USB device redirection over RDP on Windows 11 Pro — two patches that make it work.
Windows 11 Pro has full USB redirection infrastructure (drivers, services, protocol support) but artificially blocks it through a licensing check. When you try to redirect a USB device via RDP, the server logs:
Event ID 36: "Redirection of additional supported devices is disabled by policy."
This happens because umrdp.dll calls SLGetWindowsInformationDWORD("TerminalServices-RemoteConnectionManager-AllowAppServerMode") which returns 0 on non-Server editions. No amount of registry or Group Policy changes can fix this — the check is hardcoded in the binary.
Additionally, FreeRDP 3.x has a bug where USB devices connected through hub chains get incorrect device paths, causing the wrong device to be redirected.
freerdp-urbdrc-devpath.patch — Fixes device path generation in FreeRDP's URBDRC (USB Redirection) channel.
Bug: libusb_get_port_numbers() returns the full USB topology (e.g., [5,2,1,1,3]) but FreeRDP only uses the last port number, generating path 1-3 instead of 1-5.2.1.1.3. This causes redirection of the wrong device.
cd /path/to/freerdp-source
git apply /path/to/freerdp-urbdrc-devpath.patch
# rebuild and installpatch-umrdp.py — Patches umrdp.dll to bypass the AllowAppServerMode licensing check.
The patch NOPs out a single conditional jump (6 bytes at offset 0x9001), allowing the USB redirection code path to execute regardless of the licensing result.
Offset 0x9001: 0F 84 BA 00 00 00 (je +0xBA)
-> 90 90 90 90 90 90 (6x NOP)
Targets umrdp.dll version 10.0.26100.1 (Windows 11 24H2). The script includes a signature check and will refuse to patch an unrecognized version.
setup-server.ps1 — One-shot PowerShell script that configures everything on the Windows side:
- Registry values (
fDisableUSBRedir,EnableUSBRedirection,fUsbRedirectionEnableMode) - USB class filter registration (
TsUsbFltas UpperFilter) - Service configuration (
TsUsbFlt,TsUsbGD,tsusbhub,UmRdpService) - Binary patch of
umrdp.dll
Run as Administrator, then reboot.
# Run as Administrator
Set-ExecutionPolicy Bypass -Scope Process
.\setup-server.ps1
Restart-Computer# Apply the FreeRDP patch and rebuild
cd /path/to/freerdp-source
git apply freerdp-urbdrc-devpath.patch
mkdir build && cd build
cmake .. && make -j$(nproc)
sudo make install
# Connect with USB redirection (example: Logitech SpaceMouse 046d:c62b)
xfreerdp3 /v:SERVER /u:USER /p:PASS /usb:id:046d:c62b /cert:ignoreLinux Client Windows Server
───────────── ──────────────
xfreerdp3 termsrv.dll (RDP core)
└─ URBDRC channel ──── DVC ────────── rdpcorets.dll
└─ libusb └─ umrdp.dll (policy check) ← PATCHED
└─ device enum └─ tsusbhub.sys (USB hub driver)
└─ TsUsbFlt.sys (class filter)
└─ USB device appears in Windows
// umrdp.dll pseudocode at 0x8FF7
BOOL enabled = CheckUsbRedirectionLicense(); // calls SLGetWindowsInformationDWORD
if (!enabled) { // AllowAppServerMode == 0 on Win11 Pro
LogEvent(36, "disabled by policy"); // ← this is the error everyone sees
return;
}
// ... proceed with USB redirectionUSB topology: Bus 1, Port chain [5, 2, 1, 1, 3]
FreeRDP (before): path = "1-3" (wrong — matches a different device!)
FreeRDP (after): path = "1-5.2.1.1.3" (correct full topology)
| Path | Value | Type | Data | Purpose |
|---|---|---|---|---|
HKLM\SOFTWARE\Policies\Microsoft\Windows NT\Terminal Services |
fDisableUSBRedir |
DWORD | 0 | Don't disable USB redir |
HKLM\SOFTWARE\Policies\Microsoft\Windows NT\Terminal Services |
EnableUSBRedirection |
DWORD | 1 | Enable USB redir |
HKLM\SOFTWARE\Policies\Microsoft\Windows NT\Terminal Services |
fUsbRedirectionEnableMode |
DWORD | 2 | Allow admins and users |
HKLM\SOFTWARE\Policies\...\Client |
fUsbRedirectionEnableMode |
DWORD | 2 | Client-side enable |
HKLM\SYSTEM\...\Control\Class\{36fc9e60-...} |
UpperFilters |
MULTI_SZ | TsUsbFlt |
USB hub class filter |
- Server: Windows 11 Pro 24H2 (Nano11), build 26100.1
- Client: Arch Linux, FreeRDP 3.23.0
- Device: Logitech/3Dconnexion SpaceMouse Pro (046d:c62b)
This project modifies system binaries and bypasses licensing checks. Use at your own risk and only on machines you own. Windows Update may replace the patched umrdp.dll — re-run setup-server.ps1 or patch-umrdp.py after updates.