Hello Everybody,
I faced with very strange situation: trying to troubleshoot SSO for remoteApps on Windows Server 2012R2. Everything is installed and configured properly. I ran commands:
Import-module remotedesktop
Set-rdsessioncollectionconfiguration -collectionname "RemoteApps" -customrdpproperty "authentication level:i:0"
Set-rdsessioncollectionconfiguration -collectionname "RemoteApps" -customrdpproperty "alternate full address:s:remote.ccim.com"
Added <*.domainname.com>
to the Allow Delegating Default Credentials policy and forced GPudate
Added the server name individually to the Allow Delegating Default Credentials policy
Checked and confirmed that the registry entry are updated as per the policy changes
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CredentialsDelegation]
"AllowDefaultCredentials"=dword:00000001
"ConcatenateDefaults_AllowDefault"=dword:00000001
"AllowDefCredentialsWhenNTLMOnly"=dword:00000001
"ConcatenateDefaults_AllowDefNTLMOnly"=dword:00000001
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CredentialsDelegation\AllowDefaultCredentials]
"1"="TERMSRV/<My Server1>"
"2"="TERMSRV/<My Server2>"
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CredentialsDelegation\AllowDefCredentialsWhenNTLMOnly]
"1"="TERMSRV/<My Server1>"
"2"="TERMSRV/<My Server2>"
Made sure - "Always prompt client for password upon connection" policy located in Computer Configuration\Policies\Administrative Templates\Windows Components\Remote
Desktop Services\Remote Desktop Session Host\Security. is not set to "Not Configured". Changed it to "Disable"
However, still situation: I login to remote app web page with my credential and try to launch let's say Word, logon window appears saying:
Your credentials did not work.
when I enter my credentials they do not work and it asks to enter it again.
At the same time, strange record appears in the event viewer:
New RemoteApp and Desktop connection (RDS01.domain.com) is started for user (esy8OkZAZ94BHhbY+3+KU95NykY=) without authenticated credentials
Could you please hint me what to do next and do I miss something?
UPD: I did some tests. When I logging to remote.domain.com from outside organisation, I enter credentials on the first login webpage. Then I try to launch Word, it asks again for credentials, I enter them and everything is working. When I go to terminal
server and go to remote.domain.com I enter credentials on the first login webpage. Then I try to launch word, the windows with "Your credentials did not work" appears. Certificate is signed by CA and shown as OK in IE.
UPD1: also when trying to launch published web app such event logged:
Subject:
Security ID: NULL SID
Account Name: -
Account Domain: -
Logon ID: 0x0
Logon Type: 3
Account For Which Logon Failed:
Security ID: NULL SID
Account Name: magent
Account Domain: cciminstitute
Failure Information:
Failure Reason: An Error occured during Logon.
Status: 0xC000006D
Sub Status: 0x0
Process Information:
Caller Process ID: 0x0
Caller Process Name: -
Network Information:
Workstation Name: CCIM-RDS01
Source Network Address: -
Source Port: -
Detailed Authentication Information:
Logon Process:
Authentication Package: NTLM
Transited Services: -
Package Name (NTLM only): -
Key Length: 0