dbaileyUT's avatar
dbaileyUT
Copper Contributor
Apr 30, 2022
Status:
New

Support YubiKey device across RDP

Hi,

 

It would be great if my YubiKey's FIDO2, U2F, OTP, OpenPGP 3 functionality could work inside an RDP session, specifically from macOS.

8 Comments

  • Please add support for WebAuthn redirection from the macOS client. I'm also currently stuck having to use a second device to authenticate due to being unable to use the passkeys from my Yubikey via the macOS RDP client.

  • KoosG's avatar
    KoosG
    Copper Contributor

    I'm running into similar issues! Our MacOS users cannot use FIDO2 / passkeys on authentication within our Azure Virtual Desktop environment.

     

    Now we need to hand out Windows devices to these user because of the phishing-resistant MFA strength requirements.... 😞 😞

     

    Please make sure RDP for Mac has the same features as RDP for Windows.

  • gavin390's avatar
    gavin390
    Copper Contributor

    We have this same issue on macOS. We are unable to authenticate using Fido2 over RDP due to this.

  • Ian_Haken's avatar
    Ian_Haken
    Copper Contributor

    We're running into similar issues trying to roll out WebAuthn everywhere. We've found that macOS users can run a windows VM in UTM, share a yubikey into the VM with USB passthrough, and then use RDP inside the VM to authenticate on the remote workstation. I assume there's some privileged stuff that needs to be done on the macOS host to achieve USB passthrough, but being able to use a yubikey right now through a whole macOS->VM->remote chain says to me that this should at least be technically feasible.

  • llamafilm's avatar
    llamafilm
    Copper Contributor

    My organization has recently rolled out Okta Verify which requires a Yubikey for logging into all services.  Now I'm unable to use RDP on MacOS because of this.  The Windows version of RDP works fine with USB forwarding.

  • This is a feature that is really missing for us as well, it would be important to achieve feature parity with the Windows RDP Client here.