The default CFS policy is randomly applied to the users authenticated by SSO/TSA, whereas the correct CFS policy is shown next to the specific users in Users | Status.Â
This applies to all firmware versions, using CFS with App Rules or CFS via Users and Zones.Â
TSA is not designed to work perfectly without an Access Rule forcing the users loging in Terminal Servers to authenticate.Â
First of all make sure you are using the latest versions of Terminal Services Agent and the SSO Agent (Directory Services Connector) available in the free download section of your MySonicWall Account.Â
Â
We need to create the following Access Rule.
EXAMPLE:Â All Zones to WAN | Source: Firewall Terminal Services Agent | Users included: EveryoneÂ

That will force a correct SSO/TSA authentication therefore the appriate CFS policy will be applied to the users authenticated this way.Â