To use the derived credentials feature, you must create a group policy object (GPO) in Active Directory that pairs a virtual smart card with the smart card middleware installed on the remote desktop. You then apply the GPO to the organizational unit (OU) that contains the remote desktop.
Prerequisites
- Verify that the system requirements for using derived credentials are met. See Smart Card Authentication Requirements.
- Create a Virtual Smart Card.
- Verify that you can log in as an Administrator domain user on the machine that hosts your Active Directory server.
- Verify that the MMC and Group Policy Management Editor snap-in are available on your Active Directory server.
Procedure
What to do next
Log in to the server and connect to the remote desktop. The process is the same as when you use a physical smart card.
Note: If you enter the wrong PIN more than five times when using a virtual smart card to authenticate, the virtual smart card is removed and you must create a new virtual smart card.