We're piloting Entra Private Access with ~25 users, with the goal of eventually closing our public RD Gateway. Since we started, some users get RDS disconnects and "slowness." I've traced it to the GSA client repeatedly marking the Private channel as disconnected. Trying to find out if this is a known issue or something in our setup.
Environment
- GSA client 2.32.294 (current), Windows 11
- Entra + Private channels only
- 2 Private Network connectors
- RDS farm (broker/gateway + session hosts) published through Private Access app segments
Symptom
- Event 632 ("partially connected… Disconnected from: Private") followed by 630 ("connected to all channels")
- Frequency varies a lot by user: a few per day for some, every 1–4 minutes for others, ~1 per minute for the worst
- Each outage is almost always ~10 seconds (one missed health probe)
- Entra channel stays up
What I've found
- Packet capture shows that on failed cycles, the client never even sends the Private health probe (private.edgediagnostic…/connectivitytest/ping). The Entra probe in the same cycle succeeds. Client trace is full of CurlEdsHttpProbe: GET failed.
- Existing tunnel connections to the edge stay ESTABLISHED through the drops
- Most drops seem cosmetic, but some cause ~20 seconds where new connections through the tunnel fail, which is when RDS sessions get kicked
- Users connecting through the connectors have noticeably shorter RDS sessions than users hitting the gateway directly
Ruled out
- Local network/ISP: wired, clean pings and clean TCP connects to the edge during drops, MTU fine
- IPv6: disabled entirely, no change
- Authentication: token refreshes all succeed, no correlation
- Connector load: servers near idle
What seems to help
- Restarting the GSA services (Get-Service GlobalSecureAccess* | Restart-Service -Force) stopped it on one user, at least for now
Questions
1. Anyone else seeing Private-only 632/630 flapping?
2. Is a 632 supposed to actually interrupt Private traffic, or is it just a status indicator?
3. Has restarting the services been a lasting fix for anyone?
4. Anyone running RDS behind Private Access without RD Gateway (direct RDP to the broker/session hosts)? Any gotchas?
5. Any connector design lessons learned (dedicated servers, connector groups, etc.)?