Remote Session Launcher FAQ
If your account you are using with your Remote Session Launcher is a member of the “Protected Users” security Group, you will not be able to establish an RDP session with the Browser Based Launcher. This is because it is not possible to authenticate Protected Users on browsers.
It is possible to use a Protected User with the Client Based Remote Session Launcher. The local Windows machine must be a domain member and also must be Windows 10, or Server 2012 R2 or later. You cannot log in from Windows 7, or macOS (even with MS RDP client).