VMHeaven

Troubleshooting

Remote Desktop can't connect to the remote computer — fixes for Windows Server

RDP can't connect to the remote computer? Check that Windows is up, RDP is on, port 3389 is reachable and NLA/CredSSP match — in that order.

Published ~9 min read

When Remote Desktop can’t connect to a Windows Server, work outward from the server. First check that Windows has booted, then that Remote Desktop is enabled and listening, then that the firewall allows it, and finally that your PC can reach the port. Look at client-side error messages only after those four checks pass. You need a way onto the server that does not depend on RDP: your provider’s VNC or KVM console. Open PowerShell there and run the first three lines, then run the last one on your own PC:

PowerShell — server checks in the console, the last line on your PC
# on the server (console, PowerShell as Administrator)
Get-Service TermService                                  # Status: Running
Get-NetTCPConnection -LocalPort 3389 -State Listen       # a line = RDP is listening
Get-NetFirewallRule -DisplayGroup 'Remote Desktop' | ft DisplayName, Enabled

# on your own PC
Test-NetConnection 203.0.113.10 -Port 3389               # TcpTestSucceeded : True

Replace 203.0.113.10 with your server’s IP address. If you moved RDP to another port, use that number in the second and last lines. The classic client message lists the same three suspects in its own words:

the error
Remote Desktop can't connect to the remote computer for one of these reasons:
1) Remote access to the server is not enabled
2) The remote computer is turned off
3) The remote computer is not available on the network

Is the server actually up?

Open the console in your provider’s panel and look at the screen. It tells you more than any RDP error:

  • A login screen: Windows is up, so the problem is RDP, the firewall or the network. Carry on below. If it asks for Ctrl+Alt+Del, send it with the console’s own button or menu; pressing the keys reaches your own computer, not the server. Inside an RDP session the shortcut is Ctrl+Alt+End; Ctrl+Alt+Del over RDP has every variant.
  • “Getting ready”, a spinning circle or “Working on updates”: Windows is still busy. After an order or a reinstall, the first boot sets up the system and takes several minutes, much longer than a Linux image. Update installs can take longer still. Wait; RDP only answers once the login screen is there.
  • A black screen or a boot error: Windows itself has a problem. Restart the server from the panel and watch the boot in the console.

Is Remote Desktop enabled?

If TermService is stopped or nothing listens on the port, switch Remote Desktop on and allow it through Windows Firewall. In the GUI, run SystemPropertiesRemote.exe and choose “Allow remote connections to this computer”; in sconfig it is option 7. In PowerShell:

PowerShell (Administrator), in the console
Set-ItemProperty -Path 'HKLM:\SYSTEM\CurrentControlSet\Control\Terminal Server' -Name fDenyTSConnections -Value 0
Enable-NetFirewallRule -DisplayGroup 'Remote Desktop'
Restart-Service TermService -Force

# non-English Windows: the same firewall group by its resource ID
Enable-NetFirewallRule -Group '@FirewallAPI.dll,-28752'

fDenyTSConnections set to 1 means Remote Desktop is off. If it switches back after a reboot, a Group Policy is setting it. The full walk-through, that policy included, is in enabling Remote Desktop on Windows Server.

Can your PC reach the RDP port?

Test-NetConnection answers that. On macOS or Linux, nc -vz 203.0.113.10 3389 does the same. If Windows listens but the test fails, something between the two machines drops the connection. Check these, in this order:

  • A firewall rule limited to an old IP address. If you restricted the Remote Desktop rules to your own address, as you should, a new IP at home locks you out. The commands below show the scope and update it.
  • A second firewall rule. In Windows Firewall a block rule beats an allow rule, so a “block 3389” rule somebody added cancels the built-in allow rules.
  • Your own network. Office, school and hotel networks often block outgoing connections to port 3389. See below.
  • Anything upstream. Rule out the first three before suspecting the route; Test-NetConnection from a second network tells you which side the problem is on.
PowerShell (Administrator), in the console
Get-NetFirewallRule -DisplayGroup 'Remote Desktop' | Get-NetFirewallAddressFilter | ft RemoteAddress
Set-NetFirewallRule -DisplayGroup 'Remote Desktop' -RemoteAddress 198.51.100.7    # your current IP

# rules you created yourself, e.g. for a custom port, go by their name
Set-NetFirewallRule -DisplayName 'RDP 13389 TCP' -RemoteAddress 198.51.100.7

Did you move RDP to another port?

Then the client has to name it, or it still tries 3389. In Remote Desktop Connection, type the address as 203.0.113.10:13389 (mstsc /v:203.0.113.10:13389). Check which port Windows really uses from the console:

PowerShell, in the console
(Get-ItemProperty 'HKLM:\SYSTEM\CurrentControlSet\Control\Terminal Server\WinStations\RDP-Tcp').PortNumber

A number you do not recognise usually means it was entered in hexadecimal in regedit. The full procedure, including the firewall rule for the new port, is in how to change the RDP port.

Did a VPN on the server cut you off?

If RDP dropped the moment a VPN client connected on the server, the VPN is sending the replies to your PC through the tunnel instead of back the way they came. Disconnect the VPN from the console and RDP returns. The fix is a bypass route for your own IP address, explained in using a VPN on a Windows RDP server.

What do the Remote Desktop error messages mean?

Once the port answers, any remaining failure comes with its own message. These are the common ones on Windows Server 2022 and 2019.

“An internal error has occurred”

The connection reached the server, but the session could not be set up. Restart the Remote Desktop service from the console first. If that does not help, a damaged or expired self-signed RDP certificate is a common cause; delete it, and Windows creates a new one when the service starts:

PowerShell (Administrator), in the console
Restart-Service TermService -Force

# still failing: replace the RDP certificate
Get-ChildItem 'Cert:\LocalMachine\Remote Desktop' | Format-List Subject, NotAfter
Get-ChildItem 'Cert:\LocalMachine\Remote Desktop' | Remove-Item
Restart-Service TermService -Force

If a Group Policy pins RDP to a specific certificate that has expired or been removed, fix the policy. A server clock that is far off causes certificate errors too.

“This could be due to CredSSP encryption oracle remediation”

The full message starts with “An authentication error has occurred. The function requested is not supported.” One side has the 2018 CredSSP security update and the other does not; today it is almost always an old, unpatched server image or client. The fix is to update whichever side is behind. On the server, use Windows Update from the console (sconfig, option 6).

If you cannot reach the server any other way, you can enable the Encryption Oracle Remediation policy on your own PC (gpedit.msc → Computer Configuration → Administrative Templates → System → Credentials Delegation) with its protection level set to Vulnerable, connect once, update the server, and set it back. Do not leave it on Vulnerable: it re-opens the flaw the update closed.

“The remote computer requires Network Level Authentication”

With Network Level Authentication (NLA), the client must prove the password before Windows builds a session. This message appears when the client cannot do that, for example a very old client or one set to an older security mode, or when a domain-joined server cannot reach its domain controller. Use a current client first. NLA also cannot show the “change your password” screen, so an expired password, or one that must be changed at the next logon, fails before you see Windows, often as “The Local Security Authority cannot be contacted”. Set a new password in the console. As a last resort, switch NLA off temporarily from the console:

PowerShell (Administrator), in the console
$rdp = 'HKLM:\SYSTEM\CurrentControlSet\Control\Terminal Server\WinStations\RDP-Tcp'
Set-ItemProperty -Path $rdp -Name UserAuthentication -Value 0     # NLA off, temporarily
# connect, fix the cause, then switch it back on:
Set-ItemProperty -Path $rdp -Name UserAuthentication -Value 1

Turn NLA back on when you are done; why it matters is explained in how to secure a Windows RDP server.

“Your credentials did not work”

  • The user name. On VMHeaven’s Windows templates it is Administrator, not admin or root. If the client adds your own PC’s name or a Microsoft account in front, choose “Use a different account” and enter .\Administrator.
  • A saved old password. After a reinstall, the client may still send the password it remembered. Delete it with cmdkey /delete:TERMSRV/203.0.113.10 or in Credential Manager, then type it fresh.
  • The keyboard layout. A password you set through the console may have been typed with a different layout than you thought: Y and Z, many special characters and, on French keyboards, even the digits sit elsewhere. Type it into Notepad in the console to see which characters actually arrive, set it again, and change it to a strong one over RDP, where your own keyboard applies.
  • An account lockout. With a lockout policy and RDP open to the internet, bots guessing passwords can lock Administrator, and the message then says the account “has been locked”. Wait for the lockout to expire or untick “Account is locked out” in lusrmgr.msc. Console logons still work. Then restrict the firewall to your IP so it stops happening, as described in the RDP security checklist.

“The connection was denied because the user account is not authorized for remote login”

The password was right, but the account may not log in over RDP. Members of Administrators may by default; every other user needs to be in the Remote Desktop Users group. Add them from the console. The SID works on every language version of Windows:

PowerShell (Administrator), in the console
Add-LocalGroupMember -SID 'S-1-5-32-555' -Member 'alice'      # Remote Desktop Users

If that is already the case, open secpol.msc → Local Policies → User Rights Assignment. “Allow log on through Remote Desktop Services” must list the group, and “Deny log on through Remote Desktop Services” must not list the user.

“Remote Desktop can’t find the computer”

The client could not turn the name you typed into an address. Check for a typo or a trailing space, try the plain IP address, and test the name with Resolve-DnsName yourserver.example.com. A DNS record you just created may need some time before your PC sees it. An IPv6 address with a port goes in brackets: [2001:db8::10]:3389.

“No Remote Desktop License Servers available”

This only appears once someone has installed the Remote Desktop Session Host role, which runs on a grace period until RDS client access licences are configured. Windows Server allows two simultaneous administrative sessions without that role. If two are enough, remove the role (Uninstall-WindowsFeature RDS-RD-Server, then restart); if not, you need RDS CALs.

Could your own network be blocking RDP?

Yes, and it is easy to rule out. Many office, school, hotel and public Wi-Fi networks block outgoing connections to port 3389. Connect your laptop to your phone’s hotspot and try again. If RDP works over the hotspot, the server is fine and your usual network is the obstacle. In that case, move RDP to another port or reach it through a VPN or an SSH tunnel, both covered in the RDP port guide.

Why does the server disconnect or shut down every hour?

An expired evaluation licence. When the Windows Server evaluation period runs out, Windows shuts itself down roughly every hour, which looks like RDP dropping at random. The Application event log says so in plain words. How to check the days left and convert to your own key is in the Windows Server evaluation licence guide.

Frequently asked

Why does RDP work after a reboot and then stop?

Usually something that starts later takes it away. A VPN client that connects after boot can route the replies to your PC into its tunnel. Bots guessing passwords on an open port 3389 can trigger the account lockout policy for Administrator. An expired evaluation licence shuts Windows down about every hour. Open the console and check: disconnect the VPN, look for lockout event 4740 in the Security log, and look for WLMS events in the Application log.

How do I connect to a Windows server from macOS or Linux?

On macOS, use Microsoft's Windows App (formerly Microsoft Remote Desktop) from the App Store and add the server's IP address as a PC. On Linux, use Remmina or FreeRDP, for example xfreerdp /v:203.0.113.10 /u:Administrator (the binary is xfreerdp3 on newer distributions). Add :port after the address if RDP does not run on 3389.

How long after ordering can I connect over RDP?

Usually within a few minutes of the server being created, but not in seconds: Windows sets up the system on its first boot, which takes noticeably longer than a Linux image. Watch it in the VNC console. RDP starts answering once the console shows the Windows login screen.

How do I reset the Administrator password if I'm locked out of RDP?

Use the VNC console in your provider's panel. Console logons are local, so they still work when RDP fails or the account is locked for network logons. Log in, open PowerShell as Administrator and run net user Administrator * to set a new password. If you no longer know any password that works on the console either, a reinstall from the panel gets you back in, but it erases the disk, so ask support first if the data matters.

Related articles

All troubleshooting