Press Win + R , type , and hit Enter to access the Local Computer Certificate Store. Navigate to Remote Desktop > Certificates . Check the expiration date of the listed certificate.
A common solution is to renew the RDP certificate on the host machine.
Scroll down and verify that and Remote Desktop (WebSocket) are allowed on both Private and Public networks.
The Remote Desktop Service lacks permissions to access the necessary certificate's private key.
Using an outdated Remote Desktop client application can cause compatibility issues.
Once you resolve error code 0x904 extended 0x7, prevent recurrence with these policies:
: Windows generates temporary, self-signed TLS certificates for RDP listeners. If these expire or the certificate store becomes corrupt, the secure tunnel handshake fails.
This is often the most effective set of fixes, as certificate issues are a leading cause of this error.