Remote Desktop Can't Connect to Windows Server VPS: RDP Troubleshooting Guide
When Remote Desktop can't connect to your Windows Server VPS, the cause is almost always one of five things: the network path to port 3389, RDP being disabled, the Windows Firewall, an NLA/CredSSP authentication mismatch, or a locked account. This RDP troubleshooting guide walks through each check in order and applies to Windows Server 2016, 2019 and 2022 on any JUSTG cloud server, whether it runs in Johannesburg, Moscow, Tokyo or Seoul. The examples use 203.0.113.10 as the server IP; replace it with your own.
Step 1: Test RDP port 3389 from your computer
Start from the outside. If the TCP test fails, the problem is the network path or the server is not listening; if it succeeds but login fails, skip to Step 4.
# On your own Windows PC (PowerShell)
Test-NetConnection -ComputerName 203.0.113.10 -Port 3389
# On macOS / Linux
nc -vz 203.0.113.10 3389TcpTestSucceeded : True means the port is open end to end. If it is False, first confirm the VPS is running in the client area and that it answers ping. Also check your own office or ISP network: some corporate firewalls block outbound 3389, so try once from a mobile hotspot.
Step 2: Check that Remote Desktop is enabled and listening
Open the VNC console, sign in, and start PowerShell as Administrator. Verify the Remote Desktop Services (TermService) state, the fDenyTSConnections value (0 = RDP allowed, 1 = blocked) and the port RDP actually listens on:
Get-Service -Name TermService
Get-ItemProperty -Path 'HKLM:\System\CurrentControlSet\Control\Terminal Server' -Name fDenyTSConnections
Get-ItemProperty -Path 'HKLM:\System\CurrentControlSet\Control\Terminal Server\WinStations\RDP-Tcp' -Name PortNumber
Get-NetTCPConnection -LocalPort 3389 -State ListenIf someone changed the RDP port earlier, PortNumber will show it, and you must connect with IP:port. If RDP is disabled or the service is stopped, turn it back on:
Set-ItemProperty -Path 'HKLM:\System\CurrentControlSet\Control\Terminal Server' -Name fDenyTSConnections -Value 0
Set-Service -Name TermService -StartupType Automatic
Start-Service -Name TermServiceStep 3: Fix the Windows Firewall rule for Remote Desktop
A firewall hardening script or a manual rule cleanup often disables the built-in Remote Desktop rules. The display group name is translated on non-English editions, so use the resource-based group ID, which works in every language:
# Language-independent group name for the built-in Remote Desktop rules
Enable-NetFirewallRule -Group "@FirewallAPI.dll,-28752"
Get-NetFirewallRule -Group "@FirewallAPI.dll,-28752" | Select-Object DisplayName, Enabled, Profile
# If the built-in rules were deleted, create one manually
New-NetFirewallRule -DisplayName "Allow RDP 3389" -Direction Inbound -Protocol TCP -LocalPort 3389 -Action AllowIf you changed the RDP port, open that port instead of 3389. Run Step 1 again; the TCP test should now succeed.
Step 4: Solve NLA and CredSSP authentication errors
If the port is open but the client reports "An authentication error has occurred... CredSSP encryption oracle remediation" or an NLA-related message, the client and server are at different patch levels. The proper fix is to install Windows Updates on the server (via the VNC console) and on your PC. As a short-term workaround you can disable Network Level Authentication on the server, log in, update, and then re-enable it:
# Temporary: turn off Network Level Authentication (run in the VNC console)
Set-ItemProperty -Path 'HKLM:\System\CurrentControlSet\Control\Terminal Server\WinStations\RDP-Tcp' -Name UserAuthentication -Value 0
# Turn it back on after the server is fully updated
Set-ItemProperty -Path 'HKLM:\System\CurrentControlSet\Control\Terminal Server\WinStations\RDP-Tcp' -Name UserAuthentication -Value 1Step 5: Account lockout and "too many sessions"
Internet-facing RDP attracts password-guessing bots, and a lockout policy may block your account. In the VNC console, check the policy and the account state, then list active sessions. Windows Server allows two administrative sessions by default; log off a stale one by its ID:
net accounts
net user Administrator
qwinsta
logoff 2If a local account shows as locked, open lusrmgr.msc, open the user's properties and clear Account is locked out, or wait for the lockout duration shown by net accounts. To cut down on brute-force noise, consider moving RDP to a non-default port and restricting the firewall rule to your own IP addresses.
FAQ
Ping works but Remote Desktop still can't connect. Why?
Ping only proves ICMP reaches the server. RDP needs TCP 3389 (or your custom port) to be listening and allowed by the firewall. Follow Steps 2 and 3 from the VNC console.
RDP worked yesterday and stopped after Windows Update restarted the server.
Give the server a few minutes after a reboot; large updates can keep it on the "Working on updates" screen, which you can watch in the VNC console. If the client then shows a CredSSP error, update your local PC as well.
Can I connect to my JUSTG Windows VPS over IPv6?
Yes. All JUSTG cloud servers include free IPv6; once it is configured on the server, enter the address in square brackets in the Remote Desktop client, for example [2001:db8::10].
If Remote Desktop still can't connect after these checks, submit a ticket to JUSTG technical support with the output of Step 1 and Step 2, and we will help you investigate.