Package: libfreerdp2-2
Version: 2.10.0+dfsg1-1
Remmina and other RDP clients are unable to connect to Windows RDP
servers when the user is member of the group "Protected Users".
The group "Protected Users" forces the user account to use Kerberos
authentication and is recommended to prevent Kerberos Tickets and
password hashes to be cached on the server.
Typically these tickets and hashes are used for lateral movement after a
breach.
libfreerdp2-2 needs to be compiled with "WITH_GSSAPI=on" to be able to
connect with user accounts protected in such a way.
Kind Regads,
Markus Wigge