New blog post! RD Gateway Without KDC Proxy Causes NTLM Downgrade
mstsc assumes the RD Gateway is a KDC proxy — if it isn't, Kerberos fails with an NTLM fallback!
Learn about this undocumented mstsc behavior and how to work around it
https://awakecoding.com/posts/rd-gateway-without-kdc-proxy-causes-ntlm-downgrade/