Freerdp: No RDP connection to WIndows 10 laptop with Office 365 credentials

Created on 14 Mar 2020  路  14Comments  路  Source: FreeRDP/FreeRDP

Describe the bug
I cannot RDP in my Windows 10 laptop using my AzureAD/Office 365 credentials.
But I can connect to this same laptop using a local account.
And I can connect using the Office 365 credentials to Windows Server 2016/2019 on Azure.
Clone of https://gitlab.com/Remmina/Remmina/-/issues/2116

To Reproduce

xfreerdp /u:me /p:MSpasswordSoLessThan8characters /d:domain.com 192.168.0.15

Expected behavior
RDP in my Windows 10 computer using my AzureAD/Office 365 credentials.

Screenshots
The logs:

[14:40:37:703] [18152:18152] [WARN][com.freerdp.client.common.compatibility] - -d domain.com -> /d:domain.com
[14:40:37:703] [18152:18152] [WARN][com.freerdp.client.common.compatibility] - -p ****** -> /p:******
[14:40:37:703] [18152:18152] [WARN][com.freerdp.client.common.compatibility] - -u me -> /u:me
[14:40:37:703] [18152:18152] [WARN][com.freerdp.client.common.compatibility] - 192.168.0.15 -> /v:192.168.0.15
[14:40:37:703] [18152:18152] [WARN][com.freerdp.client.common.compatibility] - 
[14:40:37:703] [18152:18153] [INFO][com.freerdp.core] - freerdp_connect:freerdp_set_last_error_ex resetting error state
[14:40:37:703] [18152:18153] [INFO][com.freerdp.client.common.cmdline] - loading channelEx rdpdr
[14:40:37:703] [18152:18153] [INFO][com.freerdp.client.common.cmdline] - loading channelEx rdpsnd
[14:40:37:703] [18152:18153] [INFO][com.freerdp.client.common.cmdline] - loading channelEx cliprdr
[14:40:38:020] [18152:18153] [INFO][com.freerdp.primitives] - primitives autodetect, using optimized
[14:40:38:022] [18152:18153] [INFO][com.freerdp.core] - freerdp_tcp_is_hostname_resolvable:freerdp_set_last_error_ex resetting error state
[14:40:38:022] [18152:18153] [INFO][com.freerdp.core] - freerdp_tcp_connect:freerdp_set_last_error_ex resetting error state
[14:40:39:415] [18152:18153] [WARN][com.freerdp.crypto] - Certificate verification failure 'unable to get local issuer certificate (20)' at stack position 0
[14:40:39:415] [18152:18153] [WARN][com.freerdp.crypto] - CN = T480s14
[14:40:41:119] [18152:18153] [ERROR][com.freerdp.core] - nla_recv_pdu:freerdp_set_last_error_ex ERRCONNECT_LOGON_FAILURE [0x00020014]
[14:40:41:119] [18152:18153] [ERROR][com.freerdp.core.rdp] - rdp_recv_callback: CONNECTION_STATE_NLA - nla_recv_pdu() fail
[14:40:41:119] [18152:18153] [ERROR][com.freerdp.core.transport] - transport_check_fds: transport->ReceiveCallback() - -1

Application details

  • Version of FreeRDP
    2.0.0-dev5
  • Command line used
    xfreerdp /u:me /p:MSpasswordSoLessThan8characters /d:domain.com 192.168.0.15
  • output of /buildconfig
    This is FreeRDP version 2.0.0-dev5 (n/a)
    Build configuration: BUILD_TESTING=OFF BUILTIN_CHANNELS=ON HAVE_AIO_H=1 HAVE_EXECINFO_H=1 HAVE_FCNTL_H=1 HAVE_INTTYPES_H=1 HAVE_JOURNALD_H=TRUE HAVE_MATH_C99_LONG_DOUBLE=1 HAVE_POLL_H=1 HAVE_PTHREAD_MUTEX_TIMEDLOCK=ON HAVE_PTHREAD_MUTEX_TIMEDLOCK_LIB=1 HAVE_PTHREAD_MUTEX_TIMEDLOCK_SYMBOL= HAVE_SYSLOG_H=1 HAVE_SYS_EVENTFD_H=1 HAVE_SYS_FILIO_H= HAVE_SYS_MODEM_H= HAVE_SYS_SELECT_H=1 HAVE_SYS_SOCKIO_H= HAVE_SYS_STRTIO_H= HAVE_SYS_TIMERFD_H=1 HAVE_TM_GMTOFF=1 HAVE_UNISTD_H=1 HAVE_XI_TOUCH_CLASS=1 WITH_ALSA=ON WITH_CAIRO=OFF WITH_CCACHE=ON WITH_CHANNELS=ON WITH_CLANG_FORMAT=ON WITH_CLIENT=ON WITH_CLIENT_AVAILABLE=1 WITH_CLIENT_CHANNELS=ON WITH_CLIENT_CHANNELS_AVAILABLE=1 WITH_CLIENT_COMMON=ON WITH_CLIENT_INTERFACE=OFF WITH_CUPS=ON WITH_DEBUG_ALL=OFF WITH_DEBUG_CAPABILITIES=OFF WITH_DEBUG_CERTIFICATE=OFF WITH_DEBUG_CHANNELS=OFF WITH_DEBUG_CLIPRDR=OFF WITH_DEBUG_DVC=OFF WITH_DEBUG_KBD=OFF WITH_DEBUG_LICENSE=OFF WITH_DEBUG_MUTEX=OFF WITH_DEBUG_NEGO=OFF WITH_DEBUG_NLA=OFF WITH_DEBUG_NTLM=OFF WITH_DEBUG_RAIL=OFF WITH_DEBUG_RDP=OFF WITH_DEBUG_RDPDR=OFF WITH_DEBUG_RDPEI=OFF WITH_DEBUG_RDPGFX=OFF WITH_DEBUG_REDIR=OFF WITH_DEBUG_RFX=OFF WITH_DEBUG_RINGBUFFER=OFF WITH_DEBUG_SCARD=OFF WITH_DEBUG_SND=OFF WITH_DEBUG_SVC=OFF WITH_DEBUG_SYMBOLS=OFF WITH_DEBUG_THREADS=OFF WITH_DEBUG_TIMEZONE=OFF WITH_DEBUG_TRANSPORT=OFF WITH_DEBUG_TSG=OFF WITH_DEBUG_TSMF=OFF WITH_DEBUG_TSMF=OFF WITH_DEBUG_TSMF_AVAILABLE=0 WITH_DEBUG_WND=OFF WITH_DEBUG_X11=OFF WITH_DEBUG_X11_CLIPRDR=OFF WITH_DEBUG_X11_LOCAL_MOVESIZE=OFF WITH_DEBUG_XV=OFF WITH_DSP_EXPERIMENTAL=OFF WITH_DSP_FFMPEG=OFF WITH_EVENTFD_READ_WRITE=1 WITH_FAAC=OFF WITH_FAAD2=OFF WITH_FFMPEG=TRUE WITH_FFMPEG=TRUE WITH_GFX_H264=ON WITH_GPROF=OFF WITH_GSM=ON WITH_GSSAPI=OFF WITH_GSTREAMER_0_10=OFF WITH_GSTREAMER_1_0=ON WITH_ICU=OFF WITH_IPP=OFF WITH_JPEG=ON WITH_LAME=OFF WITH_LIBRARY_VERSIONING=ON WITH_LIBSYSTEMD=ON WITH_MACAUDIO=OFF WITH_MACAUDIO=OFF WITH_MACAUDIO_AVAILABLE=0 WITH_MANPAGES=ON WITH_MBEDTLS=OFF WITH_OPENCL=OFF WITH_OPENH264=OFF WITH_OPENSLES=OFF WITH_OPENSSL=ON WITH_OSS=ON WITH_PAM=ON WITH_PCSC=ON WITH_PROFILER=OFF WITH_PROXY=ON WITH_PROXY_MODULES=OFF WITH_PULSE=ON WITH_SAMPLE=OFF WITH_SANITIZE_ADDRESS=OFF WITH_SANITIZE_ADDRESS_AVAILABLE=1 WITH_SANITIZE_MEMORY=OFF WITH_SANITIZE_MEMORY_AVAILABLE=1 WITH_SANITIZE_THREAD=OFF WITH_SANITIZE_THREAD_AVAILABLE=1 WITH_SERVER=ON WITH_SERVER_CHANNELS=ON WITH_SERVER_INTERFACE=ON WITH_SHADOW=ON WITH_SMARTCARD_INSPECT=OFF WITH_SOXR=OFF WITH_SSE2=ON WITH_SWSCALE=OFF WITH_THIRD_PARTY=OFF WITH_VAAPI=OFF WITH_VALGRIND_MEMCHECK=OFF WITH_VALGRIND_MEMCHECK_AVAILABLE=1 WITH_WAYLAND=ON WITH_WINPR_TOOLS=ON WITH_X11=ON WITH_X264=OFF WITH_XCURSOR=ON WITH_XDAMAGE=ON WITH_XEXT=ON WITH_XFIXES=ON WITH_XI=ON WITH_XINERAMA=ON WITH_XKBFILE=ON WITH_XRANDR=ON WITH_XRENDER=ON WITH_XSHM=ON WITH_XTEST=ON WITH_XV=ON WITH_ZLIB=ON
    Build type: RELWITHDEBINFO
    CFLAGS: -g -O2 -fdebug-prefix-map=/build/freerdp2-XaBpI_/freerdp2-2.0.0~git202003120736=. -fstack-protector-strong -Wformat -Werror=format-security -Wdate-time -D_FORTIFY_SOURCE=2 -Wdate-time -D_FORTIFY_SOURCE=2 -fPIC -Wall -Wno-unused-result -Wno-unused-but-set-variable -Wno-deprecated-declarations -fvisibility=hidden -Wimplicit-function-declaration -Wredundant-decls -g -DWINPR_DLL
    Compiler: GNU, 9.2.1
    Target architecture: x64
  • OS version connecting to
    Windows 10
  • If available the log output from a run with /log-level:trace
    See above

Desktop (please complete the following information):

  • OS: [e.g. iOS] Ubuntu 19.10
  • Browser [e.g. chrome, safari]
  • Version [e.g. 22]
kerberos

Most helpful comment

I had the same problem. What worked for me was:

On laptop that you want to remote desktop to untick Allow connections only from computers running Remote Desktop with Network Level Authentication (recommended).

unknown

And then use security mode TLS:

xfreerdp /sec:tls /d:AzureAD /u:UserName /p:Password /v:1.2.3.4

Without /sec:tls it throws ERRCONNECT_LOGON_FAILURE.

All 14 comments

Please try again with the freerdp2 commandline syntax, might be a bug in the legacy parser.

the second thing you can try is /u:[email protected] syntax to provide your credentials, this is handled differently by the server than the /u:user /d:domain synatx

With the freerdp2 syntax:

[09:16:15:332] [7393:7394] [INFO][com.freerdp.core] - freerdp_connect:freerdp_set_last_error_ex resetting error state
[09:16:15:333] [7393:7394] [INFO][com.freerdp.client.common.cmdline] - loading channelEx rdpdr
[09:16:15:333] [7393:7394] [INFO][com.freerdp.client.common.cmdline] - loading channelEx rdpsnd
[09:16:15:333] [7393:7394] [INFO][com.freerdp.client.common.cmdline] - loading channelEx cliprdr
[09:16:15:658] [7393:7394] [INFO][com.freerdp.primitives] - primitives autodetect, using optimized
[09:16:15:660] [7393:7394] [INFO][com.freerdp.core] - freerdp_tcp_is_hostname_resolvable:freerdp_set_last_error_ex resetting error state
[09:16:15:660] [7393:7394] [INFO][com.freerdp.core] - freerdp_tcp_connect:freerdp_set_last_error_ex resetting error state
[09:16:17:193] [7393:7394] [WARN][com.freerdp.crypto] - Certificate verification failure 'unable to get local issuer certificate (20)' at stack position 0
[09:16:17:193] [7393:7394] [WARN][com.freerdp.crypto] - CN = T480s14
Password: 
[09:16:23:909] [7393:7394] [ERROR][com.freerdp.core] - nla_recv_pdu:freerdp_set_last_error_ex ERRCONNECT_LOGON_FAILURE [0x00020014]
[09:16:23:910] [7393:7394] [ERROR][com.freerdp.core.rdp] - rdp_recv_callback: CONNECTION_STATE_NLA - nla_recv_pdu() fail
[09:16:23:910] [7393:7394] [ERROR][com.freerdp.core.transport] - transport_check_fds: transport->ReceiveCallback() - -1

With the email-like username:
[09:18:11:054] [8120:8121] [INFO][com.freerdp.core] - freerdp_connect:freerdp_set_last_error_ex resetting error state [09:18:11:054] [8120:8121] [INFO][com.freerdp.client.common.cmdline] - loading channelEx rdpdr [09:18:11:054] [8120:8121] [INFO][com.freerdp.client.common.cmdline] - loading channelEx rdpsnd [09:18:11:054] [8120:8121] [INFO][com.freerdp.client.common.cmdline] - loading channelEx cliprdr [09:18:11:375] [8120:8121] [INFO][com.freerdp.primitives] - primitives autodetect, using optimized [09:18:11:378] [8120:8121] [INFO][com.freerdp.core] - freerdp_tcp_is_hostname_resolvable:freerdp_set_last_error_ex resetting error state [09:18:11:378] [8120:8121] [INFO][com.freerdp.core] - freerdp_tcp_connect:freerdp_set_last_error_ex resetting error state [09:18:11:536] [8120:8121] [WARN][com.freerdp.crypto] - Certificate verification failure 'unable to get local issuer certificate (20)' at stack position 0 [09:18:11:536] [8120:8121] [WARN][com.freerdp.crypto] - CN = T480s14 Password: [09:18:17:822] [8120:8121] [ERROR][com.freerdp.core] - nla_recv_pdu:freerdp_set_last_error_ex ERRCONNECT_LOGON_FAILURE [0x00020014] [09:18:17:822] [8120:8121] [ERROR][com.freerdp.core.rdp] - rdp_recv_callback: CONNECTION_STATE_NLA - nla_recv_pdu() fail [09:18:17:822] [8120:8121] [ERROR][com.freerdp.core.transport] - transport_check_fds: transport->ReceiveCallback() - -1

@roukydesbois ok, this looks like this may not be allowed.
If you have something available, can you try with mstsc (the microsoft remote desktop client) to connect?
It that fails too you need to configure your laptop to allow that ;)

I can connect, on the same computer, using a local account (no Office365/AzureAD credentials) - so RDPing must be allowed (I activated it in the Windows settings).

And I have already checked that from the Windows RDP client, I can connect to the Windows 10 using AzureAD/Office365 credentials.

@roukydesbois thing is, if all you tell me is true (you can connect with local account, you can connect with Azure credentials on some different machine) then the only reasonable explanation is you have some config on your laptop preventing that.
On the other hand, if you can connect with mstsc to your laptop with the azure credentials that contradicts that.
Could you try the same with our nightly builds https://github.com/FreeRDP/FreeRDP/wiki/PreBuilds ?
Maybe it is some bug in the distro package you use.

I found https://tech.xenit.se/how-to-rdp-into-a-azure-ad-joined-vm-in-azure/
so, do you use the domain part for your username correctly?

Hello,

Thanks for the link. I'm a bit under the weather work-wise, so I created a local account for now, so that I can work. I'll continue debugging this weekend 馃檪

Hello again!
I'm using daily builds from remmina, and nightly from yours.
I tried the credentials format that you shared, and had no success.
I also stumbled on this: https://docs.microsoft.com/en-us/windows/client-management/connect-to-remote-aadj-pc
It states that both PCs must be joined to the Azure AD, could it be an issue?

@roukydesbois yes, that explains it. Requires kerberos which we currently have no properly working implementation.

I guess I'll stay with my local account for now then :) Thanks for your time!

I had the same problem. What worked for me was:

On laptop that you want to remote desktop to untick Allow connections only from computers running Remote Desktop with Network Level Authentication (recommended).

unknown

And then use security mode TLS:

xfreerdp /sec:tls /d:AzureAD /u:UserName /p:Password /v:1.2.3.4

Without /sec:tls it throws ERRCONNECT_LOGON_FAILURE.

Can confirm, solution provided by @rootkiwi works with same kind of setup.

FWIW: Kerberos authentication using MS online identity accounts or pure azure ad accounts require account prefix credentials: account_prefix\user@dnsdomain. This value is used as the user name, and the domain value remains empty.

The prefix for a windows online account is "MicrosoftAccount" and for pure azure ad it is "AzureAD"
This prefix value is used by the OS to select the correct security provider to perform the authentication.

Was this page helpful?
0 / 5 - 0 ratings