Home

Remote App strange behavior with saved credentials

%3CLINGO-SUB%20id%3D%22lingo-sub-180691%22%20slang%3D%22en-US%22%3ERemote%20App%20strange%20behavior%20with%20saved%20credentials%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-180691%22%20slang%3D%22en-US%22%3E%3CP%3EThis%20problem%20has%20confused%20me%20for%20awhile%20now%2C%20and%20I%20haven't%20been%20able%20to%20find%20any%20solution.%3C%2FP%3E%3CP%3EI'm%20not%20sure%20if%20this%20is%20an%20issue%20with%20the%20mstsc.exe%20on%20the%20client%2C%20or%20if%20it's%20an%20issues%20server%20side%20at%20this%20point.%3C%2FP%3E%3CP%3EThe%20bottom%20line%20issue%2C%20is%20that%20the%20%22Remember%20me%22%20checkbox%20for%20the%20remote%20app%20credentials%20will%20stop%20showing%20up%2C%20preventing%20the%20user%20from%20saving%20his%20or%20her%20credentials%20for%20the%20remote%20app%20connection.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ESo%2C%20here's%20the%20scenario.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20have%20a%20Windows%20Server%202016%20environment%2C%20with%20it's%20own%20domain%20that%20provides%20access%20to%20applications%20to%20remote%20clients%20via%20Remote%20App%20services.%3C%2FP%3E%3CP%3EJoining%20the%20clients%20to%20the%20domain%20isn't%20an%20option.%3C%2FP%3E%3CP%3EWe%20have%20a%20publicly%20trusted%20certificate%20deployed%20in%20our%20Remote%20App%20servers.%3C%2FP%3E%3CP%3EWhen%20we%20setup%20a%20client%20machine%2C%20we%20do%20so%20through%20the%20Remote%20App%20and%20Desktop%20Connections%20control%20panel%20app%2C%20and%20enter%20the%20RDweb%20url.%3C%2FP%3E%3CP%3EThe%20client%20machines%20are%20a%20mix%20of%20Windows%207%20machines%20to%20Windows%2010.%3C%2FP%3E%3CP%3EWhen%20we%20give%20the%20users%20their%20credentials%2C%20it's%20always%20in%20the%20format%20of%20%3CUSERNAME%3E%40%3CDOMAIN%20name%3D%22%22%3E%20not%20%3CDOMAIN%20name%3D%22%22%3E%5C%3CUSERNAME%3E%3C%2FUSERNAME%3E%3C%2FDOMAIN%3E%3C%2FDOMAIN%3E%3C%2FUSERNAME%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWhen%20we%20initially%20setup%20the%20client%20machine%2C%20usually%20the%20user%20will%20save%20his%20credentials.%20Which%20is%20fine.%3C%2FP%3E%3CP%3EHowever%2C%20when%20their%20password%20expires%2C%20or%20when%20they%20want%20to%20change%20it%20through%20the%20web%20interface%2C%20things%20get%20weird.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWhen%20everything%20is%20working%20fine%2C%20in%20the%20windows%20credential%20manager%20there%20are%20two%20entries%2C%20both%20in%20the%20Windows%20Credentials%20section.%3C%2FP%3E%3CP%3E1)%20%3CPUBLIC%20fqdn%3D%22%22%20of%3D%22%22%20remote%3D%22%22%20app%3D%22%22%20collection%3D%22%22%3E%26nbsp%3B%20with%20the%20username%20in%20the%20format%20of%20%3CUSERNAME%3E%40domainname%26gt%3B%3C%2FUSERNAME%3E%3C%2FPUBLIC%3E%3C%2FP%3E%3CP%3E2)%20TERMSRV%2F%3CPUBLIC%20fqdn%3D%22%22%20of%3D%22%22%20remote%3D%22%22%20app%3D%22%22%20collection%3D%22%22%3E%20with%20the%20username%20in%20the%20format%20of%20%3CUSERNAME%3E%40domainname%26gt%3B%3C%2FUSERNAME%3E%3C%2FPUBLIC%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWhen%20the%20users%20change%20their%20passwords%20via%20the%20RDWeb%20portal%20page%2C%20obviously%20it%20doesn't%20update%20their%20saved%20credentials.%26nbsp%3B%3C%2FP%3E%3CP%3EThe%20expectation%20would%20be%20that%20the%20remote%20desktop%20client%20would%20prompt%20them%20for%20their%20new%20password%2C%20with%20the%20option%20to%20save%20it%2C%20as%20how%20it%20was%20when%20it%20was%20originally%20setup.%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAnd%20this%20is%20what%20happens%2C%20some%20times.%3C%2FP%3E%3CP%3EThey%20get%20prompted%20for%20their%20password%2C%20with%20a%20screen%20that%20shows%20them%20their%20username%20in%20the%20%3CDOMAIN%3E%5C%3CUSERNAME%3E%20format%2C%20with%20the%20remember%20me%20box.%3C%2FUSERNAME%3E%3C%2FDOMAIN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EEventually%20though%2C%20it%20will%20break.%20And%20this%20is%20100%25%20repeatable%20by%20changing%20the%20password%20on%20the%20AD%20side%2C%20and%20trying%20to%20conenct%20again%20from%20the%20client.%3C%2FP%3E%3CP%3EAt%20some%20point%2C%20one%20of%20those%20times%20they%20change%20their%20password%2C%20they%20will%20be%20prompted%20for%20their%20new%20password%20with%20a%20credential%20screen%20with%20no%20remember%20me%20box.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWhen%20it%20does%20this.%20if%20you%20look%20in%20the%20credential%20manager%2C%20there%20will%20be%203%20entries.%3C%2FP%3E%3CP%3EWindows%20Credentials%3A%3C%2FP%3E%3CP%3ETERMSRV%2F%3CRDSESSIONHOST%20fqdn%3D%22%22%3E%20with%20username%20in%20%3CDOMAIN%20name%3D%22%22%3E%5C%3CUSERNAME%3E%20format%3C%2FUSERNAME%3E%3C%2FDOMAIN%3E%3C%2FRDSESSIONHOST%3E%3C%2FP%3E%3CP%3ETERMSRV%2F%3CPUBLIC%20fqdn%3D%22%22%20of%3D%22%22%20remote%3D%22%22%20app%3D%22%22%20collection%3D%22%22%3E%26nbsp%3B%26nbsp%3B%20with%20the%20username%20in%20the%20format%20of%20%3CUSERNAME%3E%40domainname%26gt%3B%3C%2FUSERNAME%3E%3C%2FPUBLIC%3E%3C%2FP%3E%3CP%3EGeneric%20Credentials%3A%3C%2FP%3E%3CP%3ETERMSRV%2F%3CPUBLIC%20fqdn%3D%22%22%20of%3D%22%22%20remote%3D%22%22%20app%3D%22%22%20collection%3D%22%22%3E%26nbsp%3B%26nbsp%3Bwith%20username%20in%20%3CDOMAIN%20name%3D%22%22%3E%5C%3CUSERNAME%3E%20format%3C%2FUSERNAME%3E%3C%2FDOMAIN%3E%3C%2FPUBLIC%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAfter%20this%20happens%2C%20the%20users%20will%20never%20get%20the%20remember%20me%20box%20again%2C%20unless%20they%20completely%20delete%20the%20session%20from%20their%20control%20panel%2C%20and%20re-add%20it.%3C%2FP%3E%3CP%3EManually%20fixing%20the%20credentials%20in%20the%20credential%20manager%20to%20make%20them%20match%20how%20they%20were%20when%20it%20was%20working%20fine%20works%20temporarily%2C%20but%20will%20break%20again%20next%20time%20they%20reboot%20their%20computer%2C%20or%20the%20session%20disconnects%20from%20the%20servers.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%E2%80%99m%20not%20sure%20what%20to%20do%20with%20this%20next.%3C%2FP%3E%3CP%3EIf%20anyone%20has%20any%20ideas%2C%20it'd%20be%20greatly%20appriciated.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-180691%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3ERemote%20Desktop%20Services%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EWindows%20server%202016%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E
Robert Lawton
New Contributor

This problem has confused me for awhile now, and I haven't been able to find any solution.

I'm not sure if this is an issue with the mstsc.exe on the client, or if it's an issues server side at this point.

The bottom line issue, is that the "Remember me" checkbox for the remote app credentials will stop showing up, preventing the user from saving his or her credentials for the remote app connection.

 

So, here's the scenario.

 

I have a Windows Server 2016 environment, with it's own domain that provides access to applications to remote clients via Remote App services.

Joining the clients to the domain isn't an option.

We have a publicly trusted certificate deployed in our Remote App servers.

When we setup a client machine, we do so through the Remote App and Desktop Connections control panel app, and enter the RDweb url.

The client machines are a mix of Windows 7 machines to Windows 10.

When we give the users their credentials, it's always in the format of <username>@<domain name> not <domain name>\<username>

 

When we initially setup the client machine, usually the user will save his credentials. Which is fine.

However, when their password expires, or when they want to change it through the web interface, things get weird.

 

When everything is working fine, in the windows credential manager there are two entries, both in the Windows Credentials section.

1) <public FQDN of remote app collection>  with the username in the format of <username>@domainname>

2) TERMSRV/<public FQDN of remote app collection> with the username in the format of <username>@domainname>

 

When the users change their passwords via the RDWeb portal page, obviously it doesn't update their saved credentials. 

The expectation would be that the remote desktop client would prompt them for their new password, with the option to save it, as how it was when it was originally setup. 

 

And this is what happens, some times.

They get prompted for their password, with a screen that shows them their username in the <domain>\<username> format, with the remember me box.

 

Eventually though, it will break. And this is 100% repeatable by changing the password on the AD side, and trying to conenct again from the client.

At some point, one of those times they change their password, they will be prompted for their new password with a credential screen with no remember me box.

 

When it does this. if you look in the credential manager, there will be 3 entries.

Windows Credentials:

TERMSRV/<RDSessionHost FQDN> with username in <domain name>\<username> format

TERMSRV/<public FQDN of remote app collection>   with the username in the format of <username>@domainname>

Generic Credentials:

TERMSRV/<public FQDN of remote app collection>  with username in <domain name>\<username> format

 

After this happens, the users will never get the remember me box again, unless they completely delete the session from their control panel, and re-add it.

Manually fixing the credentials in the credential manager to make them match how they were when it was working fine works temporarily, but will break again next time they reboot their computer, or the session disconnects from the servers.

 

I’m not sure what to do with this next.

If anyone has any ideas, it'd be greatly appriciated.

Related Conversations
Extentions Synchronization
Deleted in Discussions on
3 Replies
Tabs and Dark Mode
cjc2112 in Discussions on
35 Replies
Stable version of Edge insider browser
HotCakeX in Discussions on
35 Replies
flashing a white screen while open new tab
Deleted in Discussions on
14 Replies
How to Prevent Teams from Auto-Launch
chenrylee in Microsoft Teams on
29 Replies