Policy
Enable Microsoft Entra ID Authentication Enforcement
Windows 11 25H2
Policy overview
Key metadata and intent for this policy.
Supported OS tags: Windows11
This policy setting allows you to specify whether to require server-side enforcement of Microsoft Entra ID authentication. If you enable this policy setting, all Remote Desktop Services clients must use RDS AAD Auth in order to authenticate to RD Session Host servers. This policy does not allow fallback to other authentication methods. Network Level Authentication (NLA) is required to be enabled in order for this policy to be effective. Refer to the "Require user authentication for remote connections by using Network Level Authentication" policy. If you disable or do not configure this policy setting, then Microsoft Entra ID Authentication Enforcement is not enforced.
Registry values
How enabled and disabled states update the registry.
| Registry location | Type | Enabled value | Disabled value |
|---|---|---|---|
| HKLM\SOFTWARE\Policies\Microsoft\Windows NT\Terminal Services\EnableMicrosoftEntraIdAuthenticationEnforcement | REG_DWORD | 1 | 0 |
Policy elements
Inputs and configuration options exposed by this policy.
This policy has no additional user input fields.
Other policies in this category
Explore related policies at the same level.
- ComputerAlways prompt for password upon connectionAt least Windows Server 2003 operating systems or Windows XP Professional
- ComputerDisconnect remote session on lock for legacy authenticationWindows 11 22H2 SERVER
- ComputerDisconnect remote session on lock for Microsoft identity platform authenticationWindows 11 22H2 SERVER
- ComputerDo not allow local administrators to customize permissionsAt least Windows Server 2003
- ComputerRequire secure RPC communicationAt least Windows Server 2003
- ComputerRequire use of specific security layer for remote (RDP) connectionsAt least Windows Vista
- ComputerRequire user authentication for remote connections by using Network Level AuthenticationAt least Windows Vista
- ComputerServer authentication certificate templateAt least Windows Vista
- ComputerSet client connection encryption levelAt least Windows Server 2003 operating systems or Windows XP Professional