Hi,
Things are never as simple as they seem. You are assuming that there are not some custom written components at work here, which there are. When I asked internally I was told (para-phrased):
The problem is that the assumption is that we are using tsweb, and we are not.
Although from a client perspective they get the RDP control (same as tsweb), behind the scenes its connecting to our RWW proxy code running within the worker process, thus, the client running on the customer’s browser is not actually ever talking to the RDP server on the destination, there is a layer in the middle. It is probable that this was never part of the design goals. This should not an issue in the future.
The short answer is that SBS & FIPS for the web RDP client do not mix.
I hope this helps, even if it is not the answer you wanted.
ttfn
David