Forum Discussion

Axians_CSS's avatar
Axians_CSS
Copper Contributor
Mar 01, 2019

Grant B2B users access to on-premise RDS servers (apps)

Hi there,

 

I've been looking for this issue on the internet, but can't really find a good answer or solution. We have a on-premise (iaas) 2016 RDS (mainly remoteapp) solution that we would like to share with other companies. Basicly through RDWeb. This is no problem when we give them user accounts from our RDS domain. But more and more often they want SSO with there own user accounts (AzureAD, ADFS, etc). I know we can make it work with a domain trust, but that is something usually out of the question. Begin 2018 we have been looking at the Azure B2B connector and publishd the RDWeb with the AD application proxy. (https://docs.microsoft.com/nl-nl/azure/active-directory/b2b/hybrid-cloud-to-on-premises). With a shadow account we could make it possible to access SSO to the RDWeb, but from there, starting remote apps, desktop wasn't possible. So ... the question is? Is this possible? SSO for external (other domains) access to our RDS solution? Anyone got a simular situation or some kind of direction? I know Citrix has a simular solution with FAS and b2b, but we would rather stick with a Microsoft only solution. Thx! 

  • I can't tell you if and how well it works with RDS but for other apps I got this working. You can create shadow accounts in your AD with matching UPNs and use KCD at the AppProxy.
    The trick is to use the UPN of the guest account in the format name_domain#EXT@tenant.onmicrosoft.com

    In my case the users don't need to know the passwords of their OnPrem AD user and we can deny interactive logons. In combination with the restrictions for guest users in the tenant the design is increasing security.
    • Axians_CSS's avatar
      Axians_CSS
      Copper Contributor

      Thx for the reply! Nice to hear that it could work for on-premise applications. It has been almost a year ago that we tried this solution with RDS, maybe things have been improved. 

  • JM_Tech's avatar
    JM_Tech
    Copper Contributor

    Axians_CSS  did you get this to work? still trying? or not possible? as you pointed out would be great to be able to use something like AD B2B to provide RDS based desktops and apps to external partners and let them manage their own password resets etc. Cheers!

    • Axians_CSS's avatar
      Axians_CSS
      Copper Contributor

      Hi JM_Tech, no but it has been a while that we tested this. For now we just have to live with it that we manage seperate accounts. But this gives lots of extra support calls. So like you said it would be great if a full SSO solution is possible. Partners, etc can then just manage their own accounts. When i have some time i will try to test this again. 

Resources