Forwarding Virtual Smart Card Credentials to Microsoft RDS Broker and RemoteApp with NLA Disabled

Hi everyone,

I'm encountering a scenario where I need to forward credentials inserted via a virtual smart card to Microsoft RDS Broker and RemoteApp. Here's the workflow: Client > SPS > Broker > Session Host.

To provide some context, NLA (Network Level Authentication) is disabled due to compatibility issues. The documentation explicitly states that smart card authentication cannot be used if NLA is negotiated at the beginning of the connection (source:

Given this setup, I'm wondering if it's possible to forward the credential and have users input their credentials only once. Currently, users are prompted for credentials not only for the SPS but also for the RDS Broker and the server where the RemoteApp is installed.

Has anyone encountered a similar scenario or found a workaround for this? Any insights or suggestions would be greatly appreciated.

Thank you in advance for your help!