TS Time session limit with RSA agent

Posted on 2013-12-17
Last Modified: 2014-10-28
Hi Experts,

I experiment a strange behaviour on a TS server (2003 R2) which is set to use the RSA agent. The users are disconnected of their TS session after 30 minutes of idle while the RDP-Tcp connection is directly set through tscc.msc to override user settings and disconnect from idle sessions after 18 hours only and disconnect active session after 1day. I also set the "End a disconnected session" to 1 day.

I contacted RSA and they told me that this is a Windows problem and that this can't be from RSA.

We use RSA Authentication Manager 7.1 and the Windows agent on the TS server (2003 R2)

Any idea ?

Thank you in advance for your help, best regards,
Question by:jet-info
  • 6
  • 5
LVL 62

Expert Comment

ID: 39725694
In the past, RSA also advise that their appliance does not set user session timeout values. Specific to GPO, MS has the link to the configuration (there are 3 setting namely End a disconnected session, Active session limit and Idle session limit) and the RSOP to ensure the policy is configured

Another way is to go registry to see if setting stands
1/ Goto: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Contro l\TerminalServer\WinStations\RDP-Tcp
2/ Create DWORD
3/ Name: LogonTimeout (DWORD)
4/ Value: Specifies the time in seconds – Decimal Value – 300. Hex - (12c)its 5 minutes. - 3600. Hex (e10) is 1hr
5/ Please reboot the server after adding the above key.

Author Comment

ID: 39785595
Sorry for the delay, I have to manage many networks and this problem is not in the top ten so please forgive me for the delay.
I tried all these solutions without any chance. RDP sessions still deconnect after 30 minutes... Even the registry key doesn't work!

What can I check now ?
LVL 62

Expert Comment

ID: 39787325
Wondering if this helps and if w/o RSA will the TS session still be disconnected in short while of 30mins.

Author Comment

ID: 39829028
Sorry for the delay,

I let it alone since it looks like that there is no solution... :(

I tried all theses solutions without any chance.

I don't understand, the registry key is configured, the GPO also. When I run a RSOP I can see it but it doesn't work.

The TS server is on a "SBS 2011 domain", I tried to isolate it in an inheritance blocked OU, the problem persists.

Any idea ?
LVL 62

Expert Comment

ID: 39829458
It is going wild and we need to isolate the issue which can be the Windows alone. I do suggest the RSA agent in the server be removed and ascertain the session timeout does not exist with the policy set as in accordance to the discussion.

If that works to see that user are not timeout in short period, we can proceed to have the RSA agent installed and verify again. This time round the problem resurfaced and RSA support need to clarify why then.

I know it is painful to rebuild but that is also a good ways to isolate the before and after effect. Audit can be enable to trace the event but I think it is even more tedious to correlate , you can check out this post @

I do see another option (or maybe the same as we said so far but no harm re-visit it) though I am not putting too much confidence in sieving out the root cause. It suggests configuring keep-alives.

You can work around the issue by configuring RDP session timeouts manually.
This change requires a reboot
-Issue can be masked if "reconnect if connection is dropped" is set at the client. Look for many instances of users disconnecting, then immediately reconnecting to identify the issue
--Disconnect Event ID, followed by a Reconnect Event ID about 10 seconds later for the same user name (Event IDs below)
--The disconnect / reconnect can also be seen in the Event ID logs on a Remote Desktop Gateway server
-TCPIP keep alive does NOT need to be configured for the RDP keep alive to work
-The registry locations are the same for Windows Server 2003 and Windows Server 2008
Zoho SalesIQ

Hassle-free live chat software re-imagined for business growth. 2 users, always free.


Author Comment

ID: 39839266
Sorry for the delay, I don't have a lot of time for the moment...
I come back ASAP.

Author Comment

ID: 40027654
Edited the KeepAlive settings in the registry with no luck... After 30 minutes, the session is again locked...

What could it be?

Any other idea ?
LVL 62

Accepted Solution

btan earned 500 total points
ID: 40028623
Will you be able to surface more log and error message (event log and rsa side) to isolate the issue as apparently this will required more drilled in (else we hitting with trial and error which is not optimal)

Author Comment

ID: 40117428
to be continued...

Author Closing Comment

ID: 40408425
Thanks, the problem remain but what can we do more....
LVL 62

Expert Comment

ID: 40408674
if only the support can see your log and help and this matter has been dragging .. and I wished not to change to 2008 R2 though

Featured Post

Comprehensive Backup Solutions for Microsoft

Acronis protects the complete Microsoft technology stack: Windows Server, Windows PC, laptop and Surface data; Microsoft business applications; Microsoft Hyper-V; Azure VMs; Microsoft Windows Server 2016; Microsoft Exchange 2016 and SQL Server 2016.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Account Lockouts 25 145
Active Directory delegation of control to a user 3 77
How to get AD RMS to work with Office 2016 for Mac 6 150
Blocking content from YouTube 3 80
Restoring deleted objects in Active Directory has been a standard feature in Active Directory for many years, yet some admins may not know what is available.
A customer recently asked me about anti-malware and the different deployment options available for his business. Daily news about cyberattacks, zero-day vulnerabilities, and companies that suffered a security breach made him wonder if the endpoint a…
Sending a Secure fax is easy with eFax Corporate ( First, Just open a new email message.  In the To field, type your recipient's fax number You can even send a secure international fax — just include t…
A simple description of email encryption using a secure portal service. This is one of the choices offered by The Email Laundry for email encryption. The other choices are pdf encryption which creates an encrypted pdf of your email and any attachmen…

914 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

19 Experts available now in Live!

Get 1:1 Help Now