If I connect from my domain joined client in the internal network to a RD gateway with a user who is a member of the protected users group. The logon attempt fails. If I bypass the rd gateway the logon is successful. It seems the RD gateway process the logon as NTLM (Event ID 4624). Is there a way that RD gateway can support kerberos, so a logon with protected users works?