RDP Monster

Windows Remote Desktop Connection (mstsc): The Complete Guide

Windows Remote Desktop Connection (mstsc): The Complete Guide

What Windows Remote Desktop Connection is and how to launch it

Windows Remote Desktop Connection is the RDP client that ships with every edition of Windows, Home included. The executable is mstsc.exe (Microsoft Terminal Services Client) in C:\Windows\System32. It opens a session on a remote Windows machine (a PC in another room, a server in a rack, a Windows VPS) and renders its desktop locally, by default over TCP port 3389.

Three ways to start it:

  • Press Win + R, type mstsc, press Enter.
  • Open the Start menu and search for Remote Desktop Connection.
  • From a terminal or a shortcut, run mstsc with switches (covered below) to skip the dialog.

Type the hostname or IP in the Computer field and click Connect. The client needs nothing else; the machine you are connecting to must run a Pro, Enterprise, Education, or Server edition with Remote Desktop switched on. See how to enable Remote Desktop on Windows 11 if that side is not ready yet.

Saving connections as .rdp files

Click Show Options and the General tab exposes Save, Save As, and Open. Save writes your current settings to a hidden Default.rdp in your Documents folder, reloaded on every start. Save As writes a named file you can double-click or pin to the taskbar.

An .rdp file is plain text, one name:type:value setting per line, where the type is s (string), i (integer), or b (binary). Edit it in Notepad, or reopen it in the dialog with mstsc /edit file.rdp. A minimal one:

full address:s:203.0.113.10:3389
username:s:Administrator
screen mode id:i:2
use multimon:i:0
desktopwidth:i:1920
desktopheight:i:1080
session bpp:i:32
audiomode:i:0
redirectclipboard:i:1
drivestoredirect:s:
authentication level:i:2

Two things people learn the hard way. screen mode id:i:2 means full screen and 1 means windowed. A saved password appears as a long password 51:b: line encrypted with DPAPI for your account on that specific machine; copy the file to another PC and the line is silently useless. Unsigned .rdp files also trigger a "publisher can't be identified" warning on open; that is normal for files you wrote yourself.

The five options tabs, setting by setting

Every control in the dialog maps to a line in the .rdp file.

General

Computer, user name, and the Allow me to save credentials checkbox. Append :port to the computer name when the host listens somewhere other than 3389.

Display

A resolution slider that goes up to Full Screen, the Use all my monitors for the remote session checkbox, and a colour-depth dropdown (session bpp). Leave it at 32-bit unless the link is genuinely slow. Display the connection bar keeps the strip at the top of a full-screen session.

Local Resources

This is where redirection lives. Remote audio decides where sound plays and whether your microphone is forwarded. Keyboard controls where Windows key combinations such as Alt+Tab land: locally, remotely, or only in full screen (the default, keyboardhook:i:2). Local devices and resources covers printers and the clipboard and, behind More, smart cards, ports, drives, cameras, and other Plug and Play devices. A redirected drive shows up in the session under This PC as C on YOURPC.

Experience

A connection-speed dropdown that defaults to Detect connection quality automatically, plus toggles for wallpaper, font smoothing, desktop composition, window contents while dragging, animations, visual styles, and persistent bitmap caching. On a laggy link, disabling wallpaper and animations helps more than lowering colour depth. Keep Reconnect if the connection is dropped on.

Advanced

Server authentication sets what happens when the host's certificate cannot be verified: warn me (default), connect and don't warn, or do not connect. Connect from anywhere holds the Remote Desktop Gateway settings: hostname, local-address bypass, and credential reuse. You need it only when an organisation publishes RDP through a gateway; a VPS with a public IP connects directly.

Keyboard shortcuts inside a session

In a windowed session most system shortcuts still belong to your own PC, so mstsc provides substitutes.

ShortcutWhat it does in the remote session
Ctrl+Alt+EndSends Ctrl+Alt+Del (lock, sign out, Task Manager, change password)
Ctrl+Alt+BreakToggles between full screen and a window (Ctrl+Alt+Pause on some keyboards)
Ctrl+Alt+HomeShows the connection bar in full screen
Alt+Page Up / Alt+Page DownSwitches between remote programs (Alt+Tab / Alt+Shift+Tab)
Alt+HomeOpens the remote Start menu
Ctrl+Alt+Plus (numeric keypad)Screenshots the whole remote screen to the clipboard (Print Screen)
Ctrl+Alt+Minus (numeric keypad)Screenshots the active remote window to the clipboard (Alt+Print Screen)

Laptops without a Break key vary (Fn+B, Fn+Pause, or Fn+Esc are the usual candidates), and the restore button on the connection bar does the same job with the mouse. To keep Alt+Tab and the Windows key on the remote side even in a window, change the Keyboard setting on the Local Resources tab.

Command-line switches: /v, /admin, /f, /w, /h, /multimon and more

mstsc /? lists every switch. The ones you will actually use:

mstsc /v:203.0.113.10
mstsc /v:203.0.113.10:3390
mstsc /v:203.0.113.10 /f
mstsc /v:203.0.113.10 /w:1600 /h:900
mstsc /v:203.0.113.10 /multimon
mstsc /v:203.0.113.10 /admin
mstsc /v:203.0.113.10 /public
mstsc /v:203.0.113.10 /prompt
mstsc /v:203.0.113.10 /restrictedAdmin
mstsc /edit work.rdp
mstsc work.rdp /v:203.0.113.20
mstsc /l
SwitchEffect.rdp equivalent
/v:server[:port]Target host and optional port; connects immediatelyfull address:s:
/adminAdministrative session on a server; the way in when the session limit is reachedadministrative session:i:1
/fStart in full screenscreen mode id:i:2
/w: and /h:Window width and height in pixelsdesktopwidth:i: / desktopheight:i:
/multimonRemote monitor layout mirrors your local oneuse multimon:i:1
/spanOne wide desktop stretched across monitors that form a rectanglespan monitors:i:1
/publicPublic mode: no cached credentials, bitmaps, or history—
/g:gatewayConnect through an RD Gatewaygatewayhostname:s:
/shadow:ID /controlView or control another user's session (ID from query session)—

For multiple monitors, /multimon (or the Display tab checkbox) is what you want: each local monitor becomes a monitor on the remote side, with the taskbar on your primary. /span is the older behaviour that presents one very wide desktop, so maximised windows stretch across the bezel. To use only some monitors, run mstsc /l, note the IDs, and add selectedmonitors:s:0,1 to the .rdp file next to use multimon:i:1; the chosen monitors must be adjacent.

Credentials: saving, username formats, clearing

When you tick Remember me at the credential prompt, Windows stores the password in Credential Manager under Windows Credentials as TERMSRV/hostname. Open it with control /name Microsoft.CredentialManager, or manage entries from a terminal:

cmdkey /list
cmdkey /generic:TERMSRV/203.0.113.10 /user:Administrator /pass:YourPassword
cmdkey /delete:TERMSRV/203.0.113.10

Username format trips up many first connections. For a local account on a standalone host (every VPS), use .\Administrator or HOSTNAME\Administrator; a bare Administrator usually works too, but the leading .\ stops the client from guessing a domain. Microsoft account users sign in as MicrosoftAccount\[email protected]. If the prompt keeps returning "Your credentials did not work", check for a blank password (Windows refuses network sign-ins with one) and for a Group Policy that forbids saving credentials. To fully forget a host, delete the credential and the cached certificate hash under HKCU\Software\Microsoft\Terminal Server Client\Servers\hostname.

Common errors and quick fixes

  • "Remote Desktop can't connect to the remote computer for one of these reasons": nothing answered on the port. Run Test-NetConnection host -Port 3389 from PowerShell; if TcpTestSucceeded is False, the host is off, RDP is disabled, or a firewall is in the way. The port 3389 guide covers the listener and firewall checks; if the client hangs for a long while before failing, see the Remote Desktop timeout troubleshooting guide.
  • "An authentication error has occurred. The function requested is not supported": the CredSSP mismatch from 2018 (one side is patched and the other is not). Install Windows updates on both rather than downgrading the CredSSP policy.
  • "The remote computer requires Network Level Authentication": the client cannot satisfy NLA. Sign in with a proper account on an up-to-date Windows; do not disable NLA on the host to get around it.
  • "The number of connections to this computer is limited": a client edition of Windows allows one interactive session, and a server without RD Session Host licensing allows two administrative ones. Run query session /server:host and logoff ID /server:host to clear a stale one, or reconnect with /admin.
  • Black screen after sign-in: usually a display or bitmap-cache problem. Press Ctrl+Alt+End and cancel to force a redraw; if it recurs, untick persistent bitmap caching.
  • Session freezes on a flaky link: mstsc shows "Trying to reconnect" and retries up to 20 times; if it gives up, the session normally stays alive on the host until you reconnect.

The client keeps its own log in Event Viewer under Applications and Services Logs > Microsoft > Windows > TerminalServices-RDPClient > Operational. Event 1026 carries the disconnect reason code.

mstsc or the newer Windows App?

Microsoft's newer client, Windows App, replaced the Microsoft Remote Desktop store apps in 2024-2025, and the announcement of that retirement explicitly left Remote Desktop Connection in place. The two are not interchangeable. Windows App is built around Windows 365, Azure Virtual Desktop, Microsoft Dev Box, and RDS-published resources; on macOS, iOS, and Android it also handles direct connections to a PC, while on Windows it did not at the time of writing. Check Microsoft's documentation for the current state. For plain "connect to this IP on this port" work from a Windows machine, mstsc remains the default, scriptable, better documented tool. Use Windows App when your organisation hands you a feed URL and cloud desktops; use mstsc for everything else, including anything launched from a shortcut, script, or saved .rdp file.

Everything above assumes you have a Windows host to point the client at. If you do not, a Windows RDP server from rdp.monster is the shortest route: it is delivered about 10 seconds after payment confirms, with full administrator access on dedicated CPU and RAM, unlimited (fair-use) bandwidth, no KYC, crypto accepted at checkout, from $8.99/month. Paste the IP into mstsc /v:, save the .rdp file, and the rest of this guide applies unchanged.

Frequently Asked Questions

Does Windows 11 Home include Remote Desktop Connection?

Yes, every edition of Windows, including Home, ships the mstsc client; Home just cannot accept incoming connections.
The client and the host are separate things. Remote Desktop Connection (mstsc.exe) is present on Windows 11 Home, Pro, Enterprise, and Education alike, so a Home PC can connect to any RDP host without extra software. What Home lacks is the host service: nobody can Remote Desktop into a Home machine, and the Settings toggle to allow it simply is not there. If you need to be the host, you need Pro or higher, a Windows Server, or a Windows VPS.

How do I connect to a remote desktop on a port other than 3389?

Append the port to the address: host:port in the Computer field, or mstsc /v:host:port on the command line.
Remote Desktop Connection accepts a port suffix wherever it accepts a hostname: type 203.0.113.10:3390 in the Computer field, run mstsc /v:203.0.113.10:3390, or set full address:s:203.0.113.10:3390 in the .rdp file. The port itself is changed on the host, in the PortNumber value under HKLM\SYSTEM\CurrentControlSet\Control\Terminal Server\WinStations\RDP-Tcp, followed by a matching firewall rule and a restart. Moving the port cuts scanner noise in the logs, but it is not a security measure; NLA, strong passwords, and a VPN or IP allow-list are.

Why does Remote Desktop Connection say the identity of the remote computer cannot be verified?

The host presented a self-signed certificate, which is normal for a standalone PC or VPS; verify the thumbprint once, then accept it.
Every Windows host generates a self-signed certificate for RDP unless an administrator installs a trusted one, and your client has no way to validate it, so it warns. On a machine you control, view the certificate, compare its thumbprint with the one the host reports (Get-ChildItem "Cert:\LocalMachine\Remote Desktop" in PowerShell on the host), then tick Don't ask me again. If the warning comes back for a host you already accepted, the certificate changed. Find out why before continuing.

Can I copy files between my PC and the remote session?

Yes, the clipboard is shared by default, and redirecting a local drive on the Local Resources tab mounts it inside the session.
With Clipboard ticked on the Local Resources tab (the default), you can copy files in Explorer on one side and paste on the other (slower than a real file-transfer tool). For anything larger, click More under Local devices and resources, tick the drive, and it appears in the remote session's This PC as C on YOURPC. The .rdp equivalent is drivestoredirect:s:C:;, or * for every drive. On a host you do not fully trust, remember that anything running there can read that drive.

Adrien Roche, Infrastructure & Hosting Editor

Systems engineer with 10+ years operating Windows Server and Linux fleets. Adrien runs the rdp.monster infrastructure documentation and writes our guides on RDP, VPS hosting, server administration, networking and privacy tooling.

Register to our reseller program

Your information

If you have any question, contact us by clicking here !
Name(Required)
Enter your email address, you must have an account on manager.rdp.monster !

Your company

Enter your website address if you have one
Quickly explain how you're going to sell services to your customers. For example, talk to people on forums.

We're using cookies!

We use cookies to enhance your browsing experience, serve personalized ads or content, and analyze our traffic. By clicking "Accept", you consent to our use of cookies.