Remote Desktop creates a network-accessible way to sign in to the host PC, so use it only on a trusted network, keep Network Level Authentication enabled, and grant access to as few accounts as possible. Do not expose a personal PC directly to the internet by forwarding the standard RDP port on a home router. For access from outside the local network, use an organization-approved VPN or managed remote-access solution.
Check the PC edition, account, and network first
Before enabling anything, confirm that the computer you want to control remotely meets these requirements:
- The remote PC—the PC you will connect to—runs Windows 11 or Windows 10 Pro, Enterprise, or Education.
- You are signed in to the remote PC with an account that has local administrator rights.
- The remote PC is powered on, connected to the network, and configured not to sleep while you expect to reach it.
- You have credentials for an account that is permitted to sign in to the remote PC.
- The computer you will connect from can run any Windows edition, including Home.
- For the initial test, both computers should be on the same trusted local network.
To check the edition on the remote PC:
- Open Start > Settings.
- Select System > About.
- Under Windows specifications, check Edition.
- Continue only if the remote PC shows Pro, Enterprise, or Education.
If the PC shows Windows Home, the Remote Desktop host controls will not be available. Upgrading the edition is required to use Microsoft’s built-in Remote Desktop host feature; installing a Remote Desktop client does not change that limitation.
Security warning: Do not enable Remote Desktop on a shared PC unless you know which accounts can sign in and have verified that each permitted account uses a strong, unique password. Anyone with an allowed account can access the PC’s applications, files, and network resources with that account’s permissions.
Enable Remote Desktop through System Properties
System Properties is still a useful direct route to the Remote Desktop host settings in both Windows 10 and Windows 11.
- On the remote PC, save any work that could be affected by a remote sign-in or session change.
- Press Windows key + R to open the Run dialog.
- Type the following command and select OK:
sysdm.cpl - In the System Properties window, select the Remote tab.
- Under Remote Desktop, select:
Allow remote connections to this computer - Leave the following security option selected:
Allow connections only from computers running Remote Desktop with Network Level Authentication (recommended)
Network Level Authentication, often shortened to NLA, requires the connecting user to authenticate before Windows creates a full Remote Desktop session. This reduces exposure to unauthenticated connection attempts. - Select Apply, then select OK.
The computer is now configured to accept Remote Desktop connections, subject to the firewall, network, account-permission, and organizational-policy checks later in this guide.
A restart is not normally needed just to enable Remote Desktop. Leave the remote PC powered on and signed in or at its sign-in screen so you can test the connection from the other computer.
Enable Remote Desktop through Windows Settings instead
Windows Settings provides the same core configuration and is especially convenient for finding the PC name and managing Remote Desktop users.
Windows 11
- Open Start > Settings.
- Select System.
- Select Remote Desktop.
- Turn Remote Desktop to On.
- Select Confirm when Windows asks whether you want to enable Remote Desktop.
- Keep the Network Level Authentication requirement enabled if the option is shown.
Windows 10
- Open Start > Settings.
- Select System.
- Select Remote Desktop.
- Turn on Enable Remote Desktop.
- Select Confirm.
- Keep the Network Level Authentication option enabled.
The System Properties and Settings methods change the same underlying Remote Desktop availability setting. You only need to use one method to turn it on. Use System Properties when you specifically need the classic Remote tab, or Settings when you want the modern interface and the readily visible PC name.
Add only the users who should be allowed to connect
Members of the local Administrators group can connect remotely by default once Remote Desktop is enabled. Standard users and other non-administrator accounts must be explicitly permitted.
Do not add an account merely because it is convenient. Add only the person or service account that genuinely needs remote access.
Add users from System Properties
- On the remote PC, press Windows key + R.
- Type:
sysdm.cpl - Select the Remote tab.
- Under Remote Desktop, select Select Users.
- In the Remote Desktop Users window, select Add.
- Enter the name of the local, domain, or work account that should be allowed to connect.
- Select Check Names if it is available, and confirm that Windows resolves the account correctly.
- Select OK to add the account.
- Select OK again to close the user list.
- Select Apply and OK in System Properties.
Add users from Windows Settings
- Open Settings > System > Remote Desktop.
- Select Remote Desktop users. On some builds, this can appear as Select users that can remotely access this PC.
- Select Add.
- Enter the account name.
- Select OK to add it.
Use the same account name later when you sign in from the other computer. If the account is not recognized, verify that it exists on the remote PC or that the remote PC can contact the organization’s domain or identity service.
Security warning: Do not disable Network Level Authentication simply to make an old client connect. First update the client computer or use a supported Remote Desktop client. Disabling NLA weakens the connection process and should be a short-term exception only where an administrator has established that it is necessary.
Find the remote PC name and keep it available
The remote PC name is the simplest identifier to use when both devices are on a network that can resolve computer names.
On the remote PC:
- Open Settings > System > Remote Desktop.
- Find the PC name displayed on the page.
- Record it exactly.
You can also find the device name through:
- Open Settings > System > About.
- Under Device specifications, find Device name.
For a same-network test, the PC name may work immediately. On some home networks, name resolution is incomplete or inconsistent. If the connection cannot find the PC by name, obtain its current local IP address instead:
- On the remote PC, open Start.
- Type Command Prompt and open it.
- Run:
ipconfig - Look for the IPv4 Address of the active Ethernet or Wi-Fi adapter.
A local IP address can change after a router restart or DHCP lease renewal, so use it as a troubleshooting test rather than treating it as a permanent identifier unless your network administrator has assigned the PC a stable address.
Confirm Windows Firewall allows Remote Desktop
Enabling Remote Desktop normally configures the related Windows firewall access. Still, verify it before troubleshooting the connection itself—especially if the PC has security software, custom firewall rules, or organization-managed settings.
- On the remote PC, open Start and type Windows Defender Firewall.
- Open Windows Defender Firewall.
- Select Allow an app or feature through Windows Defender Firewall.
- Select Change settings. Approve the administrator prompt if Windows displays one.
- Find Remote Desktop in the list of allowed apps and features.
- Confirm it is selected for the network profile you intend to use.
For a typical home or office LAN, the connection should be allowed on the appropriate Private or Domain profile. Avoid broadly allowing Remote Desktop on Public networks unless an administrator has designed and approved that configuration.
If the Remote Desktop entry is unavailable, blocked, or cannot be changed, do not turn off the firewall as a workaround. The firewall may be controlled by security software, a local policy, or an organization’s device-management policy. Escalate to the person responsible for the PC or network.
Test a connection from another Windows computer
Perform the first test from another Windows PC on the same local network. This separates local configuration problems from VPN, router, DNS, and internet-access issues.
- Confirm the remote PC is on, connected to the network, and not asleep or hibernating.
- On the client PC—the computer you are connecting from—open Start.
- Type Remote Desktop Connection and open the app.
You can also press Windows key + R, type the following command, and select OK:
mstsc - In the Computer field, enter the remote PC name you recorded earlier.
- Select Connect.
- If Windows cannot find the PC name, return to the remote PC, run
ipconfig, and retry using its current IPv4 address. - When prompted, enter the credentials for an account that is either:
- A local administrator on the remote PC, or
- Listed in Remote Desktop Users.
- Review the identity prompt. If you recognize the remote PC and are connecting to the expected device, continue.
- After sign-in, confirm that you can see the remote Windows desktop and open a harmless item such as File Explorer.
A successful sign-in verifies all of the basic requirements: Remote Desktop is enabled, the PC is reachable, the firewall permits the connection, and the account has permission to connect.
Troubleshoot common Remote Desktop setup problems
The Remote Desktop option is missing
The remote PC is likely running Windows Home. Windows Home can act as a Remote Desktop client, but not as a Remote Desktop host. Check Settings > System > About and confirm the Windows edition.
The client says it cannot find the remote PC
Check the PC name for spelling and try the current local IPv4 address from ipconfig.
If the IP address works but the PC name does not, Remote Desktop itself is functioning; the issue is name resolution on the local network. Continue using the address for the immediate test, then correct DNS, router, or local network naming if a stable name is required.
The remote PC is on, but connection attempts time out
Check these items on the remote PC:
- Remote Desktop remains enabled in Settings > System > Remote Desktop.
- System Properties > Remote still shows Allow remote connections to this computer.
- Windows Defender Firewall allows Remote Desktop for the applicable network profile.
- The network connection is marked appropriately for your environment. A public-network firewall profile can be more restrictive.
- Third-party endpoint security or an organization-managed firewall is not blocking the connection.
- The PC is not asleep or hibernating.
Do not disable Windows Firewall globally for testing. Instead, check or restore the specific Remote Desktop allowance.
You can reach the sign-in screen but the credentials are rejected
Verify that you are using an account that is allowed to connect. Administrators can connect by default; other accounts must appear in the Remote Desktop Users list.
Also confirm that you are entering credentials for the remote PC, not credentials for the client PC. In business environments, use the account format required by your organization. Microsoft Entra-joined devices can require a work-account sign-in format and may be governed by Conditional Access policies.
A legacy client reports that Network Level Authentication is required
Use a current Remote Desktop Connection client or supported Windows device. Keep Network Level Authentication enabled whenever possible. If an administrator determines that a specific older client must be used temporarily, document the exception and restore the NLA requirement immediately after the compatibility issue is resolved.
Remove access or turn Remote Desktop off
If you no longer need remote access, remove it rather than leaving an unnecessary service available.
To remove one user:
- Open System Properties by running
sysdm.cpl. - Select Remote > Select Users.
- Select the account you no longer want to permit.
- Select Remove, then select OK.
- Select Apply and OK.
To disable Remote Desktop completely:
- Open Settings > System > Remote Desktop.
- Turn Remote Desktop to Off.
- Confirm the change.
You can also open sysdm.cpl, select the Remote tab, choose Don’t allow remote connections to this computer, then select Apply and OK. This stops incoming Remote Desktop access while leaving the PC available for normal local use.