Verifired that it works with Server 2025 as a host
Issue with Remote Credential Guard on Windows 11 24H2 Connecting to Server 2022 RDS Hosts
Issue with Remote Credential Guard on Windows 11 24H2 Connecting to Server 2022 RDS Hosts
I am experiencing issues when using Remote Credential Guard to connect from a Windows 11 24H2 client to our Windows Server 2022 RDS hosts. When using a Windows 10 client, everything works as expected.
I have reproduced this issue in a clean lab environment with fully patched installations of both clients and servers. The clients are Entra ID-joined and use Kerberos Cloud Trust for authentication.
When connecting from Windows 11 24H2, I cannot access file shares. I am prompted for credentials, but no matter what I enter, authentication fails. However, if I log out and then connect using the same user from a Windows 10 client, Single Sign-On (SSO) works correctly—both from the client to the RDS host and from the RDS host to network resources.
For testing purposes, I have used the Netlogon share as a test case.
Clients receive configurations from Intune and are identical in setup.
RDS hosts receive settings via GPO, and the same server is used for testing, ensuring settings remain consistent across tests.
Windows Server 2022: 21H2, Build 20384.3207
Windows 11: 24H2, Build 26100.3194 (issue occurs)
Windows 10: 22H2, Build 19045.5555 (works flawlessly)
I am currently installing Windows Server 2025 to test if the issue persists.
Seems like this is a "known issues" for admins around the world but we does not seem to be able to find any information about this from Microsoft. Issue with Remote Credential Guard on Windows 11 24H2 Connecting to Server 2022 RDS Hosts
Issue with Remote Credential Guard on Windows 11 24H2 Connecting to Server 2022 RDS Hosts
I am experiencing issues when using Remote Credential Guard to connect from a Windows 11 24H2 client to our Windows Server 2022 RDS hosts. When using a Windows 10 client, everything works as expected.
I have reproduced this issue in a clean lab environment with fully patched installations of both clients and servers. The clients are Entra ID-joined and use Kerberos Cloud Trust for authentication.
When connecting from Windows 11 24H2, I cannot access file shares. I am prompted for credentials. However, if I log out and then connect using the same user from a Windows 10 client, Single Sign-On (SSO) works correctly—both from the client to the RDS host and from the RDS host to network resources.
For testing purposes, I have used the Netlogon share as a test case.
Clients receive configurations from Intune and are identical in setup.
RDS hosts receive settings via GPO, and the same server is used for testing, ensuring settings remain consistent across tests.
Windows Server 2022: 21H2, Build 20384.3207
Windows 11: 24H2, Build 26100.3194 (issue occurs)
Windows 10: 22H2, Build 19045.5555 (works flawlessly)
I am currently installing Windows Server 2025 to test if the issue persists.
Seems like this is a "known issues" for admins around the world but we does not seem to be able to find any information about this from Microsoft.
Windows for business | Windows Server | User experience | Other
4 answers
Sort by: Most helpful
-
OLA FRANSSON • 30 Reputation points
2025-03-21T07:35:56.56+00:00 -
Raphael Büchi • 2 Reputation points2025-06-26T13:32:11.6733333+00:00 Can confirm. In-place upgrade from 2022 took about 2h, and now it's finally fixed when connecting from Windows 11 24h2 (26100.4351) clients.
-
NC_GLIP • 20 Reputation points
2025-09-16T11:14:46.83+00:00 really works for you with W11 24H2 & WS2025 ?
-
Petr Bartos • 6 Reputation points
2025-09-27T18:15:35.92+00:00 maybe sometimes. In our scenario:
W11 23H2 -> WS 2025 24H2 (works) -> WS 2019 (does not work)W11 23H2 -> WS 2022 21H2 (works) -> WS 2019 (works)
So for the same destination path, the WS2025 is problem as an intermediary. Is not a problem if the server is an target.
-
NC_GLIP • 20 Reputation points
2025-09-29T07:55:49.23+00:00 -
-
NC_GLIP • 20 Reputation points
2025-10-10T06:35:40.27+00:00 it doesn't work for me when my RDS host is under WS2025
Sign in to comment -
-
Welf Alberts • 51 Reputation points
2025-03-11T09:14:08.48+00:00 Ola, I opened a ticket with paid Microsoft support back in July 24. They confirmed the problem but still haven't fixed it. I told them numerous times that fixes need to come in a timely fashion, else, we will be on a higher OS, by the time it's fixed :-(
Will keep you posted when the ticket is resolved.
-
OLA FRANSSON • 30 Reputation points
2025-03-11T09:38:25.2766667+00:00 Thanks for your reply! I would really appreciate it if you could report back with any updates.
-
Hübsch, Bartholomäus, SIT.MW, Soluvia IT-Services • 0 Reputation points
2025-05-22T08:35:44.7333333+00:00 Hello ,
is there any update for this issue?
-
MTG • 1,261 Reputation points
2025-08-05T09:52:42.34+00:00 The case is still unresolved. The communication is sparse, they say "we are discussing this internally" (for months). The support team does not to estimate this being resolved before 23 H2 goes EOL, so prepare to live with this problem! 25H2 (preview) still has this problem, by the way :-(
-
NC_GLIP • 20 Reputation points
2025-09-16T09:49:05.9566667+00:00 Hi,
I've same issue after deploying KCT & RCG on my RDSH farms .. everything works fine with W11 23H2, but the second hop won't work on 24H2, nor in preview 25H2 :(
any update on your side ?
-
MTG • 1,261 Reputation points
2025-09-17T08:05:33.9033333+00:00 YES, there is an update. Microsoft informed me that they will release a fix on the D week aof September '25, that will be the 23rd. So look out for the preview updates on the 23 and hope that these will truly fix it. Will do the same.
-
NC_GLIP • 20 Reputation points
2025-09-19T08:12:03.3666667+00:00 Thanks for that update, hope that will resolve this very annoying problem
I will post a message here as soon as I have any updates, probably next week, if Microsoft keeps its promise
-
-
Welf Alberts • 51 Reputation points
2025-09-25T12:19:11.4533333+00:00 No progress. MS hasn't yet shipped the preview updates. looking back, sometimes it took them until the end of the D week to ship the preview, so "not all hope is lost".
-
NC_GLIP • 20 Reputation points
2025-09-29T06:29:44.8366667+00:00 I haven't seen the update on my side, so let's not lose hope.
-
Welf Alberts • 51 Reputation points
2025-09-30T12:20:43.36+00:00 Guys, don't confuse credential guard and remote credential guard, these are totally different things. The remote credential guard problem exists, when downlevel OS' RDP-connect to Win11 24h2 or 25H2 or server 2025. Also the other way round, those new OS' RDP-connect to anything lower than server 2025/Win11 24H2. In the rdp session, you cannot use your credentials to do more rdp hops nor to use shares without re-authenticating. The problem still exists, the case I opened with Microsoft is still open and the technicians lately said "September 2025 D-week will bring a fix with the preview updates for 24 H2" - unfortunately I just tried these and they didn't fix it. However, the release notes didn't confirm that this preview update ought to fix it, so it seems, the fix just got delayed!
-
NC_GLIP • 20 Reputation points
2025-10-03T07:42:07.9566667+00:00 Thanks for the clarification, so this is the fix I'm waiting for, wait and see
-
Cathy Leik • 11 Reputation points
2025-10-03T11:28:56.5933333+00:00 Has Microsoft listed this as a known issue in any of their documentation? I just upgraded a site to 2025 to fix this in a Citrix environment. This is a pretty big issue for folks to get hit with.
-
NC_GLIP • 20 Reputation points
2025-10-06T12:32:39.3+00:00 are you connecting from W11 24H2 ? 25H2 ?
-
Cathy Leik • 11 Reputation points
2025-10-09T17:33:13.03+00:00 Win11 24H2 - we upgraded to server 2025 which resolved the issue.
-
NC_GLIP • 20 Reputation points
2025-10-10T06:23:46.6133333+00:00 Just to make sure we're talking about the same issue, have you upgraded your session host servers to WS2025, and/or your file servers?
are we talking about the issue of accessing file shares via the remote session (second hop with SSO (Whfb + KCT)).
-
-
BrentB • 5 Reputation points
2025-10-20T20:58:13.34+00:00 Are there any links to an official acknowledgement of this issue with Server 2022? Are they even planning on fixing this in that OS? We can't use Server 2025 yet do to software requirements.
-
-
Welf Alberts • 51 Reputation points
2025-11-04T08:15:55.21+00:00 Yes. As of October 28th, it has been patched for win11 24H2/25H2!
Please note that this patch has NO EFFECT, BUT THIS IS EXPECTED. It will start working as soon as the server OS' (2016/2019/2022) will get patched on November 11th.
-
NC_GLIP • 20 Reputation points
2025-11-04T09:25:43.57+00:00 Is it the KB5067036 ?
Ok will wait for the Windows Server Patch
Are your informations from Microsoft ?
-
Welf Alberts • 51 Reputation points
2025-11-04T09:31:32.32+00:00 Yes, KB5067036. Open its description and visit the "gradual rollout" section to find the fix described like this: "[Remote Credential Guard] Fixed: Remote Credential Guard scenarios between the latest Windows 11 builds and Windows Server 2022 or earlier might unexpectedly fail.". I get no info from Microsoft but from convergys, their support partner which does not seem to be well informed. However, the last time they had the same (exactly the same!) issue with Win11 22H2, it went the same way: preview update for clients came in end of march '23, servers were patched april 9th '23, so I have reason to assume that the servers are patched next tuesday!
-
NC_GLIP • 20 Reputation points
2025-11-04T09:36:08.46+00:00 Thanks for the clarification, fingers crossed! ;)
-
NC_GLIP • 20 Reputation points
2025-11-04T14:26:19.1766667+00:00 I've posted on the feedback hub; please vote to give it more visibility.
I've used Ola Fransson's text because the problem was very well described.
-
-
Welf Alberts • 51 Reputation points
2025-11-05T12:16:44.3+00:00 Wouwww... I just received the following hint that ought to solve it from MS support/convergys:
Thank you for your response, I just got a confirmation that further steps are needed to be done, can you check the following: a. For Win11 24H2, 25H2: deploy 2025.10D (aka. October cumulative update preview) and use the KIR GPO to enable the fix on these devices. b. Download the OS version-specific KIR MSI and install it on a domain controller: Ge October 2025 CD Key Rollout https://download.microsoft.com/download/f844fc7e-16cc-4c35-b9fa-4181d8d9777c/Windows 11 2 251003_17001 Feature Preview.msi c. Executing the MSI installs an ADMX file in the %systemroot%\policydefinitions folder that provides insight as to the OS Versionspecific KIR Group Policy Setting to configure in local or domain group policy editors d. Create the GPO: Computer config - Administrative Templates -> KB5065789 251003_17001 Feature Preview -> Windows 11, version 24H2 and Windows Server 2025 Setting KB5065789 251003_17001 Feature Preview ->Value Enabled, Reboot Requirements: A device reboot is required.
Let's try that!
-
Welf Alberts • 51 Reputation points
2025-11-06T09:43:02.4866667+00:00 Tested together with the aforementioned GPO and IT WORKS!
Please note that although it works, it will also break something, namely RCG when used against server 2025!
So before the patch:
what works: Win11 24H2/25H2 <-> Server 2025
what didn't work: "everything else"
After the patch:
what doesn't work: Win11 24H2/25H2 <-> Server 2025
What works: "everything else"
I conclude that this will be resolved at November 11th, when also server 2025 ought to get that patch!
-
NC_GLIP • 20 Reputation points
2025-11-07T08:40:40.0266667+00:00 it works for me ! W11 24H2 <==> WK22 RDS Host <==> WK22 File Server
-
Adam Karas • 0 Reputation points
2025-11-21T10:20:35.5566667+00:00 Hi, so after November 2025 update, Windows 11 KB5068861 .. it fixed W11 24H2 - 2022 server (rdp with rcg and whfb) ... but IT BROKE to server 2025!! Can someone confirm pls ? Thanks Windows 11 24H2 -> Server 2025 = OK
Windows 11 24H2 -> Server 2022 = NOT WORKING
Windows 11 24H2 2025-11 Security Update (KB5068861) (26100.7171) -> Server 2025 = NOT WORKING
Windows 11 24H2 2025-11 Security Update (KB5068861) (26100.7171) -> Server 2022 = OK
-
Welf Alberts • 51 Reputation points
2025-11-21T11:53:53.2233333+00:00 Confirmed by Microsoft. Let me share what I know: Read my thread: https://administrator.de/info/windows-remote-guard-microsoft-problem-675627.html#comment-2309359 (use translation services if needed). So far, all works now apart from 24H2/25H2 onto another24H2/25H2 - that broke with the latest patches! I am in contact with MS support and they insist that it works for them. At the moment, we are comparing lab settings, possibly, they still allow NTLM in their lab and that is the culprit (I disallow all NTLM).
-
Adam Karas • 0 Reputation points
2025-11-21T15:06:39.2466667+00:00 @Welf Alberts I will try to install these updates to Server 2025 on Sunday evening, and let you know there if it helps or not. :X
-
Adam Karas • 0 Reputation points
2025-11-24T20:07:22.55+00:00 @Welf Alberts unfortunatelly not working for me. RDP W11 24H2 to Server 2025 ... any other hints ?
-
Welf Alberts • 51 Reputation points
2025-11-25T00:13:33.6233333+00:00 Adam, thanks for trying. Rest assured, I am as worried as you are. After re-trying, Win11 24H2 or Win11 25H2->Server 2025 does not work anymore. Why did it ever work? Most probably, because I reconnected to sessions that were already authenticated before, without knowing! So at least, this behavior is consistent: working before the patches: old<->old and new2new. After the patches: new<->old works but new2new is broken! I have no idea why their supporter insists that everything works for him - will contact him again. I am tempted to say he connects to already authenticated sessions as well.
-
NC_GLIP • 20 Reputation points
2025-12-05T09:01:55.47+00:00 Hello
Please correct me if I'm wrong, but it seems the patch was included in the latest November updates.
I just reinstalled Windows 11 25H2 from scratch, and after the November updates, everything seems to be resolved, or at least RDS is working under Windows Server 2022 with SMB access under Windows Server 2022 too
Same for you ?
-
Bar Radim • 0 Reputation points
2025-12-05T09:25:24.1966667+00:00 Hello,
for me November updates doesn´t help for this configuration:
windows 11 24H2 to Win Server 2022 doesn´t work access to sharesbut still works this:
windows 11 24H2 to Win Server 2025 still work access to shares -
Welf Alberts • 51 Reputation points
2025-12-05T09:37:46.08+00:00 Be precise: did you apply the GPO as well? Only then, the situation changes. Let's call win11 24h2/25h2 and server 2025 all "new" and let's call the older OS' "old". What works now is remote credential guard when RDPing from old2new or new2old. What stops working (it worked before!) is new2new. Still in contact with MS support and they claim "all works now". We compared settings, everything is the same (clean test domains, NO further settings). But for me, new2new doesn't work, while for the MS technician, it apparently works. Puzzled to the max!
-
NC_GLIP • 20 Reputation points
2025-12-05T10:05:40.0666667+00:00 to be precise, on my desktop installed from scratch in W11 25H2, RCG seems to work without applying the GPO,
last updates applied : KB5070311, KB5068861, KB5071430
I think the patch is inside one of these updates
I'm now trying from a W11 24H2 reinstalled from scratch, news later
-
Welf Alberts • 51 Reputation points
2025-12-05T10:26:56.58+00:00 "RCG seems to work" - be precise. It works when rdp-connected to what OS? As said: 25h2<->server 2022 works for me, too, only RCG with 25H2<->25H2 doesn't work anymore.
-
NC_GLIP • 20 Reputation points
2025-12-05T10:30:41.5333333+00:00 As i said in my first comment "Dec 5, 2025, 10:01 AM", when connecting to WS2022
The difference is that now i don't need to apply the fix provided by Microsoft, you too ?
-
Welf Alberts • 51 Reputation points
2025-12-05T10:34:03.1366667+00:00 See my comment before (edited): question is: does RG work new2new for you? So connect to 25h2 or server 2025 and try to access any share in a remote session. Please note: for testing you must make sure that you connect to a target where your user is not already authenticated (= don't reconnect to a disconnected session).
-
NC_GLIP • 20 Reputation points
2025-12-05T10:41:17.1966667+00:00 This isn't relevant in my case because our RDS farms are running on WS2022, but I can run the test.
Of course, the sessions are always properly closed to avoid skewing the results.
-
NC_GLIP • 20 Reputation points
2025-12-05T11:00:25.94+00:00 actually RCG won't work between new2new (shares are not working)
but whitout installing the fix (KB5065789 251003_17001 Feature Preview)
i'm installing last updates (KB5068861) on my WS2025 test machine, news later
-
NC_GLIP • 20 Reputation points
2025-12-08T07:29:48.4933333+00:00 new2new won't work for me, even with last updates & with the fix
-
Welf Alberts • 51 Reputation points
2025-12-08T10:37:25.3366667+00:00 @NC_GLIP thanks a lot for confirming :-)
-
-
Marco Hofmann • 0 Reputation points
2026-08-03T14:23:49.7666667+00:00 Came here to express we suffer from this problem. We want to implement Citrix enhanced SSO, but FSLogix VHDX fails to mount because of this issue. As soon as we configure eSSO, FSLogix fails. But only from Win11 25H2 as a client, to Windows Server 2025 as a server. When the Citrix Server is 2019 or 2022, it works. According to my research currently only Windows Server 2025 is still affected by that bug. What can we do to solve this?
-
Cathy Leik • 11 Reputation points
2026-08-03T15:26:30.0633333+00:00 We ended up reverting the Citrix Servers to 2022.
-
MTG • 1,261 Reputation points
2026-08-03T15:31:49.7533333+00:00 It's solvable: https://learn.microsoft.com/en-us/answers/questions/5656824/kb5072033-break-remote-credential-guard-to-windows?orderby=newest&page=1#answers says (And I verified that), that all you need to do on server 2025 is this command, followed by a server restart:
reg add "HKLM\SYSTEM\CurrentControlSet\Policies\Microsoft\FeatureManagement\Overrides" /v 393858191 /t REG_DWORD /d 1 /f
Sign in to comment -
-
Adam Karas • 0 Reputation points
2025-11-25T07:02:53.7366667+00:00 Too bad, I tought W11 25H2 would work with RDP to Server 2025, but it looks like thats not the case. The real issue is update KB5068861, so for now Im just uninstalling it...Its a shame that while they are pushing passwordless so hard, they mess up quite an essential thing with such an update. Let me know if you get any more info from support pls. Thanks
-
Deleted
This answer has been deleted due to a violation of our Code of Conduct. The answer was manually reported or identified through automated detection before action was taken. Please refer to our Code of Conduct for more information.
Comments have been turned off. Learn more