Getting started

First RDP login to Windows Server: what to do in the first hour

Contents

For an administrator who has just received access from support to a dedicated server running Windows Server 2025 or 2022. In an hour you will change the password, create accounts, install updates, restrict access to RDP, check the disks and antivirus, and plan backups.

What you need#

  • The email from support with the server address, login and password. The examples use sample values: server address 203.0.113.10, office addresses 198.51.100.25 and 198.51.100.40, new accounts admin and user1.
  • An RDP client (step 1) and a password manager.
  • A static public address for your office, or a VPN — for step 5.

Run the commands in PowerShell as administrator: right-click Start and choose “Terminal (Admin)” on Windows Server 2025 or “Windows PowerShell (Admin)” on 2022. Licensing is not covered in this article.

Step 1 Connect over RDP#

From Windows#

  1. Press Win+R, type mstsc and press Enter — the built-in Remote Desktop Connection program opens.
  2. Enter the address from the email in the “Computer” field, expand “Show Options” and enter the login. The same in one line: mstsc /v:203.0.113.10.
  3. The first connection shows a certificate warning: the certificate is self-signed, so the client cannot verify it. Check the address against the email and continue.

From macOS, iPhone, iPad and Android#

On these platforms Microsoft Remote Desktop has been replaced by Windows App: it is in the Mac App Store, the App Store and Google Play. To connect to a standalone server you don’t need to sign in to the app. Select “+”, choose “Add PC” (“PC” on iPhone, iPad and Android) and enter the server address.

Step 2 Change the administrator password#

The password has travelled by email, so treat it as temporary. In the mstsc window press Ctrl+Alt+End and choose “Change a password”. Or run this command — it asks for the new password twice and does not show it on screen:

net user "$env:USERNAME" *

The password should be long (14 characters or more) and unique; keep it in a password manager. If it is longer than 14 characters, net user asks you to confirm — type Y. Test the password straight away: without ending the session, connect once more in a new window. If the password is correct, the session simply moves to the new window.

Step 3 A separate administrator and regular users#

Keep the account from the email as an emergency one and create a named account for daily work: the logs will show who did what, and the password won’t have to be shared. Pick something less obvious than admin:

$Password = Read-Host -AsSecureString
New-LocalUser -Name "admin" -Password $Password -FullName "Server administrator"
# S-1-5-32-544 is the Administrators group
Add-LocalGroupMember -SID "S-1-5-32-544" -Member "admin"

People who work on the remote desktop, say in an accounting system, don’t need administrator rights. Give each of them a separate account and add it to the Remote Desktop Users group:

$Password = Read-Host -AsSecureString
New-LocalUser -Name "user1" -Password $Password -FullName "Accountant 1"
# S-1-5-32-555 is the Remote Desktop Users group
Add-LocalGroupMember -SID "S-1-5-32-555" -Member "user1"

Read-Host waits for the password without a prompt and does not ask you to repeat it. Groups are given by SID so the commands work in any system language. By default a local account password expires after 42 days (see net accounts), and with NLA on you cannot sign in over RDP with an expired password — change passwords in advance.

Step 4 Install updates#

Open Settings → Windows Update (on Windows Server 2022: Settings → Update & Security → Windows Update) and click “Check for updates”. On Server Core, or just from the console, run sconfig and choose option 6, “Install updates”. Repeat until no new updates are left, then restart the server with Restart-Computer: the RDP session will drop for a few minutes. This command shows the latest installed updates:

Get-HotFix | Sort-Object InstalledOn -Descending | Select-Object -First 5

Check the KB numbers against the Windows Server release table.

Step 5 The firewall and access to RDP#

First make sure the firewall is on in all three profiles, and see where RDP is allowed from (examples assume the standard port 3389):

Get-NetFirewallProfile | Select-Object Name, Enabled
Get-NetFirewallRule -Group "@FirewallAPI.dll,-28752" | Select-Object Name, Enabled, Profile, Action
Get-NetFirewallRule -Group "@FirewallAPI.dll,-28752" | Get-NetFirewallAddressFilter | Select-Object RemoteAddress

@FirewallAPI.dll,-28752 is the language-independent identifier of the “Remote Desktop” rule group.

Warning. Don’t turn on a disabled profile straight away: if the rules of this group are off, the firewall will cut RDP. First run Enable-NetFirewallRule -Group "@FirewallAPI.dll,-28752", repeat the check (the Enabled column must show True in every row) and only then run Set-NetFirewallProfile -Profile Domain,Private,Public -Enabled True. If access is lost anyway, the remote console remains — on request through support (not available on the Lite line).

If RemoteAddress is Any, the server accepts RDP connections from the whole internet, and automated scanners will start guessing passwords very soon. There are two options: hide RDP behind a VPN (WireGuard between the office and the server) or allow connections only from the office addresses. Both are covered in “Secure RDP”.

Warning. A mistake in the address will cut you off from the server. Restrict RDP by address only if your office has a static public address. First check which address the server sees your connection from, and create a task that sets the rules back to Any in 10 minutes.

# the address you are connected from right now
Get-NetTCPConnection -LocalPort 3389 -State Established | Select-Object RemoteAddress

# safety net: in 10 minutes the rules go back to Any
$action = New-ScheduledTaskAction -Execute "powershell.exe" -Argument '-NoProfile -Command "Set-NetFirewallRule -Group ''@FirewallAPI.dll,-28752'' -RemoteAddress Any"'
$trigger = New-ScheduledTaskTrigger -Once -At (Get-Date).AddMinutes(10)
Register-ScheduledTask -TaskName "rdp-rollback" -Action $action -Trigger $trigger -User "SYSTEM" -RunLevel Highest

# allow RDP only from the office addresses (example)
Set-NetFirewallRule -Group "@FirewallAPI.dll,-28752" -RemoteAddress 198.51.100.25, 198.51.100.40

Without closing the session, connect once more in a new window. If you got in, remove the safety net — otherwise the restriction disappears in 10 minutes:

Unregister-ScheduledTask -TaskName "rdp-rollback" -Confirm:$false

If the session dropped, wait 10 minutes and connect again; remove the task with the same command before retrying. To roll the change back by hand, run Set-NetFirewallRule -Group "@FirewallAPI.dll,-28752" -RemoteAddress Any.

Step 6 Check NLA#

Network Level Authentication (NLA) asks for the login and password before the server creates a session and shows the sign-in screen. A value of 1 means NLA is on:

(Get-ItemProperty "HKLM:\SYSTEM\CurrentControlSet\Control\Terminal Server\WinStations\RDP-Tcp").UserAuthentication

If it is 0, turn it on — both mstsc and Windows App support NLA:

Set-ItemProperty -Path "HKLM:\SYSTEM\CurrentControlSet\Control\Terminal Server\WinStations\RDP-Tcp" -Name "UserAuthentication" -Value 1

Step 7 Time zone#

The server is in Europe, but document dates in the accounting system, logs and the backup schedule are easier to keep in Kyiv time. FLE Standard Time is the time zone for Kyiv, with daylight saving time:

Get-TimeZone
Set-TimeZone -Id "FLE Standard Time"
Get-Date

Step 8 Inspect the disks#

How the disks on your server are arranged depends on the configuration and on how the system was installed, so first look at what Windows sees:

Get-PhysicalDisk | Select-Object FriendlyName, SerialNumber, MediaType, Size, HealthStatus, OperationalStatus
Get-Volume

The number and size of the disks should match the configuration you ordered, and HealthStatus should be Healthy. How you check a mirror depends on what it is built with:

  • Storage Spaces: Get-VirtualDisk | Select-Object FriendlyName, ResiliencySettingName, HealthStatus, OperationalStatus — expect Healthy and OK. If the command prints nothing, Storage Spaces is not in use.
  • A mirror on dynamic disks: "list volume" | diskpart — the row of type Mirror should have the status Healthy; Failed Rd means the mirror has lost one disk.
  • A hardware RAID controller: Windows sees one logical disk, and the controller’s utility shows the state of the array.

If the picture is not what you expected, write to support before moving any data. More in the article on checking RAID and disks.

Step 9 Microsoft Defender#

Microsoft Defender Antivirus is part of Windows Server 2022 and 2025. Check that it is running, update the signatures and start a quick scan:

Get-MpComputerStatus | Select-Object AMRunningMode, AntivirusEnabled, RealTimeProtectionEnabled, AntivirusSignatureLastUpdated
Update-MpSignature
Start-MpScan -ScanType QuickScan

Expect AMRunningMode: Normal, two True values and a recent signature date. If PowerShell cannot find the command, the component has been removed — bring it back with Install-WindowsFeature -Name Windows-Defender and restart the server. Don’t turn protection off to make the accounting system faster: for databases, add targeted exclusions as recommended by the software vendor.

Step 10 Plan the backups#

A mirror saves you from the failure of one disk, but not from a file deleted by mistake, ransomware or a failed update. So before any working data appears, decide what to copy, where and how often, and who will test the restore: see backing up Windows Server with built-in tools and the 3-2-1 rule. On the main lines the server comes with backup space on separate storage: the size is shown on the server card, and support will send the connection details. Copying is not automatic — you set it up yourself.

How to check the result#

What to checkCommandExpected
AdministratorsGet-LocalGroupMember -SID "S-1-5-32-544"Only those who really need it
Firewall and RDPthe first command block from step 5True in all three profiles; RemoteAddress lists the office addresses or the VPN network, not Any
NLAthe first command from step 61
Disks and antivirusGet-PhysicalDisk, Get-MpComputerStatusHealthy for every disk; real-time protection is on

Finally, close all sessions and sign in again as the new administrator, and make sure Windows Update shows no pending updates.

Common mistakes#

  • Closing the only session without testing the new password or the new firewall rule. A second connection first, then sign out.
  • Restricting RDP to an address that turned out to be dynamic: the provider changed it, and access is gone. Such offices need a VPN.
  • Turning off the firewall, NLA or Defender “for a minute” to get something working, and leaving it that way.
  • Giving every user administrator rights, or one shared account.
  • Putting off the restart after updates.
  • Treating a mirror as a backup.

What next#

A power cycle, an OS reinstall, the remote console and a disk replacement are done on request through support: phone +38 044 206 08 08, email info@united.net.ua; technical support works around the clock.