To disable RDP drive redirection, you enable the “Do not allow drive redirection” Group Policy setting on the computer that accepts Remote Desktop connections, so local disks from the user’s device no longer appear inside the session. The same policy node controls clipboard, ports, Plug and Play devices, smart cards and cameras, and a sibling node controls printers. This guide covers the session host GPO, client-side values, RDS collection properties and Intune, with an exception for the IT team and a clear rollback.
Short answer: Link a GPO to the OU that holds your RDS hosts or servers and enable Computer Configuration » Policies » Administrative Templates » Windows Components » Remote Desktop Services » Remote Desktop Session Host » Device and Resource Redirection » "Do not allow drive redirection". Run gpupdate /force on the host, then sign out of any open session and connect again: drives such as C on LAPTOP01 no longer show in File Explorer, and copying files through the clipboard stops as well.
Table of Contents
Which method to use
Redirection is decided by several layers. Microsoft’s rule is simple: the most restrictive setting wins wherever it is configured. If the host blocks drives, no client or .rdp file can turn them back on.
| Method | Where it applies | Best for | Limits |
|---|---|---|---|
| Session host GPO | The server or PC that receives connections | Domain RDS farms, jump hosts, file servers | Needs a new session to take effect |
| Client-side registry values | The device running the Remote Desktop client (mstsc.exe) | Stopping managed laptops from sharing drives with third-party servers | Does not protect the host from unmanaged clients |
| RDS collection properties | All hosts in a session collection | RDS deployments managed from Server Manager | Only for brokered connections |
| Intune settings catalog | Cloud-managed Windows 11 hosts and clients | Entra-joined PCs, Azure Virtual Desktop session hosts | No servers outside Intune; one client setting does not work through Intune |
| Local Group Policy | One standalone machine | Workgroup servers, labs | No central reporting |
For a domain, the reliable way to disable RDP drive redirection is host-side Group Policy, with client-side values or collection properties as extra layers.
Prerequisites
- Session hosts running Windows Server 2016 to 2025, or Windows 11 Pro, Enterprise or Education for single-session RDP.
- Rights to create and link GPOs, and the Group Policy Management Console (
gpmc.msc). - Current ADMX files in the Central Store. The clipboard transfer restriction settings are included in Windows 11 24H2 and Windows Server 2025; Windows 11 22H2/23H2 needs the June 2024 cumulative update and Windows Server 2022 the July 2024 update.
- A test user, a test host and a client with a USB drive and a local printer.
Method 1: Session host Group Policy
This is the main way to disable RDP drive redirection for everyone who connects to a host. The settings are computer-side, so link the GPO to the OU that holds the host computer objects, not the users.
Steps
- In Group Policy Management, right-click the OU with your RDS or server computer objects and choose Create a GPO in this domain, and Link it here. Name it, for example, SEC – RDP Redirection.
- Edit the GPO and go to
Computer Configuration » Policies » Administrative Templates » Windows Components » Remote Desktop Services » Remote Desktop Session Host » Device and Resource Redirection. - Open “Do not allow drive redirection”, set it to Enabled and click OK. This single setting is enough to disable RDP drive redirection on every host in the OU.
- Enable any other redirection you want to block from the table below.
- For printers, go one level up to
Remote Desktop Session Host » Printer Redirectionand enable “Do not allow client printer redirection”. - Run
gpupdate /forceon a host, sign out of the test session completely and connect again.
Redirection settings and registry values
All values below are REG_DWORD values under HKLM\SOFTWARE\Policies\Microsoft\Windows NT\Terminal Services.
| Policy setting | To block, set | Registry value |
|---|---|---|
| “Do not allow drive redirection” | Enabled | fDisableCdm = 1 |
| “Do not allow Clipboard redirection” | Enabled | fDisableClip = 1 |
| “Do not allow COM port redirection” | Enabled | fDisableCcm = 1 |
| “Do not allow LPT port redirection” | Enabled | fDisableLPT = 1 |
| “Do not allow supported Plug and Play device redirection” | Enabled | fDisablePNPRedir = 1 |
| “Do not allow smart card device redirection” | Enabled | see note below |
| “Do not allow video capture redirection” | Enabled | fDisableCameraRedir = 1 |
| “Allow audio recording redirection” | Disabled | fDisableAudioCapture = 1 |
| “Do not allow WebAuthn redirection” | Enabled | fDisableWebAuthn = 1 |
| “Do not allow client printer redirection” (Printer Redirection node) | Enabled | fDisableCpm = 1 |
Be careful with smart cards. If users sign in to the session with a smart card or Windows Hello for Business certificate, or use a card inside the session, blocking smart card redirection breaks that sign-in. Block it only on hosts where cards are not used. WebAuthn redirection is what passes Windows Hello and security keys into browser sign-ins in the session; block it only if you have another sign-in method.
What drive redirection covers
When you disable RDP drive redirection with this setting, Windows blocks every client drive: fixed disks, USB flash drives, DVD drives and drives connected during the session. Microsoft notes that it also blocks copying files through the clipboard, even if clipboard redirection stays enabled. Copying text and images still works unless you restrict the clipboard too. The \\tsclient path inside the session stops working as well.
Allow clipboard text but not files
Users often need to paste a server name or a command, but should not move files. Two newer settings under the same node give you that control:
- “Restrict clipboard transfer from server to client” (registry value
SCClipLevel) - “Restrict clipboard transfer from client to server” (registry value
CSClipLevel)
Each offers five levels: disable transfers in that direction, allow plain text, allow plain text and images, add Rich Text Format, or add HTML. A common data-loss setup is:
- “Do not allow drive redirection”: Enabled (stops files).
- “Do not allow Clipboard redirection”: Not Configured or Disabled.
- “Restrict clipboard transfer from server to client”: Enabled, level Disable clipboard transfers from server to client, so nothing copied inside the session reaches the user’s device.
- “Restrict clipboard transfer from client to server”: Enabled, level Allow plain text.
Both restriction settings also exist under User Configuration. If both are set, the more restrictive level applies.
Method 2: Client-side controls
Host settings protect your servers. To disable RDP drive redirection from the other end, client-side values protect your managed laptops when staff connect to servers you do not control, such as a vendor’s support host. These REG_DWORD values live under HKLM\Software\Microsoft\Terminal Server Client on the client device:
| Value | Data | Effect |
|---|---|---|
DisableDriveRedirection | 1 | The client never shares local drives |
DisableClipboardRedirection | 1 | The client never shares the clipboard |
DisablePrinterRedirection | 1 | The client never shares local printers |
Deploy them with Group Policy Preferences:
- In a GPO linked to the workstation OU, go to
Computer Configuration » Preferences » Windows Settings » Registryand choose New » Registry Item. - Set Action to Update, Hive to HKEY_LOCAL_MACHINE, Key Path to
Software\Microsoft\Terminal Server Client, Value name toDisableDriveRedirection, type REG_DWORD and data1. - Repeat for the other values you need. On the Common tab, tick “Remove this item when it is no longer applied” so the value disappears when the GPO goes out of scope.
For one machine, the same result from an elevated prompt:
reg add "HKLM\Software\Microsoft\Terminal Server Client" /v DisableDriveRedirection /t REG_DWORD /d 1 /f
reg add "HKLM\Software\Microsoft\Terminal Server Client" /v DisableClipboardRedirection /t REG_DWORD /d 1 /f
Also consider Computer Configuration » Policies » Administrative Templates » Windows Components » Remote Desktop Services » Remote Desktop Connection Client » "Do not allow passwords to be saved" on the same devices.
Method 3: RDS collection properties
In an RDS deployment, each session collection has its own redirection settings, which the Connection Broker writes into the connection it hands to the client.
- Open Server Manager » Remote Desktop Services » Collections, select the collection, then Tasks » Edit Properties.
- On Client Settings, clear Drives, Clipboard, Plug and play devices, Smart cards or Windows printer as needed and click OK.
The same with PowerShell on the Connection Broker. The command keeps only audio playback and blocks all other device types:
Set-RDSessionCollectionConfiguration -CollectionName "Office Apps" `
-ClientDeviceRedirectionOptions AudioVideoPlayBack `
-ClientPrinterRedirected $false `
-ConnectionBroker rdcb01.contoso.com
Get-RDSessionCollectionConfiguration -CollectionName "Office Apps" -Client
-ClientDeviceRedirectionOptions accepts None, AudioVideoPlayBack, AudioRecording, COMPort, PlugAndPlayDevice, SmartCard, Clipboard, LPTPort, Drive and TimeZone; list the ones you want to allow, separated by commas. Leaving Drive out is how you disable RDP drive redirection at collection level. Keep the host GPO as well: collection settings only cover brokered connections, while the GPO also covers a direct connection to a host name.
Method 4: Intune settings catalog
For Entra-joined Windows 11 machines that accept RDP, and for Azure Virtual Desktop session hosts:
- In the Intune admin center, go to Devices » Configuration » Create » New policy, platform Windows 10 and later, profile type Settings catalog.
- Click Add settings and browse to Administrative templates » Windows Components » Remote Desktop Services » Remote Desktop Session Host » Device and Resource Redirection.
- Select Do not allow drive redirection, Do not allow Clipboard redirection, Do not allow supported Plug and Play device redirection or Do not allow smart card device redirection and toggle each to Enabled. Printers are under Remote Desktop Session Host » Printer Redirection.
- The clipboard restriction settings appear twice: device scope and a (User) version. Use the device version unless you target users.
- Assign the profile to a device group containing the hosts, and restart or reconnect to test.
The drive setting maps to the Policy CSP node ./Device/Vendor/MSFT/Policy/Config/RemoteDesktopServices/DoNotAllowDriveRedirection. In Azure Virtual Desktop, also set the host pool RDP property drivestoredirect:s: with an empty value, which is the default.
USB and Plug and Play redirection
RDP redirects most devices at a high level: drives appear as C on DEVICE, printers use Easy Print, and phones and cameras that use MTP or PTP are passed as supported Plug and Play devices, and webcams use video capture redirection. Opaque low-level USB redirection (RemoteFX USB) sends the raw USB device into the session instead, and is used for devices that have no high-level channel.
- On the host, “Do not allow supported Plug and Play device redirection” set to Enabled blocks both MTP/PTP devices and RemoteFX USB redirection.
- On the client, RemoteFX USB redirection is off unless you enable
Computer Configuration » Policies » Administrative Templates » Windows Components » Remote Desktop Services » Remote Desktop Connection Client » RemoteFX USB Device Redirection » "Allow RDP redirection of other supported RemoteFX USB devices from this computer"and restart the client. Microsoft states that this client setting does not currently work as expected through Intune, so use Group Policy for it.
A USB flash drive is redirected as a drive, so drive redirection controls it. Do not rely on USB storage policies on the client to stop it; see our USB storage guide for local blocks.
Exceptions for IT and admin hosts
A GPO that you use to disable RDP drive redirection has no per-user exception because the settings are computer-side. Plan exceptions per host:
- Put admin jump hosts in their own OU with a separate, less restrictive GPO, or exclude them from the main GPO with security filtering.
- For security filtering, create a group such as SEC-RDP-Redirection-Exempt and add the computer accounts of the exempt hosts.
- In GPMC, open the GPO’s Delegation tab, click Advanced, add the group and tick Deny for Apply group policy. Keep Read allowed.
- Restart the exempt hosts so they pick up their new group membership.
On RDS, a cleaner option is a second session collection for IT with its own client settings, published only to the IT group. If you need per-user clipboard levels on a shared host, use the (User) clipboard restriction settings in User Configuration together with loopback processing on the host OU.
Verify it works
- Confirm the GPO you use to disable RDP drive redirection applies to the host:
gpupdate /force
gpresult /scope computer /r
reg query "HKLM\SOFTWARE\Policies\Microsoft\Windows NT\Terminal Services"
The GPO must be listed under Applied Group Policy Objects, and values such asfDisableCdm,fDisableClipandfDisableCpmmust show0x1. - Sign out of the test session (do not just disconnect), then connect with Local Resources » More set to share all drives. In the session, File Explorer » This PC must not list C on CLIENTNAME, and
dir \\tsclient\Cmust fail. - Copy a file on the client and paste it in the session: the paste must fail. Copy a line of text and check it behaves as your clipboard levels say.
- Print from the session: only server-side printers should be listed if printer redirection is blocked.
- On RDS, run
Get-RDSessionCollectionConfiguration -CollectionName "Office Apps" -Clientand checkClientDeviceRedirectionOptions.
Troubleshooting
| Symptom | Likely cause | Fix |
|---|---|---|
Drives still appear after gpupdate | User reconnected to an existing session | Sign the user out; redirection is set when the session is created |
| Registry value missing on host | GPO linked to the user OU, or filtered out | Link to the host OU; check gpresult /scope computer /r |
| Text paste blocked as well as files | “Do not allow Clipboard redirection” enabled | Set it to Not Configured and use the clipboard restriction levels |
| Clipboard restriction settings missing in the editor | Old ADMX files in the Central Store | Update PolicyDefinitions from a Windows 11 24H2 or Server 2025 machine |
| Smart card sign-in fails in the session | Smart card redirection blocked | Set “Do not allow smart card device redirection” to Not Configured on that host |
| USB device still works in session | Redirected as a drive or camera, not as USB | Block drive and video capture redirection as well as Plug and Play |
| Collection allows drives but they are blocked | Host GPO is more restrictive | Expected: the most restrictive setting wins |
If the GPO does not appear at all, check replication, security filtering and events 1058 and 1030 on the host.
Roll back or undo
- Host GPO: set each setting back to Not Configured (or unlink the GPO) and run
gpupdate /force. Values underSOFTWARE\Policiesare removed on the next refresh; users get redirection back at their next new session. - Client values: if you ticked “Remove this item when it is no longer applied”, unlinking removes them. Otherwise run
reg delete "HKLM\Software\Microsoft\Terminal Server Client" /v DisableDriveRedirection /f. - RDS collection: run
Set-RDSessionCollectionConfigurationagain with the options you want, or tick the boxes in Client Settings. - Intune: unassign the profile, or set the settings to Disabled to allow redirection explicitly.
Test any change to disable RDP drive redirection on one host first, tell users that file transfer will move to an approved share, and document the exempt admin hosts.
Disable RDP drive redirection at a glance

Official documentation: Configure fixed, removable, and network drive redirection, RemoteDesktopServices Policy CSP, Configure the clipboard transfer direction and types of data.
Related guides: Block USB Storage Group Policy and Intune: Secure Setup · Deploy an RDS farm on Windows Server 2025 · Group Policy loopback processing: merge vs replace for RDS hosts and kiosks.
Frequently asked questions
Does disabling RDP drive redirection also stop copying files through the clipboard?
Yes. When “Do not allow drive redirection” is enabled on the session host, Windows also blocks clipboard file copy, even if clipboard redirection is allowed. Text and images can still be pasted unless you restrict the clipboard too.
Should I configure redirection on the server or on the client?
Configure the session host first, because it protects the server from every client. Client-side values under HKLM\Software\Microsoft\Terminal Server Client are an extra layer that stops managed devices from sharing drives with servers you do not control.
Why do users still see their drives after I changed the policy?
Redirection is set when a session is created. A user who only disconnected and reconnected keeps the old session, so sign them out and let them connect again.
Can I allow text in the clipboard but block files?
Yes. Block drive redirection, leave clipboard redirection allowed and use “Restrict clipboard transfer from server to client” and “Restrict clipboard transfer from client to server” with the plain text level. These need Windows 11 24H2 or Windows Server 2025, or the mid-2024 cumulative updates on older builds.
Do RDS collection settings override Group Policy?
No. The most restrictive setting wins wherever it is configured. If the host GPO blocks drives, enabling drives in the collection properties has no effect.