RDS  «Prev  Next»

Lesson 1

Remote Desktop Services

Remote Desktop Services (RDS) is the Windows Server role that enables multiple users to connect to and interact with a remote Windows Server environment simultaneously using the Remote Desktop Protocol (RDP). Each user receives an isolated session on the server, with access to applications, files, and network resources as though working locally. Windows Server 2025 includes a fully modernized RDS implementation that supports both traditional on-premises deployments and hybrid cloud environments via Azure Virtual Desktop.

RDS was introduced as Terminal Services with Windows NT 4.0 Terminal Server Edition and continued under that name through Windows Server 2003. Microsoft renamed the technology to Remote Desktop Services beginning with Windows Server 2008 R2 (released 2009) to reflect its expanded role beyond simple terminal access. The core architecture — a session host accepting RDP connections from remote clients — has remained consistent across all versions, while the feature set, security model, and cloud integration have evolved significantly.


How Remote Desktop Services Works in Windows Server 2025

Remote Desktop Services in Windows Server 2025 is delivered through three primary role services that work together to provide a complete remote access solution:

  • RD Session Host — the core role service that hosts Windows-based applications and full desktop sessions. Users connect to the RD Session Host and run applications that execute on the server while the display, keyboard, and mouse input are transmitted over RDP. Windows Server 2025 RD Session Host supports both pooled session collections (multiple users sharing a pool of session hosts) and personal session collections (users assigned to a dedicated session host).
  • RD Web Access — enables users to connect to RemoteApp programs and full desktop sessions through a web browser or the Remote Desktop Connection client without requiring direct network access to the RD Session Host. RD Web Access replaced the legacy Remote Desktop Web Connection and provides a modern web portal for session launching.
  • Remote Desktop Connection (RDC) client — the client software installed on user workstations that initiates RDP connections to the RD Session Host or RD Web Access gateway. The RDC client is available on Windows, macOS, iOS, Android, and Linux. RDP 10.0+ used in Windows Server 2025 supports H.264/AVC hardware encoding for improved performance, UDP transport via RDP Shortpath to reduce latency, multi-monitor support, and clipboard and device redirection.

Windows Server 2025 RDS requires Network Level Authentication (NLA) by default. NLA authenticates the user before the full RDP session is established, reducing the attack surface by preventing unauthenticated connections from reaching the session host. Kerberos is used for NLA in domain environments; NTLM is used as a fallback for workgroup or cross-domain scenarios.

RDS Licensing

Every user or device that connects to an RD Session Host requires a Remote Desktop Services Client Access License (RDS CAL) in addition to the Windows Server license. RDS CALs are available in two models: per-user CALs (the license follows the user account and allows connection from any device) and per-device CALs (the license is assigned to a specific device and allows any user to connect from that device). Windows Server 2025 also supports RDS CAL coverage through eligible Microsoft 365 subscriptions, which include RDS CAL rights for qualifying plans.


Windows Server 2025 RDS Features

Windows Server 2025 introduces several enhancements to the Remote Desktop Services role:

  • Azure Arc integration — RDS deployments can be managed through Azure Arc, enabling consistent policy application, monitoring, and governance across on-premises RDS farms and cloud-based resources from the Azure portal.
  • Enhanced GPU virtualization — Windows Server 2025 RD Session Host supports RemoteFX vGPU and DDA (Discrete Device Assignment) for graphics-intensive workloads such as CAD, video editing, and data visualization applications.
  • RDP Shortpath for Azure — when RDS is deployed in hybrid configurations with Azure Virtual Desktop, RDP Shortpath establishes a direct UDP-based transport between the client and the session host, bypassing the RD Gateway and reducing round-trip latency significantly compared to TCP-based connections.
  • Microsoft Entra ID authentication — Windows Server 2025 RDS supports Microsoft Entra ID (formerly Azure Active Directory) for single sign-on, enabling users to authenticate to RDS sessions using their cloud identity without requiring a separate on-premises AD DS credential.

Azure Virtual Desktop

Azure Virtual Desktop (AVD) is the cloud-based extension of on-premises Remote Desktop Services, hosted entirely in Microsoft Azure. AVD provides virtualized Windows desktops and RemoteApp programs from Azure infrastructure, using the same RDP client that connects to on-premises RDS. Organizations running Windows Server 2025 commonly deploy hybrid environments that combine on-premises RDS for internal users with AVD for remote, external, or contractor access — providing consistent user experience regardless of location while centralizing management in the Azure portal.

AVD supports Windows 11 multi-session, Windows Server 2025 session hosts, and FSLogix profile containers for persistent user profiles across pooled sessions. Unlike on-premises RDS, AVD does not require RDS CALs for users covered by eligible Microsoft 365 or Windows licenses, which simplifies licensing in hybrid deployments.

Certification Paths for RDS Administrators

Microsoft replaced the MCSE certification with role-based certifications aligned to modern Windows Server and Azure workloads. Administrators managing Remote Desktop Services and hybrid remote access environments should consider the following certification paths:

  • Microsoft Certified: Windows Server Hybrid Administrator Associate — covers on-premises Windows Server administration including RDS, combined with Azure Arc and Azure hybrid services. This is the most directly relevant certification for administrators deploying RDS on Windows Server 2025.
  • Microsoft Certified: Azure Virtual Desktop Specialty — covers the planning, delivery, and management of Azure Virtual Desktop environments. Appropriate for administrators extending on-premises RDS to Azure or managing AVD as the primary remote access solution.

Module Learning Objectives

In this module, you will learn about:

  1. The role and components of Remote Desktop Services in Windows Server 2025
  2. Installing and configuring the RD Session Host role service
  3. Configuring Remote Desktop Connection and RD Web Access
  4. Remote Desktop licensing — RDS CALs per user and per device
  5. Network Level Authentication and RDS security requirements

SEMrush Software 1 SEMrush Banner 1