RDP local drive sharing is a Remote Desktop feature that maps the client’s local disks into the remote session. It is useful for support workflows, but it expands trust across endpoints and can expose the technician’s files to modification if the remote machine is compromised.
How RDP local drive sharing works
RDP local drive sharing redirects selected local disks from the client into the remote desktop session, so the remote system can read and write those files as if they were attached drives. That convenience is what makes it useful for file transfer, but it also means the boundary between endpoints is no longer just the keyboard and screen.
In practice, the feature is usually controlled through RDP client settings and session policy, which is why it often appears in support and admin workflows rather than general end-user use. The security question is not whether the feature is legitimate, but which files and devices should be exposed to a remote host and under what trust assumptions.
Why the feature changes the trust model
Local drive sharing widens the blast radius of a compromised remote machine. If the remote endpoint is malicious, infected, or later taken over, files exposed through the redirected drives may be copied, modified, staged for exfiltration, or used to tamper with the technician’s local system.
The reverse is also true: the remote session gains visibility into a slice of the client’s file system, which can create accidental data exposure when administrators assume RDP is only a screen-sharing mechanism. The feature therefore needs to be treated as a data-access path, not just a convenience option.
That trust expansion is especially important in environments where support staff move between hardened and less trusted endpoints, or where redirected drives include broad user profiles instead of a narrowly scoped working folder. The more files you map, the less meaningful the isolation between the two systems becomes.
Common use cases and operational trade-offs
Support teams typically use local drive sharing for software deployment, log collection, patch staging, and ad hoc file exchange. It can reduce friction when secure file transfer tooling is unavailable, but the convenience comes with weaker control over what the remote host can see once the session is established.
The practical trade-off is speed versus containment. A narrow, temporary mapping of only the required folder is far safer than exposing full local drives, but even a small mapping still places trust in the remote system’s integrity for the duration of the session.
In many organisations, this feature is only appropriate in tightly governed admin workflows, especially where the remote host is already within a trusted management boundary. For ordinary user sessions, broader file transfer controls are often easier to audit than persistent drive redirection.
How to think about secure use
The safest mental model is to treat redirected drives as shared attack surface. If the remote host is compromised, the attacker may be able to harvest documents, deposit unwanted files, or abuse the redirected path to influence the local machine later through opened content or copied executables.
A useful policy stance is to limit redirection to the smallest possible scope, the shortest possible session, and the lowest possible trust tier. Where a support workflow genuinely requires file movement, organisations should prefer explicit, logged transfer paths over blanket drive mapping, because visibility and control matter more than convenience once the session crosses trust boundaries.
For broader context on how exposed credentials, secrets, and overbroad access widen attack surface, NHI Mgmt Group’s Ultimate Guide to NHIs is a useful reference point for the same least-privilege mindset. For the same reason, the PCI Security Standards Council document library is a strong control-oriented source for least privilege and system-account governance.
Risk and Threat Considerations
RDP local drive sharing creates a direct path for data exposure and host-to-host trust abuse. If the remote session is compromised, redirected drives can become a bridge for file theft, tampering, malware staging, or lateral misuse of a technician’s local data.
Failure mechanism: The remote system inherits read/write access to mapped local storage within the session, so compromise of the remote endpoint or abuse of the session can turn a convenience feature into an exfiltration and modification channel.
Impact: Sensitive files may be copied, altered, or planted with malicious content, and the local workstation may be exposed to downstream compromise if transferred files are later opened or executed.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST CSF 2.0 and CIS Controls v8 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | PR.AC-4 — Access Permissions and Authorization | Drive redirection is an access decision that broadens session permissions. |
| PR.DS-1 — Data-at-Rest Protection | Mapped local disks expose stored files to a remote session boundary. | |
| DE.CM-1 — Monitoring and Detection Processes | Redirection misuse is only visible when remote-session activity is monitored. | |
| Recommendation — Restrict redirected-drive access to the minimum session scope required. Protect data exposed through redirected drives with tighter storage and transfer controls. Monitor RDP sessions for unusual file-access and transfer behaviour. | ||
| CIS Controls v8 | 6.3 — Data Recovery | Redirected files can be modified or corrupted during a compromised remote session. |
| 6.8 — Untrusted Data Handling | Files moved through RDP redirection should be treated as potentially untrusted input. | |
| 6.4 — Access Control Management | Local-drive mapping expands what the remote session may access. | |
| Recommendation — Limit redirected files to data that can be restored and validated after transfer. Treat files transferred through shared RDP drives as untrusted until checked. Remove broad drive redirection from users and sessions that do not need it. | ||
Related resources from NHI Mgmt Group
- Why do Google Drive leaks happen even when organisations have sharing policies in place?
- Why do cloud file-sharing platforms like Google Drive create leakage risk even when encryption is enabled?
- What breaks when Google Drive sharing permissions are not reviewed regularly?
- How should security teams configure Google Drive sharing to reduce the risk of data loss?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 20, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org