You deployed an RD Gateway at rdgw.contoso.com. Members of the RemoteUsers group must be able to connect only to servers in the RD-Targets security group. Users report certificate warnings when connecting externally using the rdgw.contoso.com name. You already created an RD CAP that allows the RemoteUsers group. What two actions should you take?
Choose an answer
Tap an option to check your answer.
Correct answer: Create an RD Resource Authorization Policy (RAP) that allows connections only to the RD-Targets computer group., Replace the existing certificate with a publicly trusted certificate whose subject name is rdgw.contoso.com and bind it to RD Gateway..
Why this is the answer
To restrict access for the RemoteUsers group to only servers in the RD-Targets security group, you must create an RD Resource Authorization Policy (RAP). RD CAPs define who can connect, while RD RAPs define what resources they can connect to. The certificate warnings indicate that the current certificate is not trusted by external clients. Replacing it with a publicly trusted certificate whose subject name matches rdgw.contoso.com will resolve these warnings, as public CAs are inherently trusted by client operating systems. Creating another RD CAP is incorrect because RD CAPs control user authorization, not resource authorization. Using a self-signed certificate would require manual distribution and installation on every client, which is impractical and still prone to warnings if not properly managed. Enabling UDP transport is unrelated to certificate warnings or resource authorization.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed