Azure虚拟机无法远程连接,遭遇CredSSP Encryption Oracle Remediation Error
Fixing CredSSP Encryption Oracle Remediation Error for Azure VM RDP
Hey there, sorry to hear you're stuck with this frustrating error when trying to remote into your Azure VM. Let's walk through the most practical fixes you can try right now—no paid support plan required!
First: Adjust Your Local Client Machine (the one you're using to connect)
This error usually pops up because your local machine's security settings block the older encryption methods the VM might be relying on. Here's how to fix that:
Option 1: Use Group Policy Editor (Pro/Enterprise Windows)
- Press
Win + R, typegpedit.mscand hit Enter to open the Group Policy Editor. - Navigate to: Computer Configuration > Administrative Templates > System > Credentials Delegation > Encryption Oracle Remediation
- Double-click the policy, set it to Enabled, then under "Protection Level" select Vulnerable (this is a temporary fix to get you connected—we can tighten security later).
- Click OK, then run
gpupdate /forcein Command Prompt to apply changes right away.
Option 2: Edit the Registry (Home Windows or Group Policy unavailable)
- Press
Win + R, typeregeditand hit Enter (you'll need admin privileges). - Navigate to:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\CredSSP\Parameters- If the
CredSSPorParameterskeys don't exist, right-click to create them first.
- If the
- Right-click in the right pane, select New > DWORD (32-bit) Value, name it
AllowEncryptionOracle. - Double-click the new value, set its data to
2(this matches the "Vulnerable" policy setting). - Close Registry Editor and restart your machine.
Second: Fix the Azure VM (use Azure Serial Console since you can't RDP in)
If adjusting the client doesn't work, you'll need to tweak the VM's settings directly via the Azure Portal:
- Log into the Azure Portal, find your VM, and go to Support + Troubleshooting > Serial Console (enable it if it's turned off—this is free!).
- Once connected, log into the VM using your local admin credentials.
- Follow the same steps as the client:
- Either open
gpedit.mscand set the Encryption Oracle Remediation policy to Enabled > Vulnerable. - Or edit the registry to add
AllowEncryptionOraclewith value2in the same path as above.
- Either open
- Run
gpupdate /forceor restart the VM via the Azure Portal to apply changes.
Important Post-Connection Steps
Once you're back into the VM, don't forget to:
- Install all pending Windows updates on both the client and VM—this brings encryption protocols up to date so you won't hit this error again.
- After updating, switch the Encryption Oracle Remediation protection level back to Mitigated or Enforce for better security (avoid leaving it on Vulnerable long-term).
内容的提问来源于stack exchange,提问作者May Zin Mg
相关产品推荐
相关产品推荐

