# First steps on a Windows server with Remote Desktop

> Connect to your Windows VPS, VDS or dedicated server with Remote Desktop from Windows, macOS or Linux, change the password, install updates and limit access.

Difficulty: Beginner\
Tested on: Windows Server 2022, Windows Server 2025, Windows 11, macOS Tahoe 26, Ubuntu 24.04 LTS

Windows servers are managed through Remote Desktop: you see the server's desktop in a window on your own computer. This guide connects you to a new HyperDC Windows VPS, VDS or dedicated server and walks through the settings to change in the first session.

## Before you start

- **Your login details.** The welcome email contains the server's IP address, the user name `Administrator` and the password. The IP address is also on the service page: **Services › My Services**, open the server, then **Server Information**.
- **A Remote Desktop client.** Built into Windows; free apps for macOS, mobile devices and Linux (see Step 1).
- **Network access to TCP port 3389.** Some company networks block it; try another network if the connection times out.

In the examples, replace `203.0.113.10` with your server's IP address.

## Step 1: Connect

**Windows**

1. Press Windows + R, type `mstsc` and press Enter.
2. In **Computer**, enter `203.0.113.10`.
3. Select **Show Options** and enter `Administrator` as the user name. Select **Save** if you want to keep the connection as a file.
4. Select **Connect** and enter the password.
**macOS, iOS and Android**

1. Install **Windows App** from Microsoft (App Store or Google Play).
2. Add a PC: enter `203.0.113.10` as the PC name.
3. Add a user account with the user name `Administrator` and the password, or enter them when you connect.
4. Open the connection.
**Linux**

Remmina, available in most distributions, offers a graphical client. For the command line, install FreeRDP 3 (on Ubuntu 24.04 or later and Debian 13: `sudo apt install freerdp3-x11`) and connect:

```bash
xfreerdp3 /v:203.0.113.10 /u:Administrator /dynamic-resolution
```

On the first connection your client warns that the identity of the remote computer cannot be verified. A new server uses a self-signed certificate, so this is expected. Check that the warning refers to your server and continue.

**Verify:** the Windows Server desktop opens and Server Manager starts. In PowerShell, `hostname` and `Get-NetIPAddress -AddressFamily IPv4` show the server's name and IP address.

## Step 2: Change the Administrator password

The password in the welcome email has travelled by email. Inside the Remote Desktop session, press **Ctrl + Alt + End** (not Ctrl + Alt + Del, which goes to your own computer) and choose **Change a password**. Or open PowerShell as administrator and run:

```powershell
net user Administrator *
```

Type the new password twice. Use at least 16 characters and keep it in a password manager.

**Verify:** disconnect and connect again with the new password.

## Step 3: Install updates

Start with a fully patched server.

**Desktop Experience**

Open **Settings › Windows Update** and select **Check for updates**. Install everything offered and restart when asked.
**SConfig**

Open PowerShell as administrator, type `SConfig` and press Enter. Choose `6` (**Install updates**), then `1` for all quality updates, and `A` to install them. Option `5` (**Update setting**) chooses between automatic, download-only and manual updates.

**Verify:** after the restart, **Check for updates** reports that the server is up to date.

> **Tip**
>
> On a Windows VPS, take a snapshot before large updates or configuration changes, so you can roll back quickly. Windows VPS plans include free snapshots.

## Step 4: Set the time zone

Logs and scheduled tasks are easier to read in your own time zone. List the zone names and set yours:

```powershell
Get-TimeZone -ListAvailable | Select-Object Id, DisplayName
Set-TimeZone -Id "W. Europe Standard Time"
```

**Verify:** `Get-TimeZone` shows the zone you set.

## Step 5: Create a named administrator

Work with your own account instead of the built-in `Administrator`, so actions in the logs carry your name and you have a second way in. In PowerShell as administrator:

```powershell
$password = Read-Host -AsSecureString
New-LocalUser -Name "alex" -Password $password -FullName "Alex"
Add-LocalGroupMember -Group "Administrators" -Member "alex"
```

**Verify:** sign out and connect as `alex`. `whoami /groups` lists `BUILTIN\Administrators`.

## Step 6: Restrict Remote Desktop

Remote Desktop open to the whole internet attracts constant password guessing. Keep **Network Level Authentication** on (it is the default; SConfig option `7` shows the setting) and allow port 3389 only from your own IP addresses. [Windows Defender Firewall rules](/guides/windows-firewall) shows the exact commands; for teams, put Remote Desktop behind a VPN instead.

> **Warning**
>
> Before you change firewall rules, add your current IP address and test a second connection, so a mistake cannot lock you out. If it happens anyway, see [locked out after a firewall change](/guides/locked-out-after-firewall-change).

## Good habits for daily work

- **Sign out** when you are done instead of only closing the window. A disconnected session keeps running and uses one of the two administrative sessions.
- Install only the roles and features you need, and remove test software afterwards.
- Keep your own backups of important data in addition to the plan's backups.

## Troubleshooting

**`Remote Desktop can't connect to the remote computer`.** Test the port from your computer with `Test-NetConnection 203.0.113.10 -Port 3389`. If it fails from several networks, the server may be stopped, restarting for updates or blocked by a firewall rule.

**`The user name or password is incorrect`.** Type the user name as `Administrator` (or `.\Administrator`) and paste the password without spaces. After several failed attempts the account may be locked for a while.

**An authentication or CredSSP error.** Install the latest updates on your own computer as well as on the server; both sides must support the same security protocols.

**"The number of connections to this computer is limited".** Both administrative sessions are in use. See [Remote Desktop connection problems](/guides/rdp-connection-problems) to end an old session.

## Next steps

- Harden the server: [secure a Windows server](/guides/secure-windows-server).
- Learn what your plan includes: [Windows VPS and VDS](/guides/windows-vps).
- Restrict access by IP: [Windows Defender Firewall rules](/guides/windows-firewall).

## Frequently asked questions

### Which program do I need to connect?

On Windows, Remote Desktop Connection is built in. On macOS, iPhone, iPad and Android, install Microsoft's Windows App. On Linux, use Remmina or FreeRDP.

### How many people can use the server at the same time?

Windows Server includes two simultaneous Remote Desktop sessions for administration. If more people need to work on the server at once, the server needs the Remote Desktop Session Host role.

### Is the certificate warning on first connection dangerous?

It is expected: a new server uses a self-signed certificate that your computer does not know yet. Check that the warning names your server, then connect. You can install a trusted certificate later if you want the warning to go away.

### Should I change the Remote Desktop port?

A different port reduces automated login attempts in your logs, but it does not protect the server on its own. Restricting Remote Desktop to your own IP addresses in Windows Defender Firewall is far more effective.

### Can I take a snapshot before installing updates?

Windows VPS plans include free snapshots. Take one before updates or larger changes, so you can roll back if something goes wrong. Keep backups of important data elsewhere as well.

---

Source: <https://hyperdc.com/guides/getting-started/windows-server-first-steps-rdp>\
Updated: 2026-10-09
