diff --git a/docs/pages/enroll-resources/desktop-access/active-directory.mdx b/docs/pages/enroll-resources/desktop-access/active-directory.mdx index a944a4a88d7..698ab47498c 100644 --- a/docs/pages/enroll-resources/desktop-access/active-directory.mdx +++ b/docs/pages/enroll-resources/desktop-access/active-directory.mdx @@ -644,8 +644,6 @@ To create a role for accessing Windows desktops: windows_desktop_logins: ["jsmith"] ``` - Note that user names shared between domain and local users create login conflicts. - 1. Create the role: ```code diff --git a/docs/pages/enroll-resources/desktop-access/getting-started.mdx b/docs/pages/enroll-resources/desktop-access/getting-started.mdx index 3170e6c05ea..f392eba00f3 100644 --- a/docs/pages/enroll-resources/desktop-access/getting-started.mdx +++ b/docs/pages/enroll-resources/desktop-access/getting-started.mdx @@ -70,7 +70,15 @@ $ curl.exe -fo teleport-windows-auth-setup-v(=teleport.version=)-amd64.exe https - Enables Windows to trust the Teleport certificate authority. - Installs the required dynamic link library (DLL) for Teleport to use. - Disables Network Level Authentication (NLA) for remote desktop services. - - Enables RemoteFX compression, if using Teleport version 15 or newer. + - Enables RemoteFX compression. + + In versions below Teleport 17.4.0, the Windows auth package for local users is + "greedy" and attempts to process all smart card logins. This prevents smart + card logins from outside of Teleport from working, and also makes it + impossible to use Teleport to connect as Active Directory users. This is no + longer the case with Teleport 17.4.0 and up. To connect as local users and + Active Directory users on the same host, you need to register the host twice + with Teleport, once with `ad: true` and once with `ad: false`. Note: in order for the Windows Local Security Authority (LSA) to load the Teleport DLL, [LSA protection](https://learn.microsoft.com/en-us/windows-server/security/credentials-protection-and-management/configuring-additional-lsa-protection)