table, Microsoft Learn — CredSSP policy

↑↓ navigate · ↵ open · Esc close See all results →