All guides
Getting started
VPS
- VPS operating systems
- VPS snapshots and
off-site backups - How to host your own VPN on a VPS with WireGuard
- How to run a Tor relay, bridge or onion service on a VPS
- How to
self-host BTCPay Server on a VPS - How to run a Bitcoin or Monero node on a VPS
Dedicated servers
- Using IPMI and the KVM console on a dedicated server
- Choosing a RAID layout for your dedicated server
Windows RDP
Windows Server 2019 , 2022 or 2025 vsWindows 10 and 11 for RDP- How to connect to a Windows RDP server from any device
GPU servers
Security
On this page
You need three things from your server's page in the client area: the server's IP address (SERVER_IPAdministrator
Connect from Windows
- Press Win+R, type
and press Enter to open Remote Desktop Connection.mstsc - Click Show Options. Enter
as the computer (addSERVER_IP if you changed the port) and:PORT as the user name.Administrator - Click Connect and enter the password.
- Windows warns that the certificate is not from a trusted authority, because the server uses a
self-signed certificate. This is expected: tick Don't ask me again for connections to this computer and click Yes.
You can also start a connection from a terminal:
mstsc /v:SERVER_IP
Save the connection as an .rdp file
On the General tab, click Save As.
Clipboard and drive redirection
On the Local Resources tab, tick Clipboard to copy and paste between your computer and the server. To reach local files, click More, expand Drives and tick the drive you need; it appears in File Explorer on the server. Share only what you need: any program running in your session on the server can read and write a redirected drive.
Inside the session, Ctrl+Alt+End sends Ctrl+Alt+Del, and Ctrl+Alt+Break switches full screen on and off.
Connect from macOS
- Install Windows App from the Mac App Store. It is Microsoft's client and replaced Microsoft Remote Desktop in 2024.
- Click + and choose Add PC.
- Enter
(orSERVER_IP ) as the PC name. Under credentials, add a user account withSERVER_IP:PORT and your password.Administrator - On the Devices & Audio tab, keep clipboard sharing on. On the Folders tab, tick Redirect folders and add a folder to share with the server.
- Save,
double-click the new PC to connect, and accept the certificate prompt.
Connect from Linux
Remmina
Remmina is a graphical client packaged by most distributions. On Debian and Ubuntu:
sudo apt install remmina remmina-plugin-rdp
Create a connection profile, choose the RDP protocol, and enter SERVER_IP
FreeRDP from the command line
FreeRDP 3 is packaged as freerdp3-x11xfreerdp3xfreerdp
sudo apt install freerdp3-x11
mkdir -p ~/rdp-share
xfreerdp3 /v:SERVER_IP /u:Administrator /dynamic-resolution +clipboard /drive:share,$HOME/rdp-share
FreeRDP asks for the password and, on the first connection, asks you to accept the server's certificate. Leave the password out of the command: passed with /p:/v:SERVER_IP:PORT
Connect from iOS and Android
Install Windows App from the App Store or Google Play. It replaced Microsoft's older Remote Desktop app, also known as RD Client, on both platforms. Tap +, add a PC, enter SERVER_IP
Change the RDP port
Moving Remote Desktop off
Run these commands in PowerShell as administrator. Pick a free port between 1024 and 49151; this example uses 33890:
Set-ItemProperty -Path 'HKLM:\SYSTEM\CurrentControlSet\Control\Terminal Server\WinStations\RDP-Tcp' -Name PortNumber -Value 33890
New-NetFirewallRule -DisplayName 'RDP 33890 TCP' -Direction Inbound -Protocol TCP -LocalPort 33890 -Action Allow
New-NetFirewallRule -DisplayName 'RDP 33890 UDP' -Direction Inbound -Protocol UDP -LocalPort 33890 -Action Allow
Restart-Service -Name TermService -Force
Your session drops. Reconnect to SERVER_IP:33890
Disable-NetFirewallRule -DisplayGroup 'Remote Desktop'
Enable Network Level Authentication
With Network Level Authentication (NLA), the client must prove the password before the server creates a session or shows a login screen. Unauthenticated clients never reach the Windows login screen, which cuts the load from bots and the attack surface. NLA is on by default on current Windows versions. To check, open the Remote tab of System Properties:
SystemPropertiesRemote
Make sure Allow connections only from computers running Remote Desktop with Network Level Authentication is ticked. Or set it in PowerShell as administrator:
Set-ItemProperty -Path 'HKLM:\SYSTEM\CurrentControlSet\Control\Terminal Server\WinStations\RDP-Tcp' -Name UserAuthentication -Value 1
NLA cannot handle an expired password, or one that must be changed at the next logon, so change passwords before they expire.
Fix common errors
CredSSP: "An authentication error has occurred"
If the message mentions CredSSP encryption oracle remediation, one side is missing the CredSSP security update from 2018 (
reg add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\CredSSP\Parameters" /v AllowEncryptionOracle /t REG_DWORD /d 2 /f
Connect, run Windows Update on the server and restart it. Then remove the setting, because it weakens your PC's protection:
reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\CredSSP\Parameters" /v AllowEncryptionOracle /f
If Windows instead says that Credential Guard does not allow saved credentials, type the password at each connection instead of saving it.
"An internal error has occurred"
- Wait two minutes and try again. The server may still be booting or finishing updates.
- Disconnect any VPN or proxy on your side and try again.
- Turn off the UDP transport on your Windows PC, in a Command Prompt run as administrator, then retry:
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows NT\Terminal Services\Client" /v fClientDisableUDP /t REG_DWORD /d 1 /f
If it still fails, reset Remote Desktop Connection's saved settings by deleting the hidden Default.rdp
Black screen after login
- Wait a minute: the first login creates your profile, and updates may be finishing.
- Press Ctrl+Alt+End, open Task Manager, choose Run new task and start
.explorer.exe - In Remote Desktop Connection, untick Persistent bitmap caching on the Experience tab; on the Display tab, lower the resolution and untick Use all my monitors.
- Press Ctrl+Alt+End, choose Sign out and reconnect. If the screen stays black, restart the server from the client area.
"Remote Desktop can't connect to the remote computer"
Check the IP address and port, and whether your current IP is on the allowlist if you set one. From PowerShell on your PC, test whether the port answers:
Test-NetConnection -ComputerName SERVER_IP -Port 3389
TcpTestSucceeded : False
Secure RDP
An RDP port that is open to the whole internet receives automated password guesses around the clock. Four measures close most of that risk.
Passwords and accounts
Use a password of at least 16 random characters from a password manager, used nowhere else. Automated attacks usually try the name Administrator
Rename-LocalUser -Name 'Administrator' -NewName 'YOUR_ADMIN_NAME'
Account lockout policy
Lock an account for
net accounts /lockoutthreshold:5
net accounts /lockoutwindow:15
net accounts /lockoutduration:15
The secpol.msc
Allow RDP only from your IP
This is the most effective of these measures: connections from any other address never reach the login screen. In PowerShell as administrator, limit the
Set-NetFirewallRule -DisplayGroup 'Remote Desktop' -RemoteAddress YOUR_IP
If you moved RDP to another port, apply the same to your own rules:
Set-NetFirewallRule -DisplayName 'RDP 33890 TCP' -RemoteAddress YOUR_IP
Set-NetFirewallRule -DisplayName 'RDP 33890 UDP' -RemoteAddress YOUR_IP
Separate several addresses with commas. To check the result:
Get-NetFirewallRule -DisplayGroup 'Remote Desktop' | Get-NetFirewallAddressFilter
Review failed logons
Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4625} -MaxEvents 20
Event 4625 records a failed logon. A steady stream from unknown addresses means RDP is still open to the internet. Keep Windows updated, and see Windows versions for RDP to run a version that still receives security fixes.
Dedicated and GPU customers can open a ticket from the client area with the server’s IP address and what they tried. First reply target: under