Skip to content

TroubleshootingConnection problems

Fix Remote Desktop connection problems on Windows servers

Solve Remote Desktop errors on a Windows VPS or dedicated server: cannot connect, wrong credentials, CredSSP and NLA errors, session limits and black screens.

  • Beginner
  • 10 min read
  • Updated

Tested on: Windows Server 2022, Windows Server 2025, Windows 11, macOS Tahoe 26

This guide is not available in your language yet, so it is shown in English.

On this page
  1. Before you start
  2. "Remote Desktop can't connect to the remote computer"
  3. "The user name or password is incorrect" or "Your credentials did not work"
  4. "An authentication error has occurred… CredSSP encryption oracle remediation"
  5. "The remote computer requires Network Level Authentication"
  6. "The number of connections to this computer is limited"
  7. Black screen after signing in
  8. When to open a ticket
  9. Next steps

Remote Desktop problems fall into a few groups: the connection does not reach the server, the sign-in is refused, or the session itself misbehaves. Find your message below. Replace 203.0.113.10 with your server's address.

Before you start

  • Check the server's status under Services › My Services and known incidents under Support › Network Status.
  • Keep your client up to date: Remote Desktop Connection on Windows comes with Windows Update; on macOS, iOS and Android use the current Windows App.
  • Test the port from your computer:
PowerShell
Test-NetConnection 203.0.113.10 -Port 3389

On macOS and Linux use nc -vz 203.0.113.10 3389. TcpTestSucceeded : True means the network path is open; look at the sign-in errors. False means the network, a firewall or the server itself.

"Remote Desktop can't connect to the remote computer"

The client could not reach the service. Work through:

  1. Is the address right? Compare with Primary IP on the service page.
  2. Is the server restarting? Windows updates can take several minutes after a restart. Wait and try again.
  3. Does a firewall rule block you? If you restricted Remote Desktop to certain IP addresses, your own address may have changed. Check your current public IP and the rule; see Windows Defender Firewall rules.
  4. Is your network blocking port 3389? Try another network, such as a mobile hotspot.

If you cannot get in at all, use the web console if your service page shows one. In an administrator PowerShell window on the server, enable the built-in Remote Desktop firewall rules again:

PowerShell
Enable-NetFirewallRule -DisplayGroup "Remote Desktop"

On a server installed in another language, the group name may differ; list the rules with Get-NetFirewallRule -DisplayGroup "*Remote*".

"The user name or password is incorrect" or "Your credentials did not work"

  • Type the user as Administrator or .\Administrator (the dot means the local computer).
  • Paste the password without leading or trailing spaces. Remember that the password from the welcome email no longer works if you changed it.
  • Several failed attempts can lock the account for a while if an account lockout policy is set. Wait, or reset the password through the web console.

"An authentication error has occurred… CredSSP encryption oracle remediation"

The client and the server disagree on the security level of the CredSSP protocol, usually because one side is missing updates. Install all updates on your own computer, connect through the web console if you can and install the server's updates too. Do not lower the security policy as a permanent fix.

"The remote computer requires Network Level Authentication"

Your client is too old or not set up for NLA. Update the client (Windows App on macOS and mobile, FreeRDP 3 or a current Remmina on Linux). Keep NLA on: it stops attackers before a full session is created.

"The number of connections to this computer is limited"

Both administrative sessions are in use, often by sessions that were disconnected rather than signed out. Sign in as an administrator; Windows may offer to disconnect another user. Or end old sessions from a PowerShell window on the server:

PowerShell
quser
logoff 2

quser lists sessions with their IDs; replace 2 with the ID of the session to end. Unsaved work in that session is lost. Afterwards, sign out with Sign out instead of closing the Remote Desktop window.

Black screen after signing in

  • Wait a minute: the first sign-in after updates can take a while.
  • Press Ctrl + Alt + End and choose Task Manager, then Run new task and start explorer.exe.
  • Reconnect with a lower resolution or without multi-monitor settings.

When to open a ticket

If the port is closed from every network, the web console fails or the server does not respond at all, open a ticket with the server selected under Related Service. Include the exact error text, the output of Test-NetConnection 203.0.113.10 -Port 3389 and pathping 203.0.113.10, and what changed before the problem started.

Next steps

Frequently asked questions

Remote Desktop worked yesterday and fails today. Why?

Often the server is restarting after Windows updates, your IP address changed and no longer matches a firewall rule, or the account was locked after failed sign-ins. Wait a few minutes, test the port, then check the firewall.

How many people can connect at once?

Windows Server allows two simultaneous Remote Desktop sessions for administration. A third connection is refused or offers to disconnect someone. More users need the Remote Desktop Session Host role.

Should I turn off Network Level Authentication to fix an error?

No. NLA protects the server from attacks before a session starts. Update your Remote Desktop client instead; current clients on every platform support NLA.

What is the CredSSP error?

It appears when the client and the server have different security updates for the CredSSP protocol. Install the latest updates on both sides rather than lowering the security settings.

Can I reach the server if Remote Desktop is completely broken?

Use the web console if your service page shows one; it works without Remote Desktop. Otherwise open a support ticket with the server selected.

إنشاء كلمة مرور

Please confirm