TS User-ID does not work for IE if Enhanced Protected Mode is enabled

TS User-ID does not work for IE if Enhanced Protected Mode is enabled

0
Created On 09/25/18 19:48 PM - Last Modified 07/19/22 23:07 PM


Resolution


Symptom

Even though Terminal Server Agent connects to Paloalto Networks Firewall successfully, web-browsing traffic generated by Internet Explorer from an RDS (Remote Desktop Services) server, via Remote Desktop connection, is not identified per user.

 

The web-browsing traffic uses source ports included in "System Source Port Allocation Range" of Terminal Server Agent which should not be used.

 

The issue is only seen when "Enable Enhanced Protected Mode" is checked in the Internet options of Internet Explorer for each user who uses that browser.

 

Resolution

 

This is a limitation by Windows behavior. One needs to disable Enhanced Protected Mode.
Perform these steps on the Windows Server for each users to disable it:
(To disable for all users, use Local Security Policy.)

 

  1. Start Internet Explorer.
  2. Select Internet options > Advanced and scroll down to the Security section.
  3. Clear Enable Enhanced Protected Mode.
  4. Click OK.


Note:In Internet Explorer, Palo Alto Networks recommends that you do not disable Protected Mode, which differs from Enhanced Protected Mode.

 

This task is not necessary for other browsers such as Google Chrome or Mozilla Firefox.

 

 

See also

 



Actions
  • Print
  • Copy Link

    https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000CldsCAC&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail