Emergency server help: get in touch

Disable RDP Drive Redirection with GPO: Clipboard, Printers, USB and Smart Cards

Block drive, clipboard, printer, USB and smart card redirection in Remote Desktop sessions on Windows Server 2025 and Windows 11 with session host Group Policy, client-side registry values, RDS collection properties and Intune, and keep an exception for IT.

Published Updated 14 min read

To disable RDP drive redirection, you enable the “Do not allow drive redirection” Group Policy setting on the computer that accepts Remote Desktop connections, so local disks from the user’s device no longer appear inside the session. The same policy node controls clipboard, ports, Plug and Play devices, smart cards and cameras, and a sibling node controls printers. This guide covers the session host GPO, client-side values, RDS collection properties and Intune, with an exception for the IT team and a clear rollback.

Short answer: Link a GPO to the OU that holds your RDS hosts or servers and enable Computer Configuration » Policies » Administrative Templates » Windows Components » Remote Desktop Services » Remote Desktop Session Host » Device and Resource Redirection » "Do not allow drive redirection". Run gpupdate /force on the host, then sign out of any open session and connect again: drives such as C on LAPTOP01 no longer show in File Explorer, and copying files through the clipboard stops as well.

Which method to use

Redirection is decided by several layers. Microsoft’s rule is simple: the most restrictive setting wins wherever it is configured. If the host blocks drives, no client or .rdp file can turn them back on.

MethodWhere it appliesBest forLimits
Session host GPOThe server or PC that receives connectionsDomain RDS farms, jump hosts, file serversNeeds a new session to take effect
Client-side registry valuesThe device running the Remote Desktop client (mstsc.exe)Stopping managed laptops from sharing drives with third-party serversDoes not protect the host from unmanaged clients
RDS collection propertiesAll hosts in a session collectionRDS deployments managed from Server ManagerOnly for brokered connections
Intune settings catalogCloud-managed Windows 11 hosts and clientsEntra-joined PCs, Azure Virtual Desktop session hostsNo servers outside Intune; one client setting does not work through Intune
Local Group PolicyOne standalone machineWorkgroup servers, labsNo central reporting

For a domain, the reliable way to disable RDP drive redirection is host-side Group Policy, with client-side values or collection properties as extra layers.

Prerequisites

  • Session hosts running Windows Server 2016 to 2025, or Windows 11 Pro, Enterprise or Education for single-session RDP.
  • Rights to create and link GPOs, and the Group Policy Management Console (gpmc.msc).
  • Current ADMX files in the Central Store. The clipboard transfer restriction settings are included in Windows 11 24H2 and Windows Server 2025; Windows 11 22H2/23H2 needs the June 2024 cumulative update and Windows Server 2022 the July 2024 update.
  • A test user, a test host and a client with a USB drive and a local printer.

Method 1: Session host Group Policy

This is the main way to disable RDP drive redirection for everyone who connects to a host. The settings are computer-side, so link the GPO to the OU that holds the host computer objects, not the users.

Steps

  1. In Group Policy Management, right-click the OU with your RDS or server computer objects and choose Create a GPO in this domain, and Link it here. Name it, for example, SEC – RDP Redirection.
  2. Edit the GPO and go to Computer Configuration » Policies » Administrative Templates » Windows Components » Remote Desktop Services » Remote Desktop Session Host » Device and Resource Redirection.
  3. Open “Do not allow drive redirection”, set it to Enabled and click OK. This single setting is enough to disable RDP drive redirection on every host in the OU.
  4. Enable any other redirection you want to block from the table below.
  5. For printers, go one level up to Remote Desktop Session Host » Printer Redirection and enable “Do not allow client printer redirection”.
  6. Run gpupdate /force on a host, sign out of the test session completely and connect again.

Redirection settings and registry values

All values below are REG_DWORD values under HKLM\SOFTWARE\Policies\Microsoft\Windows NT\Terminal Services.

Policy settingTo block, setRegistry value
“Do not allow drive redirection”EnabledfDisableCdm = 1
“Do not allow Clipboard redirection”EnabledfDisableClip = 1
“Do not allow COM port redirection”EnabledfDisableCcm = 1
“Do not allow LPT port redirection”EnabledfDisableLPT = 1
“Do not allow supported Plug and Play device redirection”EnabledfDisablePNPRedir = 1
“Do not allow smart card device redirection”Enabledsee note below
“Do not allow video capture redirection”EnabledfDisableCameraRedir = 1
“Allow audio recording redirection”DisabledfDisableAudioCapture = 1
“Do not allow WebAuthn redirection”EnabledfDisableWebAuthn = 1
“Do not allow client printer redirection” (Printer Redirection node)EnabledfDisableCpm = 1

Be careful with smart cards. If users sign in to the session with a smart card or Windows Hello for Business certificate, or use a card inside the session, blocking smart card redirection breaks that sign-in. Block it only on hosts where cards are not used. WebAuthn redirection is what passes Windows Hello and security keys into browser sign-ins in the session; block it only if you have another sign-in method.

What drive redirection covers

When you disable RDP drive redirection with this setting, Windows blocks every client drive: fixed disks, USB flash drives, DVD drives and drives connected during the session. Microsoft notes that it also blocks copying files through the clipboard, even if clipboard redirection stays enabled. Copying text and images still works unless you restrict the clipboard too. The \\tsclient path inside the session stops working as well.

Allow clipboard text but not files

Users often need to paste a server name or a command, but should not move files. Two newer settings under the same node give you that control:

  • “Restrict clipboard transfer from server to client” (registry value SCClipLevel)
  • “Restrict clipboard transfer from client to server” (registry value CSClipLevel)

Each offers five levels: disable transfers in that direction, allow plain text, allow plain text and images, add Rich Text Format, or add HTML. A common data-loss setup is:

  1. “Do not allow drive redirection”: Enabled (stops files).
  2. “Do not allow Clipboard redirection”: Not Configured or Disabled.
  3. “Restrict clipboard transfer from server to client”: Enabled, level Disable clipboard transfers from server to client, so nothing copied inside the session reaches the user’s device.
  4. “Restrict clipboard transfer from client to server”: Enabled, level Allow plain text.

Both restriction settings also exist under User Configuration. If both are set, the more restrictive level applies.

Method 2: Client-side controls

Host settings protect your servers. To disable RDP drive redirection from the other end, client-side values protect your managed laptops when staff connect to servers you do not control, such as a vendor’s support host. These REG_DWORD values live under HKLM\Software\Microsoft\Terminal Server Client on the client device:

ValueDataEffect
DisableDriveRedirection1The client never shares local drives
DisableClipboardRedirection1The client never shares the clipboard
DisablePrinterRedirection1The client never shares local printers

Deploy them with Group Policy Preferences:

  1. In a GPO linked to the workstation OU, go to Computer Configuration » Preferences » Windows Settings » Registry and choose New » Registry Item.
  2. Set Action to Update, Hive to HKEY_LOCAL_MACHINE, Key Path to Software\Microsoft\Terminal Server Client, Value name to DisableDriveRedirection, type REG_DWORD and data 1.
  3. Repeat for the other values you need. On the Common tab, tick “Remove this item when it is no longer applied” so the value disappears when the GPO goes out of scope.

For one machine, the same result from an elevated prompt:

reg add "HKLM\Software\Microsoft\Terminal Server Client" /v DisableDriveRedirection /t REG_DWORD /d 1 /f
reg add "HKLM\Software\Microsoft\Terminal Server Client" /v DisableClipboardRedirection /t REG_DWORD /d 1 /f

Also consider Computer Configuration » Policies » Administrative Templates » Windows Components » Remote Desktop Services » Remote Desktop Connection Client » "Do not allow passwords to be saved" on the same devices.

Method 3: RDS collection properties

In an RDS deployment, each session collection has its own redirection settings, which the Connection Broker writes into the connection it hands to the client.

  1. Open Server Manager » Remote Desktop Services » Collections, select the collection, then Tasks » Edit Properties.
  2. On Client Settings, clear Drives, Clipboard, Plug and play devices, Smart cards or Windows printer as needed and click OK.

The same with PowerShell on the Connection Broker. The command keeps only audio playback and blocks all other device types:

Set-RDSessionCollectionConfiguration -CollectionName "Office Apps" `
  -ClientDeviceRedirectionOptions AudioVideoPlayBack `
  -ClientPrinterRedirected $false `
  -ConnectionBroker rdcb01.contoso.com
Get-RDSessionCollectionConfiguration -CollectionName "Office Apps" -Client

-ClientDeviceRedirectionOptions accepts None, AudioVideoPlayBack, AudioRecording, COMPort, PlugAndPlayDevice, SmartCard, Clipboard, LPTPort, Drive and TimeZone; list the ones you want to allow, separated by commas. Leaving Drive out is how you disable RDP drive redirection at collection level. Keep the host GPO as well: collection settings only cover brokered connections, while the GPO also covers a direct connection to a host name.

Method 4: Intune settings catalog

For Entra-joined Windows 11 machines that accept RDP, and for Azure Virtual Desktop session hosts:

  1. In the Intune admin center, go to Devices » Configuration » Create » New policy, platform Windows 10 and later, profile type Settings catalog.
  2. Click Add settings and browse to Administrative templates » Windows Components » Remote Desktop Services » Remote Desktop Session Host » Device and Resource Redirection.
  3. Select Do not allow drive redirection, Do not allow Clipboard redirection, Do not allow supported Plug and Play device redirection or Do not allow smart card device redirection and toggle each to Enabled. Printers are under Remote Desktop Session Host » Printer Redirection.
  4. The clipboard restriction settings appear twice: device scope and a (User) version. Use the device version unless you target users.
  5. Assign the profile to a device group containing the hosts, and restart or reconnect to test.

The drive setting maps to the Policy CSP node ./Device/Vendor/MSFT/Policy/Config/RemoteDesktopServices/DoNotAllowDriveRedirection. In Azure Virtual Desktop, also set the host pool RDP property drivestoredirect:s: with an empty value, which is the default.

USB and Plug and Play redirection

RDP redirects most devices at a high level: drives appear as C on DEVICE, printers use Easy Print, and phones and cameras that use MTP or PTP are passed as supported Plug and Play devices, and webcams use video capture redirection. Opaque low-level USB redirection (RemoteFX USB) sends the raw USB device into the session instead, and is used for devices that have no high-level channel.

  • On the host, “Do not allow supported Plug and Play device redirection” set to Enabled blocks both MTP/PTP devices and RemoteFX USB redirection.
  • On the client, RemoteFX USB redirection is off unless you enable Computer Configuration » Policies » Administrative Templates » Windows Components » Remote Desktop Services » Remote Desktop Connection Client » RemoteFX USB Device Redirection » "Allow RDP redirection of other supported RemoteFX USB devices from this computer" and restart the client. Microsoft states that this client setting does not currently work as expected through Intune, so use Group Policy for it.

A USB flash drive is redirected as a drive, so drive redirection controls it. Do not rely on USB storage policies on the client to stop it; see our USB storage guide for local blocks.

Exceptions for IT and admin hosts

A GPO that you use to disable RDP drive redirection has no per-user exception because the settings are computer-side. Plan exceptions per host:

  1. Put admin jump hosts in their own OU with a separate, less restrictive GPO, or exclude them from the main GPO with security filtering.
  2. For security filtering, create a group such as SEC-RDP-Redirection-Exempt and add the computer accounts of the exempt hosts.
  3. In GPMC, open the GPO’s Delegation tab, click Advanced, add the group and tick Deny for Apply group policy. Keep Read allowed.
  4. Restart the exempt hosts so they pick up their new group membership.

On RDS, a cleaner option is a second session collection for IT with its own client settings, published only to the IT group. If you need per-user clipboard levels on a shared host, use the (User) clipboard restriction settings in User Configuration together with loopback processing on the host OU.

Verify it works

  1. Confirm the GPO you use to disable RDP drive redirection applies to the host:
    gpupdate /force
    gpresult /scope computer /r
    reg query "HKLM\SOFTWARE\Policies\Microsoft\Windows NT\Terminal Services"

    The GPO must be listed under Applied Group Policy Objects, and values such as fDisableCdm, fDisableClip and fDisableCpm must show 0x1.
  2. Sign out of the test session (do not just disconnect), then connect with Local Resources » More set to share all drives. In the session, File Explorer » This PC must not list C on CLIENTNAME, and dir \\tsclient\C must fail.
  3. Copy a file on the client and paste it in the session: the paste must fail. Copy a line of text and check it behaves as your clipboard levels say.
  4. Print from the session: only server-side printers should be listed if printer redirection is blocked.
  5. On RDS, run Get-RDSessionCollectionConfiguration -CollectionName "Office Apps" -Client and check ClientDeviceRedirectionOptions.

Troubleshooting

SymptomLikely causeFix
Drives still appear after gpupdateUser reconnected to an existing sessionSign the user out; redirection is set when the session is created
Registry value missing on hostGPO linked to the user OU, or filtered outLink to the host OU; check gpresult /scope computer /r
Text paste blocked as well as files“Do not allow Clipboard redirection” enabledSet it to Not Configured and use the clipboard restriction levels
Clipboard restriction settings missing in the editorOld ADMX files in the Central StoreUpdate PolicyDefinitions from a Windows 11 24H2 or Server 2025 machine
Smart card sign-in fails in the sessionSmart card redirection blockedSet “Do not allow smart card device redirection” to Not Configured on that host
USB device still works in sessionRedirected as a drive or camera, not as USBBlock drive and video capture redirection as well as Plug and Play
Collection allows drives but they are blockedHost GPO is more restrictiveExpected: the most restrictive setting wins

If the GPO does not appear at all, check replication, security filtering and events 1058 and 1030 on the host.

Roll back or undo

  1. Host GPO: set each setting back to Not Configured (or unlink the GPO) and run gpupdate /force. Values under SOFTWARE\Policies are removed on the next refresh; users get redirection back at their next new session.
  2. Client values: if you ticked “Remove this item when it is no longer applied”, unlinking removes them. Otherwise run reg delete "HKLM\Software\Microsoft\Terminal Server Client" /v DisableDriveRedirection /f.
  3. RDS collection: run Set-RDSessionCollectionConfiguration again with the options you want, or tick the boxes in Client Settings.
  4. Intune: unassign the profile, or set the settings to Disabled to allow redirection explicitly.

Test any change to disable RDP drive redirection on one host first, tell users that file transfer will move to an approved share, and document the exempt admin hosts.

Disable RDP drive redirection at a glance

Disable RDP Drive Redirection with GPO summary card: Link a GPO to the OU that holds your RDS hosts or servers and enable Computer Configuration » Policies » Administrative…
In short: Link a GPO to the OU that holds your RDS hosts or servers and enable Computer Configuration » Policies » Administrative Templates » Windows Components » Remote Desktop Services » Remote Desktop Session Host » Device and Resource…

Official documentation: Configure fixed, removable, and network drive redirection, RemoteDesktopServices Policy CSP, Configure the clipboard transfer direction and types of data.

Related guides: Block USB Storage Group Policy and Intune: Secure Setup · Deploy an RDS farm on Windows Server 2025 · Group Policy loopback processing: merge vs replace for RDS hosts and kiosks.

Frequently asked questions

Does disabling RDP drive redirection also stop copying files through the clipboard?

Yes. When “Do not allow drive redirection” is enabled on the session host, Windows also blocks clipboard file copy, even if clipboard redirection is allowed. Text and images can still be pasted unless you restrict the clipboard too.

Should I configure redirection on the server or on the client?

Configure the session host first, because it protects the server from every client. Client-side values under HKLM\Software\Microsoft\Terminal Server Client are an extra layer that stops managed devices from sharing drives with servers you do not control.

Why do users still see their drives after I changed the policy?

Redirection is set when a session is created. A user who only disconnected and reconnected keeps the old session, so sign them out and let them connect again.

Can I allow text in the clipboard but block files?

Yes. Block drive redirection, leave clipboard redirection allowed and use “Restrict clipboard transfer from server to client” and “Restrict clipboard transfer from client to server” with the plain text level. These need Windows 11 24H2 or Windows Server 2025, or the mid-2024 cumulative updates on older builds.

Do RDS collection settings override Group Policy?

No. The most restrictive setting wins wherever it is configured. If the host GPO blocks drives, enabling drives in the collection properties has no effect.

Free website test

Is your website set up right?

Check SSL, security headers, redirects, robots.txt, sitemap, llms.txt and security.txt in one test. It takes about 30 seconds.