From 660c5dad75efdef0c7775cd880db577fc093d396 Mon Sep 17 00:00:00 2001 From: Zac Bergquist Date: Sat, 29 Mar 2025 16:03:08 +0100 Subject: [PATCH] docs: mention desktop support for AD and local users (#53369) --- .../desktop-access/active-directory.mdx | 2 -- .../desktop-access/getting-started.mdx | 10 +++++++++- 2 files changed, 9 insertions(+), 3 deletions(-) diff --git a/docs/pages/enroll-resources/desktop-access/active-directory.mdx b/docs/pages/enroll-resources/desktop-access/active-directory.mdx index a944a4a88d7..698ab47498c 100644 --- a/docs/pages/enroll-resources/desktop-access/active-directory.mdx +++ b/docs/pages/enroll-resources/desktop-access/active-directory.mdx @@ -644,8 +644,6 @@ To create a role for accessing Windows desktops: windows_desktop_logins: ["jsmith"] ``` - Note that user names shared between domain and local users create login conflicts. - 1. Create the role: ```code diff --git a/docs/pages/enroll-resources/desktop-access/getting-started.mdx b/docs/pages/enroll-resources/desktop-access/getting-started.mdx index 3170e6c05ea..f392eba00f3 100644 --- a/docs/pages/enroll-resources/desktop-access/getting-started.mdx +++ b/docs/pages/enroll-resources/desktop-access/getting-started.mdx @@ -70,7 +70,15 @@ $ curl.exe -fo teleport-windows-auth-setup-v(=teleport.version=)-amd64.exe https - Enables Windows to trust the Teleport certificate authority. - Installs the required dynamic link library (DLL) for Teleport to use. - Disables Network Level Authentication (NLA) for remote desktop services. - - Enables RemoteFX compression, if using Teleport version 15 or newer. + - Enables RemoteFX compression. + + In versions below Teleport 17.4.0, the Windows auth package for local users is + "greedy" and attempts to process all smart card logins. This prevents smart + card logins from outside of Teleport from working, and also makes it + impossible to use Teleport to connect as Active Directory users. This is no + longer the case with Teleport 17.4.0 and up. To connect as local users and + Active Directory users on the same host, you need to register the host twice + with Teleport, once with `ad: true` and once with `ad: false`. Note: in order for the Windows Local Security Authority (LSA) to load the Teleport DLL, [LSA protection](https://learn.microsoft.com/en-us/windows-server/security/credentials-protection-and-management/configuring-additional-lsa-protection)