<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.msdn.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>How to enable Single Sign-On for my Terminal Server connections</title><link>http://blogs.msdn.com/rds/archive/2007/04/19/how-to-enable-single-sign-on-for-my-terminal-server-connections.aspx</link><description>Note: This post was updated on March 12, 2009, to include the latest information. &amp;#160; What is Single Sign-On? When applied to Terminal Services, Single Sign-On means using the credentials of the currently logged on user (also called default credentials)</description><dc:language>en-US</dc:language><generator>CommunityServer 2.1 SP1 (Build: 61025.2)</generator><item><title>Single-Sign-ON</title><link>http://blogs.msdn.com/rds/archive/2007/04/19/how-to-enable-single-sign-on-for-my-terminal-server-connections.aspx#2263033</link><pubDate>Tue, 24 Apr 2007 21:50:49 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:2263033</guid><dc:creator>Rickard Wendel [Terminal Services]</dc:creator><description>&lt;p&gt;Nu finns det en guide f&amp;#246;r hur man konfigurerar SSO mellan en VISTA/Longhorn klient till en VISTA/Longhorn...&lt;/p&gt;
</description></item><item><title>re: How to enable Single Sign-On for my Terminal Server connections</title><link>http://blogs.msdn.com/rds/archive/2007/04/19/how-to-enable-single-sign-on-for-my-terminal-server-connections.aspx#2267318</link><pubDate>Wed, 25 Apr 2007 05:41:25 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:2267318</guid><dc:creator>jay</dc:creator><description>&lt;p&gt;Is it possible to provide SSO for Terminal Services in Win2k3 Server and XP/Win2k3 as clients?&lt;/p&gt;
</description></item><item><title>re: How to enable Single Sign-On for my Terminal Server connections</title><link>http://blogs.msdn.com/rds/archive/2007/04/19/how-to-enable-single-sign-on-for-my-terminal-server-connections.aspx#2273862</link><pubDate>Wed, 25 Apr 2007 19:57:29 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:2273862</guid><dc:creator>Sergey Kuzin</dc:creator><description>&lt;p&gt;Unfortunately it's not possible, because SSO requires using a special Security Support Provider currently available only in Vista.&lt;/p&gt;
</description></item><item><title>re: How to enable Single Sign-On for my Terminal Server connections</title><link>http://blogs.msdn.com/rds/archive/2007/04/19/how-to-enable-single-sign-on-for-my-terminal-server-connections.aspx#4008046</link><pubDate>Mon, 23 Jul 2007 11:22:32 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:4008046</guid><dc:creator>Olivier Blaise</dc:creator><description>&lt;p&gt;If I understood the explanation correctly, you use also a username and password to authenticate from Vista to Longhorn. The difference is that the username and password are cached and sent without user intervention.&lt;/p&gt;
&lt;p&gt;No way to rely on kerberos authentication and constrained delegation ?&lt;/p&gt;
</description></item><item><title>Single Sign On (SSO) aux connexions Terminal Services</title><link>http://blogs.msdn.com/rds/archive/2007/04/19/how-to-enable-single-sign-on-for-my-terminal-server-connections.aspx#5489769</link><pubDate>Wed, 17 Oct 2007 14:23:47 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:5489769</guid><dc:creator>Sup'Astuces</dc:creator><description>&lt;p&gt;Dans un domaine windows, on est authentifi&amp;amp;amp;#xE9; pour quasiment tous les services via Kerberos sans&lt;/p&gt;
</description></item><item><title>How to enable Single Sign-On for my Terminal Server connections</title><link>http://blogs.msdn.com/rds/archive/2007/04/19/how-to-enable-single-sign-on-for-my-terminal-server-connections.aspx#5526390</link><pubDate>Fri, 19 Oct 2007 20:13:59 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:5526390</guid><dc:creator>MarkG</dc:creator><description>&lt;p&gt;I've just foudn out that SSO will be available on XP SP3. Dev. has ported CredSSP back to XP SP3.&lt;/p&gt;
</description></item><item><title>re: How to enable Single Sign-On for my Terminal Server connections</title><link>http://blogs.msdn.com/rds/archive/2007/04/19/how-to-enable-single-sign-on-for-my-terminal-server-connections.aspx#5527551</link><pubDate>Fri, 19 Oct 2007 22:05:47 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:5527551</guid><dc:creator>MarkG</dc:creator><description>&lt;p&gt;Someone from MS Dev. need to confirm that SSO will work with WinXP SP3. &lt;/p&gt;
</description></item><item><title>re: How to enable Single Sign-On for my Terminal Server connections</title><link>http://blogs.msdn.com/rds/archive/2007/04/19/how-to-enable-single-sign-on-for-my-terminal-server-connections.aspx#5606105</link><pubDate>Mon, 22 Oct 2007 21:16:49 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:5606105</guid><dc:creator>Sergey Kuzin</dc:creator><description>&lt;p&gt;Mark,&lt;/p&gt;
&lt;p&gt;Unfortunately, SSO will not be supported on XP SP3.&lt;/p&gt;
&lt;p&gt;I'm sorry for the confusion.&lt;/p&gt;
&lt;p&gt;Sergey.&lt;/p&gt;
</description></item><item><title>re: How to enable Single Sign-On for my Terminal Server connections</title><link>http://blogs.msdn.com/rds/archive/2007/04/19/how-to-enable-single-sign-on-for-my-terminal-server-connections.aspx#6583371</link><pubDate>Wed, 28 Nov 2007 22:01:38 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:6583371</guid><dc:creator>Greg</dc:creator><description>&lt;p&gt;I was just in the Webcast today on Security in Terminal Servers and the presenter had XP SP3 in the list as supported for SSO.&lt;/p&gt;
&lt;p&gt;Was that old information?&lt;/p&gt;
</description></item><item><title>re: How to enable Single Sign-On for my Terminal Server connections</title><link>http://blogs.msdn.com/rds/archive/2007/04/19/how-to-enable-single-sign-on-for-my-terminal-server-connections.aspx#6583933</link><pubDate>Wed, 28 Nov 2007 22:53:24 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:6583933</guid><dc:creator>Greg</dc:creator><description>&lt;p&gt;BTW, it does work in XP SP3 RC1; however, the group policy templates don't provide for a means to make the change.&lt;/p&gt;
&lt;p&gt;Make the change on a vista box and export the registry key and it will work on XP. &amp;nbsp;Tried with SP2/RDP 6.1 client, that's a no-go, SP3 *IS* required.&lt;/p&gt;
</description></item><item><title>re: How to enable Single Sign-On for my Terminal Server connections</title><link>http://blogs.msdn.com/rds/archive/2007/04/19/how-to-enable-single-sign-on-for-my-terminal-server-connections.aspx#7210592</link><pubDate>Wed, 23 Jan 2008 20:16:20 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:7210592</guid><dc:creator>Paul</dc:creator><description>&lt;p&gt;Can anyone else confirm SSO works in XP Sp3?&lt;/p&gt;
</description></item><item><title>re: How to enable Single Sign-On for my Terminal Server connections</title><link>http://blogs.msdn.com/rds/archive/2007/04/19/how-to-enable-single-sign-on-for-my-terminal-server-connections.aspx#7306882</link><pubDate>Tue, 29 Jan 2008 18:05:59 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:7306882</guid><dc:creator>JDS</dc:creator><description>&lt;p&gt;Can someone post the registry changes required for the SSO to function on an XP machine?&lt;/p&gt;
</description></item><item><title>re: How to enable Single Sign-On for my Terminal Server connections</title><link>http://blogs.msdn.com/rds/archive/2007/04/19/how-to-enable-single-sign-on-for-my-terminal-server-connections.aspx#7376551</link><pubDate>Fri, 01 Feb 2008 21:14:10 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:7376551</guid><dc:creator>Sergey Kuzin</dc:creator><description>&lt;p&gt;Windows Registry Editor Version 5.00&lt;/p&gt;
&lt;p&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CredentialsDelegation]&lt;/p&gt;
&lt;p&gt;&amp;quot;AllowDefaultCredentials&amp;quot;=dword:00000001&lt;/p&gt;
&lt;p&gt;&amp;quot;ConcatenateDefaults_AllowDefault&amp;quot;=dword:00000001&lt;/p&gt;
&lt;p&gt;&amp;quot;AllowDefCredentialsWhenNTLMOnly&amp;quot;=dword:00000001&lt;/p&gt;
&lt;p&gt;&amp;quot;ConcatenateDefaults_AllowDefNTLMOnly&amp;quot;=dword:00000001&lt;/p&gt;
&lt;p&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CredentialsDelegation\AllowDefaultCredentials]&lt;/p&gt;
&lt;p&gt;&amp;quot;1&amp;quot;=&amp;quot;TERMSRV/&amp;lt;My Server1&amp;gt;&amp;quot;&lt;/p&gt;
&lt;p&gt;&amp;quot;2&amp;quot;=&amp;quot;TERMSRV/&amp;lt;My Server2&amp;gt;&amp;quot;&lt;/p&gt;
&lt;p&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CredentialsDelegation\AllowDefCredentialsWhenNTLMOnly]&lt;/p&gt;
&lt;p&gt;&amp;quot;1&amp;quot;=&amp;quot;TERMSRV/&amp;lt;My Server1&amp;gt;&amp;quot;&lt;/p&gt;
&lt;p&gt;&amp;quot;2&amp;quot;=&amp;quot;TERMSRV/&amp;lt;My Server2&amp;gt;&amp;quot;&lt;/p&gt;
&lt;p&gt;Replace &amp;quot;&amp;lt;My Server1&amp;gt;&amp;quot;, &amp;quot;&amp;lt;My Server2&amp;gt;&amp;quot;, etc. with the real server names.&lt;/p&gt;
&lt;p&gt;Do not use AllowDefCredentialsWhenNTLMOnly unless it is absolutely necessary. It is to enable SSO when Kerberos or SSL server authentication is not possible, and it is not very secure (you may end up sending your password to a wrong server).&lt;/p&gt;
</description></item><item><title>re: How to enable Single Sign-On for my Terminal Server connections</title><link>http://blogs.msdn.com/rds/archive/2007/04/19/how-to-enable-single-sign-on-for-my-terminal-server-connections.aspx#7377981</link><pubDate>Fri, 01 Feb 2008 23:24:18 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:7377981</guid><dc:creator>JDS</dc:creator><description>&lt;p&gt;Thanks! Hopefully I can get it to work. &lt;/p&gt;
</description></item><item><title>re: How to enable Single Sign-On for my Terminal Server connections</title><link>http://blogs.msdn.com/rds/archive/2007/04/19/how-to-enable-single-sign-on-for-my-terminal-server-connections.aspx#8392992</link><pubDate>Mon, 14 Apr 2008 18:00:54 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:8392992</guid><dc:creator>Alastair</dc:creator><description>&lt;p&gt;I suppose this could be pushed out using GPO to XPSP3 PCs. Has anyone done it?&lt;/p&gt;
</description></item><item><title>re: How to enable Single Sign-On for my Terminal Server connections</title><link>http://blogs.msdn.com/rds/archive/2007/04/19/how-to-enable-single-sign-on-for-my-terminal-server-connections.aspx#8399616</link><pubDate>Thu, 17 Apr 2008 00:46:17 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:8399616</guid><dc:creator>Greg</dc:creator><description>&lt;p&gt;With build 3244, the reg hacks as described above work.&lt;/p&gt;
&lt;p&gt;However, with build 3282, they don't seem to.&lt;/p&gt;
&lt;p&gt;Considering the ones in build 3244 match the ones from Vista SP1, I'm worried that they removed this feature. &amp;nbsp;We will be pissed if that is the case.&lt;/p&gt;
&lt;p&gt;We want single-sign on, but do NOT want to be forced to move to Vista for that, especially if we know it worked on one of the release candidates but was disabled from the final.&lt;/p&gt;
&lt;p&gt;Greg&lt;/p&gt;
</description></item><item><title>re: How to enable Single Sign-On for my Terminal Server connections</title><link>http://blogs.msdn.com/rds/archive/2007/04/19/how-to-enable-single-sign-on-for-my-terminal-server-connections.aspx#8437260</link><pubDate>Tue, 29 Apr 2008 15:10:53 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:8437260</guid><dc:creator>Paul</dc:creator><description>&lt;p&gt;I've tried the released version of SP3 and can confirm the single-sign on functionality has been removed from the final.&lt;/p&gt;
&lt;p&gt;I CAN'T move my desktops to Vista due to incompatibilities with certain software we use. &amp;nbsp;Come on Microsoft, how about a standalone RDC 6.1 complete with single-sign on?&lt;/p&gt;
</description></item><item><title>re: How to enable Single Sign-On for my Terminal Server connections</title><link>http://blogs.msdn.com/rds/archive/2007/04/19/how-to-enable-single-sign-on-for-my-terminal-server-connections.aspx#8437592</link><pubDate>Tue, 29 Apr 2008 16:38:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:8437592</guid><dc:creator>Paul</dc:creator><description>&lt;p&gt;Interestingly, I've been trying additional things to make this work and a desktop with &amp;nbsp;SP2 on, upgraded to build 3244 then upgraded to SP3 final appears to retain the SSO functionality, whereas SP2 straight to SP3 appears not to!&lt;/p&gt;
</description></item><item><title>re: How to enable Single Sign-On for my Terminal Server connections</title><link>http://blogs.msdn.com/rds/archive/2007/04/19/how-to-enable-single-sign-on-for-my-terminal-server-connections.aspx#8442482</link><pubDate>Wed, 30 Apr 2008 12:09:01 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:8442482</guid><dc:creator>Paul</dc:creator><description>&lt;p&gt;OK, I've managed to achieve the functionality. &amp;nbsp;Here's what to do:&lt;/p&gt;
&lt;p&gt;HKLM\SYSTEM\CurrentControlSet\Control\SecurityProviders\SecurityProviders&lt;/p&gt;
&lt;p&gt;APPEND, don't replace: credssp.dll&lt;/p&gt;
&lt;p&gt;HKLM\SYSTEM\CurrentControlSet\Control\Lsa\Security Packages&lt;/p&gt;
&lt;p&gt;APPEND, don't replace: tspkg&lt;/p&gt;
&lt;p&gt;AGAIN, you need to APPEND these values, not replace what's there&lt;/p&gt;
</description></item><item><title>Problems using default credentials with Vista RDP clients with Single Sign-on Enabled</title><link>http://blogs.msdn.com/rds/archive/2007/04/19/how-to-enable-single-sign-on-for-my-terminal-server-connections.aspx#8444931</link><pubDate>Wed, 30 Apr 2008 23:57:43 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:8444931</guid><dc:creator>Terminal Services Team Blog</dc:creator><description>&lt;p&gt;With Single Sign-on enabled , the current user’s credentials, also known as “default credentials”, are&lt;/p&gt;
</description></item><item><title>re: How to enable Single Sign-On for my Terminal Server connections</title><link>http://blogs.msdn.com/rds/archive/2007/04/19/how-to-enable-single-sign-on-for-my-terminal-server-connections.aspx#8515561</link><pubDate>Sat, 17 May 2008 01:52:50 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:8515561</guid><dc:creator>Chris Wallace</dc:creator><description>&lt;p&gt;I used the info from the postings above and specifically from KB951608, scenario 2 on a windows xp sp3 machine and am still prompted for credentials. Has anyone had any luck getting SSO to work with XP SP3 (RTM SP3, that is) clients?&lt;/p&gt;
</description></item><item><title>re: How to enable Single Sign-On for my Terminal Server connections</title><link>http://blogs.msdn.com/rds/archive/2007/04/19/how-to-enable-single-sign-on-for-my-terminal-server-connections.aspx#8515589</link><pubDate>Sat, 17 May 2008 02:00:59 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:8515589</guid><dc:creator>Chris Wallace</dc:creator><description>&lt;p&gt;I spoke too soon... MANY thanks, Paul, the registry entries from the KB and your post did the trick (credssp.dll, tspkg). If you could share your source, I'd be very greatful... thanks in any event!&lt;/p&gt;
</description></item><item><title>re: How to enable Single Sign-On for my Terminal Server connections</title><link>http://blogs.msdn.com/rds/archive/2007/04/19/how-to-enable-single-sign-on-for-my-terminal-server-connections.aspx#8527431</link><pubDate>Wed, 21 May 2008 13:24:48 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:8527431</guid><dc:creator>Dean Houben</dc:creator><description>&lt;p&gt;Got a question about SSO with Windows XP SP3.&lt;/p&gt;
&lt;p&gt;If i connect to a TS RemoteApp on hostname of a server there is no problem at all. App starts with no problems at all. Now i configured 2 TS 2008 servers in a Farm.&lt;/p&gt;
&lt;p&gt;I have put into DNS the Farm with the two ip's that are configured for it (Forward lookup zone)&lt;/p&gt;
&lt;p&gt;In TS RemoteApp Manager i configure the dns name for the farm i created.&lt;/p&gt;
&lt;p&gt;If i connect to the same TS RemoteApp with the farm-name i have to put in my credentials again, anyone have seen this problem before?&lt;/p&gt;
</description></item><item><title>re: How to enable Single Sign-On for my Terminal Server connections</title><link>http://blogs.msdn.com/rds/archive/2007/04/19/how-to-enable-single-sign-on-for-my-terminal-server-connections.aspx#8554279</link><pubDate>Tue, 27 May 2008 11:13:46 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:8554279</guid><dc:creator>Dean Houben</dc:creator><description>&lt;p&gt;Got it working now on Farm name.&lt;/p&gt;
&lt;p&gt;On XP it's impossible to get it to work with Ts Farm, so i used a Windows Vista machine. Now i got no problems anymore, can connect to the farm i configured!&lt;/p&gt;
</description></item><item><title>re: How to enable Single Sign-On for my Terminal Server connections</title><link>http://blogs.msdn.com/rds/archive/2007/04/19/how-to-enable-single-sign-on-for-my-terminal-server-connections.aspx#8569810</link><pubDate>Mon, 02 Jun 2008 20:39:48 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:8569810</guid><dc:creator>Frank</dc:creator><description>&lt;p&gt;I can confirm that SSO is not working with XP SP3 when connecting to a TS farm (using session broker). I have no issues when I connect to a standalone terminal server (following Paul's suggestions). If anyone has any ideas on how to make SSO work when connecting to a session brokered TS farm (besides upgrading to Vista), I'd love to hear them!&lt;/p&gt;
</description></item><item><title>re: How to enable Single Sign-On for my Terminal Server connections</title><link>http://blogs.msdn.com/rds/archive/2007/04/19/how-to-enable-single-sign-on-for-my-terminal-server-connections.aspx#8684071</link><pubDate>Thu, 03 Jul 2008 16:06:07 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:8684071</guid><dc:creator>Osama Sajid [MSFT]</dc:creator><description>&lt;p&gt;&lt;a rel="nofollow" target="_new" href="http://blogs.msdn.com/ts/archive/2008/04/30/problems-using-default-credentials-with-vista-rdp-clients-with-single-sign-on-enabled.aspx"&gt;http://blogs.msdn.com/ts/archive/2008/04/30/problems-using-default-credentials-with-vista-rdp-clients-with-single-sign-on-enabled.aspx&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;To enable server authentication in a server farm, use SSL certificates that are issued by a trusted Certificate Authority and that have the farm name in the subject field. Deploy them to all servers in your farm. The SSL certificate will provide server authentication for a TS server and therefore Credential Delegation policy will allow saved credentials to be used for remote desktop connections. &amp;nbsp;&lt;/p&gt;
</description></item><item><title>re: How to enable Single Sign-On for my Terminal Server connections</title><link>http://blogs.msdn.com/rds/archive/2007/04/19/how-to-enable-single-sign-on-for-my-terminal-server-connections.aspx#8870735</link><pubDate>Sat, 16 Aug 2008 00:15:08 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:8870735</guid><dc:creator>Admin</dc:creator><description>&lt;p&gt;This is a test to see if comment works on your blog or not.&lt;/p&gt;
&lt;p&gt;I'm sure this will work if comment is long enough because otherwise it will be considered as spam by blog algorithm. So shorter the length of comment , greater the chances of considering it as a spam by blog algorithm and you will end up seeing in blog home page instead of comment.&lt;/p&gt;
</description></item><item><title>re: How to enable Single Sign-On for my Terminal Server connections</title><link>http://blogs.msdn.com/rds/archive/2007/04/19/how-to-enable-single-sign-on-for-my-terminal-server-connections.aspx#8879788</link><pubDate>Wed, 20 Aug 2008 00:20:18 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:8879788</guid><dc:creator>RDP rocks!</dc:creator><description>&lt;p&gt;How I can use SSO from Windows XP x64?&lt;/p&gt;
</description></item><item><title>re: How to enable Single Sign-On for my Terminal Server connections</title><link>http://blogs.msdn.com/rds/archive/2007/04/19/how-to-enable-single-sign-on-for-my-terminal-server-connections.aspx#8879847</link><pubDate>Wed, 20 Aug 2008 00:48:16 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:8879847</guid><dc:creator>Olga</dc:creator><description>&lt;p&gt;Additional information for SSO for TS farms from XP SP3 clients:&lt;/p&gt;
&lt;p&gt;There is a QFE availbe for SSO to TS farms from XP SP3 - please see kb article located here: &amp;quot;&lt;a rel="nofollow" target="_new" href="http://support.microsoft.com/kb/953760&amp;quot;"&gt;http://support.microsoft.com/kb/953760&amp;quot;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Also, please make sure you have CredSSP enabled on your XP SP3 client - &amp;nbsp;please see kb article located here: &amp;quot;&lt;a rel="nofollow" target="_new" href="http://support.microsoft.com/kb/951608&amp;quot;"&gt;http://support.microsoft.com/kb/951608&amp;quot;&lt;/a&gt;&lt;/p&gt;
</description></item><item><title>re: How to enable Single Sign-On for my Terminal Server connections</title><link>http://blogs.msdn.com/rds/archive/2007/04/19/how-to-enable-single-sign-on-for-my-terminal-server-connections.aspx#8993495</link><pubDate>Fri, 10 Oct 2008 02:56:01 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:8993495</guid><dc:creator>Daryl</dc:creator><description>&lt;p&gt;Does this work with the standalone version of RDC6.1 for XPSP2 or is XPSP3 required?&lt;/p&gt;
</description></item><item><title>re: How to enable Single Sign-On for my Terminal Server connections</title><link>http://blogs.msdn.com/rds/archive/2007/04/19/how-to-enable-single-sign-on-for-my-terminal-server-connections.aspx#8993555</link><pubDate>Fri, 10 Oct 2008 04:13:04 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:8993555</guid><dc:creator>Olga Ivanova</dc:creator><description>&lt;p&gt;XP SP3 is required since CredSSP was ported to XP SP3 (not SP2). You will need to enable credssp on it (see KB article # 951608 for more info).&lt;/p&gt;
</description></item><item><title>re: How to enable Single Sign-On for my Terminal Server connections</title><link>http://blogs.msdn.com/rds/archive/2007/04/19/how-to-enable-single-sign-on-for-my-terminal-server-connections.aspx#9049173</link><pubDate>Thu, 06 Nov 2008 17:34:47 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9049173</guid><dc:creator>GregM</dc:creator><description>&lt;p&gt;Can this be used to connect from XP SP3 to XP SP3, or does the server still need to be 2008?&lt;/p&gt;
</description></item><item><title>re: How to enable Single Sign-On for my Terminal Server connections</title><link>http://blogs.msdn.com/rds/archive/2007/04/19/how-to-enable-single-sign-on-for-my-terminal-server-connections.aspx#9050838</link><pubDate>Fri, 07 Nov 2008 02:04:46 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9050838</guid><dc:creator>Olga Ivanova</dc:creator><description>&lt;p&gt;Unfortunately, no - XP SP3 can only be used as the client so no XP SP3 to XP SP3. Server has to be 2008 or Vista.&lt;/p&gt;
</description></item><item><title>re: How to enable Single Sign-On for my Terminal Server connections</title><link>http://blogs.msdn.com/rds/archive/2007/04/19/how-to-enable-single-sign-on-for-my-terminal-server-connections.aspx#9195446</link><pubDate>Thu, 11 Dec 2008 10:04:40 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9195446</guid><dc:creator>sai</dc:creator><description>&lt;p&gt;Hi Paul,&lt;/p&gt;
&lt;p&gt;I am trying to setup SSO with xp SP3.&lt;/p&gt;
&lt;p&gt;your previous post says APPEND,i am really unable to get what to APPEND ? please help me.&lt;/p&gt;
&lt;p&gt;Setup &lt;/p&gt;
&lt;p&gt;=====&lt;/p&gt;
&lt;p&gt;Server&lt;/p&gt;
&lt;p&gt;windows 2008 server &lt;/p&gt;
&lt;p&gt;configured the RDP accordingly&lt;/p&gt;
&lt;p&gt;client&lt;/p&gt;
&lt;p&gt;Windows XP professional with xp sp3.&lt;/p&gt;
&lt;p&gt;Earlier you said &lt;/p&gt;
&lt;p&gt;&amp;quot;OK, I've managed to achieve the functionality. &amp;nbsp;Here's what to do:&lt;/p&gt;
&lt;p&gt;HKLM\SYSTEM\CurrentControlSet\Control\SecurityProviders\SecurityProviders&lt;/p&gt;
&lt;p&gt;APPEND, don't replace: credssp.dll&lt;/p&gt;
&lt;p&gt;HKLM\SYSTEM\CurrentControlSet\Control\Lsa\Security Packages&lt;/p&gt;
&lt;p&gt;APPEND, don't replace: tspkg&lt;/p&gt;
&lt;p&gt;AGAIN, you need to APPEND these values, not replace what's there &amp;quot;&lt;/p&gt;
&lt;p&gt;i am not sure what do you mean by append&lt;/p&gt;
&lt;p&gt;please suggest&lt;/p&gt;
</description></item><item><title>re: How to enable Single Sign-On for my Terminal Server connections</title><link>http://blogs.msdn.com/rds/archive/2007/04/19/how-to-enable-single-sign-on-for-my-terminal-server-connections.aspx#9195481</link><pubDate>Thu, 11 Dec 2008 10:17:44 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9195481</guid><dc:creator>sainath</dc:creator><description>&lt;p&gt;Hi , &lt;/p&gt;
&lt;p&gt;I got it , we have to add these values to the registry .&lt;/p&gt;
&lt;p&gt;and enable credssp on windows xp professional clients &lt;/p&gt;
</description></item><item><title>re: How to enable Single Sign-On for my Terminal Server connections</title><link>http://blogs.msdn.com/rds/archive/2007/04/19/how-to-enable-single-sign-on-for-my-terminal-server-connections.aspx#9445662</link><pubDate>Thu, 26 Feb 2009 07:46:12 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9445662</guid><dc:creator>Roman Golev</dc:creator><description>&lt;p&gt;How to modify &amp;quot;Security Packages&amp;quot; with Domain Group Policy?&lt;/p&gt;
</description></item><item><title>re: How to enable Single Sign-On for my Terminal Server connections</title><link>http://blogs.msdn.com/rds/archive/2007/04/19/how-to-enable-single-sign-on-for-my-terminal-server-connections.aspx#9890322</link><pubDate>Wed, 02 Sep 2009 13:26:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9890322</guid><dc:creator>Jeef</dc:creator><description>&lt;p&gt;The article states that it's not possible to USE SSO in combination with smart cards. Is there any known work around for this?!&lt;/p&gt;
</description></item><item><title>re: How to enable Single Sign-On for my Terminal Server connections</title><link>http://blogs.msdn.com/rds/archive/2007/04/19/how-to-enable-single-sign-on-for-my-terminal-server-connections.aspx#9891037</link><pubDate>Thu, 03 Sep 2009 21:40:06 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9891037</guid><dc:creator>Jason</dc:creator><description>&lt;p&gt;SSO is working, but TS Remote Apps functionality is severely degraded due to differnet lock out time periods. &amp;nbsp;Often remote app progrmas are idle while attending to other programs and then you come back to remote apps and have to log back in. &amp;nbsp;Any suggestions? Domain lockout is 20mins and can't be changed. &lt;/p&gt;
</description></item><item><title>re: How to enable Single Sign-On for my Terminal Server connections</title><link>http://blogs.msdn.com/rds/archive/2007/04/19/how-to-enable-single-sign-on-for-my-terminal-server-connections.aspx#9891041</link><pubDate>Thu, 03 Sep 2009 21:47:53 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9891041</guid><dc:creator>Olga</dc:creator><description>&lt;p&gt;RE SSO with Smart cards: unfortunately you cannot get SSO with smart cards today unless you deploy something like ISA/UAG server.&lt;/p&gt;
&lt;p&gt;RE: lockout/timeout - thanks for your feedback. Domain lockout of 20 mins also applies to the TS where your Remote apps are hosted?&lt;/p&gt;
</description></item><item><title>re: How to enable Single Sign-On for my Terminal Server connections</title><link>http://blogs.msdn.com/rds/archive/2007/04/19/how-to-enable-single-sign-on-for-my-terminal-server-connections.aspx#9891079</link><pubDate>Thu, 03 Sep 2009 23:35:19 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9891079</guid><dc:creator>Jason</dc:creator><description>&lt;p&gt;Lockout is based on AD Policy. &amp;nbsp;I would have to create a seperate OU and drag the remote apps server into that OU and set No Timeout. &amp;nbsp;This would probably work, but would not fly with our Security team. &amp;nbsp;Any other suggestions or thoughts?&lt;/p&gt;
</description></item><item><title>re: How to enable Single Sign-On for my Terminal Server connections</title><link>http://blogs.msdn.com/rds/archive/2007/04/19/how-to-enable-single-sign-on-for-my-terminal-server-connections.aspx#9891081</link><pubDate>Thu, 03 Sep 2009 23:38:15 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9891081</guid><dc:creator>Jason</dc:creator><description>&lt;p&gt;The only thing stopping me from a full roleout of Remote Apps and 2K8 Server are users can't stand having to relog on to the application every 20 minutes of inactivity. &amp;nbsp;SSO works great for the initial launch, but after 20 minutes, SSO benefits are moot and users have to type in creds to unlock the session.&lt;/p&gt;
</description></item><item><title>re: How to enable Single Sign-On for my Terminal Server connections</title><link>http://blogs.msdn.com/rds/archive/2007/04/19/how-to-enable-single-sign-on-for-my-terminal-server-connections.aspx#9891084</link><pubDate>Thu, 03 Sep 2009 23:40:08 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9891084</guid><dc:creator>Jason</dc:creator><description>&lt;p&gt;If the Remote Apps could share the same incativity timer as the host machine, it would be a beautiful thing.&lt;/p&gt;
</description></item><item><title>re: How to enable Single Sign-On for my Terminal Server connections</title><link>http://blogs.msdn.com/rds/archive/2007/04/19/how-to-enable-single-sign-on-for-my-terminal-server-connections.aspx#9908102</link><pubDate>Fri, 16 Oct 2009 11:06:03 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9908102</guid><dc:creator>David</dc:creator><description>&lt;p&gt;Does these setting provide SSO to the TS Web Access portal ? i.e, I launch IE, navigate to my TS web access page, it auto logs on and my apps are presented. &amp;nbsp; &amp;nbsp;If so, it does not seem to work for me, I am using Windows 7 RDP 7.1. &amp;nbsp;When I use mstsc and connect to my farm, SSO does work. &amp;nbsp;Can someone clarify please :-) thanks&lt;/p&gt;
</description></item><item><title>re: How to enable Single Sign-On for my Terminal Server connections</title><link>http://blogs.msdn.com/rds/archive/2007/04/19/how-to-enable-single-sign-on-for-my-terminal-server-connections.aspx#9908246</link><pubDate>Fri, 16 Oct 2009 16:07:05 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9908246</guid><dc:creator>termserv</dc:creator><description>&lt;p&gt;@David:&lt;/p&gt;
&lt;p&gt;For Web SSO, see &lt;a rel="nofollow" target="_new" href="http://blogs.msdn.com/rds/archive/2009/08/11/introducing-web-single-sign-on-for-remoteapp-and-desktop-connections.aspx"&gt;http://blogs.msdn.com/rds/archive/2009/08/11/introducing-web-single-sign-on-for-remoteapp-and-desktop-connections.aspx&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Rob [MSFT]&lt;/p&gt;
</description></item><item><title>re: How to enable Single Sign-On for my Terminal Server connections</title><link>http://blogs.msdn.com/rds/archive/2007/04/19/how-to-enable-single-sign-on-for-my-terminal-server-connections.aspx#9913812</link><pubDate>Wed, 28 Oct 2009 00:03:02 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9913812</guid><dc:creator>Dan</dc:creator><description>&lt;p&gt;The error message in the Remote Desktop Connection app (mstsc) should be more detailed.&lt;/p&gt;
&lt;p&gt;My scenario:&lt;/p&gt;
&lt;p&gt;- domain-joined Win 7 machine at work&lt;/p&gt;
&lt;p&gt;- connecting to non-domain-joined Win 7 machine at home&lt;/p&gt;
&lt;p&gt;- saved credentials would not pass and I would get the following message:&lt;/p&gt;
&lt;p&gt;&amp;quot;Your credentials did not work. Your system administrator does not allow the use of saved credentials to log on to the remote computer my.domain.com because its identity is not fully verified. Please enter new credentials.&amp;quot;&lt;/p&gt;
&lt;p&gt;Enabling the &amp;quot;Allow Delegating Saved Credentials with NTLM-only Server Authentication&amp;quot; of course fixed the problem. &lt;/p&gt;
&lt;p&gt;In retrospect, the message now makes sense, but before I thought it was getting the wrong username/password. It seemed to me that the remote machine was rejecting it.&lt;/p&gt;
&lt;p&gt;I suggest some changes to make this clearer:&lt;/p&gt;
&lt;p&gt;1) Change the title of the error to something like &amp;quot;Saved credentials could not be sent&amp;quot;. The way it is now, sounds like they were sent and rejected by the remote machine.&lt;/p&gt;
&lt;p&gt;2) Alter the error message to include some hint that this is the result of the Local Computer Policy so that the user knows where to look.&lt;/p&gt;
&lt;p&gt;3) When opting to save credentials, a policy check should occur and the user should be informed that the policy is not going to allow it.&lt;/p&gt;
&lt;p&gt;4) A help button and page that includes information on connecting from a domain-joined PC to a non-domain-joined PC.&lt;/p&gt;
&lt;p&gt;Thanks for considering it. :)&lt;/p&gt;
</description></item><item><title>re: How to enable Single Sign-On for my Terminal Server connections</title><link>http://blogs.msdn.com/rds/archive/2007/04/19/how-to-enable-single-sign-on-for-my-terminal-server-connections.aspx#9929186</link><pubDate>Thu, 26 Nov 2009 19:57:07 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9929186</guid><dc:creator>Naresh Negi</dc:creator><description>&lt;p&gt;Can we get SSO on a thin client with windows XP SP3 embedded?&lt;/p&gt;
&lt;p&gt;I have a Session broker with NLB and I keep getting double prompts and on remote apps although I have setup credssp I am still being asked for a prompt. Is there something different I need to do for getting SSO on remote apps? I am doing all this on XP SP3 (standard) and later.&lt;/p&gt;
&lt;p&gt;TS and SSB are windows 2008 R2.&lt;/p&gt;
&lt;p&gt;TIA.&lt;/p&gt;
</description></item></channel></rss>