CyberArk RDP Asking for Password

CyberArk RDP Asking for Password

avatar

When i try to open an External RDP file from Cyberark, it asks me for a password. This doesn't happen in MSTSC or in Royal TS. I cant find a fix for this in RDM, does anyone have any suggestions?

Steps to Reproduce

  1. Log into Cyberark
  2. Connect to a server
  3. Allow file to download
  4. open file with RDM
  5. prompts for password.


All Comments (6)

avatar

Hello,

Thank you for reporting this to us,

Which version of RDM are you using ?

Which data source type are you using in RDM ?

Best regards,

avatar

I'm using 2023.2.32.0 64-bit

and for the data source, it's the RDP file that gets downloaded from Cyberark. From there I associated the file type RDP to RDM. it looks like it does try to open it as a Windows RDP connection, but prompts for a password when it shouldn't.

avatar

Hi,

I’m a bit rusty but could you try what Hubert shows deep in that thread

https://forum.devolutions.net/topics/33207/disabling-credssp-on-rdp-is-not-working#154285

NLA is an authentication prior to credentials being exchanged.

Maurice

avatar

Hey Maurice, this actually does get me closer to fixing this problem. if I import the RDP file and turn that setting off, it will connect. but the problem is that the RDP file needs to be opened within like 20 seconds or its no longer valid.

I tried changing the setting on the template, but RDP files opened ad-hoc do not respect this setting. Any ideas?

avatar

Hi all,

just a note to mention that we had moved to DMs and Enzo’s scenario was 90% met, we need to escalate to the second line for the last detail.

Maurice

avatar

Hello Enzo,

Maurice communicated your exchanges to me, and I think the behavior you're experiencing is more related to how CyberArk generates your RDP files.
I noticed some time ago that the Connection Components configuration will cause similar issues.

To prove (or disprove) my theory, before opening the RDP, try editing it and changing the "screen mode id:i:2" to "screen mode id:i:1".

If this works as intended, I would suggest you see with your CyberArk administrator what would be the implication of changing this configuration, or creating a new Connection Component to reflect such preference.

I nevertheless hope this helps.

Best regards,

Alex Belisle