<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content

Okta ASA/OPA for Windows RDP Disconnects After 60 Minutes

Advanced Server Access
Privileged Access
All Engines
Okta Classic Engine
Okta Identity Engine

Overview

A Windows Remote Desktop Protocol (RDP) session configured with Okta Advanced Server Access (ASA) or Okta Privileged Access (OPA) disconnects after 60 minutes when the server is not a member of an Active Directory (AD) domain. Ensure the server belongs to an AD domain and the user is a domain user to prevent this disconnection. When this issue occurs, the following error appears:

 

Remote Desktop License Issue

There is a problem with your Remote Desktop license, and your session will be disconnected in 60 minutes. Contact your system administrator to fix this issue.

 

Error Message

Applies To

  • Okta Identity Engine (OIE)
  • Okta Classic Engine
  • Okta Advanced Server Access (ASA)
  • Okta Privileged Access (OPA)
  • Windows Remote Desktop Protocol (RDP)
  • Per User Client Access License (CAL) Licensing

Cause

Okta ASA and OPA are compatible with Windows RDP. However, Microsoft RDP licenses require correct provisioning. RDP uses either a "per user" or "per device" license. Every unique device or unique person connecting to the RDP servers requires a purchased Remote Desktop Services (RDS) Client Access License (CAL). When using the RDS "Per User" CALs license on Windows Server 2019, the session disconnects every 60 minutes if the server is not a member of an AD domain.

Solution

How are Windows RDP disconnections resolved in Okta Advanced Server Access and Privileged Access?

Okta ASA functions with RDP "Per User" CALs on Windows 2019 when specific conditions are met. Verify the following requirements to ensure stable RDP sessions:

  • The user must be a domain user.
    NOTE: Okta OPA requires integration with AD to achieve this. Review Manage Active Directory accounts for configuration details.
  • The server must belong to an AD domain. Okta does not support Workgroups.
  • "Per User" CALs function even if licenses are depleted, but the environment requires correct and compatible licenses.
  • The Remote Desktop (RD) Session Host server must be able to request an RDS CAL from the Remote Desktop license server.
  • Contact a Microsoft representative for additional information on RDP licensing.

 

Related References

Loading
Okta ASA/OPA for Windows RDP Disconnects After 60 Minutes | Okta Support