Remote Desktop lets you sign in to a Windows 11 Pro PC from another machine and use it as if you were sitting in front of it — full desktop, your apps, your files. It’s built into Windows, so there’s nothing to install on the host. You just need to turn it on, make sure the firewall and permissions line up, and connect.
The catch most people hit isn’t enabling it — that’s one toggle. It’s the gap between “enabled” and “actually connects,” which comes down to firewall profiles, user permissions, and network reachability. This guide turns it on properly and then makes sure it works, with the security details that matter.
First: confirm you have the right edition
Remote Desktop as a host (the PC you connect to) requires Windows 11 Pro, Enterprise, or Education. Windows 11 Home can’t accept incoming connections — it can only run the client to connect out.
Check your edition under Settings → System → About → Windows specifications → Edition. If it says Home, you’ll need to upgrade to Pro before the PC can host Remote Desktop sessions.
Remote Desktop by edition
| Windows 11 Home | Client only — can connect out, can't be a host |
|---|---|
| Windows 11 Pro | Full host + client |
| Windows 11 Enterprise / Education | Full host + client |
Step 1: Turn on Remote Desktop
On the PC you want to control:
- Open Settings → System → Remote Desktop.
- Switch Remote Desktop to On.
- Confirm the prompt.
That’s the core of it. Enabling the toggle does two things automatically: it allows incoming RDP connections, and it adds the Windows Defender Firewall rule for port 3389 on your current network profile.
Click the dropdown under the toggle to see two useful options:
- Require devices to use Network Level Authentication (NLA) — leave this on.
- Remote Desktop port — shows 3389; leave it unless you have a specific reason to change it.
If you’d rather script it, enable Remote Desktop and the firewall rule from an elevated PowerShell prompt:
# Allow incoming Remote Desktop
Set-ItemProperty -Path 'HKLM:\System\CurrentControlSet\Control\Terminal Server' -Name 'fDenyTSConnections' -Value 0
# Open the firewall for Remote Desktop on all profiles where it applies
Enable-NetFirewallRule -DisplayGroup 'Remote Desktop'
Step 2: Note the PC name you’ll connect to
You connect by PC name or IP address. Find the name under Settings → System → About → Device name, or get both from a prompt:
hostname
ipconfig | findstr /i "IPv4"
On a home or office LAN, the device name usually works. Across networks you’ll typically use the IP address plus whatever VPN or gateway gets you there (covered below).
Step 3: Allow the right users
By default, members of the local Administrators group can connect over Remote Desktop. A standard user has to be added explicitly.
In Settings → System → Remote Desktop, expand Remote Desktop users and click to open the user list. Or run SystemPropertiesRemote (Win + R) and use Select Users on the Remote tab. Add the account, and Windows places it in the Remote Desktop Users group.
Permission checklist
- The account you'll sign in with has a password set (blank passwords can't use RDP)
- Standard (non-admin) users are added to Remote Desktop Users
- You know the exact username, including domain or Microsoft account form if applicable
- The account isn't currently signed in elsewhere if you need its session
Step 4: Connect from the other PC
On the machine you’re connecting from, open Remote Desktop Connection (search for it, or run mstsc).
- Enter the host’s device name or IP address.
- Click Connect.
- Enter the username and password for an account allowed on the host.
- Accept the certificate prompt the first time.
You’ll get the remote desktop in a window. From a phone or tablet, Microsoft’s Windows App (formerly Remote Desktop) does the same thing. The official how to use Remote Desktop page lists the client downloads.
Step 5: When it’s enabled but won’t connect
This is the common snag. Work through these in order:
Can't connect — check in this order
| Connection times out | Host asleep, or unreachable on the network (try ping) |
|---|---|
| Firewall blocks it | RDP rule active only on a different profile (Private vs Public) |
| 'Access denied' / can't sign in | Account not in Remote Desktop Users, or blank password |
| Works on LAN, not remotely | Need VPN or RD Gateway — see security note below |
| Name won't resolve | Use the IP address instead of the device name |
The firewall-profile mismatch trips people up a lot. The RDP rule is enabled for the network profile that was active when you flipped the toggle. If your network is set to Public, Windows tends to be stricter. Set the connection to Private for a home or work network under Settings → Network & internet → (your network) → Network profile type, then retry. Also confirm the host isn’t asleep — set Settings → System → Power → Screen and sleep so it doesn’t drop off while you’re away.
Connecting from outside your network — do it safely
Reaching the PC from another location is where security has to come first. The tempting shortcut — forwarding port 3389 on your router straight to the PC — exposes RDP directly to the internet, and that’s a well-known target for automated attacks.
Safer options:
- VPN. Connect into your network with a VPN first, then RDP to the PC’s internal address. The PC is never directly exposed.
- Remote Desktop Gateway. In business setups, an RD Gateway brokers connections over HTTPS so you don’t open 3389 at all.
- If you must forward the port, at minimum keep NLA on, use a strong unique password, limit the allowed users, and watch for failed-logon attempts.
For broader hardening of a Windows host that accepts remote connections, the principles in our Windows Server hardening checklist apply to a Pro workstation too. And if you’re remoting in to manage a PC that won’t boot properly, a Windows 11 recovery drive is a better tool for that job.
Wrapping up
Enabling Remote Desktop on Windows 11 Pro is a single toggle, and Windows handles the firewall rule for you. The work is in the details around it: confirm you’re on Pro or better, keep Network Level Authentication on, add any standard users to the Remote Desktop Users group, and make sure both machines can actually reach each other.
When it enables but won’t connect, the cause is nearly always a network profile mismatch, a sleeping host, or a permission gap — check those before anything exotic. And never expose RDP straight to the internet; a VPN or gateway in front of it is the difference between convenient and compromised.