mirror of
https://github.com/gravitational/teleport.git
synced 2026-09-24 16:17:11 +08:00
docs: mention desktop support for AD and local users (#53369)
This commit is contained in:
@@ -644,8 +644,6 @@ To create a role for accessing Windows desktops:
|
||||
windows_desktop_logins: ["jsmith"]
|
||||
```
|
||||
|
||||
Note that user names shared between domain and local users create login conflicts.
|
||||
|
||||
1. Create the role:
|
||||
|
||||
```code
|
||||
|
||||
@@ -70,7 +70,15 @@ $ curl.exe -fo teleport-windows-auth-setup-v(=teleport.version=)-amd64.exe https
|
||||
- Enables Windows to trust the Teleport certificate authority.
|
||||
- Installs the required dynamic link library (DLL) for Teleport to use.
|
||||
- Disables Network Level Authentication (NLA) for remote desktop services.
|
||||
- Enables RemoteFX compression, if using Teleport version 15 or newer.
|
||||
- Enables RemoteFX compression.
|
||||
|
||||
In versions below Teleport 17.4.0, the Windows auth package for local users is
|
||||
"greedy" and attempts to process all smart card logins. This prevents smart
|
||||
card logins from outside of Teleport from working, and also makes it
|
||||
impossible to use Teleport to connect as Active Directory users. This is no
|
||||
longer the case with Teleport 17.4.0 and up. To connect as local users and
|
||||
Active Directory users on the same host, you need to register the host twice
|
||||
with Teleport, once with `ad: true` and once with `ad: false`.
|
||||
|
||||
Note: in order for the Windows Local Security Authority (LSA) to load the Teleport DLL,
|
||||
[LSA protection](https://learn.microsoft.com/en-us/windows-server/security/credentials-protection-and-management/configuring-additional-lsa-protection)
|
||||
|
||||
Reference in New Issue
Block a user