Angelo Lee's Blog
This is my kingdom .If i don't fight for it ,who will ?

Link:Unable to Save Credentials Password For Remote Desktop(RDP)


“Your system administrator does not allow the use of saved credentials to log on to the remote computer terminal.server.com because its identity is not fully verified. Please enter new credentials.”

Reason: This happens when trying to connect to a computer / server in another domain and no trust relationships exists. Windows then steps back to use NTLM and the default domain machine policy prohibits use of saved credentials. You can change this domain based or for a individual machine:

This security measure could frustrating when you connect and disconnect a lot to the same (or many) terminal server. To get rid of it and to be able to use saved credentials in this situation you need to configure the following:


Doesn't matter how many times you have check the box save "password credentials". The very next time you try to login via RDP again and it will prompt for a password to be typed in.

Solution:

Open local policy edititor. Go to start ->run -> type gpedit.msc
Then Navigate to:
Computer Configuration ->Administrative Templates ->System -> Credentials Delegation
Then on the sixth line on the right side double click on "Allow Delegating Saved Credentials with
NTLM-only Server Authentication"

Click Enable and click on the Show button then in the Value box typeTERMSRV/terminalserver.domain.com
substitue terminalserver with your actual terminal server name.

Add “TERMSRV/” to the server list, then your domain, example: TERMSRV/mydomain.com. You can use one wildcard (*) in a name. For example to enable the setting on all servers in “mydomain.com” type “TERMSRV/*.mydomain.com” or for all servers use: TERMSRV/*


When finished, go to cmd console and type gpupdate to update the new policy or restart the computer.
Next time you try to login to the terminal server it won't ask password again.




posted on 2011-11-28 11:31  Angelo Lee  阅读(350)  评论(0编辑  收藏  举报