AD FS as gateway with RDG and RD brooker

Isssah21 1 Reputation point
2020-08-11T11:44:41.037+00:00

Have any of you tried to use AD FS as a gateway to connect to other windows via RDP? I would like to achieve redundancy between these windows connected to the FS. The first window goes down, the FS directs it to the second or third window. Something like using it partly as a load balancer. According to the documentation, after the farm is created, it is Windows (Main, with R/W database) and backup (with local R/O database, which when it detects a change, takes these changes). Or it possible to use RDG with multiple servers? To sum up, i want to create a few servers with redundancy . One is down, then AD forward user to another.

Active Directory Federation Services
Active Directory Federation Services
An Active Directory technology that provides single-sign-on functionality by securely sharing digital identity and entitlement rights across security and enterprise boundaries.
1,240 questions
Remote Desktop
Remote Desktop
A Microsoft app that connects remotely to computers and to virtual apps and desktops.
4,493 questions
{count} votes

3 answers

Sort by: Most helpful
  1. Eleven Yu (Shanghai Wicresoft Co,.Ltd.) 10,746 Reputation points Microsoft Vendor
    2020-08-12T02:55:33.133+00:00

    Hi,

    Based on your description, it seems you would like to achieve SSO (Single Sign On) together with load balance in your RDS deployment.

    If so, there is no need to use ADFS, RDCB (Remote Desktop connection Broker) can achieve both.

    Or do you have any other requirement that must use ADFS, so that you would like to integrate ADFS with RDS?

    Thanks,
    Eleven

    1 person found this answer helpful.

  2. Eleven Yu (Shanghai Wicresoft Co,.Ltd.) 10,746 Reputation points Microsoft Vendor
    2020-08-17T06:44:35.167+00:00

    Hi,

    In RDS deployment, High Availability configuration could achieve your requirement (if one server from farm is going dome, then RDCB will redirect the user to anther working server in this farm).

    But the user does not use IP address to connect to the farm but use the farm name. In DNS zone, the farm name will have several records that match with all the IP addresses of the session host servers in the farm.

    Then when the user use the farm name to connect to the remote desktop, the RDCB will redirect the user to one session host server. If there are several users connect to the farm at the same time, the RDCB will redirect them to different session host servers for load balance. Also, if one server is down, the RDCB will allow the user to reconnect to their existing session in another working one.

    Meanwhile, you can enable user profile disks instead of using GPO to copy user files on desktop.
    17874-image.png

    You can refer to below blog for RDS deployment to achieve your requirement. You need to use Standard Deployment.

    Deploying Remote Desktop Services 2016 Step-By-Step
    https://nedimmehic.org/2017/01/21/deploying-remote-desktop-services-2016-step-by-step/

    Thanks,
    Eleven

    1 person found this answer helpful.

  3. Eleven Yu (Shanghai Wicresoft Co,.Ltd.) 10,746 Reputation points Microsoft Vendor
    2020-08-19T06:36:11.05+00:00

    Hi,

    Please be informed that windows server 2019 core can only install RDCB and RD licensing role. RD session host, RD Gateway and RD Web access cannot not be installed.

    Roles, Role Services, and Features not in Windows Server - Server Core
    https://video2.skills-academy.com/en-us/windows-server/administration/server-core/server-core-removed-roles

    Role Services not in Server Core
    Note that some Remote Desktop role services are included in Server Core (Connection Broker, Licensing, Virtualization Host), but others are NOT (Gateway, RD Session Host, Web Access).

    Remote Desktop Services \ Remote Desktop Gateway (RDS-Gateway)
    Remote Desktop Services \ Remote Desktop Session Host (RDS-RD-Server)
    Remote Desktop Services \ Remote Desktop Web Access (RDS-Web-Access)

    Thanks,
    Eleven

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.