New Customers: 50% OFF Your First Month on All VPS Servers & Web Hosting Plans!

How To Connect To Windows Remote Desktop

This guide shows you how to enable Remote Desktop on Windows Server 2022, allow RDP traffic through firewalls, and connect from your computer. Follow three straightforward steps to get Remote Desktop running, whether you use the graphical interface or command line.

HostworldWindows & remote desktop 3 min read Updated 23 Sep 2026

Enable Remote Desktop on your Windows Server 2022, allow TCP and UDP 3389 through any firewall in front of the server, then connect from your computer with Remote Desktop Connection (mstsc) to the server’s IP or hostname. Use an Administrator account or a user you have added to Remote Desktop Users.

Before you start

  • Your server’s public IP or hostname, and Windows credentials.
  • Console access in case RDP is not yet enabled: use the Virtualizor VNC console from the Hostworld client area. See Virtualizor’s VNC guide.
  • If you previously changed the RDP port from 3389, know the exact port number.

Step 1: Enable Remote Desktop on the server

  • On Windows Server 2022 (Desktop Experience): open Settings, go to System, then Remote Desktop, and turn Remote Desktop on. Leave “Require devices to use Network Level Authentication” enabled for stronger security. Administrators can connect by default. To allow others, open System Properties, Remote tab, select “Select Users…”, then add the accounts.
  • On Windows Server 2022 Core: run SConfig, choose the Remote Desktop option, and enable it for clients that support NLA.
  • From a console session, you can switch RDP on and enable the built-in firewall rules. This enables Remote Desktop and allows the Windows Firewall “Remote Desktop” rules group:
    reg add "HKLM\SYSTEM\CurrentControlSet\Control\Terminal Server" /v fDenyTSConnections /t REG_DWORD /d 0 /f
    netsh advfirewall firewall set rule group="Remote Desktop" new enable=Yes

When you turn on Remote Desktop in Settings or System Properties, Windows Defender Firewall allows it automatically.

Step 2: Allow RDP ports in any upstream firewall

This ensures traffic reaches the server if another firewall is in the path.

  • Permit inbound TCP 3389 and UDP 3389. Microsoft recommends allowing both for best performance.
  • If you disabled or replaced Windows Defender Firewall, you still need to allow these ports in the replacement or upstream firewall.

Step 3: Connect from your computer

  • On Windows: use Remote Desktop Connection. This connects to a server, optionally specifying a port:
    mstsc.exe /v:server-or-ip[:port] /admin /f
    • /v:server-or-ip[:port] sets the destination. Add :port if you changed it from 3389.
    • /admin uses an administrative session, useful if the two admin sessions are in use.
    • /f starts full screen. You can also use /w: and /h: to set width and height.
  • On macOS and iOS: use Microsoft’s “Windows App” or the Microsoft Remote Desktop client from the app store to connect to the server’s IP or hostname.

If it does not work

  • You see “The connection was denied because the user account is not authorised for remote login” or get prompted to authenticate twice: make sure the user is an Administrator or in the Remote Desktop Users group. Check that NLA is enabled and that the account is permitted. Add users via System Properties, Remote, “Select Users…”.
  • You cannot reach the login screen: confirm TCP and UDP 3389 are open end to end. On the server, verify the RDP listener is bound to the expected port and that the “Remote Desktop” firewall rules are enabled. If you changed the RDP port, connect using server-or-ip:port, allow the new port in the firewall, then restart the Remote Desktop Services (TermService) service after any registry or port change. If you are locked out, use the Virtualizor VNC console to get in. Do not use “Re‑Install OS” in Virtualizor as it wipes the VPS entirely.
  • You hit a session limit: Windows Server allows two concurrent administrative sessions. Ask someone to sign out, or connect with /admin to take the console session.

If you are still stuck, open a support ticket and we will help.

What next

For deeper Windows VPS setup, console recovery and networking tips, see our VPS guides. If you want a new UK location server, see UK London VPS. Keep this article handy for enabling RDP after rebuilds or firewall changes and browse more in our VPS guides.

Common questions

Can I change the RDP listening port?

Yes, but Microsoft does not recommend changing it unless necessary. If you do, allow the new TCP and UDP port in any firewall, connect using server-or-ip:port, and restart the Remote Desktop Services (TermService) service after making the change. Keep a console path, such as the Virtualizor VNC console, available in case of lockout.

Do I need both TCP and UDP 3389?

For best performance you should allow both TCP 3389 and UDP 3389. Windows uses TCP for the session and UDP to improve responsiveness where available.

How many people can connect at the same time?

Windows Server provides two concurrent administrative sessions. If more users need interactive sessions, you must deploy Remote Desktop Services with the appropriate CALs. For administration, use /admin to take the console session if the two standard admin sessions are occupied.

Was this article helpful?