All articles
Guides

How to connect to a Windows VPS via RDP: Windows, macOS, phone

In short

You connect to a Windows VPS over RDP on port 3389: on Windows with the built-in Remote Desktop Connection (mstsc), on macOS, iPhone and Android with Microsoft's Windows App. You need the server IP, the login (Administrator on Windows Server) and the password; after logging in, set a strong password and limit RDP to your own IP in Windows Firewall.

Key takeaways
  • You connect to a Windows VPS over RDP (port 3389/TCP): on Windows 10/11 with the built-in mstsc (Remote Desktop Connection), on macOS, iPhone and Android with Microsoft's Windows App.
  • An RDP connection needs three values: the server IP address, the login and the password; on Windows Server the built-in administrator account is called Administrator.
  • Files and the clipboard travel through the RDP session: in mstsc go to Show Options → Local Resources and enable the clipboard and the local drives you need.
  • Bots constantly brute-force RDP port 3389, so a Windows VPS needs a long unique password, a Windows Firewall rule for your IP only and regular updates.
  • For a Tihost VPS, the IP address, login and password of a Windows server are shown in the tihost.io panel and the @tihost_bot bot, and if RDP does not respond the server is reachable through the browser VNC console.

Step 1. Get the IP address, login and password

Your hosting provider gives you the login details. At Tihost, the IP address, login and password of a Windows server are shown in the panel under «My Servers» and in the Telegram bot @tihost_bot; on Windows Server the login is Administrator. You can replace the password with the «Change Password» button - the server gets the new password and the panel shows exactly that one.

Step 2. Connect from Windows with mstsc

  1. Press Win+R, type mstsc and press Enter - Remote Desktop Connection opens.
  2. Enter the server IP in the Computer field. If RDP was moved off port 3389, add the port after a colon: IP:port.
  3. Click Show Options and enter the login from the panel in the User name field, for example Administrator.
  4. Click Connect, enter the password and accept the certificate warning.

A certificate warning on the first login is normal: by default Windows Server protects RDP with a self-signed certificate your computer does not trust yet. Tick "Don't ask me again for connections to this computer" and the prompt goes away. You can save the connection settings to an .rdp file with Save As.

Step 3. Connect from macOS, iPhone or Android with Windows App

  1. Install Windows App by Microsoft from the App Store or Google Play - it is the new name of Microsoft Remote Desktop. If your platform's store still only lists Remote Desktop, that works too.
  2. Tap "+" and choose Add PC.
  3. Enter the server IP address in PC name and add an account under Credentials: the login from the panel and the password.
  4. Save and open the connection, and click Continue at the certificate prompt.

On a phone the server is easier to use in landscape: the screen is resized for the device and a tap works as a mouse click. For longer sessions, connect a keyboard to your tablet.

Step 4. Move files and the clipboard

RDP can pass the clipboard and local drives into the session, so files copy with plain Copy and Paste or through the server's File Explorer, without FTP or cloud folders.

  • mstsc: Show Options → Local Resources - tick Clipboard, then click More and pick the drives. Inside the server they appear in File Explorer as "C on YOUR-PC".
  • Windows App: open the connection settings (Edit PC) - the clipboard is enabled in the devices section, and a Mac folder is shared in the Folders section.
  • Large files copy more reliably through a redirected drive: a clipboard paste is cut off together with the session.

Step 5. Set a long unique password

Bots start brute-forcing an internet-facing port 3389 almost immediately, so the administrator password must be long (16+ characters) and used nowhere else. The easiest way is the «Change Password» button in the panel or bot. If you change it inside Windows (in an RDP session, Ctrl+Alt+End → Change a password), write it down: the panel does not learn about that change and keeps showing the old password.

Step 6. Allow RDP only from your IP

The strongest RDP protection is letting only known addresses reach port 3389. In Windows Firewall this is set on the Remote Desktop rules:

  1. Open wf.msc (Win+R) → Inbound Rules.
  2. Find the Remote Desktop - User Mode (TCP-In and UDP-In) rules.
  3. In each rule's properties, on the Scope tab under Remote IP address, choose These IP addresses and add your address.

The same with one PowerShell command run as administrator (the address is an example, use your own; on a Russian-language Windows the group is called «Удаленный рабочий стол»):

PowerShell
Set-NetFirewallRule -DisplayGroup "Remote Desktop" -RemoteAddress 198.51.100.7
Get-NetFirewallRule -DisplayGroup "Remote Desktop" | Get-NetFirewallAddressFilter

Step 7. Keep Windows updated

RDP vulnerabilities are closed by updates, so do not postpone them: open Windows Update in Settings and click Check for updates. After installing, the server reboots and the RDP session drops - reconnect in a couple of minutes.

What if RDP does not connect?

First check whether the connection reaches port 3389. In PowerShell on your own computer:

PowerShell
Test-NetConnection SERVER_IP -Port 3389
  • TcpTestSucceeded : True but login fails - the login or password is wrong: compare them with the panel or set a new password.
  • TcpTestSucceeded : False - the port is closed: the server is still booting after the order or a reboot, a firewall rule blocks your IP, or Remote Desktop is turned off.
  • In every case «Console (VNC)» on the server page in the panel helps: log in and check Settings → System → Remote Desktop and the wf.msc rules.

Still choosing an OS? See Linux vs Windows on a VPS, and how much memory Windows Server needs in how much RAM a VPS needs.

Launch a server in 2 minutes

AMD Ryzen 9, NVMe and DDoS protection in Germany, Finland and Poland. Pay with crypto or card.

Order a Server

FAQ

What is the login for a Windows VPS?

On Windows Server the built-in administrator account is called Administrator. For a Tihost VPS, the login and password are shown in the tihost.io panel and the @tihost_bot bot next to the IP address.

Which port does RDP use?

RDP uses port 3389 by default (TCP, plus UDP for better performance). If the port was changed, mstsc and Windows App take it after a colon: IP:port.

How do I connect to a Windows server from a Mac?

Install Microsoft's free Windows App (formerly Microsoft Remote Desktop) from the App Store, click "+" → Add PC and enter the server IP address, login and password.

Can I connect to a Windows VPS from my phone?

Yes: Microsoft's Windows App is available for iPhone and iPad, and on Android use Windows App or the older Remote Desktop client. The connection is set up the same way as on a computer - IP address, login and password.

Should I change the RDP port 3389?

Changing the RDP port only reduces random login attempts and is not real protection. It is more reliable to allow port 3389 only from your IP in Windows Firewall and set a long password.

What if I locked myself out of RDP with the firewall?

Open «Console (VNC)» on the server page in the Tihost panel: it is the server's screen in the browser and needs neither RDP nor networking. Log in and fix the rule in wf.msc.