Skip to content

Securing Remote PS

Securing Remoting Sessions

Implement robust encryption, authentication, and audit logging to protect remote session integrity and confidentiality.

Encryption Requirements

Enforce strong encryption protocols to secure data in transit:
- TLS 1.2+ Enforcement:

# Enable TLS 1.2 and disable older protocols  
[Net.ServicePointManager]::SecurityProtocol = [Net.SecurityProtocolType]::Tls12  
Ensure servers and clients use TLS 1.2 or higher and disable TLS 1.0/1.1.
- HTTPS Usage: Configure remoting endpoints (e.g., IIS, PowerShell remoting) to use HTTPS with valid SSL/TLS certificates.

Authentication Best Practices

Strengthen access control to prevent unauthorized session entry:
- Certificate-Based Authentication:

# Configure WinRM to require client certificates  
Set-ItemProperty -Path "HKLM:\SOFTWARE\Microsoft\Windows\CurrentVersion\WinRM\Client" -Name "EnableCredSSP" -Value 1  
Set-ItemProperty -Path "HKLM:\SOFTWARE\Microsoft\Windows\CurrentVersion\WinRM\Client" -Name "TrustedHosts" -Value "*"
Use client certificates for mutual TLS authentication and validate certificate chains.
- Multi-Factor Authentication (MFA): Integrate MFA via Azure AD, Microsoft Authenticator, or third-party solutions for administrative remoting.
- Session Timeouts:
# Set idle session timeout to 15 minutes  
Set-ItemProperty -Path "HKLM:\SOFTWARE\Microsoft\Windows\CurrentVersion\WinRM\Service" -Name "IdleTimeoutSec" -Value 900  
Enforce session termination after inactivity and disable Keep-Alive to prevent persistent connections.

Audit Logging

Enable detailed logging to track remote session activity and detect suspicious behavior.

Enable WinRM Logging

Configure WinRM to log requests and responses:

# Set log directory and level (0 = None, 4 = Full)  
Set-ItemProperty -Path "HKLM:\SOFTWARE\Microsoft\Windows\CurrentVersion\WinRM\Service" -Name "LogLevel" -Value 4  
Set-ItemProperty -Path "HKLM:\SOFTWARE\Microsoft\Windows\CurrentVersion\WinRM\Service" -Name "LogPath" -Value "C:\Windows\System32\LogFiles\WinRM"  
Ensure the log directory exists and has appropriate permissions.

Monitor Logs

Use Event Viewer to review security events:
- Event ID 4104: Successful WinRM connection.
- Event ID 4105: Failed authentication attempt.
- Event ID 4106: Successful authentication.
Regularly analyze logs for anomalies, such as repeated failed attempts or unexpected client IPs.