When Remote Desktop fails to connect, the wording of the error tells you which of four layers broke: the network path to port 3389, the Remote Desktop service on the server, the security handshake (certificates, CredSSP and Network Level Authentication), or the sign-in itself. Check them in that order, because each layer needs the one before it. Microsoft names a listener that isn't running and wrong network settings as the main causes of "Remote Desktop can't connect to the remote computer", so the first two checks clear most cases in minutes. Below, each real error message has its cause and fix, and the Linux part (xfreerdp3 and Remmina, shared folders included) was reproduced in our lab.
Key facts, checked on 9 October 2026:
- Microsoft's article Remote Desktop can't connect to the remote computer (updated 12 February 2026) gives "the RDP-TCP listener not working and incorrect network configurations" as the main root causes.
- Windows Server accepts two Remote Desktop connections at once without extra licences. Adding the RD Session Host role for more starts a 120-day licensing grace period (Microsoft Learn).
- The CredSSP error goes back to CVE-2018-0886; Microsoft's fix is the CredSSP updates, first released on 13 March 2018, on both client and server (Microsoft Learn).
- In our lab, a firewall silently dropping port 3389 made xfreerdp3 wait 15.1 seconds before failing; a stopped RDP service failed in 0.15 seconds. The delay alone tells you which problem you have.
- Debian 13 ships FreeRDP 3.15.0 and Remmina 1.4.39, and both keep accepted server certificates in the same folder,
~/.config/freerdp/server/.
The one-minute decision flow
- Error before any password prompt? The network or the RDP service. Run the port test below.
- Port test fails? The server is off or booting, the address is wrong, or a firewall rule blocks you, often because your home IP changed. Work from the server's console.
- Port test works, but you get an "authentication error" or a certificate warning? The security handshake: CredSSP updates, Network Level Authentication or a changed certificate.
- Password prompt, then "Your credentials did not work"? User name format, password or lockout.
- A licence error, or a hang at "Connecting to the RD Connection Broker server"? A Remote Desktop Services role is installed on the server.
This port test is the one we ran on our own Windows server for the Windows RDP VPS setup guide:
# on your own Windows PC, in PowerShell as your normal user
Test-NetConnection -ComputerName YOUR_SERVER_IP -Port 3389
The last line should read TcpTestSucceeded : True. On Linux, netcat answers the same question; these outputs are from our lab:
# as your normal user on a Linux PC (package netcat-openbsd)
nc -vz -w 5 YOUR_SERVER_IP 3389
succeeded! means the port answers. Connection refused means the server is up but nothing listens on 3389, so Remote Desktop is off or its service stopped. timed out means packets vanish on the way: a firewall or a wrong address.
Every common error message, its cause and the fix
Network faults come first because they are behind most cases. Messages are quoted in Microsoft's wording where Microsoft documents them.
| What you see | Usual cause | Fix |
|---|---|---|
| "Remote Desktop can't connect to the remote computer for one of these reasons: 1) Remote access to the server is not enabled 2) The remote computer is turned off 3) The remote computer is not available on the network" | Port 3389 unreachable: server off or booting, wrong IP, firewall rule, RDP listener down | Port test, then the console |
| "This computer can't connect to the remote computer." | The same network causes, or an account without Remote Desktop sign-in rights | Add the account to Remote Desktop Users |
| "Windows Security error: Your credentials did not work" | Name format, typo or a locked account | Use .\Administrator or COMPUTERNAME\user, then check lockout |
| "An authentication error has occurred. The function requested is not supported. ... This could be due to CredSSP encryption oracle remediation." | CredSSP updates missing on one side | Update the PC and the server |
| "An authentication error has occurred. The Local Security Authority cannot be contacted" | The computer or domain part of the user name is wrong | Correct it, or use a local account |
| "The remote computer requires Network Level Authentication, which your computer does not support" | A very old client, or a Linux client forced to /sec:tls or /sec:rdp | Update the client or drop the option; keep NLA on |
| "The remote session was disconnected because there are no Remote Desktop License Servers available to provide a license." | RD Session Host role installed, grace period over | mstsc /admin, then remove the role or license it |
| Stuck at "Connecting to the RD Connection Broker server" | Broker role on a single server with its service or group broken | Remove unneeded RDS roles and restart |
| Windows App error 0x204 | The app can't reach port 3389 | Same as the first row |
| Windows App error 0x904 | Undocumented; reported with unstable or VPN links | Try without the VPN, update the app |
"Remote Desktop can't connect to the remote computer": work from the console
If the port test fails, Remote Desktop can't help you. Every RS Computers VPS and VDS has a console in the client area that shows the server's screen as a monitor would, so it works while RDP is down. Open it first: a server still installing updates or booting refuses connections until it finishes. If Windows is up, these are the usual suspects, most likely first.
Your IP changed after you limited RDP to it
Limiting Remote Desktop to your own IP is good practice and also the most common self-lockout, because home IPs change. In the console, reopen the rule for a moment. These are the commands we tested on our own Windows server for the setup guide:
# as the Administrator user, in an administrator PowerShell window on the server (console)
Set-NetFirewallRule -DisplayGroup "Remote Desktop" -RemoteAddress Any
Connect over Remote Desktop, then read the address the server sees and lock the rule to it:
# as the Administrator user, in an administrator PowerShell window on the server
Get-NetTCPConnection -LocalPort 3389 -State Established
Set-NetFirewallRule -DisplayGroup "Remote Desktop" -RemoteAddress YOUR_NEW_IP
The RemoteAddress column shows your current public IP. If it changes often, a VPN with a fixed exit address ends this; our WireGuard guide for Debian 13 builds one.
The Remote Desktop firewall rules are off
Open wf.msc on the server, go to Inbound Rules and check that the two Remote Desktop User Mode rules (TCP-In and UDP-In) are enabled for all profiles. Microsoft's troubleshooting article also gives a one-line PowerShell version that pipes Get-NetFirewallRule -DisplayGroup "Remote Desktop" into Set-NetFirewallRule -Enabled True. We haven't run that one ourselves, so take it from Microsoft's page.
The RDP listener isn't running
The listener is the part of Windows that waits for connections on port 3389. Microsoft's documented check is qwinsta in an administrator Command Prompt: a line rdp-tcp in the state Listen means the listener runs. To see whether another program took the port, Microsoft compares the process ID from tasklist /svc | findstr TermService with the one from netstat -anob | findstr 3389; they should match. We had no broken Windows server to run these on, so the expected output here is Microsoft's.
No rdp-tcp line usually means Remote Desktop is off: press Win+R, run SystemPropertiesRemote and allow remote connections on the Remote tab. The same Microsoft article lists the services and registry values to check next. One trick from it separates server faults from network faults: on the server, connect Remote Desktop Connection to localhost. If that fails too, the server is the problem.
"Your credentials did not work" and accounts that lock
Here the connection worked and Windows rejected the sign-in. The usual causes:
- The user name format. Type
.\Administrator(the dot means "this computer") orCOMPUTERNAME\user; if Windows offers your PC's account, choose More choices, then Use a different account. - Caps Lock or a different keyboard layout.
- An old password saved in the client. Show Options in Remote Desktop Connection lets you edit or delete it.
- Lockout. With the defaults our Windows template uses (Microsoft's since October 2022), 10 wrong passwords in 10 minutes lock the account for 10 minutes, and even the right password is refused.
On our Windows server these show the lockout policy and the latest failed sign-ins:
# as the Administrator user, in an administrator PowerShell window on the server
net accounts
Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4625} -MaxEvents 5 | Format-List TimeCreated, Message
In event 4625, Sub Status 0xC000006A means a wrong password, 0xC0000064 a user that doesn't exist, and Status 0xC0000234 a locked account. If bots keep Administrator locked, limit port 3389 to your IP as in our RDP security steps. "The connection was denied because the user account is not authorized for remote login" belongs here too: add the account to Remote Desktop Users.
CredSSP and Network Level Authentication errors
CredSSP is the Windows component that passes your password to the server securely. Network Level Authentication (NLA) uses it to check who you are before Windows draws a login screen, which keeps bots away from the desktop. Both sides must speak the same version.
"An authentication error has occurred ... CredSSP encryption oracle remediation"
Microsoft's table explains it: a client with the CredSSP update, set to Force updated clients or Mitigated, refuses a server without it. Run Windows Update on both machines. The fix dates from 2018, so the side that fails is usually one that has missed years of updates; a home PC still on Windows 10 only gets security updates through Extended Security Updates. Microsoft also documents setting the client's Encryption Oracle Remediation policy to Vulnerable, and warns that this exposes the server to attacks. Use it only to reach a server you are about to update, then set it back.
"The remote computer requires Network Level Authentication"
The server insists on NLA and the client won't do it. Microsoft's NLA page says the About box of Remote Desktop Connection shows "Network Level Authentication supported" when the client can. On Linux it happens when a guide adds /sec:tls or /sec:rdp. We reproduced the mirror image by forcing NLA against an xrdp server without it and got Protocol Security Negotiation Failure; removing the forced option fixed it.
Turning NLA off puts the login screen in front of every scanner, so update the client instead. To check NLA, run the query we tested on our Windows server; 1 means required:
# as the Administrator user, in an administrator PowerShell window on the server
$ts = Get-CimInstance -Namespace root\cimv2\TerminalServices -ClassName Win32_TSGeneralSetting -Filter "TerminalName='RDP-tcp'"
$ts.UserAuthenticationRequired
Licence errors and "Connecting to the RD Connection Broker server"
Remote Desktop Services (RDS) is the set of extra Windows Server roles for many users. Microsoft says the Connection Broker "manages incoming remote desktop connections to RD Session Host server farms" and reconnects users to their sessions (RDS roles). On a single VPS these roles usually appear because someone wanted a third seat.
Two things then break. After 120 days without a licence server, Windows disconnects you with the "no Remote Desktop License Servers available" message. And if the broker service (TSSDis) is stopped, or the local group RDS Endpoint Servers lacks NT AUTHORITY\NETWORK SERVICE, connections hang at the broker step; Microsoft's troubleshooting article lists both conditions.
If two sessions are enough, connect for administration with the /admin switch from Microsoft's mstsc reference: on your PC, press Win+R and run mstsc /v:YOUR_SERVER_IP /admin. Microsoft says this disables licensing for that one connection; we followed its documentation here rather than a licence-expired server of our own. Then open Server Manager, choose Manage, Remove Roles and Features, untick Remote Desktop Services under Server Roles and restart. Need more than two users? Read our RDS grace period guide for Windows Server 2025.
Error codes 0x204 and 0x904 on Mac, iPhone and Android
Windows App, Microsoft's client for Mac, iOS and Android, reports failures as hex codes, and its troubleshooting page lists no meanings. What follows is field experience from Microsoft's Q&A forum. 0x204 almost always means the app never reached port 3389: check the address, the firewall rule and whether your IP changed. 0x904 appears when a connection starts and then breaks, typically over slow or VPN links, and in one reported case because of a damaged RDP certificate on the server. Try without the VPN and update the app from the release notes; if every device fails, look at the server.
Linux clients: what xfreerdp3 and Remmina errors mean
We ran an xrdp server in one Debian 13 container, connected with xfreerdp3 3.15.0 and Remmina 1.4.39 from another, and broke things on purpose. The client tools:
# as root on your Linux PC (or put sudo in front)
apt install freerdp3-x11 remmina remmina-plugin-rdp netcat-openbsd
/cert:tofu accepts the server's certificate the first time and checks it on every later visit:
# as your normal user on the Linux PC
xfreerdp3 /v:YOUR_SERVER_IP /u:YOUR_USER /cert:tofu
It asks Password: and opens the desktop; the first time, the log says No certificate stored, automatically accepting. The failures we caused:
| What xfreerdp3 printed | What caused it in our lab | Fix |
|---|---|---|
ERRCONNECT_CONNECT_TRANSPORT_FAILED [0x0002000D] in 0.15 s | RDP service stopped (netcat: Connection refused) | Start the service from the console |
ERRCONNECT_CONNECT_FAILED [0x00020006] after 15 s | Firewall dropping 3389 (netcat: timed out) | Firewall rule or changed IP |
WARNING: NEW HOST IDENTIFICATION!, ERRCONNECT_TLS_CONNECT_FAILED [0x00020008] | New server certificate | If expected, delete the stored certificate |
Do you trust the above certificate? (Y/T/N) | First visit without /cert:tofu | Answer Y, or use /cert:tofu |
ERRCONNECT_SECURITY_NEGO_CONNECT_FAILED [0x0002000C] | /sec:nla against a server without NLA | Remove the /sec: option |
One quirk: on a first visit without /cert:tofu, FreeRDP 3.15 also prints a "REMOTE HOST IDENTIFICATION HAS CHANGED" block, because it compares against a certificate file that doesn't exist yet. Harmless the first time; on later visits, take it seriously. When the certificate really changed, for example after Windows was reinstalled, delete the old file, named after the address and port:
# as your normal user on the Linux PC
rm ~/.config/freerdp/server/YOUR_SERVER_IP_3389.pem
Remmina reads the same folder: after we removed the file, it showed an "Accept certificate?" dialog with the fingerprint, and Yes wrote the file back. Against a Linux xrdp server, a wrong password gives no client error; xrdp's login screen appears and its log says User does not exist, or could not be authenticated.
Remmina shared folder: setting it up and finding it
Sharing a local folder over RDP is called drive redirection. Remmina 1.4.39 offers it twice in an RDP profile. Share folder picks one folder and names the share after its path; ours arrived as _home_ma, the start of /home/maria. Redirect directory takes your own names as name,path pairs separated by semicolons, such as Work,/home/you/Work, and our server showed a share called Work. With xfreerdp3 it is one option, and we copied files both ways through it:
# as your normal user on the Linux PC
mkdir -p ~/shared
xfreerdp3 /v:YOUR_SERVER_IP /u:YOUR_USER /cert:tofu /drive:shared,/home/YOUR_USER/shared
On an xrdp server it shows up in ~/thinclient_drives/shared, which is where we found it. On a Windows server, Microsoft's policy documentation says redirected drives appear in File Explorer in the format "name on computername", so look for something like "shared on YOUR-PC". If it is missing:
- Reconnect. Redirection is set up when the connection starts.
- Check the server's Do not allow drive redirection policy (registry value
fDisableCdm). This one fails silently: with drive redirection off on our xrdp server, the client loggedLoading device service drive [shared], raised no error, and the share never appeared. - With Remote Desktop Connection on Windows, opening a saved .rdp file now brings up the security dialog Microsoft added in April 2026, and every local resource in it, drives included, starts unticked. Tick Drives before you connect.
Locked out completely?
The client-area console reaches Windows without RDP, the network or the firewall, so you can undo a rule, switch Remote Desktop back on or wait out a lockout there. If the server won't boot, message us on Telegram with its IP and the exact error text.
Frequently asked questions
Why does Remote Desktop say it can't connect when the server is running?
Because running and reachable on port 3389 are different things. A firewall rule limited to an old IP, Remote Desktop switched off, or a stopped listener all give the same message. If Test-NetConnection -ComputerName YOUR_SERVER_IP -Port 3389 says False, fix it from the server's console.
What does Remote Desktop error 0x204 mean?
Microsoft publishes no official meaning, but in Windows App 0x204 means in practice that the device could not reach port 3389. Check the address, the server's firewall rule and whether your public IP changed.
How do I fix the CredSSP "An authentication error has occurred" message?
Install the latest Windows updates on your PC and on the server. The error appears when only one side has the CredSSP updates for CVE-2018-0886. Microsoft's Vulnerable policy workaround weakens security and is only for briefly reaching a server to update it.
What does "Connecting to the RD Connection Broker server" mean?
The server has the Remote Desktop Services Connection Broker role, which hands connections to session hosts in multi-server setups. A single VPS rarely needs it; if connections hang there, connect with mstsc /admin and remove the RDS roles, or repair the broker service and its group as Microsoft describes.
How do I share a folder with Remmina?
In the RDP profile, set Share folder to a local folder, or use Redirect directory with name,path, for example Work,/home/you/Work. Reconnect, and the folder appears in File Explorer on a Windows server or in ~/thinclient_drives on an xrdp server, unless the server blocks drive redirection.
Should I turn off Network Level Authentication to fix a connection?
No. NLA checks your password before Windows shows a login screen, so turning it off exposes the server to every scanner. Update the client, or remove options that force an older security mode.
Want a Windows server that's easy to get back into?
RS Computers runs Windows on VPS Mini and every VDS plan in Amsterdam, Dublin and Prishtina, each with its own IPv4 and IPv6 address and a console in the client area for the days RDP won't answer. Availability by city is on the plans page: compare them on the Windows VPS page, or ask us on Telegram for a quote to secure Remote Desktop for you.