HCHTech
Well-Known Member
- Reaction score
- 4,256
- Location
- Pittsburgh, PA - USA
I haven't run into this before, but after setting up a new computer at the office for someone, they were unable to RDP into it, credentials not accepted no matter what I tried:
enablecredsspsupport:i:0
to the RDP shortcut. In other words, NLA wasn't working over the VPN for some reason. The old office machine that this new machine replaced was Windows 10 and was not AzureAD-joined, and the worker had been using RDP-over-VPN for a couple of years successfully.
I'm glad to get it working, but not very happy disabling NLA to do so. Is there some hidden checkbox in Entra or Intune I need to check? Anything else I can try?
- Machine was AzureAD-joined (Business Premium licenses for everyone)
- Remote desktop was enabled
- Windows Hello configured with PIN login on machine
- Username for the RDP session was the Work-or-school account email address (although I also tried AzureAD\Username and AzureAD\emailaddress in desperation)
- Password was confirmed correct, Office & Sharepoint were accessed successfully on the computer with those same credentials
- Reviewed both Windows firewall and network firewall for any stupidity, none found
- Resetting both the password and the Windows Hello PIN had no impact on the problem
enablecredsspsupport:i:0
to the RDP shortcut. In other words, NLA wasn't working over the VPN for some reason. The old office machine that this new machine replaced was Windows 10 and was not AzureAD-joined, and the worker had been using RDP-over-VPN for a couple of years successfully.
I'm glad to get it working, but not very happy disabling NLA to do so. Is there some hidden checkbox in Entra or Intune I need to check? Anything else I can try?