9 Common Remote Desktop Connection and Screen Issues (With Fixes)

Most Remote Desktop faults trace back to the host PC: Remote Desktop switched off, the RDP listener not running, TCP port 3389 blocked, or an .rdp display value that no longer matches your monitors.

Advertisement

This guide fixes the 9 issues that stop or spoil a session, from authentication errors and blank screens to licence warnings, lag and missing audio.

The fastest fix when Remote Desktop will not connect

Run these checks on the host PC, the machine you are trying to reach. They clear the three settings behind most failed connections.

  1. On the host PC, select Start > Settings > System > Remote Desktop.
  2. Set Enable Remote Desktop to On, then select Confirm.
  3. Note the PC name shown on the same page. You connect with that name.
  4. Open Services and confirm Remote Desktop Services and Remote Desktop Services UserMode Port Redirector are running.
  5. Open wf.msc, select Inbound Rules, and enable Remote Desktop – User Mode (TCP-In) and Remote Desktop – User Mode (UDP-In) for all profiles.
  6. On your own PC, open Remote Desktop Connection, type the host PC name, and select Connect.

Still refused after these steps? The longer walkthrough in Fix: Remote Desktop Not Working in Windows 10/11 covers the same host in more detail.

Match your symptom to the right fix

Each row points at the section that finishes that job. Start with the row that matches what you see on screen.

What you see Go to Why
"Remote Desktop can't connect to the remote computer" Issue 1 Remote access is off, the listener is down, or a firewall blocks port 3389
Credentials rejected, or a CredSSP error Issue 2 Group membership, a user right, or an unpatched CredSSP on one end
Session opens tiny, stretched, or on one monitor only Issue 3 The .rdp file carries a fixed width and height
Mouse and typing lag behind Issue 4 Auto bandwidth detection or compression has been switched off
Black screen with only a cursor Issue 5 The shell did not load, or the graphics stack stalled
Connection sits and then times out Issue 6 Name resolution, a changed listening port, or no route from outside the network
"No Remote Desktop License Servers available" Issue 7 The 120-day grace period on a session host has ended
Host CPU or memory pinned, sessions crawling Issue 8 Disconnected sessions are still holding processes
No sound, or no microphone in the session Issue 9 audiomode and audiocapturemode, or a redirection policy on the host

What you need before you start

Requirement Detail
Host edition Windows Pro, Enterprise, Education or Windows Server. Home editions cannot host a Remote Desktop session.
Client edition Any Windows edition, including Home. macOS, iOS and Android connect through Windows App or the Remote Desktop app.
Account rights Membership of the Administrators group to change the setting, and membership of Remote Desktop Users to connect.
Network The host powered on, reachable, and allowing Remote Desktop through its firewall.
Default port TCP 3389, stored as PortNumber under HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Terminal Server\WinStations\RDP-Tcp.
Outside the network A VPN, or port forwarding on the router. Microsoft recommends the VPN.

Issue 1: Unable to Connect to Remote Desktop

The client reports that remote access is not enabled, the computer is off, or it is not available on the network. The two usual root causes are a stopped RDP-TCP listener and a blocked port.

  1. On the host, open Registry Editor and check HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Terminal Server. The DWORD fDenyTSConnections must be 0.
  2. Check HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\Terminal Services as well. If a policy sets fDenyTSConnections to 1, it overrides the Settings app.
  3. Check HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Terminal Server\WinStations\RDP-Tcp. The DWORD fEnableWinStation must be 1.
  4. Start the Remote Desktop Services service. Select Yes when Windows offers to restart Remote Desktop Services UserMode Port Redirector with it.
  5. Run qwinsta on the host. The line rdp-tcp must show the state Listen.
  6. Open a command prompt as administrator and run gpresult /H c:\gpresult.html. In the report, find Allow users to connect remotely by using Remote Desktop Services under Computer Configuration\Administrative Templates\Windows Components\Remote Desktop Services\Remote Desktop Session Host\Connections.
  7. If that policy reads Disabled, set it to Enabled or Not configured in the Group Policy Object Editor, then run gpupdate /force on the host.

Issue 2: Authentication Errors

Two error texts dominate here. "The system administrator has restricted the type of logon" is a rights problem, and "CredSSP encryption oracle remediation" is a patch-level problem.

  1. On the host, open Settings > System > Remote Desktop and select Select users that can remotely access this PC. Newer builds label this Remote Desktop users.
  2. Select Add, type the account name, then select OK. Administrators already have access.
  3. If the account is already listed, open the Group Policy Object Editor against the host and go to Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment.
  4. Open Access this computer from the network and confirm Remote Desktop Users, or a parent group, appears in the list. Add it if a policy removed Everyone.
  5. For a CredSSP encryption oracle remediation error, install all pending Windows updates on both the client and the host. The fix is the CredSSP update for CVE-2018-0886 on each end.
  6. Leave Network Level Authentication enabled. It forces authentication before the session starts and is the recommended setting.

Lowering the Encryption Oracle Remediation protection level restores the connection but reopens the vulnerability on the patched machine. Patch the other end instead.

Advertisement

Issue 3: Screen Resolution and Display Issues

Remote Desktop stores display settings in the .rdp file, not in the host. A session that opens at the wrong size is reading a stale desktopwidth and desktopheight pair.

  1. Close the session. For a one-off size, run mstsc /v:HOST-PC /w:1920 /h:1080 from the Run box.
  2. For a permanent change, run mstsc /edit Default.rdp. Each user has a hidden Default.rdp in the Documents folder, and saved .rdp files live there too.
  3. Set desktopwidth:i:1920 and desktopheight:i:1080 in the file. Any value from 200 to 8192 pixels is accepted.
  4. Set dynamic resolution:i:1 so the session resolution follows the window as you resize it.
  5. Set smart sizing:i:1 if you would rather scale the existing content to the window than change the resolution.
  6. Set screen mode id:i:2 to start full screen, or 1 to start windowed.
  7. For several monitors, set use multimon:i:1. Run mstsc.exe /l to list local display IDs, then set selectedmonitors:s: with the IDs you want, separated by commas.
  8. Reconnect with mstsc HOST-PC.rdp and check the session fills the displays you chose.

Text still too small on a high-DPI laptop? Scaling the local desktop first often helps more than changing the session, and How to Zoom In and Out on Desktop Screen in Windows covers that.

Issue 4: Lagging or Slow Performance

RDP adapts to the link automatically unless something turned that off. Check the .rdp values before blaming the connection.

  1. Open the .rdp file with mstsc /edit filename.rdp.
  2. Set bandwidthautodetect:i:1 so the client measures available bandwidth. This is the default.
  3. Set networkautodetect:i:1 so the client detects the network type.
  4. Set compression:i:1 to keep RDP bulk compression on for data sent to your device.
  5. Set videoplaybackmode:i:1 so video uses RDP multimedia streaming rather than raw screen updates.
  6. Drop the session resolution with desktopwidth and desktopheight. Fewer pixels means less to send on a slow link.
  7. Set audiomode:i:2 while you test. Silencing the session removes the audio stream from the link.
  8. Reconnect over a wired connection or a VPN and compare the responsiveness.

Issue 5: Blank Screen on Connection Attempt

The session authenticates, then shows black with a visible cursor. The desktop shell failed to load, or the graphics stack stalled.

Advertisement
  1. Press Windows logo key + Ctrl + Shift + B inside the session to reset the graphics driver.
  2. If the screen stays black, press Ctrl + Alt + End to reach the security options screen. Ctrl + Alt + Del goes to your own PC instead.
  3. Select Task Manager. Use the arrow keys and Enter if the mouse does not respond.
  4. Open the Details tab and look for explorer.exe and userinit.exe in the process list.
  5. If explorer.exe is missing, open Registry Editor on the host and go to HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon.
  6. Confirm the Shell value data reads explorer.exe. Back up the key before changing it.
  7. If the value is correct and the screen is still black, perform a clean boot on the host to find the startup app or service responsible.

A screen that flickers rather than stays black is usually a local display fault, and Fix Screen Flashing Issue in Windows 10 handles that case.

Issue 6: Connection Timeout

A timeout means the packets never arrived. Work outwards: name, port, route.

  1. Connect using the host IP address instead of its name. If the IP works, the fault is name resolution, not Remote Desktop.
  2. Check HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Terminal Server\WinStations\RDP-Tcp on the host. The DWORD PortNumber should read 0x00000d3d, which is 3389.
  3. If PortNumber differs, connect as hostname:port or IPaddress:port instead.
  4. Restart the Remote Desktop Services service after any port change.
  5. Open wf.msc on the host, select Inbound Rules, and confirm Remote Desktop – User Mode (TCP-In) and Remote Desktop – User Mode (UDP-In) are enabled for all profiles.
  6. Connecting from outside the network? Set up a VPN so the client joins the same network. Microsoft recommends this over exposing the PC.
  7. If you must use port forwarding, map port 3389 on the router to the host internal IPv4 address, restrict the source IP where the router allows it, and set a strong password on every account with remote access.
Remote Desktop Connection error: computers could not connect in the time allotted
This exact message signals a timeout: work outward from name resolution to the port to the network route. (Image: Microsoft Q&A)

Issue 7: License Issues

This one only appears on a Remote Desktop Services deployment on Windows Server. Each user or device connecting to a session host needs a Remote Desktop Services client access licence, an RDS CAL.

A new session host runs for a 120-day grace period with no licence server. Once that period ends, clients need a valid RDS CAL before they can sign in.

Advertisement
  1. Confirm the host is a Remote Desktop Session Host on Windows Server. A Windows client edition never asks for an RDS CAL.
  2. Check how long the session host has been in service. Past 120 days, the grace period has expired and a licence server is mandatory.
  3. Install and activate a Remote Desktop Licensing server, then install your RDS CALs on it.
  4. Match the CAL version to the session host. Later CALs cover earlier hosts, but a Windows Server 2022 CAL cannot serve a Windows Server 2025 session host.
  5. Install the CALs on a licence server running the same Windows Server version as the CALs, or a later one.
  6. Choose the licensing model. Per device CALs are assigned to hardware and up to 20 percent can be revoked. Per user CALs are assigned in Active Directory and cannot be revoked.
  7. Open Remote Desktop Licensing Manager and check how many CALs are issued against how many you own.

Per device temporary CALs are issued on first sign-in and last 90 days. Per user CALs show a 60-day expiry that extends each time the user signs in.

Issue 8: High Resource Consumption

Disconnected sessions keep running. Closing the Remote Desktop window ends nothing, so processes, memory and CPU stay allocated on the host.

  1. Run qwinsta on the host to list every session with its name, user, ID and state. Sessions marked Disc are disconnected but still alive.
  2. Warn the user first with the msg command. Logging someone off without warning can lose unsaved work.
  3. Run logoff <sessionID> to end a session and delete it from the server. All its processes stop.
  4. Add /server:<servername> to act on a different session host, and /v to see what the command is doing.
  5. Inside your own session, sign out from Start rather than closing the window, so the session is deleted instead of parked.
  6. Open Task Manager on the host and sort the Details tab by CPU or Memory to find the process holding the resources.

Full Control permission is required to log off anyone else. You can always log yourself off from your own session.

Issue 9: Audio Issues

Audio has two independent directions. Playback sends the session's sound to your speakers, and recording sends your microphone into the session.

  1. Open the connection file with mstsc /edit filename.rdp.
  2. Set audiomode:i:0 to play sounds on your local device. That is the default. 1 plays them on the host and 2 mutes them.
  3. Set audiocapturemode:i:1 to redirect your microphone into the session. The default is 0, which is why microphones often appear missing.
  4. If audio is still silent, open the Group Policy editor against the host and go to Computer Configuration > Administrative Templates > Windows Components > Remote Desktop Services > Remote Desktop Session Host > Device and Resource Redirection.
  5. Set Allow audio and video playback redirection to Enabled.
  6. Set Allow audio recording redirection to Enabled for microphone access.
  7. Run gpupdate /force on the host and reconnect.

The most restrictive setting wins. A policy that blocks redirection on the host overrides an .rdp file that allows it.

Local Group Policy Editor Device and Resource Redirection settings for Remote Desktop Session Host
Enable Allow audio and video playback redirection and Allow audio recording redirection here for sound and microphone. (Image: Microsoft)

Test the port before you change anything else

Run this from another PC on the same network as the host. It separates a network problem from a Remote Desktop problem in one step.

Test-NetConnection -ComputerName HOST-PC -Port 3389 -InformationLevel Detailed

-ComputerName takes the host name or IP address. -Port 3389 tests the default RDP listening port. -InformationLevel Detailed adds the name resolution and route results to the output.

You should see: TcpTestSucceeded : True means the port is reachable and the fault lies in the session itself. False means a firewall, a route or a stopped listener is blocking it.

How to check it worked

  1. Run qwinsta on the host. The rdp-tcp line must read Listen.
  2. On a Windows Server host, open Remote Desktop Connection, type localhost, and select Connect. Success here rules out the server and points at the network.
  3. Run Test-NetConnection -ComputerName HOST-PC -Port 3389 from another PC and confirm TcpTestSucceeded : True.
  4. Reconnect and confirm the session fills the resolution you set, with no black border and no stretched text.
  5. Play a sound inside the session and confirm it reaches the device you chose in audiomode.

Fix Remote Desktop when it still will not connect

Remote Desktop never connects, with no error to work from

The RDP-TCP listener is not running, or another application has taken port 3389.

  1. Run qwinsta on the host and look for rdp-tcp in the Listen state.
  2. Run cmd /c 'netstat -ano | find "3389"' in an elevated PowerShell window and note the PID listening on the port.
  3. Run cmd /c 'tasklist /svc | find "<pid>"' with that PID to name the process holding it.
  4. If the process is not Remote Desktop Services, reconfigure that application to use another port.
  5. Restart the Remote Desktop Services service and test again.

"Remote Desktop cannot connect to the remote computer"

Remote access is off, a self-signed certificate is missing, or the service account lacks permissions.

  1. Confirm fDenyTSConnections is 0 and fEnableWinStation is 1 on the host.
  2. Check HKEY_LOCAL_MACHINE\SYSTEM\Setup. Both SystemSetupInProgress and OOBEInProgress must be 0, or the machine is still in Sysprep state.
  3. Open the Certificates snap-in for the Computer account on the host, expand Remote Desktop, and delete the RDP self-signed certificate.
  4. Restart the Remote Desktop Services service and refresh the snap-in. Windows recreates the certificate.
  5. If it is not recreated, open C:\ProgramData\Microsoft\Crypto\RSA\, right-click MachineKeys, and confirm Builtin\Administrators has Full control and Everyone has Read and Write.

Remote Desktop works on the same network but not from a different network

Remote Desktop is a peer-to-peer connection, so it needs a route into the host network.

  1. Connect to the network over a VPN first, then start Remote Desktop. The client then behaves as if it were local.
  2. If port forwarding is the only option, find the host internal IPv4 address under Settings > Network & Internet > Status > View your network properties.
  3. Map port 3389 on the router to that internal address.
  4. Restrict the source IP or network on the router so the port is not open to the whole internet.
  5. Set a static internal IP on the host, or use Dynamic DNS, so the mapping survives an address change.

Conclusion

Check the host first every time: Remote Desktop enabled, the RDP-TCP listener in the Listen state, and port 3389 reachable. Only then edit the .rdp file for display, performance and audio faults. Connection failures live on the host and in the network path, while resolution, lag and audio faults live in the .rdp file the client reads. Fixing them in that order stops you changing client settings against a host that was never listening.

Frequently Asked Questions

How do you use Remote Desktop Connection?

Turn on Enable Remote Desktop under Settings > System > Remote Desktop on the host PC and note its PC name. On the other device, open Remote Desktop Connection, type that name, select Connect, and sign in with an account allowed to connect.

Where is Remote Desktop Connection located?

Type Remote Desktop Connection in the taskbar search box and open it. It also starts from the Run box as mstsc, and mstsc /? shows the full usage dialog with every switch the client accepts.

Do I need Remote Desktop Connection?

Only if you connect to a PC from another device. If you use your PC locally, leave Remote Desktop off. Enabling it opens a port and makes the PC reachable from the local network, so turn it on only on trusted networks.

Why is Remote Desktop Connection installed on my PC?

The client ships with Windows as mstsc.exe, on Home editions too. Having the client installed does not make your PC reachable. Only turning on Enable Remote Desktop on a Pro, Enterprise, Education or Server edition does that.

Is Remote Desktop Connection good?

It gives full access to a remote PC's apps, files and network resources, with multiple monitor support, device redirection and single sign-on. Keep Network Level Authentication enabled, since it forces authentication before the session starts.

Do I need Microsoft Remote Desktop instead?

On Windows, use the built-in Remote Desktop Connection client. On macOS, iOS, iPadOS and Android, use Windows App, which replaces the Remote Desktop client. Microsoft recommends Windows App wherever it supports your platform.

Can Remote Desktop allow more than 2 connections?

Concurrent remote sessions are a Remote Desktop Services feature of Windows Server. Every user or device connecting to a session host needs an RDS CAL issued by a Remote Desktop Licensing server once the 120-day grace period ends.

Why does Remote Desktop not connect from a different network?

Remote Desktop creates a peer-to-peer connection, so the client needs direct access to the host. From outside the host network, connect through a VPN, or forward port 3389 on the router to the host's internal IP address.

What version of Remote Desktop Connection do I have?

Run mstsc /? to open the Remote Desktop Connection usage dialog. On macOS, iOS, iPadOS and Android, the version is shown inside Windows App, which Microsoft updates through the relevant app store.

Why does Remote Desktop cannot connect to the remote computer keep appearing?

That message covers three causes: remote access is not enabled, the remote computer is off, or it is not available on the network. Check fDenyTSConnections is 0, run qwinsta for an rdp-tcp listener in the Listen state, then test port 3389.

Philip Celasco

Philip is a Texas-based technology writer and IT administrator at Techdows.com with more than 10 years of experience creating practical content for everyday users and professionals. He specializes in web browsers, particularly Chromium-based platforms such as Google Chrome, Microsoft Edge, Brave, and Opera. Through his work as an IT administrator, Philip has hands-on experience managing devices, configuring browser policies, troubleshooting software and network issues, and helping people resolve problems that affect productivity and security. His articles are based on practical testing and real-world technical experience. He covers browser settings, extensions, performance problems, privacy controls, security features, and Windows troubleshooting. Outside work, Philip enjoys the quieter side of life in Texas and stepping away from the screen when he can. He has two kids, two cats and loves to play golf with his mother during the weekends.

Leave a Reply

Your email address will not be published. Required fields are marked *