Windows Defender Remote Credential Guard - SSO on client machine not remote host not working when credential guard on remote client is active

Peter 6 Reputation points
2021-02-22T11:29:43.14+00:00

Surface 4 Pro Client (machine A) can connect via mstsc /remoteguard to (machine B) without entering passwords (SSO).

Inside of machine the file shares of Machine C should be accessed:

  1. Secure Boot disabled (meaning Credential Guard disabled) on machine A --> Successfully SSO connect via mstsc /remoteguard to (machine B) and inside machine B successfully opening of file shares.
  2. Secure Boot enabled (meaning Credential Guard enabled) on machine A --> Successfully SSO connect via mstsc /remoteguard to (machine B) BUT inside machine B error messages opening of file shares. "No domain controller found" (misleading) error message.

Any helpful ideas or troubleshooting steps out there?

I'm collecting experiences for an greater rollout here.

Windows 10 Security
Windows 10 Security
Windows 10: A Microsoft operating system that runs on personal computers and tablets.Security: The precautions taken to guard against crime, attack, sabotage, espionage, or another threat.
2,767 questions
{count} votes

6 answers

Sort by: Most helpful
  1. Zacharias Embaxter 35 Reputation points
    2023-05-26T20:22:22.0133333+00:00

    It seems that the problem is back.

    Logging on with RCG to Windows 11 22H2 (from Win10 or Win11 doesn’t matter) is possible with SSO, but then you cannot connect from that system to e.g. a network share with SSO.

    Connecting to Win10 via RCG and further still works how it should.

    cu…

    Zetup

    0 comments No comments