When running in restricted mode participating apps do not expose credentials to remote computers (regardless of the delegation method). Restricted mode may limit access to resources located on other servers or networks beyond the target computer because credentials are not delegated.Participating apps:Remote Desktop ClientIf you enable this policy setting restricted mode is enforced and participating apps will not delegate credentials to remote computers.If you disable or do not configure this policy setting restricted mode is not enforced and participating apps can delegate credentials to remote computers.Note: To disable most credential delegation it may be sufficient to deny delegation in Credential Security Support Provider (CredSSP) by modifying Administrative template settings (located at Computer Configuration\Administrative Templates\System\Credentials Delegation).
System\Credentials Delegation
Machine
At least Windows Server 2012 R2 Windows 8.1 or Windows RT 8.1
HKLM\Software\Policies\Microsoft\Windows\CredentialsDelegation!RestrictedRemoteAdministration
CredSsp.admx