Common causes
- Remote Desktop is turned off on the host PC, so nothing is listening for incoming connections, which is the most common reason for this exact message.
- The host runs Windows 10 or 11 Home, which can connect out with Remote Desktop Connection but cannot accept incoming Remote Desktop sessions.
- The host PC is asleep, hibernating, or shut down, and a Remote Desktop connection attempt cannot wake it on its own.
- You are using the wrong PC name or an outdated IP address, often because the router handed the host a new address after a restart.
- The host's network is set to Public, or the Remote Desktop rule in Windows Defender Firewall is not allowed for the active network profile.
- A third-party firewall, security suite, or VPN on either computer is blocking or rerouting traffic to TCP port 3389.
- The Remote Desktop Services (TermService) service has stopped on the host, or someone changed the listening port from the default 3389.
- Your account is not allowed to connect, or you are signing in with a PIN or short name instead of the full Microsoft account email and password.
Advertisement
Step-by-step fixes
Step 1
Check the host's Windows edition and keep it awake
On the PC you want to connect to, open Settings > System > About and check Edition under Windows specifications. Hosting Remote Desktop requires Windows 10 or 11 Pro, Enterprise, or Education. If it says Home, the PC cannot accept Remote Desktop connections at all; you can buy an upgrade through Settings > System > Activation (Update & Security > Activation on Windows 10), or use a third-party tool instead. Next, make sure the host is not going to sleep. In Windows 11, go to Settings > System > Power & battery (Power on some desktops) and set the plugged-in sleep timer under Screen and sleep to Never; newer builds label this section Screen, sleep, & hibernate timeouts. In Windows 10, use Settings > System > Power & sleep. Success means a supported edition and a host that stays awake.
Step 2
Turn on Remote Desktop and use the correct PC name or IP
On the host, open Settings > System > Remote Desktop, switch Remote Desktop to On, and confirm the prompt. Note the PC name, shown as Device name under Settings > System > About. You can also press Windows + R, type SystemPropertiesRemote, and select Allow remote connections to this computer on the Remote tab. Turning Remote Desktop on this way normally enables the matching firewall rule too. Because names do not always resolve on home networks, note the host's IP address as well: open Command Prompt, run ipconfig, and copy the IPv4 Address of the active adapter, such as 192.168.1.25. On the other PC, press Windows + R, type mstsc, and enter the name or IP address. If the IP works but the name does not, keep using the IP and reserve it in your router's DHCP settings so it does not change.
Step 3
Set the host's network profile to Private
Windows treats Public networks as untrusted and blocks more incoming traffic on them, which can stop Remote Desktop even when it is turned on. On the host in Windows 11, open Settings > Network & internet, select Wi-Fi and then your network's properties, or select Ethernet, and set Network profile type to Private network. In Windows 10, go to Settings > Network & Internet, choose Wi-Fi or Ethernet, click the connected network, and select Private. Only do this on a network you trust, such as your home or office; keep public Wi-Fi in cafes and hotels set to Public. After changing the profile, try connecting again. Success looks like the connection reaching the sign-in prompt instead of failing straight away.
Advertisement
Step 4
Allow Remote Desktop through Windows Defender Firewall
On the host, open Control Panel > System and Security > Windows Defender Firewall and select Allow an app or feature through Windows Defender Firewall. Click Change settings, find Remote Desktop in the list, tick its checkbox, and make sure the Private column is ticked. On a work PC joined to a domain, Domain should be ticked too. Avoid enabling it for Public unless you have a specific reason. Click OK and retry the connection. If you use a third-party security suite with its own firewall, open its firewall settings and allow Remote Desktop or inbound TCP port 3389 on your trusted network, or check its logs for blocked connections. Success means Remote Desktop is ticked for your active profile and nothing is blocked in your security software.
Step 5
Test port 3389 and check the Remote Desktop service
From the PC you are connecting from, open PowerShell and run Test-NetConnection -ComputerName 192.168.1.25 -Port 3389, using the host's name or IP. If TcpTestSucceeded shows True, the network path is fine and the problem is sign-in, so move to the next step. If it shows False, check the host. Press Windows + R, type services.msc, and find Remote Desktop Services. Its status should be Running and its startup type should not be Disabled; if it is stopped, right-click it and choose Start. Then run netstat -an | findstr 3389 in Command Prompt on the host; a line ending in LISTENING confirms Remote Desktop is waiting. If nothing appears, the port may have been changed. Check it without editing anything by running Get-ItemProperty -Path "HKLM:\SYSTEM\CurrentControlSet\Control\Terminal Server\WinStations\RDP-Tcp" -Name PortNumber in PowerShell, then add that port to the address in mstsc, such as 192.168.1.25:3390.
Step 6
Allow your account and sign in with the right credentials
Administrator accounts on the host can connect by default, but standard accounts must be added. On the host, go to Settings > System > Remote Desktop and select Remote Desktop users (Select users that can remotely access this PC on Windows 10), click Add, and enter the account name. Alternatively, run net localgroup "Remote Desktop Users" USERNAME /add in an elevated Command Prompt, replacing USERNAME with the local account name. When you connect, use the host's credentials, not your own PC's. For a Microsoft account, enter the full email address and the account password, not your Windows Hello PIN. If you have only ever signed in to the host with a PIN, sign in there once with the password. For a local account, enter PCNAME\username. On Windows 11, if password sign-in keeps failing, check Settings > Accounts > Sign-in options and turn off the option to only allow Windows Hello sign-in for Microsoft accounts.
Step 7
Check Network Level Authentication and pending updates
Network Level Authentication (NLA) makes you sign in before a full session starts, which protects the host and should normally stay on. If the connection fails with an authentication or NLA-related error, first install all pending updates on both PCs from Settings > Windows Update (Update & Security > Windows Update on Windows 10), since mismatched security updates can break the sign-in handshake. If it still fails, test briefly without NLA on a trusted network only: press Windows + R on the host, type SystemPropertiesRemote, and clear Allow connections only from computers running Remote Desktop with Network Level Authentication. If you can now connect, the problem is the account's credentials rather than the network, so fix the sign-in issue from the previous step and turn NLA back on straight away.
Step 8
Connect from outside your network through a VPN, not an open port
Remote Desktop is designed for local networks. If it works at home but not when you are away, that is expected, and the fix is not forwarding port 3389 on your router. Internet-facing Remote Desktop is constantly scanned and hit with automated password guessing, and it is a well-known entry point for ransomware. Instead, set up a VPN into your home or office network: many routers include a built-in VPN server, and mesh VPN services such as Tailscale can link your devices without port forwarding. Connect to the VPN first, then open mstsc and use the host's local IP address. Businesses should use their company VPN or a Remote Desktop Gateway. If running a VPN is more than you want to manage, a remote access app that connects through its own servers is the simpler route.
How to prevent it
- Reserve a fixed local IP address for the host in your router's DHCP settings so the address you connect to never changes.
- Keep the host's sleep timer set to Never while plugged in, or set up Wake-on-LAN if your hardware and router support it.
- Leave Network Level Authentication on and use a strong, unique password for every account allowed to connect.
- Never forward port 3389 to the internet; use a VPN or a Remote Desktop Gateway for outside access.
- Install Windows updates on both PCs regularly so security changes do not break the connection.
- Set only trusted networks to the Private profile.
Tools that can help
If the host runs Windows Pro on your own network, the built-in steps above usually solve the problem without extra software. If the host runs Windows Home, or you need dependable access from anywhere without setting up a VPN, a remote access app that connects through its own servers is often the easier choice.
Best for business
Splashtop
Good fit for stable remote access, support, and multi-device access in professional setups.
Visit SplashtopBest free option
Chrome Remote Desktop
Google's free remote access tool lets you reach your own computers from a browser or phone and offer one-time support with an access code. It needs a Google account and has no paid tier.
Visit Chrome Remote DesktopFast support sessions
AnyDesk
Useful for users who need low-friction remote access and a faster alternative to heavier remote tools.
Visit AnyDeskTechyLeakz may earn a commission if you buy through these links, at no extra cost to you. Affiliate disclosure
What to do next if this fails
- Move to the next fix instead of repeating the same step multiple times.
- Check the related guides in this cluster before attempting a full reset.
- If startup, update, and corruption symptoms overlap, widen the diagnosis instead of treating one error in isolation.
Advertisement
FAQ
Why does Remote Desktop say it can't connect when the PC is on?
Being switched on is not enough. The host must also have Remote Desktop turned on, run a Pro, Enterprise, or Education edition, be awake rather than sleeping, and accept traffic on port 3389 through its firewall and network profile. Run Test-NetConnection against port 3389 from the other PC; if it fails, the block is on the host or the network, not your credentials.
Can Windows 11 Home use Remote Desktop?
Windows 11 Home can use Remote Desktop Connection to connect to another PC, but it cannot be controlled through Remote Desktop, because hosting is limited to Pro, Enterprise, and Education. To reach a Home PC remotely, upgrade it to Pro through Settings > System > Activation, or use a free third-party tool such as Chrome Remote Desktop, or AnyDesk for personal use.
What port does Remote Desktop use?
Remote Desktop listens on TCP port 3389 by default and can also use UDP port 3389 to improve performance. If someone changed the port on the host, add it to the address when connecting, such as 192.168.1.25:3390, and make sure the firewall allows the custom port. Changing the port is not a security measure on its own and is no substitute for a VPN.
Is it safe to open port 3389 on my router?
No. Forwarding port 3389 exposes the host directly to the internet, where automated tools constantly scan for Remote Desktop and try common passwords, and exposed Remote Desktop has been a common way into ransomware attacks. Use a VPN into your network, a Remote Desktop Gateway for business setups, or a remote access app that brokers connections through its own servers instead.
Why does Remote Desktop say my credentials did not work?
That message means the network connection worked but sign-in failed. Use an account that exists on the host, not on your own PC. For a Microsoft account, type the full email address and password rather than your PIN, and sign in to the host with the password at least once. For a local account, use PCNAME\username. Also confirm the account is listed under Remote Desktop users.
Can I use Remote Desktop from a Mac or phone?
Yes. Microsoft offers free Remote Desktop client apps for macOS, iPhone, iPad, and Android, and on Apple devices the app is now called Windows App. The host still needs a Pro, Enterprise, or Education edition with Remote Desktop turned on, and the same network rules apply, so connect over your local network or through a VPN when you are away from home.