Skip to content

Commit a10bcb2

Browse files
authored
Merge pull request #8650 from MicrosoftDocs/main
Auto push to live 2025-04-06 10:00:02
2 parents af7c449 + d867e17 commit a10bcb2

File tree

1 file changed

+20
-10
lines changed

1 file changed

+20
-10
lines changed

support/windows-server/remote/rdc-stuck-on-src-screen.md

Lines changed: 20 additions & 10 deletions
Original file line numberDiff line numberDiff line change
@@ -1,11 +1,11 @@
11
---
22
title: Remote desktop connection is stuck
33
description: Fixes an issue when remote desktop may stick on the Securing remote connection screen.
4-
ms.date: 01/15/2025
4+
ms.date: 04/03/2025
55
manager: dcscontentpm
66
audience: ITPro
77
ms.topic: troubleshooting
8-
ms.reviewer: kaushika, ryhayash, mmiura, jarrettr, v-isboua
8+
ms.reviewer: kaushika, ryhayash, mmiura, jarrettr, v-isboua, warrenw
99
ms.custom:
1010
- sap:remote desktop services and terminal services\web access (includes remoteapp and desktop connections)
1111
- pcy:WinComm User Experience
@@ -30,9 +30,7 @@ Securing remote connection...
3030

3131
Remote desktop connection uses the highest possible security level encryption method between the source and destination.
3232

33-
In Windows 7 or later versions, the remote desktop connection uses the SSL (TLS 1.0) Protocol and the encryption is Certificate-based.
34-
35-
It means the authentication is performed by using self-signed certificates (default), or a certificate issued by a certification authority installed on the remote session host server (Terminal Server).
33+
Authentication is performed by using self-signed certificates (default behavior), or a certificate issued by a certification authority installed on the Remote Desktop Session Host server (RD Session Host).
3634

3735
If you use a self-signed certificate, the system tries to retrieve the trusted certification authority list from the Internet to check the publish and revocation status of the certificate. Therefore, the **Securing remote connection** screen may appear for a while.
3836

@@ -78,10 +76,22 @@ To work around this behavior, use either of the following methods:
7876
7977
### Method 2
8078

81-
Deploy a Group Policy Object to the client to turn off Automatic Root Certificates Update. To do it, follow these steps on a Windows Server 2012 R2-based computer:
79+
Deploy a Group Policy to the client to turn off Automatic Root Certificates Update. To create a Group Policy, follow these steps on a Windows Server computer that is used for Group Policy management in the same Active Directory domain as the RD Session Host and client:
80+
81+
1. Open the Group Policy Management Console (GPMC) by using the following steps:
82+
83+
1. Press the Windows key+<kbd>R</kbd> to open the **Run** box.
84+
2. Type **Gpmc.msc** in the **Run** box, and then select **OK**.
85+
86+
> [!NOTE]
87+
> GPMC is installed by default on domain controllers and on any Windows Server or client that has the Remote Server Administration Tools installed.
88+
89+
2. Create a new Group Policy Object (GPO) or select an existing GPO to change.
90+
3. Right-click the selected GPO, select **Edit**, and browse to the following Group Policy:
91+
92+
**Computer Configuration** > **Administrative Templates** > **System** > **Internet Communication Management** > **Internet Communication settings**
8293

83-
1. Open Group Policy Management Console. To do it, hold the Windows key and press the r key. Type *Gpmc.msc* in the **Run** box, and then select **OK**.
84-
2. Create a new Group Policy Object (GPO) or select an existing Group Policy Object (GPO) to change.
85-
3. Right-click the selected Group Policy Object (GPO) and then select **Edit** and browse to the following Group Policy:
86-
**Computer Configuration** > **Administrative Templates** > **System** > **Internet Communication Management** > **Internet Communication settings**
8794
4. In the details pane, double-click **Turn off Automatic Root Certificates Update**, and then select **Enabled**.
95+
96+
> [!WARNING]
97+
> Turning off Automatic Root Certificates Update means you need to update any client or server when a new root certificate update is rolled out.

0 commit comments

Comments
 (0)