Start typing to search across invoices, services, domains, tickets, and more...
One of the most common issues after deploying a Windows VPS or dedicated server is a failed Windows Remote Desktop connection: the client says it "can't connect to the remote computer", hangs forever, or throws a CredSSP / NLA authentication error. This guide walks you through RDP troubleshooting from the outside in — port 3389, Windows Firewall, Remote Desktop Services, Network Level Authentication and account credentials — on Windows Server 2016, 2019 and 2022.
From your local computer, ping the server and then test the Remote Desktop port. Many servers block ICMP, so a failed ping alone does not mean the server is down — the port test is what matters. In PowerShell on your local Windows PC, run:
ping 203.0.113.10
Test-NetConnection 203.0.113.10 -Port 3389
If you see TcpTestSucceeded : True, the port is open and the problem is most likely authentication or the account. If it is False, continue with the service and firewall checks below. On macOS or Linux you can use nc -vz 203.0.113.10 3389. If you changed the RDP port earlier, test that port instead and connect using IP:port.
You do not need to reinstall the OS when RDP fails. Log in to the IMIDC client area → My Products & Services → select your server → Manage, then open the VNC / console (dedicated servers usually provide IPMI/KVM). This gives you a local-screen session to repair Windows. If you cannot find the console, open a ticket and our support team will help.
In the VNC console, open PowerShell as Administrator and check whether Remote Desktop is disabled, whether the TermService service is running and whether port 3389 is listening:
reg query "HKLM\SYSTEM\CurrentControlSet\Control\Terminal Server" /v fDenyTSConnections
Get-Service TermService
netstat -ano | findstr :3389
A value of 0x1 for fDenyTSConnections means Remote Desktop is turned off. Re-enable it and restart the service:
Set-ItemProperty -Path "HKLM:\SYSTEM\CurrentControlSet\Control\Terminal Server" -Name fDenyTSConnections -Value 0
Set-Service TermService -StartupType Automatic
Restart-Service TermService -Force
A firewall or security tool blocking port 3389 is a very common cause of RDP failures. The following commands use the language-independent rule group name, so they work on both English and localized editions of Windows:
Enable-NetFirewallRule -Group "@FirewallAPI.dll,-28752"
Get-NetFirewallRule -Group "@FirewallAPI.dll,-28752" | Select-Object DisplayName, Enabled, Profile
If you installed third-party security software, also review its port blocking and IP blacklist settings. To confirm whether the firewall is the culprit, you can briefly disable it and then turn it back on immediately afterwards:
Set-NetFirewallProfile -Profile Domain,Public,Private -Enabled False
Set-NetFirewallProfile -Profile Domain,Public,Private -Enabled True
The message "An authentication error has occurred. The function requested is not supported… This could be due to CredSSP encryption oracle remediation" means your PC and the server are on different security patch levels. The proper fix is to fully update both sides. If you cannot update the server right away, run this on your local PC as Administrator as a temporary workaround:
reg add "HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System\CredSSP\Parameters" /f /v AllowEncryptionOracle /t REG_DWORD /d 2
If Network Level Authentication (NLA) is blocking the login, temporarily disable it on the server from the VNC console:
Set-ItemProperty -Path "HKLM:\SYSTEM\CurrentControlSet\Control\Terminal Server\WinStations\RDP-Tcp" -Name UserAuthentication -Value 0
If you see "Your credentials did not work" or "The logon attempt failed", check that the username is Administrator (or the account you created), remember that passwords are case-sensitive, and avoid copying trailing spaces. Repeated failures may lock the account. Reset the password and unlock the account from the VNC console:
net user Administrator *
net user Administrator /active:yes
net accounts
net user Administrator * prompts for the new password twice (nothing is echoed). Windows Server also allows only two concurrent admin sessions by default; if they are in use, list them with query session and sign one out with logoff <session ID>.
This is usually packet loss, a server running out of CPU or memory, or a session timeout policy. Check resource usage in Task Manager and run ping -t <server IP> locally to look for sustained packet loss.
Not necessarily. Windows Firewall often blocks ICMP by default. If Test-NetConnection succeeds on port 3389, the server is online.
Your ISP or corporate network may block port 3389, or your IP may be blacklisted by security software on the server. Try changing the RDP port or check the server's IP blacklist.
If none of the steps above solve the problem, submit a ticket to IMIDC 24/7 technical support with your server IP, a screenshot of the error and the steps you have already tried.