Windows 11 22H2 - Remote Credential Guard (RCG) hop (SMB) not working.

Zacharias Embaxter 60 Reputation points
2023-05-30T09:11:39.2366667+00:00

Hello,

apparently the "double-hop" problem (https://learn.microsoft.com/en-us/answers/questions/744867/remote-credential-guard-double-hop-issue-after-ser) when using Remote Credential Guard (RCG) on a Windows 11 22H2 (Build 22621.1702) endpoint is present again. I.e. after connecting via mstsc /remoteGuard to a Windows 11 PC it is not possible to access network drives. A login dialog appears with the error message "No connection to a domain controller could be established to handle the authentication request."

Win11 configuration (target system):

HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Lsa.

"DisableRestrictedAdmin"=dword:00000000

(https://learn.microsoft.com/en-us/windows/security/identity-protection/remote-credential-guard)

Configuration Win10/Win11 (source system):

Encryption Oracle Remediation - Force: Updated Clients

Remote host allows delegation of non-exportable credentials - Active

Restrict delegation of credentials to remote servers - Active (Require Remote Credential Guard)

The only thing that currently helps is to lock the computer 1x and log in again. After that the connection to network drives etc. works.

The problem does not exist between Windows 10 systems with the same GPO settings. There everything works as it should (even with activated Credential Guard).

Any help would appreciated. Thx.

cu..

Z. Embaxter

Remote Desktop
Remote Desktop
A Microsoft app that connects remotely to computers and to virtual apps and desktops.
4,646 questions
Windows 11
Windows 11
A Microsoft operating system designed for productivity, creativity, and ease of use.
10,266 questions
{count} votes

1 answer

Sort by: Most helpful
  1. Hania Lian 19,601 Reputation points Microsoft Vendor
    2023-05-31T09:02:51.6566667+00:00

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.