Using Yubikey inside RDP Session (Terminal Server)

Michael Strecker 6 Reputation points
2022-11-28T07:44:04.49+00:00

I was asked to crosspost this, so here we go:

Hello, I am currently validating Yubikey Security Keys for my business. The use case is logging in to Salesforce with MFA, but only after connecting to a Terminal Server from a Thin Client via RDP - meaning the SF-user is working on the TS, not on the local machine.

I have most possibly tried all solutions out there (RemoteFX, registry hacks, etc), but up to now, I am unable to get it to work.

For testing purposes, I have as clients

  • a Macbook Pro with a Windows 10 VM (latest build, latest patches)
  • an Intel NUC Thin Client with Windows 10 Enterprise LTSC 2021 (latest patches)

On the remote side, I have

  • a regular Win 10 VM (latest build, latest patches)
  • TS 2012 R2 (latest patches)
  • TS 2016 (latest patches)
  • TS 2019 (latest patches)

On both the Win 10 VM and the TC, I can select "Webauthn (Windows Hello or Security Key)" from "Local devices and ressources" in the RDP-Client. And indeed, it works perfectly when I connect to the regular Win 10 VM. This tells me that using the Yubikey inside a RDP session is possible after all.

The problem: It will NOT work with Terminal Servers at the remote end. I have checked group policies and allowed basically everything, but to no avail. Why does it work with a Win 10 VM, but not with Terminal Servers? Is there any way to make it work?

Any help is greatly appreciated.

Edit: I do not need Smartcard features or anything fancy, I don't need TOTP, I just need U2F to work like it does between two non-Terminal-Server-Windows-10s.

Windows for business | Windows Client for IT Pros | User experience | Remote desktop services and terminal services
0 comments No comments
{count} vote

1 answer

Sort by: Most helpful
  1. TP 146.3K Reputation points Volunteer Moderator
    2022-11-28T08:22:29.057+00:00

    Hi,

    Please test with Windows Server 2022 as your remote desktop session host server (instead of previous versions). I've not had a chance to test it with my Yubikey yet or I would give you a more definitive answer as to whether or not it works. I know the feature is in Preview for AVD, and since it lists 2022 I'm thinking it will work:

    https://learn.microsoft.com/en-us/azure/virtual-desktop/authentication#in-session-passwordless-authentication-preview

    Thanks.

    -TP


Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.