docs: mention desktop support for AD and local users (#53369)

This commit is contained in:
Zac Bergquist
2025-03-29 15:03:08 +00:00
committed by GitHub
parent d002d1e43a
commit 660c5dad75
2 changed files with 9 additions and 3 deletions
@@ -644,8 +644,6 @@ To create a role for accessing Windows desktops:
windows_desktop_logins: ["jsmith"]
```
Note that user names shared between domain and local users create login conflicts.
1. Create the role:
```code
@@ -70,7 +70,15 @@ $ curl.exe -fo teleport-windows-auth-setup-v(=teleport.version=)-amd64.exe https
- Enables Windows to trust the Teleport certificate authority.
- Installs the required dynamic link library (DLL) for Teleport to use.
- Disables Network Level Authentication (NLA) for remote desktop services.
- Enables RemoteFX compression, if using Teleport version 15 or newer.
- Enables RemoteFX compression.
In versions below Teleport 17.4.0, the Windows auth package for local users is
"greedy" and attempts to process all smart card logins. This prevents smart
card logins from outside of Teleport from working, and also makes it
impossible to use Teleport to connect as Active Directory users. This is no
longer the case with Teleport 17.4.0 and up. To connect as local users and
Active Directory users on the same host, you need to register the host twice
with Teleport, once with `ad: true` and once with `ad: false`.
Note: in order for the Windows Local Security Authority (LSA) to load the Teleport DLL,
[LSA protection](https://learn.microsoft.com/en-us/windows-server/security/credentials-protection-and-management/configuring-additional-lsa-protection)