When the Remote Desktop Connection (RDC) 7.0 client is used to connect through the RD Gateway, you receive the following error message:
Remote Desktop can�t connect to the remote computer "<End Resource Name>" for one of these reasons:
1) Your user account is not authorized to access the RD Gateway "<RD Gateway Server Name>"
2) Your computer is not authorized to access the RD Gateway "<RD Gateway Server Name>"
3) You are using an incompatible authentication method (for example, the RD Gateway might be expecting a smart card but you provided a password)
1) Your user account is not authorized to access the RD Gateway "<RD Gateway Server Name>"
2) Your computer is not authorized to access the RD Gateway "<RD Gateway Server Name>"
3) You are using an incompatible authentication method (for example, the RD Gateway might be expecting a smart card but you provided a password)
Terminal Services connection authorization policy (TS CAP) is preventing connection to the remote computer through TS Gateway, possibly due to one of the following reasons:
* You do not have permission to connect to the TS Gateway server.
* You used password authentication but the TS Gateway server is expecting smart card authentication (or vice versa).
* You do not have permission to connect to the TS Gateway server.
* You used password authentication but the TS Gateway server is expecting smart card authentication (or vice versa).
A sample scenario
Definitions of terms that are used in the following sections
- A foreign user or group: A user or security group that belongs to one domain (domain B) and that is included as a member of a security group that is defined in another domain (domain A).
- A CAP root group: A security group that is included in the RD Gateway Connection Authorization Policy (RD CAP).
Configuration
To authorize users who belong to a cross-forest user group, you must add the cross-forest user group directly as one of the authorized user groups in the RD Gateway CAP policy.To authorize specific foreign users and not all users in a foreign group, you must add the users directly to universal groups in the RD Gateway domain.
For example, suppose that there is a Domain Local security group that is known as �CAP_root,� and this security group is created in domain A. This group is added as an authorized user group in the RD CAP.
The CAP_root security group has the following users and groups from domain A and domain B as its members:
Members of �CAP_root� security group | Description |
---|---|
UserA | User from domain A |
UserB | User from domain B |
GroupA | Security group that was created in domain A and that contains users from domain A |
GroupB | Security group that was created in domain B and that contains users from domain B |