Skip to main content

Enable Remote Desktop on Windows with PowerShell

When to use this​

You need to turn on Remote Desktop (RDP) on a Windows machine without using the GUI, for example on Server Core or over a remote PowerShell session.

Steps​

Run PowerShell as administrator.

1. Allow Remote Desktop connections​

Set-ItemProperty -Path 'HKLM:\System\CurrentControlSet\Control\Terminal Server' -Name 'fDenyTSConnections' -Value 0

2. Enable the firewall rule group​

Enable-NetFirewallRule -DisplayGroup 'Remote Desktop'
Set-ItemProperty -Path 'HKLM:\System\CurrentControlSet\Control\Terminal Server\WinStations\RDP-Tcp' -Name 'UserAuthentication' -Value 1

4. Allow a user​

Users must be members of the local Remote Desktop Users group (or be administrators):

Add-LocalGroupMember -Group 'Remote Desktop Users' -Member 'DOMAIN\username'

Verify​

From another machine:

Test-NetConnection <server> -Port 3389
warning

Never expose TCP 3389 directly to the internet. Use a VPN or a remote access gateway.