For this RD Gateway + NPS extension design, the supported server-side components are Windows Server 2022/2019/2016 for RD Gateway, and the client side supports Windows 10 Pro, Windows 10 Enterprise, Windows 11 Pro, and Windows 11 Enterprise.
For the configuration already described, the first checks should be these:
- Verify RD Gateway is using a central NPS store:
- On the RD Gateway server, open Server Manager > Tools > Remote Desktop Services > Remote Desktop Gateway Manager.
- Open [Server Name] (Local) > Properties > RD CAP Store.
- Confirm Central server running NPS is selected.
- Confirm the NPS server name or IP is the server where the NPS extension is installed.
- Confirm the shared secret matches the one configured on the NPS server.
- Increase the RADIUS timeout on the RD Gateway:
- On the RD Gateway server, open Server Manager > Tools > Network Policy Server.
- Go to RADIUS Clients and Servers > Remote RADIUS Server.
- Open TS GATEWAY SERVER GROUP.
- Edit the NPS server entry, open the Load Balancing tab.
- Change Number of seconds without response before request is considered dropped from 3 to a value between 30 and 60 seconds.
- Change Number of seconds between requests when server is identified as unavailable to a value equal to or greater than the previous setting.
- Verify the RD Gateway connection request policy:
- In NPS (Local) on the RD Gateway, open Policies > Connection Request Policies.
- Open TS GATEWAY AUTHORIZATION POLICY.
- On Settings, under Forwarding Connection Request, confirm Authentication is selected.
- Verify the NPS server configuration:
- On the NPS server where the extension is installed, open Network Policy Server.
- Right-click NPS (Local) and select Register server in Active Directory.
- Under RADIUS Clients, confirm the RD Gateway is added as a client with the correct IP/DNS name and the same shared secret.
- Verify the network policy on the NPS server:
- Under Policies > Network Policies, confirm the RD Gateway policy is enabled, grants access, and is at the top of the list.
- In that policy, on Constraints, confirm Allow clients to connect without negotiating an authentication method is checked.
- If conditions are configured, verify Windows 10/11 users are not being excluded by group membership or other conditions.
- Check the RD RAP setting on the RD Gateway:
- Remote Desktop Client does not support RD Gateway messaging.
- If the RD Gateway Resource Access Policy is set to Only allow computers with support for RD Gateway Messaging, Windows clients will not connect.
- Confirm the NPS extension is installed on the correct server:
- The NPS extension should be installed on the NPS server, not on the RD Gateway server.
If Windows Server clients work but Windows 10/11 clients fail, the most directly supported client-specific check in the documentation is the RD Gateway messaging setting. The other high-value check is the RADIUS timeout, because MFA processing requires more time than the default 3-second timeout.
References: