Getting rid of the RDC certificate warnings
Upgrade RDS Connection Broker to Windows Server 2016
Hello, I tried to research this, but Microsoft (or anyone else) doesn't seem to have to much info on this. https://technet.microsoft.com/en-us/windows-server-docs/compute/remote-desktop-services/upgrade-to-rds-2016 only states that Connection Brokers must be upgraded first; it doesn't state if they should be new servers, upgrades, etc.
I have an HA RDCB Farm (2 Servers) both running Windows Server 2012 R2. What is the correct way to start getting to server 2016. Typically, I try to rebuild new servers and migrate, but not sure if that is the case or recommended with RDCB? Is the recommended method to just upgrade the servers in place? Is there a supported method to do this with new servers?
Anyone have any insight? Thanks!
login failure: unknown user name or bad password
Hi,
I am facing a chalenging situation.
In a windows 2012 RDS Farm i have published a group of applications and have provided them to users via RemoteApps and via Web Access.
This is working for long time without any issues for 100+ users.
This week a user got a new laptop and I tried to configure the RemoteApps again.
After providing the URL and giving the account's credentials I get the following:
I checked everything about Access Rights and I found no issues there.
This is confirmed also by 2 facts:
The user has still the RemoteApps working on his old laptop.
User is able to access the application via Web Access URL with no problems
A day later another user got the same issue when trying to configure the RemoteApps on his new laptop. Same description applies for second user.
I guess i will be having more incidents like this soon.
------------------------------------------------
Environment details:
RDS Farm
1x Broker [2012]
2x RDHS [2012]
Client devices are Win7
-----------------------------------------------
Do you have any ideas where to look for a solution or even identify the issue?
The error message is about misauthentication but RemoteApps are working on old laptops and via Web Access....
How to setup passwordless connection like ssh between windows servers
Dear all,
I have two servers (Windows Server 2012), I need to setup passwordless connections between them. I downloaded Cygwin and Putty to generate authorized_keys and private keys, but I am still unable to connect to either one using this ssh setup.
Can anyone share his/her experience on how to setup passwordless connections between two Windows servers?
Thanks,
Wujee
Web Application Proxy and RDS Server - Authorization policy being ignored
I have set up a RDS server which uses Azure MFA. Everytime I connect to the box and try to connect to one of the web apps that I have published. It basically returns an error and will not connect, the error in the event logs states
The user "xxxx\user" on client computer "192.168.100.50" did not meet resource authorization policy requirements and was therefore not authorised to resource "rdg.xxx.com" The following error occurred.
I have set an authorisation policy to state allow this client computer which is our Web Application Proxy server to be able to connect but it as if the authorization policy is being ignored?
Has anyone else come across this before?
2012 R2 Server with Roaming Profiles - Some Systems Fail to Find or synchronize Roaming Profile
I have a roaming profile on a Windows 2012 R2 Active Directory Server.
When I Remote Desktop into some systems (ie Hypervisor1 - 2012 Physical Box) I get an Application User Profile Service event ID 1511 message:
- Windows cannot find the local profile and is logging you on with a temporary profile. Changes you make to this profile will be lost when you log off.
When I Remote Desktop into other systems (ie management - 2012 virtual box) everything works fine.
On yet other systems when I Remote Desktop (or connect via Hyper-V console) I get an event ID 1540 message:
- Your roaming profile is not synchronized correctly with the server. Windows will load your previously-saved local profile instead. See the previous events for details.
I tried this procedure which is loosely related with no success:
- https://support.microsoft.com/en-au/kb/947215
Any suggestions will be greatly appreciated!
'Allow New Connections' - change logon /enable | /disable | /query
Hi All
Does RDS Server Manager > Collection Name > Host Servers > Allow New Collections effect the traditional TS key on host servers as this command would have traditionally CMD > change logon /enable | /disable | /query :
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows
NT\CurrentVersion\Winlogon]
"WinStationsDisabled"="0" / "1"
Or does it simply inform the RDCB?
Reason I ask is this reg key doesn't appear to change and I'm not sure if it should or something's broken!
Thanks
Lea
Revoke RDS CAL from powershell or and command
I am trying to use powershell to query all the LicenseID and the ones that come up as unknown send a revoke command.
I have everything ready up to the revoke part. i cannot find a revoke command . i saw this on a site but now sure how to implement it :
Win32_TSIssuedLicense:
Windows Server 2008 has a WMI class named "Win32_TSIssuedLicense" for managing issued per device CALs. This WMI class provides the following interface to manually revoke issued CALs:
Revoke: This API can be used to manually revoke an issued CAL. This is a not a static function.
The syntax of the API is
uint32 Revoke(
[out] uint32 RevokableCals,
[out] DATETIME NextRevokeAllowedOn );
Windows 2012R2 RDS hangs on (4) users
I see Citrix users are experiencing, that 4 process hangs on session limit time out GPO when it is enabled. They have a hotfix for their VDA environment.
We have the same problem on our RDS farm that just got fully patched.
The issue is still present on the farms. A solution to disable the GPO can´t be done. Because of the session broker, doesn't like disconnected sessions for a longer period. Then it doesn't get re-connected to the session, but rather the user
get's a new session and temp profile.
This is how the issue looks like. The RDS server needs a power cycle before it is okay again. You can't sign users out either, tried on may different ways. And the users can not sign in while their session/process hangs.
I can't seem to find any patch or hotfix for this.
Have anyone else run into the problem and have anything to share about a fix or resolution to it. Anything would will be highly appreciate.
Regards
Adam Andersen
Remote App window stays minimized
your password cannot be changed. please contact your administrator for assistance RDWEB 2012 R2
I activate today on our RDweb Server (server 2012 R2) the ablility to reset user's password following the link here:
http://social.technet.microsoft.com/wiki/contents/articles/10755.enabling-the-rd-webaccess-expired-password-reset-option-in-windows-server-2012.aspx
the page is active and a link was inserted on the main page of the RDweb, but when I try to reset a expired user's password, I receive the following message:
Your password cannot be changed. Please contact your administrator for assistance.
I found KB2793072 regarding this issue https://support.microsoft.com/en-us/kb/2793072 , but it's only valid for Server 2008R2 or Server 2012.
No clue at all of what's happening here.
The server is e member server of our domain, the message happen for evey reset password attemps (expired or not)
Any help woud be appreciated.
Remote Desktop Services has taken too long to load the user configuration from server Event ID 20499
I keep getting Event ID 20499 "Remote Desktop Services has taken too long to load the user configuration from server \\SERVERNAME for user USERNAME" in our event logs for multiple servers that are running 2012 R2
I noticed that when this happens the user often is missing items that get applied via group policies such as desktop wallpapers and mapped drives.
I am also using the Microsoft Remote Desktop for Mac that was release yesterday on another Mac computer and for certain users it won't launch the redirected folder that I specified when I get this Event ID 20499
Disable Dynamic DPI Scaling
I have some older applications being distributed via RemoteApp that don't handle DPI scaling very well, while it isn't terrible, they appear somewhat fuzzy and it tends to drive the users crazy. I know that RDP 8.1 will scale the RemoteApps according to the users DPI settings on the connecting machine, however all the user machines are set to 100% (no scaling) and the resolutions actually aren't that high.
Is there a way to disable some of the new RDP 8.1 display optimizations via the server side so I can get the app to look normal? The app looks just fine when loaded directly on the user machine and is only fuzzy over RDP.
Thanks for any suggestions.
Jay Schwegler
Win CE 6.1 device no longer able to login to Server 2016 RDS
I can no longer connect through the handheld, after I activated RDS CALs. It worked fine when it was in "trial" mode, prior to activation.
I have tried reducing security levels and disabling NLA. I can login to Server 2016 RDS from a different desktop using the same user account.
Cannot RDP to Server 2012 R2
Dear All,
Anyone has any idea on how to resolve this?
It is already a member of Remote Desktop Users
RDP getting logged out automatically after sucessful login
Hi All,
I am having a windows server 2012 standard r2 installed on a Dedicated machine.For few days when i try to login via RDP it shows successful login and goes to "Waiting for Local session Manager"
then suddenly throws me out.
Waiting for your help.
Mix different OS for RDSH in RDS deployment?
Hi. Is it possible to mix different OS versions in a single RDS deployment? Say we want to install new RDS deployment based on WS2016 (RDCB, RDWA and at least one RDSH). Is it possible to add 2012R2 RDSH to this deployment (and session collection)? Ie. mixing WS2012R2 and WS2016 as RDSH servers.
Apologies if this is answered elsewhere, but I couldn't find this info.
Thank you in advance
Microsoft recommended design for publishing RemoteApp only to internet
Requirement : Remoteapp only to be published to internet with SSO- using Server 2012 RS / 2016
Without RD gateway
1. Do we need a RDGateway still or can we manage with only RD Webaccess role . i.e. Reverseproxy (from DMZ) just RDS WebAccess (internal domain joined network)
If RD gateway is required
2. Forest trust model: One-way trust between the perimeter network AD DS and the internal network AD DS. RDG is joined to perimeter AD DS.
Does it work? researched to find "RD Gateway is not supported in one-way forest trust AD DS model. This is because RD Gateway wont be able to check for user group membership in RAP. Hence one gets a RAP failure with domain user." your feedback pls
3. Extended corporate forest model: Can we leverage ADFS already in DMZ/perimeter, instead of allowing ports from DMZ to internal AD or even placing RODC
Is it possible?any article which can be referred
Best recommended Design on RDSGateway/RDS Webaccess placement
4. Like Lync Edge server which is in DMZ and on workgroup .Has there been any improvement on server 2016 RDS Gateway which can work on workgroup?
or for SSO do we still have a dependency RDS Gateway to be Internal AD DS joined
5. Currently Best RDS design from what I could gather seems to have all RDS farm internal AD DS joined and in internal network.Have DMZ Reverseproxy pass on the traffic to RD Gateway.Is there a better approach that I am missing
(most of the articles are'nt updated I still find is on majorly referring to server 2008 R2 ,very few on 2012,almost none on 2016.)
Your suggestion is greatly valued
Start Screen Layout on Server 2012 R2
I am trying to set a specific start screen layout for a remote users group. I have created a group policy assigned to the Organizational Unit 'remotes'.
I logged in as a remote user and edited the start screen to my liking. Then I used Powershell to export the XML of the start screen layout. I then logged back in as an administrator user.
I changed the Start Screen Layout under User Configuration (UC -> Policies -> Admin Templates -> Start Menu and Taskbar -> Start Screen Layout). I entered the path of XML file I had exported.
I ran [gpupdate /force], then logged back in as the remote user but the start layout does not reflect the change.
This server does not have Remote Desktop Session Host Role Service installed. Is that necessary for this to work? I don't recall needing it for previous servers I have set up on 2012R2, but I can't figure out what else could be wrong here.
Here is a link to the group policy report (exceeds 60,000 characters so I cannot include as HTML here):Remote User Group Policy Report
we haven't able login server using RDP connection
we haven't able login server using RDP , upon checking server with another source RDP enable and required services running fine.
what would be the reason ,is there any one have idea please share.
Thanks in advance!