Start Free Trial

Free Trial is currently available for our Business Plans.
Please choose an option that meets your trial needs below

SecureRDP Icon

SecureRDP Business

$15 per user per month

Starts at 20 Users / unlimited computers

No credit card required

SecureRDP Icon

BitLocker Business

$2.22
per computer per month

Minimum 20 Computers

No credit card required

Compare all plans & features on the Pricing page

Network Level Authentication (NLA)

Network Level Authentication (NLA) is the RDP feature that forces a user to authenticate before a remote desktop session ever gets established. Without it, any connection reaches the Windows logon screen first, consuming a session and handing the logon surface to anyone who can connect at all. With NLA, authentication happens up front via CredSSP, and an unauthenticated connection cannot proceed to normal session establishment.

NLA authenticates the connecting identity at the gate, before the session is ever allowed to reach the host.

What NLA changes

Pre-NLA RDP handed out real session resources to every connection attempt, authenticated or not, which was both a denial-of-service problem and an attack-surface problem at the same time. NLA moves authentication down to the network layer instead. The CredSSP exchange completes inside a TLS channel before any session gets created, so a failed logon costs the server almost nothing and the graphical logon screen never shows itself to a stranger. NLA can mitigate vulnerabilities that require an unauthenticated RDP session, although it is not a substitute for patching.

NLA and CredSSP

NLA is the policy; CredSSP is the machinery. The client collects credentials locally, CredSSP authenticates and delegates them over TLS, and only a successful outcome triggers session setup. This coupling is why CredSSP patch mismatches (the encryption-oracle error) surface as NLA connection failures.

NLA's limits

NLA provides Windows credential authentication; it is not, by itself, a substitute for MFA. It will not stop an attacker who already has a valid password, will not hide the listener from a scanner, and will not limit what an authenticated user can reach once inside. It is table stakes, enabled by default on modern Windows, and it should stay enforced everywhere without exception. Everything it does not cover, meaning MFA, exposure, and least privilege, is the rest of RDP security →

FAQs

Should NLA be enabled?

Yes. NLA should remain enabled whenever possible. Disabling it should generally be limited to temporary troubleshooting or compatibility scenarios.

Does NLA support MFA?

Not on its own. NLA only authenticates Windows credentials. MFA gets enforced in front of the session separately, by a broker, gateway, or identity platform.

Why does NLA block a connection after password reset?

Expired or must-change passwords cannot complete CredSSP pre-auth in some configurations; resetting via another path resolves it.

Where TruGrid fits. TruGrid SecureRDP keeps NLA enforced and adds the one factor NLA was never going to give you: MFA before every session, with no exposed listener sitting behind it. Explore SecureRDP →

Put the concepts to work.

TruGrid SecureRDP delivers Zero Trust remote desktop access: MFA, least privilege, and zero open inbound ports.

Explore SecureRDP →