Forum Discussion

jdewing's avatar
jdewing
Icon for Cirrus rankCirrus
Mar 07, 2019

Kerberos SSO failed for Microsoft Remote Desktop Services

I’m trying to setup Kerberos SSO for Remote Desktop using smartcard and the SSO is not working. After authenticated via F5 against LDAP server and validated, I see icons populated from MS Remote Desktop Web Access, however when I clicked on the icons, it prompted for AD username/password. I know the Kerberos is working because I can see it’s obtained Kerberos tickets in the logs. S4U ======> OK! So I know the Kerberos is working but not able to provide SSO.

 

F5 APM v13

 

Microsoft Windows 2016; MS RDS Web Access

 

For Remote Desktop profile, I enabled both Single Sign-on and Standalone Client Settings.

 

Any idea?

 

  • Hi James,

     

    Did you assign your action box to map sso credentials in the vpe?

     

    • jdewing's avatar
      jdewing
      Icon for Cirrus rankCirrus

      Yes, I have variable box to mapped to SAMAccount.

       

       

      I'm not using the password field since it's a smart card authentication that validated against LDAP server including CERT auth.