When the Primary SPP appliance in a multi-node SPP cluster is unexpectedly shut down, SPP-initiated RDP sessions launched from replica appliances may fail with the following error: Authentication Failed
This can occur even when:
- The remaining replica appliances are online.
- The cluster state is reported as ReplicaWithQuorum.
- SPS is healthy and reachable.
- Session requests are initiated from a replica appliance.
Analysis showed that SPP may continue to select the former Primary appliance as the vault address for session launches because appliance fitness scores are cached. As a result, the generated connection string may contain the IP address of the offline Primary appliance, causing SPS authentication requests to fail.
STATUS
Enhancement Request #710968 has been created to address this issue in a future release of Safeguard for Privileged Passwords (SPP), subject to successful QA testing and product management approval.
Workaround
Allow sufficient time for appliance fitness score recalculation after the Primary appliance becomes unavailable. Once the fitness scores are refreshed (typically after approximately 8 minutes), SPP should begin selecting an available replica appliance and new RDP session launches should succeed.
© 2026 One Identity LLC. ALL RIGHTS RESERVED. Terms of Use Privacy Cookie Preference Center