---
title: "How to Connect to a Windows RDP Server from Any Device"
description: "Connect to a Windows server from Windows, macOS, Linux, iOS or Android, change the RDP port, enable NLA and fix common errors."
url: https://offshoreserv.com/docs/rdp/connect
lang: en
updated: 2026-09-25
source: HTML page at the url above (canonical); this is its Markdown version
---

Knowledge base · Windows RDP

# How to connect to a Windows RDP server from any device

Connect to your OffshoreServ Windows server from Windows, macOS, Linux, iOS or Android, change the RDP port, enable NLA, fix common errors and lock down access.

Updated 25 September 2026 7 min read

In this guide

- Use Remote Desktop Connection (mstsc) on Windows, Windows App on macOS, iOS and Android, and Remmina or FreeRDP on Linux.
- Keep Network Level Authentication on and allow RDP only from your own IP with Windows Firewall.
- Changing the port reduces log noise but is not a security control on its own.
- Most CredSSP, internal error and black screen problems have a quick fix on your side.

Windows RDP8 sections

You need three things from your server's page in the client area: the server's IP address (`SERVER_IP` below), the username and the password. On full [RDP plans](https://offshoreserv.com/offshore-rdp) the username is `Administrator`; on a shared seat, use the username shown there. Remote Desktop listens on port 3389 unless you change it.

## Connect from Windows

1. Press Win+R, type `mstsc` and press Enter to open Remote Desktop Connection.
2. Click **Show Options**. Enter `SERVER_IP` as the computer (add `:PORT` if you changed the port) and `Administrator` as the user name.
3. Click **Connect** and enter the password.
4. Windows warns that the certificate is not from a trusted authority, because the server uses a self-signed certificate. This is expected: tick **Don't ask me again for connections to this computer** and click **Yes**.

You can also start a connection from a terminal:

```
mstsc /v:SERVER_IP
```

### Save the connection as an.rdp file

On the **General** tab, click **Save As**. Double-click the file later to reconnect with the same settings. Tick **Allow me to save credentials** only on a computer that nobody else uses.

### Clipboard and drive redirection

On the **Local Resources** tab, tick **Clipboard** to copy and paste between your computer and the server. To reach local files, click **More**, expand **Drives** and tick the drive you need; it appears in File Explorer on the server. Share only what you need: any program running in your session on the server can read and write a redirected drive.

Inside the session, Ctrl+Alt+End sends Ctrl+Alt+Del, and Ctrl+Alt+Break switches full screen on and off.

## Connect from macOS

1. Install **Windows App** from the Mac App Store. It is Microsoft's client and replaced Microsoft Remote Desktop in 2024.
2. Click **+** and choose **Add PC**.
3. Enter `SERVER_IP` (or `SERVER_IP:PORT`) as the PC name. Under credentials, add a user account with `Administrator` and your password.
4. On the **Devices & Audio** tab, keep clipboard sharing on. On the **Folders** tab, tick **Redirect folders** and add a folder to share with the server.
5. Save, double-click the new PC to connect, and accept the certificate prompt.

## Connect from Linux

### Remmina

Remmina is a graphical client packaged by most distributions. On Debian and Ubuntu:

```
sudo apt install remmina remmina-plugin-rdp
```

Create a connection profile, choose the RDP protocol, and enter `SERVER_IP`, the username and the password. The **Share folder** option makes a local folder available on the server, and the clipboard is shared by default. Save, connect and accept the certificate.

### FreeRDP from the command line

FreeRDP 3 is packaged as `freerdp3-x11` on current Debian and Ubuntu, and its command is `xfreerdp3`. Older FreeRDP 2 packages call it `xfreerdp` and accept the same options.

```
sudo apt install freerdp3-x11
mkdir -p ~/rdp-share
xfreerdp3 /v:SERVER_IP /u:Administrator /dynamic-resolution +clipboard /drive:share,$HOME/rdp-share
```

FreeRDP asks for the password and, on the first connection, asks you to accept the server's certificate. Leave the password out of the command: passed with `/p:`, it would end up in your shell history. For a custom port, use `/v:SERVER_IP:PORT`.

## Connect from iOS and Android

Install **Windows App** from the App Store or Google Play. It replaced Microsoft's older Remote Desktop app, also known as RD Client, on both platforms. Tap **+**, add a PC, enter `SERVER_IP` and add your user account, then tap the new PC to connect. A phone works well for checking on a running job or restarting a program; for longer sessions, use a computer.

## Change the RDP port

Moving Remote Desktop off port 3389 cuts the number of automated login attempts in your logs. It does not hide the service from a thorough scan, so treat it as noise reduction and combine it with the IP allowlist below.

> Open the new port in Windows Firewall before you restart the service, or you will lock yourself out. If that happens, the way back in is a reinstall from your server's page in the client area, which erases the disk.

Run these commands in PowerShell as administrator. Pick a free port between 1024 and 49151; this example uses 33890:

```
Set-ItemProperty -Path 'HKLM:\SYSTEM\CurrentControlSet\Control\Terminal Server\WinStations\RDP-Tcp' -Name PortNumber -Value 33890
New-NetFirewallRule -DisplayName 'RDP 33890 TCP' -Direction Inbound -Protocol TCP -LocalPort 33890 -Action Allow
New-NetFirewallRule -DisplayName 'RDP 33890 UDP' -Direction Inbound -Protocol UDP -LocalPort 33890 -Action Allow
Restart-Service -Name TermService -Force
```

Your session drops. Reconnect to `SERVER_IP:33890`, and once that works, disable the built-in rules for port 3389:

```
Disable-NetFirewallRule -DisplayGroup 'Remote Desktop'
```

## Enable Network Level Authentication

With Network Level Authentication (NLA), the client must prove the password before the server creates a session or shows a login screen. Unauthenticated clients never reach the Windows login screen, which cuts the load from bots and the attack surface. NLA is on by default on current Windows versions. To check, open the Remote tab of System Properties:

```
SystemPropertiesRemote
```

Make sure **Allow connections only from computers running Remote Desktop with Network Level Authentication** is ticked. Or set it in PowerShell as administrator:

```
Set-ItemProperty -Path 'HKLM:\SYSTEM\CurrentControlSet\Control\Terminal Server\WinStations\RDP-Tcp' -Name UserAuthentication -Value 1
```

NLA cannot handle an expired password, or one that must be changed at the next logon, so change passwords before they expire.

## Fix common errors

### CredSSP: "An authentication error has occurred"

If the message mentions CredSSP encryption oracle remediation, one side is missing the CredSSP security update from 2018 (CVE-2018-0886). The fix is to update Windows on both computers. If you cannot reach the server to update it, allow the connection temporarily on your own PC, in a Command Prompt run as administrator:

```
reg add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\CredSSP\Parameters" /v AllowEncryptionOracle /t REG_DWORD /d 2 /f
```

Connect, run Windows Update on the server and restart it. Then remove the setting, because it weakens your PC's protection:

```
reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\CredSSP\Parameters" /v AllowEncryptionOracle /f
```

If Windows instead says that Credential Guard does not allow saved credentials, type the password at each connection instead of saving it.

### "An internal error has occurred"

1. Wait two minutes and try again. The server may still be booting or finishing updates.
2. Disconnect any VPN or proxy on your side and try again.
3. Turn off the UDP transport on your Windows PC, in a Command Prompt run as administrator, then retry:

```
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows NT\Terminal Services\Client" /v fClientDisableUDP /t REG_DWORD /d 1 /f
```

If it still fails, reset Remote Desktop Connection's saved settings by deleting the hidden `Default.rdp` file in your Documents folder, and restart the server from the client area.

### Black screen after login

- Wait a minute: the first login creates your profile, and updates may be finishing.
- Press Ctrl+Alt+End, open Task Manager, choose **Run new task** and start `explorer.exe`.
- In Remote Desktop Connection, untick **Persistent bitmap caching** on the **Experience** tab; on the **Display** tab, lower the resolution and untick **Use all my monitors**.
- Press Ctrl+Alt+End, choose **Sign out** and reconnect. If the screen stays black, restart the server from the client area.

### "Remote Desktop can't connect to the remote computer"

Check the IP address and port, and whether your current IP is on the allowlist if you set one. From PowerShell on your PC, test whether the port answers:

```
Test-NetConnection -ComputerName SERVER_IP -Port 3389
```

`TcpTestSucceeded: False` means the server is down or still booting, or a firewall blocks you. Check the [status page](https://offshoreserv.com/status), then reboot the server from the Server actions on its page in the client area.

## Secure RDP

An RDP port that is open to the whole internet receives automated password guesses around the clock. Four measures close most of that risk.

### Passwords and accounts

Use a password of at least 16 random characters from a password manager, used nowhere else. Automated attacks usually try the name `Administrator`, so rename the built-in account; you then sign in with the new name:

```
Rename-LocalUser -Name 'Administrator' -NewName 'YOUR_ADMIN_NAME'
```

### Account lockout policy

Lock an account for 15 minutes after 5 wrong passwords within 15 minutes. In a Command Prompt run as administrator:

```
net accounts /lockoutthreshold:5
net accounts /lockoutwindow:15
net accounts /lockoutduration:15
```

The built-in Administrator account is exempt from lockout unless the policy **Allow Administrator account lockout** is enabled. Microsoft added that policy with the October 2022 updates; you find it in Local Security Policy (`secpol.msc`) under Account Policies, Account Lockout Policy. A lockout policy also lets bots lock you out by guessing your username, which is one more reason to limit who can connect at all.

### Allow RDP only from your IP

This is the most effective of these measures: connections from any other address never reach the login screen. In PowerShell as administrator, limit the built-in Remote Desktop rules to your address:

```
Set-NetFirewallRule -DisplayGroup 'Remote Desktop' -RemoteAddress YOUR_IP
```

If you moved RDP to another port, apply the same to your own rules:

```
Set-NetFirewallRule -DisplayName 'RDP 33890 TCP' -RemoteAddress YOUR_IP
Set-NetFirewallRule -DisplayName 'RDP 33890 UDP' -RemoteAddress YOUR_IP
```

Separate several addresses with commas. To check the result:

```
Get-NetFirewallRule -DisplayGroup 'Remote Desktop' | Get-NetFirewallAddressFilter
```

> If your home IP changes, you lose access. Allow a fixed address instead, for example a small [VPS](https://offshoreserv.com/offshore-vps) that you use as a VPN or jump host, and keep a second allowed address as a fallback.

### Review failed logons

```
Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4625} -MaxEvents 20
```

Event 4625 records a failed logon. A steady stream from unknown addresses means RDP is still open to the internet. Keep Windows updated, and see [Windows versions for RDP](https://offshoreserv.com/docs/rdp/windows-versions) to run a version that still receives security fixes.

**Stuck on a step?**

Dedicated and GPU customers can open a ticket from the [client area](https://offshoreserv.com/account/support) with the server’s IP address and what they tried. First reply target: under 12 hours. For every other server, use the Server actions on its page, the [guides](https://offshoreserv.com/docs) and the [network status](https://offshoreserv.com/status) page.

---

OffshoreServ is an offshore hosting provider: VPS, dedicated servers, Windows RDP and GPU servers in seven jurisdictions (Iceland, Switzerland, Moldova, Romania, the Netherlands, Bulgaria and Malaysia), paid only in cryptocurrency (Bitcoin, Ethereum, Monero, Tether (USDT) and Solana), with no identity checks (no KYC).

Prices and plans: https://offshoreserv.com/pricing · Answers: https://offshoreserv.com/faq · Every page: https://offshoreserv.com/llms.txt
