Publishing of Windows 2016 Server RemoteApp and automatic delivery of icons to the Start Menu doens't workRemote Desktop Services Gateway IssueWindows 2008 R2 RDS - Double LoginRDS, RDWeb, and RemoteApp: How to use public certificate for launching apps on session host?RDWeb TS connection broken for some users post RemoteApp certificate changeHow to secure a Remote Application server farm to prohibit users from running unpublished applications?Windows Server 2016 Start Menu Options Disabled on Admin LoginTerminal Server 2016 RemoteApp Create Windows Installer PackageRDP from Mac failsFix Start menu in Windows 2016 with Roaming profilesWindows Server 2016 disabling shutdown and restart in the start menu
Why is C++ template use not recommended in space/radiated environment?
What game uses dice with compass point arrows, forbidden signs, explosions, arrows and targeting reticles?
Why do the “Shtei HaLechem” not play a prominent part in the davenning for Shavuos?
Why can't we feel the Earth's revolution?
Print the phrase "And she said, 'But that's his.'" using only the alphabet
What does the "titan" monster tag mean?
Why is Skinner so awkward in Hot Fuzz?
Can Mage Hand be used to indirectly trigger an attack?
How to represent jealousy in a cute way?
Past vs. present tense when referring to a fictional character
Harley Davidson clattering noise from engine, backfire and failure to start
usage of mir gefallen
Purpose of cylindrical attachments on Power Transmission towers
Are athletes' college degrees discounted by employers and graduate school admissions?
Why not make one big cpu core?
Why is gun control associated with the socially liberal Democratic party?
My parents claim they cannot pay for my college education; what are my options?
How can I find out about the game world without meta-influencing it?
French citizen, did I need a visa in 2004 and 2006 when I visited the US as a child?
Is it possible to install Firefox on Ubuntu with no desktop enviroment?
What's the reason for the decade jump in the recent X-Men trilogy?
I sent an angry e-mail to my interviewers about a conflict at my home institution. Could this affect my application?
Jam with honey & without pectin has a saucy consistency always
How to search for Android apps without ads?
Publishing of Windows 2016 Server RemoteApp and automatic delivery of icons to the Start Menu doens't work
Remote Desktop Services Gateway IssueWindows 2008 R2 RDS - Double LoginRDS, RDWeb, and RemoteApp: How to use public certificate for launching apps on session host?RDWeb TS connection broken for some users post RemoteApp certificate changeHow to secure a Remote Application server farm to prohibit users from running unpublished applications?Windows Server 2016 Start Menu Options Disabled on Admin LoginTerminal Server 2016 RemoteApp Create Windows Installer PackageRDP from Mac failsFix Start menu in Windows 2016 with Roaming profilesWindows Server 2016 disabling shutdown and restart in the start menu
.everyoneloves__top-leaderboard:empty,.everyoneloves__mid-leaderboard:empty,.everyoneloves__bot-mid-leaderboard:empty height:90px;width:728px;box-sizing:border-box;
I'm trying to setup a lab with a VM hosting all the roles for Windows 2016 Server Remote Desktop Services (CB, SH, WA) to publish few apps to be delivered to Windows 10 Professional Clients.
All machines are joined to a domain. There is an Active Directory Certification Autority installed in the domain who issued trusted certificates for all the roles of the RDS server. The certificate issued has proper Subject Name and Subject Alternate Names.
The _msradc DNS records (TXT type) point to the web feed of the published apps: https://rds.lan....biz/rdweb/feed
A Group Policy Object provide the address of the web feed to the clients:
https://rds.lan....biz/RDWeb/feed/webfeed.aspx
Indeed I checked in the registry o the client machine and under HKCUSoftwarePoliciesMicrosoftWorkspaces there is the proper value "DefaultConnectionURL". The key HKCUSoftwareMicrosoftWorkspacesFeeds is empty.
But in the Start Menu there is no RemoteApp.
If I go through the Control Panel, Manually Login to RemoteApp & Desktop, and I add input something@lan....biz I'm asked for credentials.
This is a bit surprising because:
- SSO is not effective at this level?
- how the RemoteApp can be delivered to my Start Menu automagically if the the list of those published RemoteApp (the web feed) is not accessible without prior authentication?
Because the list of RemoteApp is customized per-user it is logical that authentication is required to get this list. So I suspect there is some setting/policy to be applied so that credentials of currently logged on users are passed automatically to IIS and RDS. I hope that solving this solve also the problem of missing apps in the Start Menu.
authentication windows-server-2016 remote-desktop-services single-sign-on
add a comment |
I'm trying to setup a lab with a VM hosting all the roles for Windows 2016 Server Remote Desktop Services (CB, SH, WA) to publish few apps to be delivered to Windows 10 Professional Clients.
All machines are joined to a domain. There is an Active Directory Certification Autority installed in the domain who issued trusted certificates for all the roles of the RDS server. The certificate issued has proper Subject Name and Subject Alternate Names.
The _msradc DNS records (TXT type) point to the web feed of the published apps: https://rds.lan....biz/rdweb/feed
A Group Policy Object provide the address of the web feed to the clients:
https://rds.lan....biz/RDWeb/feed/webfeed.aspx
Indeed I checked in the registry o the client machine and under HKCUSoftwarePoliciesMicrosoftWorkspaces there is the proper value "DefaultConnectionURL". The key HKCUSoftwareMicrosoftWorkspacesFeeds is empty.
But in the Start Menu there is no RemoteApp.
If I go through the Control Panel, Manually Login to RemoteApp & Desktop, and I add input something@lan....biz I'm asked for credentials.
This is a bit surprising because:
- SSO is not effective at this level?
- how the RemoteApp can be delivered to my Start Menu automagically if the the list of those published RemoteApp (the web feed) is not accessible without prior authentication?
Because the list of RemoteApp is customized per-user it is logical that authentication is required to get this list. So I suspect there is some setting/policy to be applied so that credentials of currently logged on users are passed automatically to IIS and RDS. I hope that solving this solve also the problem of missing apps in the Start Menu.
authentication windows-server-2016 remote-desktop-services single-sign-on
add a comment |
I'm trying to setup a lab with a VM hosting all the roles for Windows 2016 Server Remote Desktop Services (CB, SH, WA) to publish few apps to be delivered to Windows 10 Professional Clients.
All machines are joined to a domain. There is an Active Directory Certification Autority installed in the domain who issued trusted certificates for all the roles of the RDS server. The certificate issued has proper Subject Name and Subject Alternate Names.
The _msradc DNS records (TXT type) point to the web feed of the published apps: https://rds.lan....biz/rdweb/feed
A Group Policy Object provide the address of the web feed to the clients:
https://rds.lan....biz/RDWeb/feed/webfeed.aspx
Indeed I checked in the registry o the client machine and under HKCUSoftwarePoliciesMicrosoftWorkspaces there is the proper value "DefaultConnectionURL". The key HKCUSoftwareMicrosoftWorkspacesFeeds is empty.
But in the Start Menu there is no RemoteApp.
If I go through the Control Panel, Manually Login to RemoteApp & Desktop, and I add input something@lan....biz I'm asked for credentials.
This is a bit surprising because:
- SSO is not effective at this level?
- how the RemoteApp can be delivered to my Start Menu automagically if the the list of those published RemoteApp (the web feed) is not accessible without prior authentication?
Because the list of RemoteApp is customized per-user it is logical that authentication is required to get this list. So I suspect there is some setting/policy to be applied so that credentials of currently logged on users are passed automatically to IIS and RDS. I hope that solving this solve also the problem of missing apps in the Start Menu.
authentication windows-server-2016 remote-desktop-services single-sign-on
I'm trying to setup a lab with a VM hosting all the roles for Windows 2016 Server Remote Desktop Services (CB, SH, WA) to publish few apps to be delivered to Windows 10 Professional Clients.
All machines are joined to a domain. There is an Active Directory Certification Autority installed in the domain who issued trusted certificates for all the roles of the RDS server. The certificate issued has proper Subject Name and Subject Alternate Names.
The _msradc DNS records (TXT type) point to the web feed of the published apps: https://rds.lan....biz/rdweb/feed
A Group Policy Object provide the address of the web feed to the clients:
https://rds.lan....biz/RDWeb/feed/webfeed.aspx
Indeed I checked in the registry o the client machine and under HKCUSoftwarePoliciesMicrosoftWorkspaces there is the proper value "DefaultConnectionURL". The key HKCUSoftwareMicrosoftWorkspacesFeeds is empty.
But in the Start Menu there is no RemoteApp.
If I go through the Control Panel, Manually Login to RemoteApp & Desktop, and I add input something@lan....biz I'm asked for credentials.
This is a bit surprising because:
- SSO is not effective at this level?
- how the RemoteApp can be delivered to my Start Menu automagically if the the list of those published RemoteApp (the web feed) is not accessible without prior authentication?
Because the list of RemoteApp is customized per-user it is logical that authentication is required to get this list. So I suspect there is some setting/policy to be applied so that credentials of currently logged on users are passed automatically to IIS and RDS. I hope that solving this solve also the problem of missing apps in the Start Menu.
authentication windows-server-2016 remote-desktop-services single-sign-on
authentication windows-server-2016 remote-desktop-services single-sign-on
asked Nov 9 '17 at 16:28
unlikelyunlikely
13818
13818
add a comment |
add a comment |
1 Answer
1
active
oldest
votes
I think I got a result. To summarize:
Windows 10 Pro v1709 seems mandatory for RemoteApp publishing through WebFeed works properly; it's very disappointing that an update is not available for previous versions of Windows 10 considering the fact WebFeed publishing is the official way of publishing RemoteApp;
in my case the update to v1709 wasn't enough; but at least some error message appeared at the event log; after reinstalling the RDWA role, things gone better;
despite what written above, the membership of RDWA server to Local Intranet Zone of Internet Explorer seems not necessary for SSO;
but it's mandatory to add "TERMSRV/*.lan.mydomain.com" to SPN list allowed for default credential passing through CredSSP;
it's also advisable to add the thumbprint of the certificate used to sign .rdp files to the proper policy.
add a comment |
Your Answer
StackExchange.ready(function()
var channelOptions =
tags: "".split(" "),
id: "2"
;
initTagRenderer("".split(" "), "".split(" "), channelOptions);
StackExchange.using("externalEditor", function()
// Have to fire editor after snippets, if snippets enabled
if (StackExchange.settings.snippets.snippetsEnabled)
StackExchange.using("snippets", function()
createEditor();
);
else
createEditor();
);
function createEditor()
StackExchange.prepareEditor(
heartbeatType: 'answer',
autoActivateHeartbeat: false,
convertImagesToLinks: true,
noModals: true,
showLowRepImageUploadWarning: true,
reputationToPostImages: 10,
bindNavPrevention: true,
postfix: "",
imageUploader:
brandingHtml: "Powered by u003ca class="icon-imgur-white" href="https://imgur.com/"u003eu003c/au003e",
contentPolicyHtml: "User contributions licensed under u003ca href="https://creativecommons.org/licenses/by-sa/3.0/"u003ecc by-sa 3.0 with attribution requiredu003c/au003e u003ca href="https://stackoverflow.com/legal/content-policy"u003e(content policy)u003c/au003e",
allowUrls: true
,
onDemand: true,
discardSelector: ".discard-answer"
,immediatelyShowMarkdownHelp:true
);
);
Sign up or log in
StackExchange.ready(function ()
StackExchange.helpers.onClickDraftSave('#login-link');
);
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
StackExchange.ready(
function ()
StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fserverfault.com%2fquestions%2f882692%2fpublishing-of-windows-2016-server-remoteapp-and-automatic-delivery-of-icons-to-t%23new-answer', 'question_page');
);
Post as a guest
Required, but never shown
1 Answer
1
active
oldest
votes
1 Answer
1
active
oldest
votes
active
oldest
votes
active
oldest
votes
I think I got a result. To summarize:
Windows 10 Pro v1709 seems mandatory for RemoteApp publishing through WebFeed works properly; it's very disappointing that an update is not available for previous versions of Windows 10 considering the fact WebFeed publishing is the official way of publishing RemoteApp;
in my case the update to v1709 wasn't enough; but at least some error message appeared at the event log; after reinstalling the RDWA role, things gone better;
despite what written above, the membership of RDWA server to Local Intranet Zone of Internet Explorer seems not necessary for SSO;
but it's mandatory to add "TERMSRV/*.lan.mydomain.com" to SPN list allowed for default credential passing through CredSSP;
it's also advisable to add the thumbprint of the certificate used to sign .rdp files to the proper policy.
add a comment |
I think I got a result. To summarize:
Windows 10 Pro v1709 seems mandatory for RemoteApp publishing through WebFeed works properly; it's very disappointing that an update is not available for previous versions of Windows 10 considering the fact WebFeed publishing is the official way of publishing RemoteApp;
in my case the update to v1709 wasn't enough; but at least some error message appeared at the event log; after reinstalling the RDWA role, things gone better;
despite what written above, the membership of RDWA server to Local Intranet Zone of Internet Explorer seems not necessary for SSO;
but it's mandatory to add "TERMSRV/*.lan.mydomain.com" to SPN list allowed for default credential passing through CredSSP;
it's also advisable to add the thumbprint of the certificate used to sign .rdp files to the proper policy.
add a comment |
I think I got a result. To summarize:
Windows 10 Pro v1709 seems mandatory for RemoteApp publishing through WebFeed works properly; it's very disappointing that an update is not available for previous versions of Windows 10 considering the fact WebFeed publishing is the official way of publishing RemoteApp;
in my case the update to v1709 wasn't enough; but at least some error message appeared at the event log; after reinstalling the RDWA role, things gone better;
despite what written above, the membership of RDWA server to Local Intranet Zone of Internet Explorer seems not necessary for SSO;
but it's mandatory to add "TERMSRV/*.lan.mydomain.com" to SPN list allowed for default credential passing through CredSSP;
it's also advisable to add the thumbprint of the certificate used to sign .rdp files to the proper policy.
I think I got a result. To summarize:
Windows 10 Pro v1709 seems mandatory for RemoteApp publishing through WebFeed works properly; it's very disappointing that an update is not available for previous versions of Windows 10 considering the fact WebFeed publishing is the official way of publishing RemoteApp;
in my case the update to v1709 wasn't enough; but at least some error message appeared at the event log; after reinstalling the RDWA role, things gone better;
despite what written above, the membership of RDWA server to Local Intranet Zone of Internet Explorer seems not necessary for SSO;
but it's mandatory to add "TERMSRV/*.lan.mydomain.com" to SPN list allowed for default credential passing through CredSSP;
it's also advisable to add the thumbprint of the certificate used to sign .rdp files to the proper policy.
edited May 29 at 18:37
yagmoth555♦
12.8k31842
12.8k31842
answered Nov 26 '17 at 16:25
unlikelyunlikely
13818
13818
add a comment |
add a comment |
Thanks for contributing an answer to Server Fault!
- Please be sure to answer the question. Provide details and share your research!
But avoid …
- Asking for help, clarification, or responding to other answers.
- Making statements based on opinion; back them up with references or personal experience.
To learn more, see our tips on writing great answers.
Sign up or log in
StackExchange.ready(function ()
StackExchange.helpers.onClickDraftSave('#login-link');
);
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
StackExchange.ready(
function ()
StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fserverfault.com%2fquestions%2f882692%2fpublishing-of-windows-2016-server-remoteapp-and-automatic-delivery-of-icons-to-t%23new-answer', 'question_page');
);
Post as a guest
Required, but never shown
Sign up or log in
StackExchange.ready(function ()
StackExchange.helpers.onClickDraftSave('#login-link');
);
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
Sign up or log in
StackExchange.ready(function ()
StackExchange.helpers.onClickDraftSave('#login-link');
);
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
Sign up or log in
StackExchange.ready(function ()
StackExchange.helpers.onClickDraftSave('#login-link');
);
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown