Relay Pass (passwordless Windows logon)
Relay Pass lets DartRelay log a person on to a Windows host without their password. When they launch a Pass-Through resource, DartRelay obtains a short-lived logon certificate for their Active Directory account from your own certificate authority and presents it to the host like a smart card. This page explains when you need it and walks through the certificate authority, DartRelay and host setup.
Why you would use it New in 2.1
A resource set to Pass-Through logs people on to the host with their own Windows account. Normally DartRelay uses the password they typed at sign-in. In some cases there is no password to use:
- the person signed in with Microsoft Entra ID or an OpenID Connect provider, so DartRelay never saw a password;
- the person signed in through a load balancer or appliance that passes their identity in a header (see Load balancer and ADC integration);
- the person signed in with their Windows password, but it is no longer held, for example after DartRelay has restarted or when another server in a pool handles the launch.
Without Relay Pass, the portal asks for the Windows password once in a small prompt. With Relay Pass, there is no prompt: the person clicks the resource and it opens.
Relay Pass needs nothing extra installed: DartRelay itself requests the certificates, on behalf of each user, from your existing Active Directory Certificate Services. Nothing is needed per user.
How it works
- The person signs in to the portal by any of the methods above, and DartRelay knows their Active Directory account.
- At their first Pass-Through launch, DartRelay creates a new key pair in memory and asks your certificate authority for a logon certificate for that account. It signs the request with its own enrollment agent certificate, which is what allows it to request certificates on behalf of other users.
- DartRelay presents the certificate to the host as a virtual smart card. Windows on the host checks it with your domain controller and logs the person on, exactly as if they had used a physical smart card.
- The certificate is kept in memory for that portal sign-in and reused for further launches until it expires or the person signs out. It is never written to DartRelay's database.
If anything goes wrong, such as the certificate authority not answering, DartRelay falls back to the Windows password prompt and records the reason in the log, so people are never stuck.
For every sign-in method you switch Relay Pass on for, DartRelay can log on to hosts as whichever Active Directory account that sign-in maps to. Only switch it on for sign-in methods you trust as much as a password. Use the certificate authority's enrollment agent restrictions (step 6 below) to limit which users DartRelay may request certificates for.
Before you begin
- An enterprise certificate authority (Active Directory Certificate Services) in the users' domain or forest.
- Each domain controller in that domain has a domain controller certificate (from the Kerberos Authentication or Domain Controller Authentication template). Domain controllers enrolled from an enterprise CA usually have one already.
- The hosts are joined to the users' domain, so they trust the certificate authority.
- DartRelay runs on Windows. Certificate requests use Windows' own certificate enrolment.
- Hosts have a management account set in DartRelay, so DartRelay can prepare them (see Adding and preparing hosts).
Part 1: prepare the certificate authority
Do these steps once, as a domain or enterprise administrator, on your certificate authority. The detail page of each pass in DartRelay also carries these steps in a folding AD CS preparation block.
- Create the logon template. Open Certificate Templates (
certtmpl.msc), right-click Smartcard Logon and choose Duplicate Template. Name it, for example, DartRelay Logon. - Set compatibility and key. On the Compatibility tab, set both the certificate authority and the certificate recipient to Windows Server 2016 or later. On the Cryptography tab, use an RSA key of 2048 bits.
- Build the subject from Active Directory. On the Subject Name tab, choose Build from this Active Directory information and include the user principal name (UPN) in the alternative subject name. This makes the certificate authority add the user's security identifier to the certificate, which domain controllers require for strong certificate mapping.
- Require the enrollment agent's signature. On the Issuance Requirements tab, tick This number of authorized signatures, set it to 1, choose the policy type Application policy and the application policy Certificate Request Agent.
- Keep it short-lived. On the General tab, set the validity period to a few hours; 8 hours is a good choice. DartRelay simply requests a new certificate when one expires, so renewal is not needed. Its readiness check warns if the validity is longer than one day. On the Request Handling tab, leave Allow private key to be exported off.
- Allow only DartRelay to enrol. On the Security tab, give Read and Enroll to the account the DartRelay service runs as. If the service runs as the local system account, that is the DartRelay server's computer account (
SERVERNAME$). Do not give Enroll to users. - Publish the templates. Open Certification Authority (
certsrv.msc), right-click Certificate Templates, choose New → Certificate Template to Issue, and add your new logon template. Make sure the Enrollment Agent template is issued too. - Limit what the enrollment agent may do. In the certificate authority's properties, on the Enrollment Agents tab, restrict enrollment agents so that DartRelay's agent may use only the logon template, and only for the user groups DartRelay serves. This is the safeguard behind the warning above.
- Check the authority is in NTAuth. An enterprise certificate authority is normally published to the domain's NTAuth store automatically, and domain controllers will only accept smart-card logons from authorities listed there. If DartRelay's readiness check says it is missing, export the CA certificate and publish it as an enterprise administrator:
The second command must list your certificate authority.certutil -dspublish -f ca-certificate.cer NTAuthCA certutil -enterprise -store NTAuth - Give DartRelay an enrollment agent certificate. Request a certificate from the Enrollment Agent template so that its private key is usable by the account the DartRelay service runs as. Note the certificate's thumbprint and the certificate store it is in; you will enter both in DartRelay.
Part 2: switch on certificate logon in DartRelay
Certificate logon is set per pass on Authentication → Relay Pass. Each pass, whether a Microsoft Entra ID, Okta, Google or other OpenID Connect sign-in, has its own Windows logon card with its own certificate settings, so different passes can use different certificate authorities. Two built-in rows are always on the list and cannot be removed; they have only the Windows logon card:
| Built-in row | Covers |
|---|---|
| Sign-in by header | People signed in by a load balancer or appliance that passes their identity in a header. The appliance itself is set up under Authentication → Authentication Methods. |
| Windows password, no longer held | People who signed in with their Active Directory password, when that password is no longer held (after a restart, or on another server in a pool). Relay Pass replaces the password prompt for them. |
Relay Pass is never used for portal accounts or for anonymous visitors.
- Open the pass. Go to Authentication → Relay Pass and open the pass (or built-in row) whose users should get certificate logon.
- Switch on Log on with a certificate on the Windows logon card.
- Enter the certificate settings. Fill in the certificate authority, the logon template name, and the enrollment agent certificate's thumbprint and store.
- Save.
- Click Check readiness. DartRelay checks the enrollment agent certificate (found, private key usable, correct purpose, not expired), that the certificate authority answers, that it is listed in NTAuth, that the template exists and is published, and the template's validity. Each check reads Pass, Warn or Fail with an explanation.
- Click Test enrol. DartRelay requests a certificate for a user you name and shows the result. Tests always use the saved settings.
| Field | What it does | Default |
|---|---|---|
| Log on with a certificate | Whether this pass's users are logged on to hosts with a certificate. When off, they get the Windows password prompt. | Off |
| Certificate authority | The certificate authority to request from, in its usual server\CA name form. | — |
| Template | The logon template's name, as created in Part 1. | — |
| Enrollment agent thumbprint | The thumbprint of DartRelay's enrollment agent certificate. | — |
| Enrollment agent store | The certificate store that holds it. | — |
Part 3: prepare each host
Windows has to accept a smart-card logon from DartRelay. DartRelay can make the changes for you.
- Open the host. Go to Catalog → Hosts and open the host.
- Click Check on the Certificate sign-in (Relay Pass) card. This reads the host's settings and changes nothing. It reports the Smart Card service, whether the virtual card type is registered, Network Level Authentication, the certificate authorities the host trusts for logon, the session settings and any disconnected sessions.
- Click Prepare this host. Using the host's management account, DartRelay:
- turns off Network Level Authentication for Remote Desktop and allows the TLS security layer, which a smart-card logon of this kind requires;
- sets the Smart Card service to start automatically and starts it;
- registers the virtual smart card type so Windows uses its built-in smart card driver;
- applies the host's session settings (one session per account, and ending disconnected sessions after the time you chose), then refreshes Group Policy on the host so they take effect.
- Click Sign out disconnected sessions once, if the check lists any. Old disconnected sessions can stop a certificate logon (see below).
- Click Check again and confirm every line passes.
Turning off Network Level Authentication means the host's Remote Desktop port answers before anybody has signed in. Limit Remote Desktop (TCP 3389) on each prepared host to the DartRelay server's address with Windows Firewall or your network firewall, so only DartRelay can connect to it.
Why disconnected sessions matter
If an account has two or more disconnected sessions on a host, Windows asks which one to reconnect to at logon. A published application cannot show that question, so the tab says the application "has not appeared" and Windows ends the attempt after about 30 seconds. Keeping hosts on one session per account and ending disconnected sessions after a sensible time (one hour is a good choice) prevents this. The setting End disconnected sessions after is on the host's page; see Host session options. A new limit only applies to sessions that disconnect after it is set, which is why the Sign out disconnected sessions button exists.
Example: Microsoft sign-in with no password at all
A company uses Microsoft Entra ID with multi-factor authentication and wants staff to reach their desktop without typing a Windows password.
- They set up the Microsoft pass as described in Microsoft Entra ID sign-in.
- On their certificate authority they create the DartRelay Logon template with an 8-hour validity, give the DartRelay server's computer account Enroll, and restrict the enrollment agent to the group
CORP\Remote staff. - On the Microsoft pass they switch on Log on with a certificate, fill in the settings, and run Check readiness and Test enrol.
- They run Prepare this host on both desktop hosts and limit port 3389 to the DartRelay server.
Staff now click Sign in with Microsoft, approve the multi-factor prompt on their phone, click their desktop, and it opens. Each person gets their own certificate automatically.
If something goes wrong
| Problem | Cause and fix |
|---|---|
| People still get the Windows password prompt. | Log on with a certificate is off for the pass they signed in with, or the certificate could not be obtained. The DartRelay log records why. Run Check readiness on the pass. |
| Test enrol fails with an access or permission error. | The account DartRelay runs as lacks Read and Enroll on the template, cannot use the enrollment agent certificate's private key, or the CA's enrollment agent restrictions exclude that user. |
| Readiness says the template is not published. | Add it under Certificate Templates → New → Certificate Template to Issue on the certificate authority. |
| Readiness says the authority is not in NTAuth. | Publish it with certutil -dspublish as shown in Part 1. If the domain store is correct but a host still reports it missing, refresh Group Policy on the host and check again. |
| The host refuses the connection with a security negotiation error. | The host has not been prepared, or a Group Policy turns Network Level Authentication back on. Run Prepare this host and check which policy applies. |
| The tab says the application "has not appeared", then the session ends after about 30 seconds. | The account has disconnected sessions on the host and Windows is asking which to reconnect to. Click Sign out disconnected sessions and set End disconnected sessions after on the host. |
| Check reports the session settings are controlled by Group Policy. | A domain policy overrides the host's own setting. Change the policy, or accept the policy's values. |
Related pages
Microsoft Entra ID
The most common reason to use Relay Pass.
OpenID Connect
Okta, Google and other providers.
Hosts
Management accounts and host readiness.
Host session options
Sessions per account and disconnected-session limits.
