Okta Advanced Server Access And Okta Privileged Access RDP Fails With Credentials Did Not Work Error
Last Updated:
Overview
When attempting to establish an RDP connection via Okta Advanced Server Access (ASA) or Okta Privileged Access (OPA), the connection fails with a credentials error. This occurs due to a Windows environment configuration mismatch, such as the client using LM or NTLMv1 protocols while the server only allows NTLMv2. Resolve this by updating the Windows Group Policy Object (GPO) to enforce NTLMv2 responses.
Your credentials did not work. The logon attempt failed.
An account failed to log on
Unknown user name or bad password
Applies To
- Okta Identity Engine (OIE)
- Okta Classic Engine
- Okta Advanced Server Access (ASA)
- Okta Privileged Access (OPA)
Cause
A configuration mismatch in the Windows environment causes this issue. For example, the Windows client is configured to use LM or NTLMv1 protocols to authenticate the session, but the server only allows NTLMv2.
Solution
How is the NTLMv2 protocol enforced for RDP sessions?
Update the Windows Group Policy Object (GPO) to ensure clients only use NTLMv2 for authentication by following these steps.
- Navigate to Computer Configuration > Windows Settings > Security Settings > Local Policies > Security Options.
- Locate the Network security: LAN Manager authentication level policy.
- Set the policy to Send NTLMv2 response only.
NOTE: Consult with Windows administrators before making this change to ensure there are no broader environmental implications. If this does not resolve the issue, investigate further in the Windows environment, as the lack of errors in the Okta logs indicates the issue is outside the scope of Okta Advanced Server Access or Okta Privileged Access.
