← Back to Blog

Windows VPS with RDP: Remote Desktop for Trading and Office Apps

Published · by RS Computers

Windows VPS Remote Desktop MetaTrader

Rent a Windows VPS with RDP and you get a Windows Server computer in a data centre that you use through Remote Desktop: you open an app on your PC or phone, type the server's address, and its desktop appears in a window. Whatever you start there keeps running after you close the window or switch your own computer off. Traders use it to keep MetaTrader connected overnight. Small offices use it for the one Windows-only accounting program that two people need to reach.

In a nutshell:

Who a Windows VPS with RDP is for, and who can skip it

A VPS (virtual private server) is your own slice of a large physical server, with its own operating system and IP address. Ours run on KVM, the virtualization built into the Linux kernel, which gives each server a complete virtual machine; that is why a full Windows Server runs on it. On screen you see an ordinary Windows desktop; if Server Manager, the admin console of Windows Server, opens when you sign in, just close it. Think of a PC without a screen, in a rack instead of under your desk.

Traders who need MetaTrader running all night

MetaQuotes' help pages put it simply: an Expert Advisor (a trading robot inside the terminal), a Market robot or a copied Signal needs a terminal that is always connected and powered, which a home computer can't always provide. If your laptop goes to sleep at one in the morning, or Windows restarts for an update at three, the EA stops. Your positions don't.

MetaQuotes' built-in hosting is simpler for one account with ordinary EAs, but it allows one trading account per rented terminal, stops EAs that call DLLs and has no desktop. Your own server runs two brokers' terminals and a trade copier at once. One caveat: MetaQuotes officially lists Windows 10 and 11, so MetaTrader on Windows Server is common practice, not a vendor promise.

Offices with one Windows-only program

The usual story is a bookkeeping program that runs only on Windows and two people who need it from two places. On the server it opens from the office and from home, the data stays in one place, and only the picture of the screen travels. Eurostat counted 23.0% of employed people aged 15 to 64 in the EU working from home usually or sometimes in 2025, and 52.3% in the Netherlands. Mind the two-person limit below.

Mac and iPad users with one Windows-only tool

StatCounter put Apple's Mac systems (OS X and macOS together) at about 16.5% of European desktop traffic in September 2026, roughly one visit in six. If you are one of them, a server opened from Windows App is less hassle than running Windows on the Mac, and the same desktop follows you to the iPad.

Who should not bother

Scalpers who need to sit next to the broker's matching engine want co-location, a different product. And no server rescues a losing strategy.

Amsterdam, Dublin or Prishtina: two different delays

RS Computers has servers in Amsterdam (Netherlands), Dublin (Ireland) and Prishtina (Kosovo). Availability by city is on the plans page. Choosing means separating two delays. Screen delay, between you and the server, decides how typing feels; Microsoft's remote desktop guidance rates under 150 ms per frame as good and over 300 ms as bad, so for office work take the nearest city. Order delay, between the server and your broker's trade server, is what your EA feels, so for automated trading put the server near the broker. In MetaTrader on the server, the connection indicator at the bottom right shows the ping to each trade server.

Amsterdam and Dublin keep EU personal data inside the EU. Prishtina keeps Kosovo data at home, one of the reasons to buy a VPS in Kosovo, but for an EU company it is a third-country transfer, since Kosovo has no EU adequacy decision (general information, not legal advice).

Which plan: sizing Windows for trading and office work

Every RS Computers plan is a KVM virtual machine on NVMe storage (fast solid-state drives attached over PCIe), with unmetered traffic and its own IPv4 and IPv6 addresses. VPS plans have a 1 Gb/s port, VDS plans 10 Gb/s. Windows is available on the four plans in the table below, and you can move up a plan later from the client area, with a short reboot on the same server.

Sizing starts with Microsoft's hardware requirements: 2 GB of memory is the minimum for Windows Server with the desktop, 4 GB is recommended for the current release, and 32 GB of disk is the absolute minimum. The right-hand column is our own sizing: MetaQuotes says only that the hardware a terminal needs depends on how many programs, symbols and charts it runs.

PlanWorks well for
VPS Mini (4 vCPU, 4 GB, 80 GB NVMe, 1 Gb/s)One person with one or two MetaTrader terminals, or a light accounting program. 4 GB is what Microsoft recommends for Windows alone, so there is little room left over.
VDS Small (4 vCPU, 8 GB, 240 GB NVMe, 10 Gb/s)Several terminals from different brokers, or an accounting or ERP program with two people connected at once. Our usual suggestion.
VDS Medium (8 vCPU, 16 GB, 480 GB NVMe, 10 Gb/s)Many terminals and EAs, Strategy Tester optimisations that keep every vCPU busy, or an ERP with its own database on the same machine.
VDS Large (16 vCPU, 32 GB, 960 GB NVMe, 10 Gb/s)Long back-tests, a large database, or several memory-hungry programs side by side.

vCPUs are shared with other servers on the host, as on most cloud platforms. Before upgrading, check Task Manager's Performance tab: memory near 100% calls for a bigger plan, while free memory and a laggy screen point at the connection.

Your first connection, step by step

  1. On the VPS and VDS plans page, pick a location and VPS Mini or a VDS plan, and choose Windows at the configure step.
  2. When the server is ready, note its IPv4 address, the administrator user name and the password.
  3. On your Windows PC, open PowerShell from the Start menu.

These lines test the Remote Desktop port, then open Remote Desktop Connection with the address filled in:

# as the normal user on your own PC (PowerShell)
Test-NetConnection -ComputerName YOUR_SERVER_IP -Port 3389
mstsc /v:YOUR_SERVER_IP

The test's last line should read TcpTestSucceeded : True. WARNING: TCP connect to ... failed means a wrong address or a server still being set up.

  1. Click Connect and type the administrator user name and password. If Windows offers your own PC's account, click More choices, then Use a different account.
  2. A warning says the identity of the remote computer cannot be verified. That is normal the first time, because the server made its own certificate: tick Don't ask me again and click Yes.
  3. The server's desktop fills your screen, with a small bar at the top showing the address.
  4. Change the password now: Ctrl+Alt+End is Remote Desktop's Ctrl+Alt+Delete and offers Change a password.

"Your credentials did not work" usually means the user name format. Try .\Administrator (the dot means "this computer") and check Caps Lock and the keyboard layout.

To keep the connection as an icon, click Show Options, then Save As. Since the April 2026 Windows security update, opening a saved .rdp file brings up a security dialog every time. For a file you saved yourself it reads Caution: Unknown remote connection, which is expected, and every local resource starts unticked; tick Clipboard if you want copy and paste between your PC and the server. Typing the address into Remote Desktop Connection, as above, skips the dialog. Microsoft added it because phishing emails carry .rdp files that connect victims to an attacker's server and share their drives, as its guide to the new RDP file warnings explains. Never open an .rdp file you didn't save yourself.

Which Remote Desktop app to use on each device

Microsoft renamed and retired several Remote Desktop apps in 2024 and 2025 and called the replacement Windows App, a name about as searchable as a car called Car, so many tutorials name apps that are gone. The current map, with details in Microsoft's Windows App release notes:

Your deviceApp to installGood to know
Windows 10 or 11Remote Desktop Connection (mstsc), built inWindows App has offered direct PC connections on Windows only as a preview since February 2026 (version 2.0.964.0), and as of October 2026 Microsoft still points to mstsc for a generally available app. The Remote Desktop app from the Microsoft Store is out of support.
MacWindows App, Mac App StoreThe former Microsoft Remote Desktop, renamed with version 11.0.0 on 19 September 2024.
iPhone and iPadWindows App, App StoreRenamed the same day as the Mac app.
Android and ChromebookWindows App, Google PlayReplaced the Remote Desktop app on 2 April 2025.
LinuxRemmina or xfreerdp3From your distribution's own packages; commands below.
Web browserNothing from Microsoft for a single serverWindows App on the web only reaches Microsoft's cloud desktops, and the web client for Windows Server needs a full Remote Desktop Services deployment.

On first start, Windows App suggests signing in with a work or school account. Skip it: a direct connection to your own server needs no sign-in, and personal Microsoft accounts aren't accepted anyway.

Connecting from a Mac, iPhone, iPad or Android device

  1. Install Windows App from your device's app store and open it.
  2. Press the + button and choose Add PC (on an iPhone, iPad or Android device, just PC).
  3. Type the server's IP address as the PC name and choose Add (Save on a phone or tablet).
  4. Open the new tile (double-click on a Mac, tap on a phone or tablet), enter the user name and password, and accept the first-time warning about the server's certificate. Android first asks you to make sure you trust the remote PC: tap Connect.
  5. To leave, close the window. That disconnects you and leaves your programs running.

Error code 0x204 means the device cannot reach port 3389: check the address and, once RDP is limited to your IP (step 5 below), that your home IP hasn't changed. A phone is fine for checking an EA from a café; spreadsheets on it are miserable.

Connecting from Linux (Debian 13, Ubuntu 24.04 or 26.04)

All three use the same package names: Remmina, a window that keeps your saved connections, and the FreeRDP client, which the last line uses to connect:

# as the normal user on your Linux PC (an account with sudo rights)
sudo apt update
sudo apt install remmina remmina-plugin-rdp freerdp3-x11
xfreerdp3 /v:YOUR_SERVER_IP /u:YOUR_USER /cert:tofu +dynamic-resolution +clipboard

Answer Y when apt asks to continue; Remmina then appears in your applications menu. The last line asks for the password and opens the desktop in a resizable window. /cert:tofu trusts the certificate the first time and checks it afterwards, safer than the /cert:ignore in older guides. On Ubuntu 26.04, freerdp3-x11 is a transitional package that pulls in FreeRDP 3.32 under the name freerdp-x11, and the xfreerdp3 command still works. On Debian without sudo, run the apt lines as root after su -, without the word sudo, then type exit and connect as yourself.

How to secure RDP on a VPS

Anything listening on port 3389 gets knocked on. On a freshly delivered Windows server we tested on, the first failed RDP sign-in arrived seven minutes after boot, and 65 within about nine hours. When Microsoft's Defender researchers studied about 45,000 machines with RDP open to the internet, several hundred a day showed a brute-force attack, meaning automated password guessing. Attacks lasted 2 to 3 days on average, with more than 10 failed sign-ins a day in 90% of cases. About 0.08% of the attacked machines were broken into. Bots cost nothing to run, so they can live with those odds. The Sophos 2026 Active Adversary Report, published in February 2026 and built on 661 incidents handled between November 2024 and October 2025, again found compromised credentials the top root cause, at 42%, with brute-force attacks behind about 16%. Attackers abused RDP to move around inside the victim's network in 66% of cases and to get in from outside in 10%.

Server commands run in an administrator PowerShell window: click Start, type PowerShell, right-click Windows PowerShell and choose Run as administrator.

1. A long password beats a clever one

NIST's SP 800-63B-4 (August 2025) asks for at least 15 characters when a password is the only thing protecting a login, as with plain RDP, and drops forced symbols and scheduled changes. Four or five unrelated words are easier to type than P@ssw0rd! and far harder to guess. Windows Server does want three of four kinds of character (capitals, small letters, digits, symbols) and doesn't count spaces, so four lowercase words are refused; capitalise one word and join them with hyphens, and it passes. Keep it in a password manager and use it nowhere else.

2. Keep Network Level Authentication on

Network Level Authentication (NLA) makes the client prove who it is before Windows creates a session, so a bot without a valid password never gets a login screen. Microsoft advises keeping it enabled whenever possible, and our Windows template has it switched on from the first boot. You can check it yourself:

# as the Administrator user, in an administrator PowerShell window on the server
$ts = Get-CimInstance -Namespace root\cimv2\TerminalServices -ClassName Win32_TSGeneralSetting -Filter "TerminalName='RDP-tcp'"
$ts.UserAuthenticationRequired

1 means NLA is required, as it should be. 0 means it is off: press Win+R, run SystemPropertiesRemote, tick the Network Level Authentication box on the Remote tab and click OK.

3. A normal account for daily work

Administrator is the first name every bot tries, so keep it for installs and updates and work in a separate account. These lines create one, allow it to use Remote Desktop and list who is allowed:

# as the Administrator user, in an administrator PowerShell window on the server
$Password = Read-Host -AsSecureString
New-LocalUser -Name "trader" -Password $Password -FullName "Daily account" -PasswordNeverExpires
Add-LocalGroupMember -Group "Remote Desktop Users" -Member "trader"
Get-LocalGroupMember -Group "Remote Desktop Users"

After the first line, type the new password and press Enter (asterisks appear). If New-LocalUser stops with InvalidPasswordException, the password failed the rule from step 1; run the lines again with a better one. The last command lists the computer name, a backslash and trader. -PasswordNeverExpires stops Windows demanding a new password every few weeks, which NIST no longer recommends. A later "not authorized for remote login" means the group line was skipped.

4. Check that account lockout is on

Microsoft's KB5020282 calls brute force one of the top three ways Windows computers are attacked, made the built-in Administrator lockable, and recommends 10/10/10: lock after 10 failed attempts within 10 minutes, for 10 minutes. Windows installed with the October 2022 updates or later gets those values by default, and our Windows template ships with them, Administrator included. Older installs default to 0, which means accounts never lock, however many wrong passwords arrive. To see what is in force on your server right now:

# as the Administrator user, in PowerShell on the server
net accounts

Look for Lockout threshold: 10 and two lines showing 10 minutes. On that same server, the tenth wrong password locked our test account, and even the right one was refused until the 10 minutes were up. If the threshold says Never, set it yourself and run net accounts again:

  1. Press Win+R, type secpol.msc, press Enter, then open Account Policies and Account Lockout Policy.
  2. Set Account lockout threshold to 10, then Account lockout duration and Reset account lockout counter after to 10 minutes each.
  3. Set Allow Administrator account lockout to Enabled.

Lockout cuts both ways: anyone who knows your user name can lock you out on purpose, and bots that keep guessing at Administrator keep it locked. If that happens, wait out the 10 minutes or message us on Telegram. The real cure is step 5: bots that can't reach the port can't lock anyone out.

5. Allow RDP only from your own IP address

This step does the most. Finish steps 1 to 4 first, and if you don't know of a way into your server besides RDP, ask us before you start. First, find out which address the server sees you connecting from:

# as the Administrator user, in an administrator PowerShell window on the server
Get-NetTCPConnection -LocalPort 3389 -State Established

The RemoteAddress column is your public IP (IPv6 works too). Put it in place of YOUR_HOME_IP, carefully, since a typo locks you out. The first line limits the Remote Desktop rule group, TCP and UDP 3389, to that address; the second shows the result:

# as the Administrator user, in an administrator PowerShell window on the server
Set-NetFirewallRule -DisplayGroup "Remote Desktop" -RemoteAddress YOUR_HOME_IP
Get-NetFirewallRule -DisplayGroup "Remote Desktop" | Get-NetFirewallAddressFilter | Format-Table RemoteAddress

The second command lists your address once per rule. Leave the session open and run Test-NetConnection on your own PC again: True means you are still welcome. If it says False, undo on the server with Set-NetFirewallRule -DisplayGroup "Remote Desktop" -RemoteAddress Any and check the address.

Separate home and office addresses with a comma. Home IPs change now and then; Microsoft suggests allowing your provider's range (like 198.51.100.0/24) or using a VPN. On non-English Windows the group name is translated; set the same address on the Scope tab of each Remote Desktop rule in wf.msc instead.

6. Or put RDP behind a VPN

If your IP changes often or you work over mobile data, a VPN (an encrypted tunnel between your device and the server) saves chasing addresses. WireGuard's official Windows installer supports Windows Server: open its UDP port (51820 by convention), then point the Remote Desktop rules at the tunnel's address range. The other route keeps the Windows server untouched: run WireGuard on a small Linux VPS, as in our WireGuard VPN setup on Debian 13, connect your devices through it, and allow RDP only from that VPS's fixed IPv4 address in step 5. Your home IP can then change as often as it likes. Microsoft's own advice is blunt: opening RDP to the internet isn't recommended, and a VPN is preferable.

7. A different port is not a lock

Moving RDP off 3389 makes the logs quieter, because lazy scanners only try 3389. A full port scan still finds it, and the login screen behind it is exactly as exposed. The troubleshooting articles on Microsoft Learn recommend against changing the port, and the Q&A forum there has owners who changed it, forgot the firewall rule for the new one and locked themselves out. Leave it on 3389 and put the effort into step 5.

8. Look at failed logins now and then

Every failed sign-in lands in the Security log as event 4625, and the newest five are one command away:

# as the Administrator user, in an administrator PowerShell window on the server
Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4625} -MaxEvents 5 | Format-List TimeCreated, Message

The Account Name under Account For Which Logon Failed is the user name tried, and Source Network Address shows where the attempt came from. For a wrong name or password, Status reads 0xC000006D and the Sub Status line says which: 0xC000006A means a wrong password for a real account, 0xC0000064 a user that doesn't exist. Status 0xC0000234 means the attempt hit an account that lockout (step 4) has already locked. Old entries stay until the log fills up, so after step 5 watch the newest TimeCreated: if it stops moving, strangers no longer reach the login. A red line saying no events were found means no failed sign-ins at all. From this log, that is good news.

Keeping MetaTrader running through disconnects and updates

The easiest way to stop an EA on a healthy server is to sign out. Close the window or choose Disconnect instead: Microsoft's client documentation says apps stay active as long as the session is active, and Windows keeps disconnected sessions indefinitely unless the policy Set time limit for disconnected sessions is set. Connect from your phone as the same user and you take over that session, terminals still running.

A restart signs everyone out. Put a terminal shortcut in the trading account's Startup folder (Win+R, shell:startup); after each restart, connect, check that AutoTrading (Algo Trading in MetaTrader 5) is on, and disconnect. Auto sign-in tools exist, but they store a usable password on the server; we would rather connect after a planned restart.

Security updates arrive on Patch Tuesday, the second Tuesday of each month around 10:00 Pacific time, which is Tuesday evening in Europe. Choose when the server restarts:

  1. In the administrator PowerShell window, type sconfig and press Enter. A text menu appears.
  2. Type 5 for Update setting. A new server shows Not configured. Skip 1, Automatic: it installs updates daily at 3:00 AM server time. If the server's taskbar clock runs nine hours behind Central Europe, it is set to US Pacific time, and 3:00 AM there is noon in Central Europe. Type 2, Download only, which fetches updates and waits for you.
  3. Weekly, ideally at the weekend while the forex market is closed, type 6 for Install updates, then 1 for all quality updates and A to install them all, and restart.

To check that updates are actually arriving, list the latest few with their install dates:

# as the Administrator user, in PowerShell on the server
Get-HotFix | Where-Object InstalledOn | Sort-Object InstalledOn -Descending | Select-Object -First 5

Windows lists some updates without a date; Where-Object InstalledOn skips those, which would otherwise trigger a red error about InstalledOn. On a brand-new server the dates come from its Windows image, so run Install updates once on the first day. After that, if the newest InstalledOn date is over a month old, updates are not happening.

Don't let that slide. BlueKeep (CVE-2019-0708) let attackers run code through RDP without signing in on unpatched Windows Server 2008 R2 and older, and NIST rated it 9.8 out of 10. Its successors keep coming: the 8 September 2026 updates fixed CVE-2026-69525, a memory bug in Remote Desktop Services on Windows Server 2019, 2022 and 2025, also rated 9.8 and also reachable without a password. Microsoft knew of no attacks when it shipped the fix but rated exploitation more likely. The same updates made Remote Desktop unstable on some servers, with connections failing after a few minutes, until an out-of-band fix on 14 September (KB5129235 on Windows Server 2025). If RDP misbehaves right after an update, check Microsoft's release health page for Windows Server 2025 (there is one per version) before anything else.

Patch your own PC too, because mismatched patch levels make Remote Desktop fail with "An authentication error has occurred" and a mention of CredSSP. A home PC still on Windows 10 gets those fixes only through Extended Security Updates, which Microsoft extended in June 2026 to run until 12 October 2027 for personal devices.

How to back up and monitor a Windows VPS

Every RS Computers server gets a free weekly backup of the whole machine, restorable from the client area for big accidents like a failed update. A week is long for a trading journal, so copy daily data off too; in MetaTrader, File, then Open Data Folder shows where EAs, templates and profiles live. The backup tool restic runs on Windows, and our guide to off-site backups with restic covers the receiving end; for shared documents, a Nextcloud server for file sync keeps everyone on one version. For alerts, an Uptime Kuma monitor from our Uptime Kuma and Grafana guide can test port 3389 every minute, once its IP is added to the Remote Desktop rule.

Why does Remote Desktop feel slow?

RDP is light. Microsoft measured it at 1920x1080: an idle session uses about 0.3 Kbps and Excel work 150 to 200 Kbps, while video in half the screen takes 8.5 to 9.5 Mbps. Before blaming the server:

Two sessions without extra licences: the limit to plan around

In Microsoft's words, "Remote Desktop supports two concurrent remote connections to the computer", and those two need no Remote Desktop Services client access licences (RDS CALs). More than two administrative connections, or multiple user connections, need the RD Session Host role plus the matching RDS CALs. In practice that means you and one colleague. A whole office needs a licensed terminal server.

Don't install that role just to get a third seat. It works during a 120-day grace period, then sessions are cut off with an error saying no Remote Desktop License Servers are available. If two connections are enough, Microsoft's fix is to connect with mstsc /admin and remove the role in Server Manager.

Frequently asked questions

Will MetaTrader keep running when I close Remote Desktop?

Yes, if you close the window or choose Disconnect, since the session stays alive on the server. Signing out or a restart closes MetaTrader, so after updates, connect once and check AutoTrading.

Is it safe to leave Remote Desktop open to the internet?

Not with default settings and a short password: the 2024 CISA and FBI advisory on Phobos ransomware describes attackers scanning for exposed RDP and then brute-forcing it. With the port limited to your IP or a VPN, plus NLA, lockout and a long password, the risk becomes small.

How much RAM does a VPS need for MT4 or MT5?

There is no official number: MetaQuotes ties it to the programs, symbols and charts you run, and Microsoft recommends 4 GB for the current Windows Server with the desktop before any program is open. One or two terminals fit on VPS Mini; for several, or MetaTrader 5 with many charts and EAs, we would start at VDS Small with 8 GB.

What port does RDP use?

Port 3389, over TCP and UDP. If it has been moved, add the port after the address, as in mstsc /v:YOUR_SERVER_IP:3390, and allow the new port in the firewall for both protocols.

Can RS Computers set up and secure the Windows server for me?

Yes. Message us on Telegram or email info@rscomputers-ks.com with what you want to run and how many people will connect, and we will suggest a plan and quote the setup.

The order we would do it in

Pick a city near you, or near your broker if an EA does the trading, and a plan on the Windows VPS page, choosing Windows at the configure step. Then connect, set a long passphrase, confirm NLA, create your daily account, check lockout, limit RDP to your IP and test from home, and install the waiting updates. Install MetaTrader or your accounting program last, once the doors are shut. Rather hand it over? Tell us on Telegram what the server is for.

← All articles

Chat on Telegram