Skip to content
Protect Sensitive Data in Transit with Network Level Authentication using Intune Policy

Protect Sensitive Data in Transit with Network Level Authentication using Intune Policy

Written By Anoop C Nair
Last Updated January 9, 2026
Posted In Intune
SHARE

In this post Protect Sensitive Data in Transit with Network Level Authentication using Intune Policy. This setting is about making Remote Desktop connections safer by asking users to prove who they are at an early stage. When someone tries to connect remotely, the system checks their login details before fully opening the Remote Desktop session. This helps ensure that only valid users can reach the system and reduces unnecessary exposure.

Remote Desktop is commonly used by IT teams and employees to access systems from different locations. Because it allows direct access to a computer, it can become a target for attackers if not protected properly. Enabling stronger authentication helps control who can connect and keeps systems more secure.

Network Level Authentication works in the background before the Remote Desktop screen appears. It verifies the user’s credentials first and only then allows the session to start. This approach reduces the load on the system and blocks many unauthorized or malicious attempts.

This policy is especially important because it stops attackers from even reaching the Remote Desktop login screen unless they are authenticated. Without this setting, attackers could try repeated login attempts or exploit weaknesses during the connection process. Enabling it adds an extra layer of protection right at the start.

Patch My PC

Protect Sensitive Data in Transit with Network Level Authentication using Intune Policy

Other key reason this setting matter is that it helps protect sensitive data. Since authentication happens earlier, the connection is more secure and less vulnerable to interception or misuse. This aligns with best practices for protecting data while it is being accessed remotely.

Create Profile

Now, let’s see how this policy can be deployed through the Microsoft Intune Admin Center. First, go to the Devices section. In Devices, select Configurations. In Configurations, click on the + Create policy option.

  • Then click on the Next.
  • Next, fill in the Platform and Profile type details in the Create profile window.
  • Set Platform and Windows 10 later and set Profile type to Settings catalog.
Protect Sensitive Data in Transit with Network Level Authentication using Intune Policy -Fig.1
Protect Sensitive Data in Transit with Network Level Authentication using Intune Policy -Fig.1

What is Basics

The Basics tab is the quickest step. Here, you need to enter the basic details such as the NameDescription, and Platform information. Since the platform is already set as Windows and you only need to provide a specific name and description for the policy, then click Next.

Protect Sensitive Data in Transit with Network Level Authentication using Intune Policy -Fig.2
Protect Sensitive Data in Transit with Network Level Authentication using Intune Policy -Fig.2

Configuration Settings

In the Configuration settings page, click Add settings. This opens the Settings picker window. In the Category section, navigate to Administrative Templates > Windows Components > Remote Desktop Services > Security. Under this category, you will find the required policy setting. From the list of policies, locate Require user authentication for remote connections by using Network Level Authentication

Protect Sensitive Data in Transit with Network Level Authentication using Intune Policy -Fig.3
Protect Sensitive Data in Transit with Network Level Authentication using Intune Policy -Fig.3

Disabled Mode

Now you are on the Configuration settings main page. Here, you will see that the selected policy has appeared in the list. By default, it is set to Disabled. If you want to keep it disabled that means, you do not want Require user authentication for remote connections by using Network Level Authentication enabled in your organization, so you can just click Next to continue.

Protect Sensitive Data in Transit with Network Level Authentication using Intune Policy -Fig.4
Protect Sensitive Data in Transit with Network Level Authentication using Intune Policy -Fig.4

Enable the Policy

After closing settings picker, turn the toggle from Not configured to Enabled to enforce Network Level Authentication (NLA), which ensures users must authenticate before a remote desktop session is established. After enabling the policy, click Next to continue and complete the profile configuration.

Protect Sensitive Data in Transit with Network Level Authentication using Intune Policy -Fig.5
Protect Sensitive Data in Transit with Network Level Authentication using Intune Policy -Fig.5

Known about Scope Tags

The Scope tags section is an important part of policy deployment. The advantage of this section is that it allows you to assign the policy to specific groups or departments within your organization. However, adding a scope tag is not mandatory and you can still deploy the policy successfully without using this step.

Protect Sensitive Data in Transit with Network Level Authentication using Intune Policy -Fig.6
Protect Sensitive Data in Transit with Network Level Authentication using Intune Policy -Fig.6

Assignment Section

The Assignment section is very important for policy deployment. In this section, you decide who will receive the policy within the organization. If you want to target specific groups, users, or devices, you can add them here to ensure the policy is applied only to the intended audience.

Protect Sensitive Data in Transit with Network Level Authentication using Intune Policy -Fig.7
Protect Sensitive Data in Transit with Network Level Authentication using Intune Policy -Fig.7

Review + Create

Review + Create is the last stage of policy creation. In this step, you will see a summary of all the details, including Basics, Configuration Settings, Assignments, and more. You can review all the information, and if anything needs to be changed, you can go back to the previous steps and edit them easily.

  • In the Review + Create section, you will see a Create button
Protect Sensitive Data in Transit with Network Level Authentication using Intune Policy -Fig.8
Protect Sensitive Data in Transit with Network Level Authentication using Intune Policy -Fig.8

Monitoring Details

After creating the policy, you might in a thought that whether it was successfully applied or not. It is very important to verify this. To check, you normally need to wait up to 8 hours for the policy to sync automatically. However, if you want faster results, you can manually sync the policy through the Company Portal.

  • Using this method ensures the policy is applied more quickly and you can confirm the outcome without waiting the full sync time. To check the Monitoring status follow the steps;
  • Click on the policy to view its deployment status and details.
  • Sign into the Microsoft Intune Admin Center.
  • Navigate to Devices > Configuration Policies.
  • In the Configuration Policies list, look for the policy you created.
Protect Sensitive Data in Transit with Network Level Authentication using Intune Policy -Fig.9
Protect Sensitive Data in Transit with Network Level Authentication using Intune Policy -Fig.9

Client-Side Verification

To get the client-side verification, open the Event Viewer and navigate to Applications and Services Logs > Microsoft> Windows Device Management > Enterprise Diagnostic Provider > Admin. Once there, you can search for specific policy results by using the Filter Current Log feature located in the right pane. This helps quickly get the relevant results within the log.

Policy Details
MDM PolicyManager: Set policy string, Policy: (TS_USER_AUTHENTICATION_POLICY), Area:
ADMX_TerminalServer), EnrollmentID requestinq merqe: (EB427D85-802F-46D9-A3E2-
5B414587F63), Current User: (Device), Strinq: (), Enrollment Type: (0x6), Scope: (0x0).
Protect Sensitive Data in Transit with Network Level Authentication using Intune Policy -Fig.10
Protect Sensitive Data in Transit with Network Level Authentication using Intune Policy -Fig.10

Removing the Policy Group

If you want to remove any group from your policy after the policy creation you can easily do that. First go to the Device Configuration then search the policy name and now you get the policy monitoring status page. Here you have to scroll down, and you will get the Assignment section there you will get an edit option.

  • In the Assignment page you can see the Remove option Click on that for removing the Policy.

To get more detailed information, you can refer to our previous post – Learn How to Delete or Remove App Assignment from Intune using by Step-by-Step Guide.

Protect Sensitive Data in Transit with Network Level Authentication using Intune Policy -Fig.11
Protect Sensitive Data in Transit with Network Level Authentication using Intune Policy -Fig.11

How to Delete the Policy that you created

You can easily delete the Policy from the Intune Portal. From the Configuration section, you can delete the policy. It will completely remove it from the client devices. For that search the picy name in the configuration profiles. Locate and select the specific policy you want to remove.

  • When you’re on the policy details page, click the More menu in the top right corner and choose Delete from the available options.

For detailed information, you can refer to our previous post – How to Delete Allow Clipboard History Policy in Intune Step by Step Guide.

Protect Sensitive Data in Transit with Network Level Authentication using Intune Policy -Fig.12
Protect Sensitive Data in Transit with Network Level Authentication using Intune Policy -Fig.12

Need Further Assistance or Have Technical Questions?

Join the LinkedIn Page and Telegram group to get the step-by-step guides and news updates. Join our Meetup Page to participate in User group meetings. Also, Join the WhatsApp Community to get the latest news on Microsoft Technologies. We are there on Reddit as well.

Author

Anoop C Nair has been Microsoft MVP for 10 consecutive years from 2015 onwards. He is a Workplace Solution Architect with more than 22+ years of experience in Workplace technologies. He is a Blogger, Speaker, and Local User Group Community leader. His primary focus is on Device Management technologies like SCCM and Intune. He writes about technologies like Intune, SCCM,   Windows, Cloud PC,  Windows, Entra, Microsoft Security, Career, etc

Written by

Anoop C Nair is Workplace Technology solution architect with 25+ years of experience in global enterprise organizations such as JP Morgan, Capgemini, etc. Microsoft Certified Trainer. Microsoft MVP from 2015 onwards for consecutive 11+ years! He also conducts Intune and modern workplace tech training for enterprise organizations. He is Blogger, Speaker, and Founder of HTMD Community and HTMD Conference. His main focus is on Device Management technologies like Intune, Windows, Cloud PC. He writes about technologies like Intune, SCCM, Windows, Cloud PC, Windows, Entra, Microsoft Security.

Discussion

Join the discussion

Your email address will not be published. Required fields are marked *

Related guides

Intune

Simplify Windows Devices to Run Only the Required Applications using Intune

Key Takeaways Hey, let’s learn about Simplify Windows Devices to Run Only the Required Applications using Intune. This policy lets administrators replace the default windows shell with a custom or lightweight shell. it improves performance by using system resources and is useful for devices that run a dedicated application. If the policy is disabled or […]

AC Anoop C Nair 8 min read
Intune

Enhance macOS Compliance with Custom Security and Compliance Checks to Improve Device Security using Microsoft Intune

Key Takeaways In this post we are discussing about Enhance macOS Compliance with Custom Security and Compliance Checks to Improve Device Security using Microsoft Intune. Microsoft has announced the general availability of Custom Compliance Settings for macOS in Microsoft Intune. The feature helps organizations strengthen security controls while supporting many types of macOS management scenarios. […]

AC Anoop C Nair 4 min read
Intune

Manage Samsung Galaxy Firmware Versions to Improve Security and Compliance using Microsoft Intune

Key Takeaways In this post we are discussing Manage Samsung Galaxy Firmware Versions to Improve Security and Compliance using Microsoft Intune. Microsoft Intune has received a new update that expands firmware management capabilities for Samsung Galaxy devices through Firmware Versionsintegration. This enhancement gives IT administrators more control over firmware and operating system updates, helping them […]

AC Anoop C Nair 4 min read
Intune

MS Intune Adds Windows Registry Data Collection to Device Inventory for Single Values All Key Values and Subkeys

Key Takeaways Microsoft Intune 2607 introduces Windows Registry Data collection in Device Inventory, allowing IT admins to verify actual device configurations without relying on custom discovery or remediation scripts. Using the Properties Catalog, admins can collect registry information through Single Value, All Values Under a Key (Non-Recursive), or Same Value Across Subkeys. MS Intune Adds […]

AC Anoop C Nair 5 min read