When establishing an RDP application connection from SPP. the connection succeeds if "require host asset account" is set or enabled.
However, when the 'Require Host Asset Account' option is disabled, users are prompted to enter credentials for RDS server manually. In this scenario, the connection attempt fails, and the RDP window shows the blue splash screen displaying an 'Authorization Failed' error.
SPS logs show the following error:
[TimeStamp] [SPS_Hostname] zorp/scb_rdp[292214]: scb.info(4): (svc/2bYJVQCntHwmMkeFBTqixB/safeguard_rdp:312/stub): Plugin(aa/SGAA/main.py): [ERROR] Denied by password vault; code=400, data="[Plugin Authentication] Error authorizing session request. token:#################, sessionId: svc/############/safeguard_rdp:###, Reason: (BadRequest) {\"Code\":90508,\"Message\":\"The requested session target does not match the target of the access request.\",\"InnerError\":null} Call failed with status code 400 (Bad Request): POST https://localhost:9443/iservice/accessrequestworkflow/v4/AccessRequests/AuthorizeSession"
STATUS:
Change Request # 483394 was created to address this issue in a future release of SPP and SPS
© 2025 One Identity LLC. ALL RIGHTS RESERVED. Terms of Use Privacy Cookie Preference Center