SSO (SAML) with Entra for Webinterface
Hello TSplus Team,
our goal is a real SSO solution for customers with Microsoft 365 / Entra.
We achieved this partial with the Connection Client.
The problem
The load-balancing decision happens before the user has signed in, so at that point the Connection Client doesn't know who the user is:
With Enable Windows SSO, the client sends the local Windows user name of the workstation. That name has nothing to do with the account that later signs in through Entra ID. Sticky Sessions look for the wrong user and never resume a disconnected session.
With
*SSO, the user enters their AD user name and a dummy password once (firststart) and the client stores them on the workstation. This breaks sticky sessions on workplaces with one local user (autologon) and on a rename (i.e. User changes surname because of a wedding)Proposal
Move the Entra ID sign-in in front of the load-balancing decision:
The Connection Client starts a sign-in at the Gateway / Web Portal using SAML or OpenID Connect against Entra ID. This would build on the web portal SSO you are already developing.
Now that the user's identity is known (UPN → on-prem account via
onPremisesSamAccountName), the Gateway evaluates load balancing and Sticky Sessions for the correct user.The Gateway hands the chosen session host to the Connection Client.
The client connects to that host with Entra ID authentication. As today, the host receives the Entra RDP token and exchanges it for a Kerberos ticket.
Bonus: Reverse Proxy together with Entra ID
Today Entra ID authentication only works with the Reverse Proxy turned off. Every session host therefore needs its own public DNS name, port or public IP. The Reverse Proxy could carry the connection through the Gateway while keeping the session host as the RDP target, the way Microsoft RD Gateway does (the session host stays in
full address). Entra token and certificate would then match again. Only the Gateway would be exposed to the internet: fewer open ports and a smaller attack surface.

Log in to comment and vote
No comments yet
Be the first to share your thoughts.