Windows 2008 R2 + Remote Desktop Web Access + Single Sign-On + 2 servers

Hi
First sorry for my English. I have got problem with run SSO with RDWeb. I configured everything follow this instructions:  http://blogs.msdn.com/b/rds/archive/2009/08/11/introducing-web-single-sign-on-for-remoteapp-and-desktop-connections.aspx
and http://blogs.technet.com/b/mrsnrub/archive/2010/03/22/remote-desktop-services-websso.aspx. After logon to RDWeb web page I click application icon. Then I see dialog box for credentials - SSO not working.
I have got 2 servers with Windows Server 2008 R2 Standard:
Server OL-AP1 with role Remote Desktop Session Host (RDSH) and certificate for digital sign RemoteApps
Server OL-AP04 with ONLY Remote Desktop Web Access (RD Web) with certificate for https
Client PC: Windows 7 SP1 with installing certificate for OL-AP01 witch I used for digital sign RemoteApps
All certificates created by enterprise domain CA - Active Directory Certificate Services (AD CS)

Hi,
Thank you for posting in Windows Server Forum.
Do you have RD Gateway setup in your environment?
Have you configure RD Connection Broker and set the Fully Qualified Domain Name (FQDN) of the RD Connection Broker server in case of RD Connection Broker mode. In RD Session mode, it is set to the FQDN of the RD Web Access server. 
Client operating systems must trust the certificate with which the RemoteApp programs are signed. Suggest to install RDP 8.1 for client OS.
Do you have a trusted certificate with a matching name configured on your RDSH server in RD Session Host Configuration? (Means cert must match the name that clients use to connect to it for running the RemoteApp).
Hope it helps!
Thanks.
Dharmesh Solanki

Similar Messages

  • Windows 8.1 pro Remote App crashes connecting to 2012 Remote Desktop Web Access published application

    Using 2012 Remote Desktop Web access to gain access to published applications. The workstation was a Windows 8.1 (home) upgraded to Windows 8.1 Pro with the Media Center add on. Launching the url to the login page for the RDW works fine. When the app is
    clicked on to launch the Remote App crashes. How do I get it to properly connect. Other Windows 8.1 pro workstations work. Although none were upgraded from the 8.1 (home) Here is the event.
    Faulting application name: mstsc.exe, version: 6.3.9600.16384, time stamp: 0x5215e2b5
    Faulting module name: ntdll.dll, version: 6.3.9600.17031, time stamp: 0x530895af
    Exception code: 0xc0000005
    Fault offset: 0x0000000000065e8e
    Faulting process id: 0xab4
    Faulting application start time: 0x01cf5f2ed029e83f
    Faulting application path: C:\Windows\System32\mstsc.exe
    Faulting module path: C:\Windows\SYSTEM32\ntdll.dll
    Report Id: 21a471d6-cb22-11e3-8263-a0886933dd25
    Faulting package full name:
    Faulting package-relative application ID:

    More info.
    The computer is brand new HP.
    Windows 8.1 pro with media center
    processor Intel i7-4700mq - 12gig ram -64bit
    Full windows touch support with 10 touch points 
    The computer is connecting to a 2012 Server hosted on Microsoft's Azure platform. Trying to access applications hosted by this server with Remote Desktop Web services. The computer can RDP using just the mstsc.exe to other computers and to the server with
    no problem.
    The computer presents the following msg box  Body: Remote Desktop Connection has stopped working. I have tried the following to resolve this and narrow the scope:
    -Created a new user account for the computer with admin rights, rebooted and logged in as the new user.
    -Tried a different user account for the portal, that does work. The user does not show up as connected.
    -All MS updates were loaded.
    -Added these changes to the registry to keep alive the connection: HKEY_CURRENT_USER\Software\Microsoft\Terminal Server Gateway\Transports\Rpc-----HttpKeepAliveTimeout=dword:00000001
    And HKEY_CURRENT_USER\Software\Microsoft\Terminal Server Client----RDGClientTransport=dword:00000001
    Loaded this update http://support.microsoft.com/kb/2919394/EN-US
    -Removed all printers
    -Removed Antivirus
    -Added the server to HKEY_CURRENT_USER\Software\Microsoft\Terminal Server Client\Default
    -Disabled everything in MSCONFIG startup
    -Ran sfc /scannow as administrator - no integrity violations
    Any suggestions?

  • Using remote desktop web access (RDWEB) with remoteapps and a traditional remote desktop

    I configured windows 2012 r2 remote desktop services and remote desktop web access (rdweb) and was able to click the icon on the rdweb page to log on to a remote desktop session. When I published a remoteapp program, the remote desktop icon went away. How
    do I get it back? Do I need to publish remote desktop as a remoteapp so users can both use remote apps and log on to a traditional remote desktop session?
    thanks in advance for the help

    Hi,
    You can just publish RDC as RemoteApp and then can connect to the desired remote desktop connection. You can check the below snap.
    Hope it helps!
    Thanks.
    Dharmesh Solanki
    Please remember to mark the replies as answers if they help and unmark them if they provide no help. If you have feedback for TechNet Support, contact [email protected]

  • Audio Redirection and Remote Desktop Web Access

    I recently deployed a 2012r2 Remote Desktop solution. I have a collection published for remote desktop sessions and have configured it to allow all redirection shown in the interface. However when users connect through Web Access, they do not get audio recording
    redirection.
    Is there a way to enable this through Remote Desktop Web Access?

    Hi,
    Glad to hear that it is up now. Please keep us informed when the issue is resolved.
    Best Regards.
    Jeremy Wu
    TechNet Community Support

  • Remote Desktop Web Access Administration not in menu

    I am trying to figure out why RemoteApp is working and Remote Desktop connection isn't on my very simple installation. One thing I came across is that something seems to be missing from my Remote Desktop Services menu. According to the TechNet article at https://technet.microsoft.com/en-us/library/ee891009(WS.10).aspx
    if I should be able to access RD Web administration by following these instructions: 
    On the RD Web Access server, click Start, point to Administrative Tools, point to Remote Desktop Services, and then click Remote Desktop Web Access Administration.
    But when I go there I find that there is no Remote Desktop Web Access Administration. Any ideas on why it doesn't exist?

    Yes, that's the OS I'm using. Those settings are set properly as far as I know. Since this is all on one server, the DC (very small office that can't justify second server), I'm not using an RD Connection Broker so it's set to the RemoteApp sources and
    the Source name is the internal FQDN of the server. servername.domain.local. The weird thing is that when I log in via RD Web the RemoteApps Programs tab has a Remote Desktop icon that successfully connects me to the server but the Remote Desktop tab always
    fails, telling me it can't connect to the computer.

  • Windows 2008 R2 Remote Desktop Services - user profile path not working

    Trying to setup remote desktop profiles. We have 1 farm with 2 Windows 2008R2 RD session hosts and a broker server and want the all of the remote user  profiles to reside on a dedicated profile server. We've created the user shares but when a remote
    user logs in their user profiles is automatically created on the session hosts. Each remote users profile path is specified in AD under the user's Remote Desktop Profile tab.
    I've seen posts about creating a GPO to handle roaming profiles but I'm not sure as to where this needs to be created...should it be done on each of the session hosts? Are their any step by step instructions out there on how to achieve this that I just haven't
    found yet?
    bl

    Hi,
    Thank you for posting in Windows Server Forum.
    Do you have RD Gateway setup in your environment?
    Have you configure RD Connection Broker and set the Fully Qualified Domain Name (FQDN) of the RD Connection Broker server in case of RD Connection Broker mode. In RD Session mode, it is set to the FQDN of the RD Web Access server. 
    Client operating systems must trust the certificate with which the RemoteApp programs are signed. Suggest to install RDP 8.1 for client OS.
    Do you have a trusted certificate with a matching name configured on your RDSH server in RD Session Host Configuration? (Means cert must match the name that clients use to connect to it for running the RemoteApp).
    Hope it helps!
    Thanks.
    Dharmesh Solanki

  • Windows 2008 R2 Remote Desktop install Error on AD auth.

    Hi ALL, I just did a clean install of Windows 2008 R2 and a refresh install of Business Object XI R3 sp3. When I try and have a user authenticate I get an error :
    [repo_proxy 13] SessionFacade::openSession -
    (com.crystaldecisions.sdk.exception.SDKException$SecurityError: The secWinAD
    security plugin is not enabled. Contact your system administrator for
    details. (FWB 00002)) [repo_bridge - BridgeSessionFacade::openSession]
    On are other TS server that is just 2008 we don't get the error.
    Could anyone point me in the right direction to troubleshoot this one. 
    -i

    this error means that on this "refresh install of Business Object XI R3 sp3" AD authentication is not enabled.
    you need to enable and configure AD in CMC, only then login with seWinAD autentication from client tools.

  • Windows 2008 R2 Remote Desktop Service Role pickup 2012 RDS License Server.

    I am installing Citrix onto a Windows 2008 R2 server as part of this I need to setup the RDS Role on the same box and then point it to the Windows RDS License server.
    Our plan is to have a Windows 2012 License server for RDS Licenses i.e. install 2012 RDS Licenses.
    I was wondering if it was possible for a 2008 R2 RDS role to pick up 2012 RDS Licneses from a Windows 2012 RDS Server?
    Many thanks,
    Steve

    Hi Steve,
    Thank you for posting in Windows Server Forum.
    Yes, agree with TP’s comment. You can also check below interoperability matrix link for details.
    RDS and TS CAL Interoperability Matrix
    http://social.technet.microsoft.com/wiki/contents/articles/14988.rds-and-ts-cal-interoperability-matrix.aspx
    Hope it helps!
    Thanks.
    Dharmesh Solanki

  • Intermittent Disconnects for clients of 2008 R2 Remote Desktop Services

    Hello, I have an issue that I am trying to work on for a client who is experiencing intermittent disconnected sessions when logged into a Windows 2008 R2 Remote Desktop Services (RDS) server.
    As I mentioned, the disconnect is intermittent in nature and almost appears to be network related, although I cannot find any data in the Application, System, or application specific logs to support that.
    The RDS server overall does not exhibit any error, but the user's session is briefly interrupted and then restored.  I would like to be able to gain some additional information about what is going on under the hood, but I am having trouble finding any
    details on how to turn on debug logging for Terminal Services (er, RDS) on 2008 R2.
    Can someone provide some additional details on what kind of logging or other means that I can take on this server in order to gain some additional insight?
    Thanks in advance for any advice.

    Hi,
    There are certain reason for which the client get disconnect from the server. The following are some of the commonly seen symptoms:
    • You may be limited in the number of users who can connect simultaneously to a Remote Desktop session or Remote Desktop Services session.
    • You may have a port assignment conflict.
    • You may have an incorrectly-configured Authentication and Encryption setting.
    • You may have a certificate corruption.
    More information.
    http://support.microsoft.com/kb/2477176
    If you want to have log for login\logoff for the client on server end then you can get the information from below log.
    Event Viewer>Application and Service Logs>Microsoft>Windows>TerminalServices-LocalSessionManager>Operational
    Hope it helps!
    Thanks.
    Dharmesh Solanki
    Please remember to mark the replies as answers if they help and unmark them if they provide no help. If you have feedback for TechNet Support, contact [email protected]

  • I am accessing a windows server using remote desktop and I am wondering if I can transfer files by sharing drives?

    I am accessing a windows server using remote desktop and I am wondering if I can transfer files by sharing drives?

    Probably. You may be able to use Finder > Go > Connect to server to access the server. You may be able to share folders using Remote Desktop too. Whichever one you like the best.

  • How to enable users to access windows 2012 through remote desktop client on windows XP SP3

    Hi I have just installed Windows Server 2012 and trying to give access to the users. The users are on windows XP Pro SP3 remote desktop client (Shell and control version 6.1.7600 with Remote Desktop Protocol 7.0 support). 
    I have enabled the windows server 2012 remote desktop users through "control panel -> systems and security ->  Remote access" for the users. When I try to connect to the windows server as administrator, it is getting connected.
    But when I try to connect as other users I get the following message.
    "To sign in remotely, you need the right to sign in through Remote Desktop Services. By default members of the Administrators group have this right. If the group you're in does not have the right, or  if the right has been removed from the Administrators
    group, you need to be granted the right manually."
    Is there any other setting to be done to eanble the Remote Desktop for the users.

    Hi I have just installed Windows Server 2012 and trying to give access to the users. The users are on windows XP Pro SP3 remote desktop client (Shell and control version 6.1.7600 with Remote Desktop Protocol 7.0 support). 
    I have enabled the windows server 2012 remote desktop users through "control panel -> systems and security ->  Remote access" for the users. When I try to connect to the windows server as administrator, it is getting connected.
    But when I try to connect as other users I get the following message.
    "To sign in remotely, you need the right to sign in through Remote Desktop Services. By default members of the Administrators group have this right. If the group you're in does not have the right, or  if the right has been removed from the Administrators
    group, you need to be granted the right manually."
    Is there any other setting to be done to eanble the Remote Desktop for the users.
    Have you tried adding those users to the "Remote Desktop Users" group? It's in Active Directory Users and Computers and it's a Built-In group. Might want to give that a try ...
    - JJ

  • WRT54GL not allowing Remote Desktop Web Connection

    Im currently using a WRT54GL in a network with just two computer. Computer A is using a wired connection and Computer B is wireless with a Linksys adapter. Public IP address from ISP is a static IP address and all is setup in the router allowing both computers internet access with no problems. Both computers are setup with static IP. Computer A is 192.168.1.101. Computer B is 192.168.1.103. Both computers are installed with Internet Information Services.
    1) Setting Up The Two Computers: I setup Computer A for port 50001, ie. I opened Control Panel, clicked Performance & Maint., Clicked Admin Tools, Double clicked IIS. Expanded Websites, right clicked Default Website and clicked on Properties. On the Website tab, I changed the value of the TCP port to the one above, 50001. I Opened the Properties Window of My Computer and clicked to the Remote tab. I placed a green Check into where it states, [Allow users to connect remotely to this computer]. On side note, I have admin rights to the computer so I  did not click to [Select Remote Users]. I then accessed the Windows Firewall Settings, In the Exception Tab, I have Remote Desktop with a Check - Set with TCP 3389. I also added new port - game it Name: Remote Access, Port:50001. Settings were all saved. (I did all the same exact steps for Computer B, but the only difference is I used for 50002 instead)
    2) Setting up the router: I access the router configuration with IP 192.168.1.1 Clicked to the Applications and Gaming. Selected [Port Range Forward]. Below where it tells to enter the ports and name for each port I entered for the first port. Application: FM-HS01, Start and End Ports: 50001 to 50001, Protocol: TCP, IP Address: 192.168.1.101, Enabled: {checked}. I again setup another below that for Computer B. FM-HS02, 50002 to 50002, TCP, 192.168.1.103, Enabled: {Checked}. I then clicked to Port Triggering screen. Under Application: [Remote Access], Trigger Range Start - End: [50001 to 50002], Forwarded Range Start - End: [3389 to 3389], Enabled [Checked]
    Under the Security Tab for Firewall - I unchecked {Block Anonymous Internet Requests}, but have {Filter Multicast}, {Filter Internet NAT Redirection} , {Filter IDENT(Port 113)} all checked.
    I also enabled remote access to router using default port 8080.
    By using the ISP Static IP: ie http://64.193.93.46:8080/, I am able to access the router config page no problems. Problem is trying to access each Computer A and B. For Example: in IE address bar, I entered http://64.193.93.46:50001/ I get page stating Under Construction. Now if I try http://64.193.93.46:50001/tsweb/ I actually get the Microsoft Windows Remote Desktop Web Connection screen stating to enter Server __________ Size: and Connection Button. I enter the Computer Name for Computer A: FM-HS01, Choose the appropriate size and clicked connect. Page loads then all I see is an outline of a box where I assume the remote computer's screen should show. A message appears after trying to load stating: "
    Remote Desktop can’t find the computer “FM-HS01”. This might mean that “FM-HS01” does not belong to the specified network. Verify the computer name and domain that you are trying to connect to."
    This is where I have been ending up at. I have not able to get pass this part. Any Help Please??? I am not sure is there are other ports I would need to open along with the ones I have specified above. On another side note, my Antivirus software for both computers are CA eTrust AntiVirus which I have also configured for both computers.

    Just change the ports to what ever you think of and be sure to make the right single port forwards (if you put comp A to 50001, make *.*.*.101:50001 forward and so on). Just be sure you are not running anything else on the same port, on the same computer (for excample the IIS terminal server client application). And from outside you just connect the remote desktop client to your external iport_number ie use the comp_ip:50001 for comp A in the client program connection window (not http:// in browser).
    - who stole my beer? -

  • HT1338 can apple remote desktop 3 access my pc work desktop?

    can apple remote desktop 3 access my pc work desktop? Do I have to get microsoft office 2011 in order to do this?

    Microsoft Remote Desktop Connection Mac OS X Client (free)
    <http://www.microsoft.com/mac/products/remote-desktop/default.mspx]]>
    Applications -> Remote Desktop Connection
    Computer:  windows.pc.address
    -OR-
    Computer:  windows.pc.address/console
    Microsoft provides setup instructions on the web page where you download the RDC client.
    -OR-
    CoRD (Microsoft RDC Screen Sharing)
    <http://www.macupdate.com/info.php/id/22770/cord>
    -OR-
    You could also install a VNC server on your Windows system and use a VNC client on your Mac

  • I don't have a wireless keyboard or mouse for my 2007 iMac, is there any way that can use remote desktop and access it from my 2010mbp.

    i don't have a wireless keyboard or mouse for my 2007 iMac, is there any way that can use remote desktop and access it from my 2010mbp

    Hi champrider,
    You can use an application such as Apple Remote Desktop to control your iMac remotely. See this article -
    OS X Mavericks: Allow access using Apple Remote Desktop
    This help page will provide you with some other useful resources for Apple Remote Desktop -
    Remote Desktop Help
    Thanks for using Apple Support Communities.
    Best,
    Brett L 

  • Windows Server 2008 R2 Remote Desktop - The requested session access is denied

    Hi, I have been using Windows Server 2008 R2 since it was released, and have 100 servers up and running. I configured Allow Remote Desktop on all of them and have been able to connect to them and manage them via RDP since then. I also have two servers configured as Remote Desktop Services.
    That was up until yesterday. Yesterday afternoon I started getting the The requested session access is denied. I managed all Terminal services via Group Policy and have three users entered.
    I am connecting to the servers via Windows XP SP3 and Windows 7. Both clients have been updated to the latest Remote Desktop Services client.
    I have been searching for the answer, and I am not finding it.
    I have also tried KB954369 without any success. 
    Thanks,
    Brian

    Ok, from my trials and tribulations and discussions with Microsoft I have identified the following;
    Assumptions;
    A. My terminal server is in domain widget
    B. All the users are in domain contoso
    1. I had the Terminal Server configurured with a specific Login, which would launch a specific application only and not give them any desktop functions. Wiht this configured this way, I get the error I wrote about.
    2. If I turn the specific login off, then I can login normally and perform the functions as Administrator that I need/want to do.
    3. Microsoft said to configure the Terminal Server with Single Sign-on. I did as instructed and went thru all the steps, however because my terminal server is in domain widget, the users get prompted twice each time for login. Once on the website, and then again as the application launches. Microsoft said that the users needed to Remote Desktop Client 7.x or the self-signed certificate that I have has to be included in the domain contoso certificate authority so that they will not be prompted for the second sign-on.
    4. Conclusions - I need to have a chat with our enterprise security team about including the self-signed certificate in the contoso certificate authority. I need to also work on my RDWeb website so that it meets our company standard look.
    Here are the links that Microsoft provided;
    http://technet.microsoft.com/en-us/library/cc772108(WS.10).aspx
    Enable RDC Client Single Sign-On for Remote Desktop Services
    http://technet.microsoft.com/en-us/library/cc742808.aspx
    Blogs -
    http://blogs.msdn.com/rds/archive/2007/04/19/how-to-enable-single-sign-on-for-my-terminal-server-connections.aspx
    http://blogs.msdn.com/rds/archive/2009/08/11/introducing-web-single-sign-on-for-remoteapp-and-desktop-connections.aspx
    http://blogs.msdn.com/rds/archive/2009/06/05/publishing-in-windows-server-2008-r2.aspx
    http://blogs.technet.com/pfe-ireland/archive/2008/09/05/windows-server-2008-terminal-services-presentation-virtualisation-and-windows-xp-clients.aspx
    I hope this help you in your troubleshooting.
    Brian

Maybe you are looking for

  • Issue with RAW files from Canon 5DMKIII

    Hello,  I use Adobe Photoshop CS6 with Camera Raw 7. Photoshop  Bridge CS6 do not recognize the RAW files from the Canon 5D Mark III, any idea? Thanks in advance.

  • Iphone uptade back from 7.0.2 to 6.1.3

    Hello, i am iphone 4 user. i have update my iphone v6.1.3 to v7.0.2 now i want how i back my iphone 4 v 6.1.3 please help me.

  • Aargh! How do I convert to .swf?

    We have a client that wants to post some stuff on line. First they wanted .wmv, then decided that wouldn't work. Ditto with QT and Flash versions. Now they are asking for .swf versions, by the end of the day of course. I'm stumped as to how to do thi

  • Quick question STM1 vs. STM4

    Hi, We are using an STM1 card for channelized E1 connectivity on a 7600 chassis. Now, we need to add support and we're looking at the STM4 for 7600s. Can we do the same on the STM4? Can't find information on the web.  Federico.

  • Using iTunes in sync with Windows Live Messenger

    According to Windows Live Messenger help you can display your iTunes song information under your personal message. I was using this, then started using Windows Media Player because I had music that was protected and would only play on Windows Media P