Remote Desktop Can't Connect to Windows Server VPS: RDP Troubleshooting Guide

13 min read 2 views 0
On this page

When Remote Desktop can't connect to your Windows Server VPS, the cause is almost always one of five things: the network path to port 3389, RDP being disabled, the Windows Firewall, an NLA/CredSSP authentication mismatch, or a locked account. This RDP troubleshooting guide walks through each check in order and applies to Windows Server 2016, 2019 and 2022 on any JUSTG cloud server, whether it runs in Johannesburg, Moscow, Tokyo or Seoul. The examples use 203.0.113.10 as the server IP; replace it with your own.

You do not need RDP to repair RDP. Every JUSTG VPS has a browser-based VNC console: log in to the client area → My Products & Services → select the VPS → open the management/control panel and launch the console. If you cannot find it, submit a ticket and we will point you to it.

Step 1: Test RDP port 3389 from your computer

Start from the outside. If the TCP test fails, the problem is the network path or the server is not listening; if it succeeds but login fails, skip to Step 4.

# On your own Windows PC (PowerShell)
Test-NetConnection -ComputerName 203.0.113.10 -Port 3389

# On macOS / Linux
nc -vz 203.0.113.10 3389

TcpTestSucceeded : True means the port is open end to end. If it is False, first confirm the VPS is running in the client area and that it answers ping. Also check your own office or ISP network: some corporate firewalls block outbound 3389, so try once from a mobile hotspot.

Step 2: Check that Remote Desktop is enabled and listening

Open the VNC console, sign in, and start PowerShell as Administrator. Verify the Remote Desktop Services (TermService) state, the fDenyTSConnections value (0 = RDP allowed, 1 = blocked) and the port RDP actually listens on:

Get-Service -Name TermService
Get-ItemProperty -Path 'HKLM:\System\CurrentControlSet\Control\Terminal Server' -Name fDenyTSConnections
Get-ItemProperty -Path 'HKLM:\System\CurrentControlSet\Control\Terminal Server\WinStations\RDP-Tcp' -Name PortNumber
Get-NetTCPConnection -LocalPort 3389 -State Listen

If someone changed the RDP port earlier, PortNumber will show it, and you must connect with IP:port. If RDP is disabled or the service is stopped, turn it back on:

Set-ItemProperty -Path 'HKLM:\System\CurrentControlSet\Control\Terminal Server' -Name fDenyTSConnections -Value 0
Set-Service -Name TermService -StartupType Automatic
Start-Service -Name TermService

Step 3: Fix the Windows Firewall rule for Remote Desktop

A firewall hardening script or a manual rule cleanup often disables the built-in Remote Desktop rules. The display group name is translated on non-English editions, so use the resource-based group ID, which works in every language:

# Language-independent group name for the built-in Remote Desktop rules
Enable-NetFirewallRule -Group "@FirewallAPI.dll,-28752"
Get-NetFirewallRule -Group "@FirewallAPI.dll,-28752" | Select-Object DisplayName, Enabled, Profile

# If the built-in rules were deleted, create one manually
New-NetFirewallRule -DisplayName "Allow RDP 3389" -Direction Inbound -Protocol TCP -LocalPort 3389 -Action Allow

If you changed the RDP port, open that port instead of 3389. Run Step 1 again; the TCP test should now succeed.

Step 4: Solve NLA and CredSSP authentication errors

If the port is open but the client reports "An authentication error has occurred... CredSSP encryption oracle remediation" or an NLA-related message, the client and server are at different patch levels. The proper fix is to install Windows Updates on the server (via the VNC console) and on your PC. As a short-term workaround you can disable Network Level Authentication on the server, log in, update, and then re-enable it:

# Temporary: turn off Network Level Authentication (run in the VNC console)
Set-ItemProperty -Path 'HKLM:\System\CurrentControlSet\Control\Terminal Server\WinStations\RDP-Tcp' -Name UserAuthentication -Value 0

# Turn it back on after the server is fully updated
Set-ItemProperty -Path 'HKLM:\System\CurrentControlSet\Control\Terminal Server\WinStations\RDP-Tcp' -Name UserAuthentication -Value 1
Leaving NLA off exposes the login screen to anyone on the internet. Re-enable it as soon as updates are installed, and use a strong password.

Step 5: Account lockout and "too many sessions"

Internet-facing RDP attracts password-guessing bots, and a lockout policy may block your account. In the VNC console, check the policy and the account state, then list active sessions. Windows Server allows two administrative sessions by default; log off a stale one by its ID:

net accounts
net user Administrator
qwinsta
logoff 2

If a local account shows as locked, open lusrmgr.msc, open the user's properties and clear Account is locked out, or wait for the lockout duration shown by net accounts. To cut down on brute-force noise, consider moving RDP to a non-default port and restricting the firewall rule to your own IP addresses.

FAQ

Ping works but Remote Desktop still can't connect. Why?

Ping only proves ICMP reaches the server. RDP needs TCP 3389 (or your custom port) to be listening and allowed by the firewall. Follow Steps 2 and 3 from the VNC console.

RDP worked yesterday and stopped after Windows Update restarted the server.

Give the server a few minutes after a reboot; large updates can keep it on the "Working on updates" screen, which you can watch in the VNC console. If the client then shows a CredSSP error, update your local PC as well.

Can I connect to my JUSTG Windows VPS over IPv6?

Yes. All JUSTG cloud servers include free IPv6; once it is configured on the server, enter the address in square brackets in the Remote Desktop client, for example [2001:db8::10].

If Remote Desktop still can't connect after these checks, submit a ticket to JUSTG technical support with the output of Step 1 and Step 2, and we will help you investigate.

Was this answer helpful?

Related Tutorials

Windows PowerShell PS> Get-ItemProperty -Path 'HKLM:\SYSTEM\CurrentC…PS> Get-NetTCPConnection -LocalPort 40125 -ErrorA…PS> $port = 40125 Windows Server How to Change the Remote Desktop (RDP) Port on Windows Server Change the Windows Server RDP port from 3389 with PowerShell: registry PortNumber, firewall rules, TermService restart and safe rollback. 12 min read 2 Read tutorial Windows PowerShell PS> Get-WinSystemLocalePS> Get-WinUILanguageOverridePS> Get-WinUserLanguageList Windows Server Change Windows Server Display Language, System Locale and Time Zone (2016/2019/2022) Change the Windows Server display language with Install-Language or a language pack, then set system locale, user languages and time zone. 12 min read 1 Read tutorial Windows PowerShell PS> Update-HostStorageCachePS> Get-Disk | Select-Object Number, FriendlyName…PS> Get-Partition -DiskNumber 0 | Select-Object P… Windows Server Extend C: Drive on Windows Server After a Disk Upgrade and Initialize a New Data Disk Extend the C: drive on Windows Server after a disk upgrade, fix a blocking recovery partition and initialize a new data disk with PowerShell. 12 min read 1 Read tutorial Windows PowerShell PS> Get-NetAdapterPS> Get-NetIPConfiguration -InterfaceAlias "Ether…PS> Get-NetIPInterface -InterfaceAlias "Ethernet"… Windows Server Add an Additional IPv4 Address and Configure IPv6 on Windows Server Add an extra IPv4 and configure IPv6 on Windows Server via GUI, PowerShell or netsh, with SkipAsSource, gateway, DNS and connectivity tests. 14 min read 2 Read tutorial