First steps on a Windows server with Remote Desktop
Connect to your Windows VPS, VDS or dedicated server with Remote Desktop from Windows, macOS or Linux, change the password, install updates and limit access.
- Beginner
- 15 min read
- Updated
Tested on: Windows Server 2022, Windows Server 2025, Windows 11, macOS Tahoe 26, Ubuntu 24.04 LTS
On this page
Windows servers are managed through Remote Desktop: you see the server's desktop in a window on your own computer. This guide connects you to a new HyperDC Windows VPS, VDS or dedicated server and walks through the settings to change in the first session.
Before you start
- Your login details. The welcome email contains the server's IP address, the user name
Administratorand the password. The IP address is also on the service page: Services › My Services, open the server, then Server Information. - A Remote Desktop client. Built into Windows; free apps for macOS, mobile devices and Linux (see Step 1).
- Network access to TCP port 3389. Some company networks block it; try another network if the connection times out.
In the examples, replace 203.0.113.10 with your server's IP address.
Step 1: Connect
Windows
- Press Windows + R, type
mstscand press Enter. - In Computer, enter
203.0.113.10. - Select Show Options and enter
Administratoras the user name. Select Save if you want to keep the connection as a file. - Select Connect and enter the password.
macOS, iOS and Android
- Install Windows App from Microsoft (App Store or Google Play).
- Add a PC: enter
203.0.113.10as the PC name. - Add a user account with the user name
Administratorand the password, or enter them when you connect. - Open the connection.
Linux
Remmina, available in most distributions, offers a graphical client. For the command line, install FreeRDP 3 (on Ubuntu 24.04 or later and Debian 13: sudo apt install freerdp3-x11) and connect:
xfreerdp3 /v:203.0.113.10 /u:Administrator /dynamic-resolutionOn the first connection your client warns that the identity of the remote computer cannot be verified. A new server uses a self-signed certificate, so this is expected. Check that the warning refers to your server and continue.
Verify: the Windows Server desktop opens and Server Manager starts. In PowerShell, hostname and Get-NetIPAddress -AddressFamily IPv4 show the server's name and IP address.
Step 2: Change the Administrator password
The password in the welcome email has travelled by email. Inside the Remote Desktop session, press Ctrl + Alt + End (not Ctrl + Alt + Del, which goes to your own computer) and choose Change a password. Or open PowerShell as administrator and run:
net user Administrator *Type the new password twice. Use at least 16 characters and keep it in a password manager.
Verify: disconnect and connect again with the new password.
Step 3: Install updates
Start with a fully patched server.
Desktop Experience
Open Settings › Windows Update and select Check for updates. Install everything offered and restart when asked.
SConfig
Open PowerShell as administrator, type SConfig and press Enter. Choose 6 (Install updates), then 1 for all quality updates, and A to install them. Option 5 (Update setting) chooses between automatic, download-only and manual updates.
Verify: after the restart, Check for updates reports that the server is up to date.
Step 4: Set the time zone
Logs and scheduled tasks are easier to read in your own time zone. List the zone names and set yours:
Get-TimeZone -ListAvailable | Select-Object Id, DisplayName
Set-TimeZone -Id "W. Europe Standard Time"Verify: Get-TimeZone shows the zone you set.
Step 5: Create a named administrator
Work with your own account instead of the built-in Administrator, so actions in the logs carry your name and you have a second way in. In PowerShell as administrator:
$password = Read-Host -AsSecureString
New-LocalUser -Name "alex" -Password $password -FullName "Alex"
Add-LocalGroupMember -Group "Administrators" -Member "alex"Verify: sign out and connect as alex. whoami /groups lists BUILTIN\Administrators.
Step 6: Restrict Remote Desktop
Remote Desktop open to the whole internet attracts constant password guessing. Keep Network Level Authentication on (it is the default; SConfig option 7 shows the setting) and allow port 3389 only from your own IP addresses. Windows Defender Firewall rules shows the exact commands; for teams, put Remote Desktop behind a VPN instead.
Good habits for daily work
- Sign out when you are done instead of only closing the window. A disconnected session keeps running and uses one of the two administrative sessions.
- Install only the roles and features you need, and remove test software afterwards.
- Keep your own backups of important data in addition to the plan's backups.
Troubleshooting
Remote Desktop can't connect to the remote computer. Test the port from your computer with Test-NetConnection 203.0.113.10 -Port 3389. If it fails from several networks, the server may be stopped, restarting for updates or blocked by a firewall rule.
The user name or password is incorrect. Type the user name as Administrator (or .\Administrator) and paste the password without spaces. After several failed attempts the account may be locked for a while.
An authentication or CredSSP error. Install the latest updates on your own computer as well as on the server; both sides must support the same security protocols.
"The number of connections to this computer is limited". Both administrative sessions are in use. See Remote Desktop connection problems to end an old session.
Next steps
- Harden the server: secure a Windows server.
- Learn what your plan includes: Windows VPS and VDS.
- Restrict access by IP: Windows Defender Firewall rules.
Frequently asked questions
Which program do I need to connect?
On Windows, Remote Desktop Connection is built in. On macOS, iPhone, iPad and Android, install Microsoft's Windows App. On Linux, use Remmina or FreeRDP.
How many people can use the server at the same time?
Windows Server includes two simultaneous Remote Desktop sessions for administration. If more people need to work on the server at once, the server needs the Remote Desktop Session Host role.
Is the certificate warning on first connection dangerous?
It is expected: a new server uses a self-signed certificate that your computer does not know yet. Check that the warning names your server, then connect. You can install a trusted certificate later if you want the warning to go away.
Should I change the Remote Desktop port?
A different port reduces automated login attempts in your logs, but it does not protect the server on its own. Restricting Remote Desktop to your own IP addresses in Windows Defender Firewall is far more effective.
Can I take a snapshot before installing updates?
Windows VPS plans include free snapshots. Take one before updates or larger changes, so you can roll back if something goes wrong. Keep backups of important data elsewhere as well.
Sources
- learn.microsoft.com/en-us/windows-server/remote/remote-desktop-serv…
- learn.microsoft.com/en-us/windows-server/administration/server-core…
- learn.microsoft.com/en-us/powershell/module/microsoft.powershell.lo…
- learn.microsoft.com/en-us/powershell/module/microsoft.powershell.ma…
- packages.ubuntu.com/noble/amd64/freerdp3-x11/filelist
- freerdp.com