Technical Tip: Configure FortiPAM RDP settings for Windows 7 compatibility
Description
This article describes how to configure FortiPAM to establish Remote Desktop Protocol (RDP) connections to Windows 7 devices. Windows 7 only supports TLS 1.0 for RDP communication by default, which may prevent successful connections when newer TLS versions are enforced.
Scope
FortiPAM.
Solution
Windows 7 only supports TLS 1.0 for Remote Desktop Protocol (RDP) communication unless additional Microsoft updates and configuration changes have been applied. As a result, FortiPAM RDP sessions to Windows 7 devices may fail if a newer TLS version is configured.
Security notice: TLS 1.0 is considered a legacy protocol and is no longer recommended for production environments because it is susceptible to known cryptographic weaknesses. Most modern operating systems disable TLS 1.0 by default or no longer support it. Configure TLS 1.0 only for Windows 7 targets when required for compatibility. Migrating the target system to a supported Windows version is the recommended long-term solution.
Configure the following settings in FortiPAM:
Configure the RDP Security Level.
Go to Secret -> Settings -> RDP service and set RDP Security Level to TLS:

Configure the TLS version for the target.
Go to Secret -> Target, select the target, then navigate to Advanced RDP Setting and set TLS Version to TLSv1:

After applying these settings, FortiPAM will negotiate the RDP session using TLS 1.0, allowing successful connections to Windows 7 systems that do not support newer TLS versions.
