PAM-RDP Relay should work on customized port instead of default port 3389, along with that the below should not be a constraint
Disable Network level Authentication for MS RDP should not be constraint
RDP Session Host Configuration- Security negotiation should be High, instead of negotiable,
and PAM RDP should work with systems enabled with FIPS encryption.
