Enable RDP to take remote of Intune managed devices, Firewall blocking the connection

Deleted
Not applicable

Hello Experts,
I need to enable RDP to take remote of Intune managed devices, could you please suggest the best solution through Intune, looks like the firewall
blocking the connection.

7 Replies

Hey !@Deleted

 

We have the same issue and we are working on it, if we find something, we'll share with you !

 

For now, here's the procedure we are trying :

https://www.prajwaldesai.com/disable-remote-desktop-access-using-intune/ "Do it for enable it"

https://www.reddit.com/r/Intune/comments/vy69k8/enable_remote_desktop/

 

Regards

Hi @Deleted 

 

Have you tried using Intune - EndPoint Security - Firewall - Create New Policy - Windows 11 - Microsoft Defender Firewall Rules

 

I have done the opposite recently (Locking Outbound Ports on Browsers), it worked like a treat. 

 

Hope this helps!

Moe

 

 

I'm working with a customer to enable RDP on some AAD joined, Intune managed devices in the company. This is the configuration I'm testing at the moment:

 

- Enable RDP on device: Configuration Profile, Administrative template:

Allow users to connect remotely by using Remote Desktop Services - Enabled
Require user authentication for remote connections by using Network Level Authentication - Disabled

 

- Allow RDP/3389 through Windows Firewall: Device Configuration Profiles - Endpoint protection

Firewall rules - Allow TCP/3389

 

- Add users in local "Remote Desktop Users" group:

Endpoint security - Account protection - Local user group membership. Add users (not AAD groups) in "Remote Desktop Users" group.

 

There is a couple of drawback from this configuration. 

- Managment - I dont want this configuration to all Windows clients in the company. An AAD groups with devices must be maintained.

- I my testing, adding AAD group in the Endpoint security - Account protection - Local user group membership policy is not working, only users can be added.

- All users added in the policy "Local user group membership", are added in the local group "Remote Desktop Users" on all devices assigned to this policy.

@Moe_Kinani Could you please elaborate more on this/ if possible share all screenshots 

Hi @Deleted 

 

I was suggesting using the new Firewall Rules in Endpoint Security, located here.  Create New Profile Windows 10/11 - Microsoft Defender Firewall Rule - Edit Rule - Then Apply the Settings below and test. 

 

How did you confirm the issue from Windows firewall? Are your devices Azure AD Joined? Have you enabled the remote setting setting under Setting - System - Remote Desktop? I was prompted to enter creds without firewall policy as soon as I enabled the setting. You may need that setting only.

 

It will be great if you send us screenshot of the error you seeing.

 

Moe

 

https://learn.microsoft.com/en-us/windows/security/threat-protection/windows-firewall/create-windows-firewall-rules-in-intune

@Deleted 

 

I would suggest the following:

 

- Check the Firewall Rules in Intune. Particularly if you have any Security / Defender Baseline policies set. There is a setting called Policy rules from group policy not merged which I set to 'Not Configured' for the Private Firewall Profile

 

- Use the Scripts policy tool (or just do it manually) in Intune to deploy the following settings (PowerShell)

Set-NetFirewallRule -DisplayName "Remote Desktop - User Mode (TCP-In)" -Profile "Private"
Enable-NetFirewallRule -DisplayName "Remote Desktop - User Mode (TCP-In)"

 

- Check your network adaptor is using the Private Network Profile Type. (Settings > Network & Internet - Properties)

 

- Within Intune, create a Configuration Profile and enable the following settings: 

- Allow users to connect remotely by using Remote Desktop Services

- Require user authentication for remote connections by using Network Level Authentication

In the Windows 11 settings (System > Remote Desktop) it will show RDC as being OFF, but within The RDC options found in Control Panel, it will be turned on. Who knows what's going on here?

 

I believe that setting the Policy rules from group policy not merged to 'Not Configured' does open some doors in terms of security but I've had no luck using Intune FW rules.

 

I'd be interested if anyone has been able to do this recently with all the security baselines enabled.