RDS: Do Not Allow COM Port Redirection- The Policy Expert

By Keren Pollack, on January 13th, 2020

COM port is the name of the serial port interface on IBM PC-compatible computers. It can refer not only to physical ports but also to emulated ports, such as ports created by Bluetooth or USB-to-serial adapters.


Server hardening can be a painful procedure. If you’re reading this article, you probably already know it. Endless hours, labor and money are invested in this process, which can often result in production breakdown despite the effort to prevent it. CSH by CalCom is automating the entire server hardening process. CHS’s unique ability to ‘learn’ your network abolishes the need to perform lab testing while ensuring zero outages to your production environment. CHS will allow you to implement your policy directly on your production hassle-free. want to know more? Click here and get the datasheet. 


This blog post will demonstrate:

  1. COM port redirection policy description.
  2. COM port potential vulnerability.
  3. How to mitigate COM port vulnerability.
  4. The potential impact of changing this setting on your production.
  5. COM port redirection recommended value.
  6. How to change COM port settings. 



This policy setting will determine whether the redirection of data to client COM ports from the remote computer will be allowed in the RDS session. By default, RDS allows COM port redirection. It can be used, for example, to use a USB dongle in an RDS session.



When not enabled, users can redirect data to COM port peripherals or map the local COM ports while using the Remote Desktop Service session.

How to Secure Remote Desktop – The Complete Guide


Enable this object wherever’s possible.

If the status is set to Disabled, Remote Desktop Services always allows COM port redirection. If the status is set to Not Configured, COM port redirection is not specified at the Group Policy level. However, an administrator can still disable COM port redirection using the Remote Desktop Session Host Configuration tool.



RDS users won’t be able to access a client’s COM port peripherals such as USB dongles and Bluetooth.





RDS: Require user authentication for remote connections by using Network Level Authentication (NLA)- The policy expert


1. Press Windows Logo+R, type gpedit.msc, and press Enter.


2. Click the arrow next to Computer Configuration under Local Computer Policy to expand it.


3. Click the arrow next to Administrative Templates to expand it.


4. Click All Settings to show all group policy settings.


5. Scroll down to Do not allow COM port redirection and double-click on it to view the setting.


6. Ensure the policy isn’t Disabled and click OK. (Enabled must be selected).