https://learn.microsoft.com/en-us/entra/identity/authentication/howto-mfa-nps-extension-rdg
When looking at the sign-in logs for RDP clients that use Entra ID for two factor auth the log entries might show the IP address as the IP Address and Port of the RDS Gateway Server NOT the connecting client.
To view the connecting RDP client's IP Address you can use either of the following methods
Event viewer
RD Gateway logs under Event Viewer\Applications and Services Logs\Microsoft\Windows\TerminalServices-Gateway\Operational include the client IP.
RD Gateway Manager
RD Gateway Manager shows the connecting clients "Client IP Address"


0 Comments