# Test a new RDS session after disabling automatic reconnection

> How should administrators verify that an RDS automatic-reconnection change actually applies?

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260908-178-test-a-new-rds-session-after-disabling-automatic-reconnection/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-08T18:14:13+00:00
- Modified: 2026-09-08T18:26:31+00:00
- Last reviewed by DSE: 2026-09-08
- Resource type: Guide
- DSE priority: Information
- Topics: IT, Networks & Infrastructure
- Reading time: 2 minutes

## What you need to know

How should administrators verify that an RDS automatic-reconnection change actually applies?

## Potentially affected

Administrators setting automatic reconnection behavior for Remote Desktop clients and session hosts.

## DSE recommendation

Record the current setting and the exact configuration surface to be changed.

## Article

## Source facts

RDS can preserve connection information and reconnect a locked session without asking the user to authenticate again; Microsoft says the remote lock screen is not a security boundary. Disabling automatic reconnection at the server prevents clients from using it regardless of their client setting. A changed reconnection setting applies to newly created sessions, while existing sessions retain their original setting. [Microsoft Learn](https://learn.microsoft.com/en-us/windows-server/remote/remote-desktop-services/automatic-reconnection-lock-screen).

## Applicability

Decide which session population and connection paths require the change. Review client, session-host, collection, and Group Policy configuration as applicable. Include user continuity expectations and security requirements in the same decision, with an owner for each.

## DSE recommendation

Record the current setting and the exact configuration surface to be changed. Tell pilot users how their next connection should behave during a brief network interruption. Require a newly established session for acceptance rather than relying on a session that predates the change. Keep an approved reconnect procedure available so users can regain access during the exercise.

## Verification

Create a new session, lock it, and perform a controlled interruption. Record reconnection behavior and any authentication interaction. Compare with a pre-existing session only as a separate observation. Verify the intended setting on each relevant host and investigate inconsistent behavior before extending the policy.

## Official references

[Microsoft Learn: Disable Automatic Reconnection in Remote Desktop Service for Windows Server](https://learn.microsoft.com/en-us/windows-server/remote/remote-desktop-services/automatic-reconnection-lock-screen). Source reviewed September 8, 2026.

## Primary reference

- Name: Disable Automatic Reconnection in Remote Desktop Service for Windows Server
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/windows-server/remote/remote-desktop-services/automatic-reconnection-lock-screen
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Test a new RDS session after disabling automatic reconnection,” DSE Security, https://update.dsesecurity.com/updates/dse-20260908-178-test-a-new-rds-session-after-disabling-automatic-reconnection/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
