The New Lockdown: How Microsoft’s April 2026 Update Silos Remote Desktop to Kill Phishing
ID: 9d94c62d-1468-5e6b-934f-5e199ea5ac36
STIX ID: report--9d94c62d-1468-5e6b-934f-5e199ea5ac36
Feed Name: securityonline.info
Microsoft's April 2026 RDP update introduces a mandatory first-connection warning and a default isolation policy that restricts access to smart cards, Windows Hello for Business, WebAuthn, clipboards, cameras, printers, microphones, and plug-and-play or local network discovery devices. Users must explicitly authorize these permissions for unsigned RDP files each session, while digitally signed files can retain preferences and display publisher information; unsigned files show an amber warning. The changes aim to mitigate phishing campaigns that deploy malicious RDP servers to exfiltrate data from connecting devices.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
