CredSSP encryption oracle remediation 🪟 Windows

Remote Desktop: An authentication error has occurred. The function requested is not supported. This could be due to CredSSP encryption oracle remediation

The RDP client and server disagree on CredSSP security updates — one side is patched and enforcing, the other isn’t.

Seen on: Windows

Meaning

After the CVE-2018-0886 updates, patched clients refuse to connect to unpatched servers (and vice versa depending on policy). The real fix is updating the server; a temporary client policy can relax it.

Common causes

  • Server missing CredSSP security updates
  • Client policy set to Force Updated Clients
  • NLA/CredSSP misconfiguration

⚡ Quick fix

  1. Install current Windows updates on the server
  2. Temporarily set Encryption Oracle Remediation to Vulnerable on the client (then revert)
  3. Use the console/Hyper-V/Azure serial console to patch the server

Detailed fix by platform

Windows

  1. reg add HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\CredSSP\Parameters /v AllowEncryptionOracle /t REG_DWORD /d 2 /f # temporary; revert after patching

How to diagnose

  1. Patches — Server patch level
  2. Policy — Encryption Oracle Remediation setting on both sides

🔧 Still not fixed?

Many errors look alike. If the steps above didn’t solve it, one of these is probably what you’re facing:

🧠 Still stuck? Analyze your error

Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.