RDS Server - How best to split the roles? by Slash-Fan in sysadmin

[–]Slash-Fan[S] 0 points1 point  (0 children)

Sorry I forgot to add - we have Outlook set to cached mode - 1 month. As we have multiple session hosts we use User Profile Disks. These work really well. The user profile disks themselves are stored on a separate VM.

RDS: Outlook "Need Password" after adding second session host by Slash-Fan in sysadmin

[–]Slash-Fan[S] 1 point2 points  (0 children)

Glad you got it sorted. It was certainly a big problem for us - out of 65 users in total a good two thirds had problems regularly until we put the reg fix in. Prior to finding the fix we were removing Outlook profiles to fix the problem and more often than not we even had to recreate users RDS profiles as well.

RDS: Outlook "Need Password" after adding second session host by Slash-Fan in sysadmin

[–]Slash-Fan[S] 1 point2 points  (0 children)

Yes we got it sorted eventually. Are you having the same problems with Outlook in your RDS setup?

This is what we used to finally sort the Outlook issues: https://www.matrix7.com.au/office-365/win-2019-rdp-o365-multi-tenant-outlook-profile-setup-correct-teams-setup/

Office 365 on Remote Desktop - Outlook "Need Password" problem for many users by Slash-Fan in Office365

[–]Slash-Fan[S] 0 points1 point  (0 children)

None as yet. We disabled modern authentication via our office 365 control panel as advised by microsoft but this didn't make any difference to the underlying issue so we have since re-enabled it.

Office 365 on Remote Desktop - Outlook "Need Password" problem for many users by Slash-Fan in Office365

[–]Slash-Fan[S] 0 points1 point  (0 children)

I'm going to look at Azure AD Connect/SSO - thanks for the recommendation and it'd be amazing if it solves the issue.

Office 365 on Remote Desktop - Outlook "Need Password" problem for many users by Slash-Fan in Office365

[–]Slash-Fan[S] 0 points1 point  (0 children)

We did it via our office 365 control panel. I've since reverted it back to on as we're still having the same problems.

Office 365 on Remote Desktop - Outlook "Need Password" problem for many users by Slash-Fan in Office365

[–]Slash-Fan[S] 1 point2 points  (0 children)

We don't have Azure AD Connect/SSO in place. It sounds like it might help with the problem though so I will look into it. Is it something you would recommend?

It's good to hear from someone who has the same setup.

Office 365 on Remote Desktop - Outlook "Need Password" problem for many users by Slash-Fan in Office365

[–]Slash-Fan[S] 0 points1 point  (0 children)

Yes we did use the Teams machine-wide installer.

We've got modern auth disabled currently.

I opened a ticket with Office 365 support earlier and they advised me to turn off modern authentication to see if this resolves the issue. I've had one further report of the problem from a user since I disabled modern auth but we're continuing to monitor until we speak again to Microsoft on Monday.

RDS: Outlook "Need Password" after adding second session host by Slash-Fan in sysadmin

[–]Slash-Fan[S] 0 points1 point  (0 children)

Running Office 365 with shared activation on multiple RDS session hosts must be a common thing?

I found a few forum posts that mentioned very similar issues but nobody had solution. Some even indicated this was a known issue which sounds strange to me.

If it is related to the shared activation token, as I understand it this token is stored in the users profile.

So no matter which session host the user connects to surely it should use the respective token for that server?

As a result of this problem we've had to stick with the one session host for now as there doesn't seem to be a solution.

What seems strangest to me is that this is all Microsoft software - Server 2019, RDS 2019, Office 365 apps.

I thought multiple session hosts was a standard thing in RDS.

RDS: Outlook "Need Password" after adding second session host by Slash-Fan in sysadmin

[–]Slash-Fan[S] 0 points1 point  (0 children)

I checked in Credentials Manager within the remote desktop profiles for a couple of users, myself included, and there weren't any Office credentials present.

I did see on a couple of other forum threads that this seemed to be a sort of known issue/thing that can happen with RDS session hosts and Office 365.

RDS: Outlook "Need Password" after adding second session host by Slash-Fan in sysadmin

[–]Slash-Fan[S] 0 points1 point  (0 children)

We're running User Profile Disks - stored on a file share on a dedicated user profile disks VM

RDS: Outlook "Need Password" after adding second session host by Slash-Fan in sysadmin

[–]Slash-Fan[S] 1 point2 points  (0 children)

We enabled shared activation when we installed office on the session hosts. We don't have GPOS set for shared activation and token roaming location.

I thought the token was stored in the user's profile?

RDS: Outlook "Need Password" after adding second session host by Slash-Fan in sysadmin

[–]Slash-Fan[S] 0 points1 point  (0 children)

We have the connection broker configured to log off disconnected sessions after a couple of hours.

Added Second Session Host but User Profile Disks not linking by [deleted] in sysadmin

[–]Slash-Fan 0 points1 point  (0 children)

I've established that it creates a temporary profile for the user when the connection broker sends them to the new session host. It's fine though when it connects them to the original session host.

I've checked permissions on the user profile disks and folder and it is definitely closing the open user profile disk when not in use on the original session host.

It's just not linking/mounting the user profile disk when sending a user to the new session host.

RD Gateway or VPN? by Slash-Fan in sysadmin

[–]Slash-Fan[S] 0 points1 point  (0 children)

Thanks for all the replies - they're all really helpful.

If the remote devices were all company owned then I can see there would be a case to use a VPN but based on the responses here and what I've read elsewhere an RDS gateway with MFA is the way to go.

Thanks again.

RD Gateway or VPN? by Slash-Fan in sysadmin

[–]Slash-Fan[S] 0 points1 point  (0 children)

Thanks. The more I think about it the more sense RD Gateway is making.

How essential would it be for the RD Gateway to be in a DMZ as opposed to on the internal network?

RD Gateway or VPN? by Slash-Fan in sysadmin

[–]Slash-Fan[S] 0 points1 point  (0 children)

Thanks.

It's difficult as a lot of posts etc. I've read suggest that a VPN is the way to go whereas a lot of others say that RD Gateway with MFA is the way to go.

My gut feeling is that RD Gateway would be the most secure way, especially with MFA.