NPS and Remote Desktop gateway

OussamaHawa-2566 0 Reputation points
2026-10-09T05:53:14.7266667+00:00

I have 2 windows server 2022 , on one server NPS is installed and on the second server remote desktop gateway, the NPS is configured and Auzre extension is installed and network policies and radius server is configured , and the same on remote desktop gateway, i am able to connect if the client is a wndows servers but if the client is windows 10 or 11 it failed

Windows for business | Windows Server | User experience | Remote desktop services and terminal services
0 comments No comments

2 answers

Sort by: Oldest
  1. AI answer

    2026-10-09T05:53:35.8233333+00:00

    For this RD Gateway + NPS extension design, the supported server-side components are Windows Server 2022/2019/2016 for RD Gateway, and the client side supports Windows 10 Pro, Windows 10 Enterprise, Windows 11 Pro, and Windows 11 Enterprise.

    For the configuration already described, the first checks should be these:

    1. Verify RD Gateway is using a central NPS store:
      • On the RD Gateway server, open Server Manager > Tools > Remote Desktop Services > Remote Desktop Gateway Manager.
      • Open [Server Name] (Local) > Properties > RD CAP Store.
      • Confirm Central server running NPS is selected.
      • Confirm the NPS server name or IP is the server where the NPS extension is installed.
      • Confirm the shared secret matches the one configured on the NPS server.
    2. Increase the RADIUS timeout on the RD Gateway:
      • On the RD Gateway server, open Server Manager > Tools > Network Policy Server.
      • Go to RADIUS Clients and Servers > Remote RADIUS Server.
      • Open TS GATEWAY SERVER GROUP.
      • Edit the NPS server entry, open the Load Balancing tab.
      • Change Number of seconds without response before request is considered dropped from 3 to a value between 30 and 60 seconds.
      • Change Number of seconds between requests when server is identified as unavailable to a value equal to or greater than the previous setting.
    3. Verify the RD Gateway connection request policy:
      • In NPS (Local) on the RD Gateway, open Policies > Connection Request Policies.
      • Open TS GATEWAY AUTHORIZATION POLICY.
      • On Settings, under Forwarding Connection Request, confirm Authentication is selected.
    4. Verify the NPS server configuration:
      • On the NPS server where the extension is installed, open Network Policy Server.
      • Right-click NPS (Local) and select Register server in Active Directory.
      • Under RADIUS Clients, confirm the RD Gateway is added as a client with the correct IP/DNS name and the same shared secret.
    5. Verify the network policy on the NPS server:
      • Under Policies > Network Policies, confirm the RD Gateway policy is enabled, grants access, and is at the top of the list.
      • In that policy, on Constraints, confirm Allow clients to connect without negotiating an authentication method is checked.
      • If conditions are configured, verify Windows 10/11 users are not being excluded by group membership or other conditions.
    6. Check the RD RAP setting on the RD Gateway:
      • Remote Desktop Client does not support RD Gateway messaging.
      • If the RD Gateway Resource Access Policy is set to Only allow computers with support for RD Gateway Messaging, Windows clients will not connect.
    7. Confirm the NPS extension is installed on the correct server:
      • The NPS extension should be installed on the NPS server, not on the RD Gateway server.

    If Windows Server clients work but Windows 10/11 clients fail, the most directly supported client-specific check in the documentation is the RD Gateway messaging setting. The other high-value check is the RADIUS timeout, because MFA processing requires more time than the default 3-second timeout.


    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

  2. Domic Vo 34,490 Reputation points Independent Advisor
    2026-10-09T06:22:29.0133333+00:00

    Hello,

    Windows Server clients can connect but Windows 10/11 clients fail, check Event Viewer → Custom Views → Server Roles → Network Policy and Access Services on the NPS server for Event ID 6273 and its failure reason.

    Verify that the RD Gateway uses the correct NPS server IP and RADIUS shared secret, and that the Network Policy permits the affected users. If Azure MFA is enabled, check the NPS extension logs and confirm the users' authentication methods are supported.

    What error message do Windows 10/11 clients receive, and what is the reason code in Event ID 6273? This will help identify the root cause.

    I hope you've found something useful here. If it helps you get more insight into the issue, it's appreciated to accept the answer. Should you have more questions, feel free to leave a message. Have a nice day!

    Domic Vo.

    Was this answer helpful?

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.