AD SSO - Cannot establish NTLM authentication channel with xxx

Getting hundreds of these in the log for Authentication:

Cannot establish NTLM authentication channel with

Have read through all the other forum posts and they say to disable AD SSO in Device Access, but it's already disabled

But if I try to remove the AD server from authentication methods, I get this

  • Nevermind.

    Per-connection AD SSO was enabled in Web Authentication for the Terminal Server.

    If we're using STAS, what's the method that should be used for terminal servers? Still STAC?

    • You can use AD SSO Multi-Host (kerberos) on Terminal Server or the Intercept X (SATC). 
      If you have SATC, you can disable Kerberos. 
