RESOLUTION:
1. Upgrade SPP and SPS to version 8.2.2 which will include support for RDP Kerberos authentication for SPP initiated sessions.
2. SPS needs to be joined to the Domain
3. Create a new SPS RDP Settings policy that is configured with Kerberos authentication and link it to the RDP connection policy.
Enabling Kerberos Authentication: Use this option to connect to RDP servers that support Kerberos authentication. Kerberos is the preferred option and considered more secure than the authentication provided by the Server logon screen option or NTLM.
NOTE: When enabling Kerberos authentication for SPP initiated sessions, note that:
- The Require domain authentication option is not selected.
- You cannot select both NTLM and Kerberos authentication at the same time.
- SPS has to forward the incoming service ticket to the required target server. Therefore, the referrer connection policy has to use inband target selection.
- The Act as Remote Desktop Gateway option cannot be selected for the referrer connection policy.
WORKAROUND
For older versions of SPP and SPS
- None, users will need to be removed from the "Protected Users" AD group to be able to authenticate using NTLM