Win 2016+2019: Remote Desktop Services attributes of ENVIRONMENT tab of a users object properties in AD DS are not applied

Since Windows server 2016, the attributes of theese tabs, are no longer applied:

This is because Microsoft changed the way it works, and therefore doomed it “legacy RCM”:

This article describes the Remote Connection Manager (RCM) and the changes to RCM in

Windows Server Standard, version 1803, Windows Server Datacenter, version 1803, Windows Server version 1709 and Windows Server 2016.

In Windows Server 2012 R2 and earlier versions, when a user logs on to a terminal server, the RCM contacts the domain controller (DC) to query the configurations that are specific to Remote Desktop on the user object in Active Directory Domain Services (AD DS). This information is displayed in the Remote Desktop Services Profile tab of a users object properties in the Active Directory Users and Computers MMC snap-in.

Starting in Windows Server 2016, RCM no longer queries the users object in AD DS. If you require RCM to query AD DS because you are using the Remote Desktop Services attributes, you must manually enable RCM.

Additionally, consider the following scenario:

  • You install Windows Server Standard, version 1803, Windows Server Datacenter, version 1803, Windows Server version 1709 or Windows Server 2016 with the Remote Desktop Session Host role.

  • You configure a local user account to start an application during logon by using the Local Users and Groups tool in Computer Management.

Luckily, it can be enabled, by adding this, on all your RDS hosts:


HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\Terminal Services 
Name: fQueryUserConfigFromDC
Type: Reg_DWORD
Value: 1 (Decimal)

Then it will work again 🙂

Read more here:

Changes to Remote Connection Manager in Windows Serverchanges-to-remote-connection-manager-in-windows-server



  1. Conrad Noche

    Do you have to delete the profile on the rdshost first and then apply the registry entry?

    1. Martin (Post author)

      No – that is not neccessary 😉

  2. Joost Brenters

    Is it also applicable to Windows 2012 R2 with latest patches on AD Controller and RDS hosts (june 2020)?

    1. Martin (Post author)

      No., this behavior is changed since 2016 🙂

  3. Gabriel Kaplan

    Hello, this solution worked perfectly well for me having Active Directory installed
    But if AD is not installed it did not work for me, is there any way to solve it in these cases?

    1. Martin (Post author)

      No sorry have none running i Workgroup mode, I only found this:

  4. Ricardo Augusto

    Dont work in server 2019

    1. Martin (Post author)

      Yes it does! 🙂 – What is your issue?

      1. Chris

        Not working for me either

        1. Martin (Post author)

          What Windows, 2019? I have set this up on Windows 2019 several times, with no issues.

          Are they domain joined, do you type the key case-sensitive?

          Regards Martin

  5. Nigel

    This was helpful! thank you.

  6. Mr. Lucas

    This solution worked with me. Thank you so much for your best solution, it made saving lot time.
    Have a nice day

    1. Martin (Post author)

      Thanks – you too 🙂

  7. Chris DeRusseau

    Does the RDS server need rebooted? I added this and it didn’t map my drive letter from AD. Or does it need to go under terminal Services\Client in the registry?

    1. Martin (Post author)

      Hi Chris,

      No – it should run just right away 🙂

      Best regards Martin

  8. Basilio

    Hi, works for me on Server 2016 Workgroup.

    Thanks Martin!


Leave a Comment

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.

By continuing to use the site, you agree to the use of cookies. more information

The cookie settings on this website are set to "allow cookies" to give you the best browsing experience possible. If you continue to use this website without changing your cookie settings or you click "Accept" below then you are consenting to this.