You want to allow RDP access to one particular device that is not a part of a device group.
For that you added the computer as the device, an AD type target application for a non domain controller computer.
When you create a target account for this application, you get the attached error, saying that the domain controller cant be found.
PAM 4.2.2
Clear the Active Directory site and once empty as image below, it worked fine