How to Set Up Multiple RDP Sessions on Windows Server: Step-by-Step RDS Guide

Multiple RDP Setup Requires, Steps you Must Follow
🗓️ Last Updated: October 2026
⏱️ 8 Min Read
🛡️ Peer-Reviewed & Production-Tested
⚡ Quick Answer: Multiple RDP Sessions on Windows Server

By default, Windows Server permits only two concurrent administrative Remote Desktop (RDP) sessions. To support multiple RDP sessions for team members simultaneously, you must install the Remote Desktop Services (RDS) server role, specifically the Remote Desktop Session Host (RDSH) and Remote Desktop Licensing role services via Server Manager. Next, activate your RDS license server and install Client Access Licenses (CALs) (Per User or Per Device). Finally, configure Group Policy (gpedit.msc) to disable single-session restrictions by setting “Restrict Remote Desktop Services users to a single Remote Desktop Services session” to Disabled.

In modern enterprise environments, centralized server management is critical for distributed workforces, remote accounting departments, software development teams, and customer support centers. Instead of purchasing dozens of expensive physical high-end workstations, organizations deploy a powerful centralized Windows Server host where multiple remote employees can log in concurrently to run specialized line-of-business applications.

When a third user attempts to connect via Remote Desktop, Windows Server blocks the session due to three operational design constraints: For modern production environments, provisioning workloads on enterprise Windows RDP VPS server hosting solutions provides dedicated vCPU allocations, ultra-fast NVMe storage, and complete root administrative access.

  1. 1. Default Administrative Session Cap: By default, Windows Server only permits two concurrent administrative sessions intended strictly for maintenance.
  2. 2. Missing RDS Host Role Service: Multi-user concurrency requires installing the Remote Desktop Session Host (RDSH) role and licensing service.
  3. 3. Licensing Compliance Protocol: Production multi-session environments mandate configuring Remote Desktop Client Access Licenses (RD CALs).

This technical deployment manual guides systems administrators through the complete architecture of Remote Desktop Services (RDS), compares RDS licensing models (Per User vs. Per Device), provides a step-by-step role installation runbook, and outlines critical security policies to protect RDP servers against external ransomware attacks.

Understanding Remote Desktop Services (RDS) Architecture

To enable multi-user concurrent desktop hosting, Windows Server relies on a suite of modular services known collectively as Remote Desktop Services (RDS):

  • Remote Desktop Session Host (RDSH): The core engine that hosts Windows desktops and applications. It partitions user memory and process trees, ensuring that User A’s active applications (e.g., QuickBooks or Excel) remain isolated from User B’s desktop session.
  • Remote Desktop Licensing (RD Licensing): The licensing authority that manages and tracks RDS Client Access Licenses (CALs). When a user connects, the RDSH contacts the Licensing server to validate and issue a valid CAL token.
  • Remote Desktop Connection Broker (RDCB): In multi-server enterprise environments, the Connection Broker balances incoming connections across a farm of RDSH servers and reconnects disconnected users to their existing active sessions.
  • Remote Desktop Gateway (RD Gateway): An edge reverse-proxy service that encapsulates standard RDP traffic (TCP port 3389) inside secure HTTPS (TCP port 443), allowing remote users to connect securely over the internet without exposing internal RDP ports directly.

Deploying multi-user terminal environments on high-performance enterprise Windows RDP VPS server hosting solutions provides enterprise scalability with dedicated CPU cores, redundant ECC memory, and fast NVMe storage arrays.

Licensing Model Comparison: Per User vs. Per Device CALs

Microsoft requires every individual or hardware device connecting to an RDS server to possess a valid Client Access License (CAL). Choosing the right model dictates your licensing expenditure:

CAL License Type Assignment Scope Device Flexibility Active Directory Requirement Recommended Use Case
Per User CAL Assigned to a specific named user account Unlimited devices (Laptop, Home PC, Mobile) Mandatory Active Directory Domain Remote employees accessing the server from multiple locations
Per Device CAL Assigned to a specific physical hardware machine Single device; unlimited users on that machine Supported in Workgroup & Domain Shift workers sharing a single physical workstation (e.g., call centers)

For organizations managing high-density enterprise accounting software or multi-user ERP systems, provisioning dedicated bare metal compute on building specialized Windows virtualization environments with GPU passthrough ensures that intensive multi-user database operations do not suffer from shared hypervisor resource contention. For comprehensive implementation details and operational workflows, review our guide on building specialized Windows virtualization environments with GPU passthrough.

Step-by-Step Runbook: Installing Remote Desktop Services

Follow this production sequence on Windows Server 2019 or Windows Server 2022 to install and configure multi-session RDP support:

Step 1: Install RDS Roles via Server Manager

Open Server Manager, click Manage → Add Roles and Features. In the wizard, select Role-based or feature-based installation, select your local server, and scroll to Remote Desktop Services. On the Role Services screen, check:

  • Remote Desktop Session Host (RDSH)
  • Remote Desktop Licensing

Complete the wizard and restart the server when prompted. Alternatively, install these roles instantly via PowerShell as Administrator:

💻 Terminal: PowerShell RDS Role Installation powershell
# Install Remote Desktop Session Host and Licensing roles
Install-WindowsFeature -Name RDS-RD-Server, RDS-Licensing -IncludeManagementTools -Restart

Step 2: Configure Group Policy for Multi-User Sessions

Even after installing RDS, Windows enforces a policy restricting each user account to a single active session. Open the Local Group Policy Editor by pressing Win + R and typing gpedit.msc. Navigate to:

Computer Configuration → Administrative Templates → Windows Components → Remote Desktop Services → Remote Desktop Session Host → Connections

  • Restrict Remote Desktop Services users to a single Remote Desktop Services session: Double-click this policy and set it to Disabled. This permits multiple distinct logins under independent desktop sessions.
  • Limit number of connections: Double-click this policy, set it to Enabled, and specify the maximum number of concurrent connections permitted (e.g., 10 or 50).

Next, navigate to the Licensing folder directly above Connections:

  • Use the specified Remote Desktop license servers: Set to Enabled and enter localhost (or your licensing server’s IP address).
  • Set the Remote Desktop licensing mode: Set to Enabled and select either Per User or Per Device depending on your purchased CAL licenses.

Apply policy updates immediately by running gpupdate /force in an administrative command prompt.

Security Hardening: Protecting Multi-Session RDP Servers

Exposing Remote Desktop Protocol (port 3389) directly to the public internet without defense invites continuous automated credential stuffing and ransomware attacks. Apply these four enterprise security controls:

  • Enforce Network Level Authentication (NLA): NLA requires remote clients to authenticate themselves to the Windows Security Support Provider before the server creates an active desktop session, neutralizing remote denial-of-service vulnerabilities like BlueKeep.
  • Change Default RDP Port (3389): In the Windows Registry under HKLM\System\CurrentControlSet\Control\Terminal Server\WinStations\RDP-Tcp, change PortNumber to a non-standard high port (e.g., 49152-65535) and update your Windows Defender Firewall rules accordingly.
  • Implement IP Whitelisting & VPN Tunnels: Block public access to the RDP port entirely. Mandate that employees connect through a private WireGuard or IPSec VPN tunnel before accessing the RDP terminal.

Review our comprehensive guide on hardening remote administrative access against automated brute-force attacks to implement account lockout policies, multi-factor authentication (MFA), and automated intrusion detection.

Publishing RemoteApp Programs: Seamless Application Streaming

In many enterprise workflows, remote employees do not require a full Windows Server desktop interface; they only need access to a single enterprise accounting suite (e.g., Tally, SAP, or QuickBooks) or custom database client. Providing an entire desktop session wastes server RAM on explorer shell rendering and increases security attack surfaces.

With Remote Desktop Services, administrators can publish RemoteApp programs. RemoteApp packages target applications as seamless windowed utilities that launch directly on the user’s local client computer. The application window blends into the local taskbar and desktop, while all computational logic, file I/O, and database transactions execute securely on the remote server host. To strengthen overall system reliability and security, explore our technical tutorial on hardening remote administrative access against automated brute-force attacks.

Session Shadowing and Administrative Assistance

When multiple users connect to a shared RDS terminal server, technical support teams frequently need to observe or assist remote workers with application issues. RDS includes native Session Shadowing capabilities:

💻 Terminal: PowerShell Active Session Audit and Shadowing powershell
# View all active RDP user sessions and their session IDs
quser

# Shadow an active user session with control (replace SessionID with target ID)
mstsc /shadow:SessionID /control

# View active session without taking control (view-only mode)
mstsc /shadow:SessionID /noConsentPrompt

Frequently Asked Questions

How many concurrent RDP sessions does Windows Server allow by default?

Windows Server allows exactly two simultaneous administrative sessions by default. These sessions are intended exclusively for server maintenance. Expanding beyond two connections requires installing Remote Desktop Services (RDS) and licensing CALs.

What is the RDS 120-day grace period?

When you install the RD Session Host role, Microsoft grants an uninhibited 120-day licensing grace period during which unlimited users can connect without active CAL licenses. Once the 120-day window expires, all non-administrative RDP connections are blocked until valid CALs are registered.

Can two people log into the exact same user account simultaneously?

Yes, provided the Group Policy setting “Restrict Remote Desktop Services users to a single Remote Desktop Services session” is set to Disabled. However, the best practice is to assign distinct user accounts to prevent desktop file conflicts.

How much RAM should I allocate per RDP user on Windows Server?

For standard office productivity tasks (web browsing, email, Microsoft Office, lightweight accounting), allocate approximately 1GB to 2GB of RAM per concurrent user, in addition to the 4GB reserved for the base Windows Server operating system.

Can Windows 10 or Windows 11 Pro support multiple concurrent RDP users?

No. Desktop client versions of Windows (Windows 10/11) are legally and architecturally restricted to a single active user session. Attempting to log in remotely will lock the local console. Multi-user concurrent desktop hosting requires Windows Server or Azure Virtual Desktop.

🎯
Executive Summary & Final Verdict

Conclusion: High-Concurrency Multi-User RDP Deployment

Best Practices

Setting up multiple concurrent Remote Desktop sessions transforms a standard Windows Server instance into an enterprise remote working hub. By deploying Remote Desktop Services (RDS), activating Per-User CAL licensing, and configuring session limits, organizations enable secure remote workforce productivity.

⚡ Network Level Authentication (NLA)
Always enforce NLA and transition default RDP port 3389 to a non-standard high port to mitigate automated brute-force attacks.
🛡️ Session Timeouts
Configure Active Directory group policies to disconnect idle sessions after 30 minutes, freeing up server memory and CPU threads for active staff.
Deploy your remote workforce workstation on high-performance Windows RDP servers with guaranteed RAM and low-latency global network connections on our Windows VPS hosting. Enterprise 24/7 Hosting Support ✓
Naveen Rajput
✓ Verified Technical Author 16+ Years Experience in Enterprise Server Infrastructure & Bare-Metal Systems

Naveen Rajput (CEO & Infrastructure Architect)

Naveen Rajput is the CEO and Director of Onlive Server Private Limited. With over 16 years of hands-on expertise across global datacenters, high-throughput hypervisors, and disaster-recovery architectures, he provides production-tested server engineering insights to enterprise CTOs and system administrators worldwide.