Emergency server help: get in touch

RDS Farm Windows Server 2025: Complete Deployment in 9 Steps

Build a session-based Remote Desktop Services farm on Windows Server 2025 with Server Manager or PowerShell: role placement, collections, profiles, certificates, RD Gateway, RemoteApps and a highly available Connection Broker.

Published Updated 14 min read

A complete RDS farm Windows Server 2025 deployment combines five role services (RD Connection Broker, RD Session Host, RD Web Access, RD Gateway and RD Licensing) into one managed deployment that gives users full desktops or RemoteApp programs on shared servers. This guide walks through role placement, the Server Manager wizard, the same build in PowerShell, session collections, user profiles, certificates, RemoteApp publishing and a highly available Connection Broker.

Short answer: On a domain-joined management server, open Server Manager » Manage » Add Roles and Features, choose Remote Desktop Services installation, Standard deployment and Session-based desktop deployment, then pick your Connection Broker, Web Access and Session Host servers. Add RD Licensing and RD Gateway from the deployment overview, set the licensing mode, create a session collection and install public certificates. The PowerShell equivalent is New-RDSessionDeployment, Add-RDServer and New-RDSessionCollection.

RDS role services and where to put them

Each role service has a distinct job. Small farms can combine some of them; larger farms keep them apart so each can scale or fail over on its own.

Role serviceWhat it doesTypical placement
RD Connection BrokerHolds the deployment configuration, load-balances new sessions across Session Hosts and reconnects users to their existing sessionDedicated server; two brokers plus SQL Server for high availability
RD Session HostRuns the user sessions, desktops and RemoteApp programsTwo or more servers sized for the user load
RD Web AccessIIS portal (/RDWeb) and web client that list the published desktops and appsCan share a server with RD Gateway
RD GatewayTunnels RDP over HTTPS (TCP 443, plus UDP 3391) so users can connect from the internet without exposing TCP 3389DMZ or edge server, often with RD Web Access
RD LicensingIssues RDS Client Access Licences (CALs) to users or devicesAny member server; often the broker or a management server

A common layout for an RDS farm Windows Server 2025 build for a small or mid-sized business is four servers: one broker that also holds RD Licensing, one RD Web Access and RD Gateway server, and two Session Hosts. Do not install RD Session Host on a domain controller. Keep the Session Hosts identical (same applications, same updates) because the broker treats every host in a collection as interchangeable.

Which deployment method to use

MethodResultBest forLimits
Quick Start (Server Manager)Connection Broker, RD Web Access and RD Session Host on one server, plus a default session collectionLabs and proofs of conceptNo choice of role placement; you still add Licensing and Gateway yourself
Standard deployment (Server Manager)Each role on the servers you chooseProduction farms built interactivelyManual steps are harder to repeat
PowerShell (RemoteDesktop module)Same as Standard deployment, scriptedRepeatable builds, test and production pairsNeeds the same prerequisites; errors are less descriptive than the wizard

For any production RDS farm Windows Server 2025 build, use the Standard deployment, either through the wizard or the script, so you control where each role runs.

Prerequisites

  • All servers run Windows Server 2025 (Standard or Datacenter), are joined to the same Active Directory domain and have static IP addresses.
  • A domain account that is a local administrator on every server in the farm. Run the deployment from the server that will be the Connection Broker, or from a management server that has all farm servers added in Server Manager.
  • Remote management (WinRM) enabled on every server; it is on by default in Windows Server 2025.
  • Windows Server 2025 RDS CALs. Earlier CAL versions cannot license 2025 Session Hosts, and the licence server must run Windows Server 2025 to hold 2025 CALs.
  • For internet access: a public DNS name (for example remote.contoso.com) and a trusted certificate covering it, plus a firewall rule for TCP 443 and UDP 3391 to the RD Gateway.
  • A file share for user profiles (User Profile Disks or FSLogix containers), ideally on a separate file server.

The examples below use rdcb01 (Connection Broker and RD Licensing), rdgw01 (RD Web Access and RD Gateway), and rdsh01 and rdsh02 (Session Hosts) in contoso.com.

Step 1: Add the servers to Server Manager

  1. On rdcb01, open Server Manager, choose Manage » Add Servers.
  2. On the Active Directory tab, click Find Now, select every farm server and add it to the list.
  3. Check All Servers: each server must show Online in the Manageability column. Fix WinRM or firewall issues before continuing.

Step 2: Run the Standard deployment wizard

  1. Choose Manage » Add Roles and Features.
  2. On Installation Type, select Remote Desktop Services installation.
  3. On Deployment Type, select Standard deployment.
  4. On Deployment Scenario, select Session-based desktop deployment.
  5. Review the role services page, then add rdcb01 as RD Connection Broker, rdgw01 as RD Web Access and both rdsh01 and rdsh02 as RD Session Host.
  6. On the confirmation page, tick Restart the destination server automatically if required and click Deploy.

The Session Hosts restart during installation. When the progress page shows every server as Succeeded, the core RDS farm Windows Server 2025 deployment exists, and Server Manager » Remote Desktop Services » Overview shows the deployment diagram.

Step 3: The same build with PowerShell

Scripting the RDS farm Windows Server 2025 build makes it easy to rebuild a test farm or a second site with identical settings. The RemoteDesktop module is installed with the RDS management tools. Run the commands from the Connection Broker in an elevated session:

Import-Module RemoteDesktop
$cb = "rdcb01.contoso.com"
New-RDSessionDeployment -ConnectionBroker $cb -WebAccessServer "rdgw01.contoso.com" -SessionHost @("rdsh01.contoso.com","rdsh02.contoso.com")
Add-RDServer -Server "rdcb01.contoso.com" -Role "RDS-LICENSING" -ConnectionBroker $cb
Add-RDServer -Server "rdgw01.contoso.com" -Role "RDS-GATEWAY" -ConnectionBroker $cb -GatewayExternalFqdn "remote.contoso.com"
Set-RDLicenseConfiguration -LicenseServer "rdcb01.contoso.com" -Mode PerUser -ConnectionBroker $cb -Force
Get-RDServer -ConnectionBroker $cb

Valid -Role values for Add-RDServer are RDS-RD-SERVER, RDS-CONNECTION-BROKER, RDS-WEB-ACCESS, RDS-GATEWAY, RDS-LICENSING and RDS-VIRTUALIZATION. Use RDS-RD-SERVER later to add a third Session Host to the farm.

Step 4: Add RD Licensing and set the licensing mode

If you used the wizard, add the licence server from the diagram:

  1. In Remote Desktop Services » Overview, click the + RD Licensing icon, select rdcb01 and finish the wizard.
  2. Choose Tasks » Edit Deployment Properties » RD Licensing, select Per User or Per Device to match the CALs you bought, and confirm the licence server is listed.
  3. Activate the licence server and install the CALs in Remote Desktop Licensing Manager.

Without a configured mode, Session Hosts run in a 120-day grace period and then refuse connections. Activation, CAL types and Group Policy alternatives are covered in our RDS licensing guide.

Step 5: Add RD Gateway for external access

  1. In the overview, click + RD Gateway, select rdgw01 and enter the external name remote.contoso.com as the SSL certificate name.
  2. Open Edit Deployment Properties » RD Gateway and choose Use these RD Gateway server settings. Keep Bypass RD Gateway server for local addresses ticked if internal users should connect directly, and set the logon method to Password Authentication.
  3. Tick Use RD Gateway credentials for remote computers so users sign in once.

The wizard creates a connection authorisation policy (who may connect) and a resource authorisation policy (which servers they may reach) in RD Gateway Manager. Restrict both to your RDS user group and the farm servers. The scripted equivalent of the deployment settings is:

Set-RDDeploymentGatewayConfiguration -GatewayMode Custom -GatewayExternalFqdn "remote.contoso.com" -LogonMethod Password -UseCachedCredentials $true -BypassLocal $true -ConnectionBroker "rdcb01.contoso.com" -Force

Step 6: Create the session collection

A collection is the group of Session Hosts that serves one set of users and one set of desktops or apps.

  1. Go to Remote Desktop Services » Collections » Tasks » Create Session Collection.
  2. Name it (for example Office), add rdsh01 and rdsh02, and replace Domain Users with a dedicated group such as CONTOSO\RDS-Office-Users.
  3. On Specify user profile disks, either enable them with a UNC path or leave them off if you will use FSLogix (see below).
  4. Click Create.

With PowerShell:

New-RDSessionCollection -CollectionName "Office" -SessionHost @("rdsh01.contoso.com","rdsh02.contoso.com") -CollectionDescription "Office desktop" -ConnectionBroker "rdcb01.contoso.com"
Set-RDSessionCollectionConfiguration -CollectionName "Office" -UserGroup "CONTOSO\RDS-Office-Users" -IdleSessionLimitMin 60 -DisconnectedSessionLimitMin 120 -AuthenticateUsingNLA $true -ConnectionBroker "rdcb01.contoso.com"

Collection settings worth changing

  • Session: end disconnected sessions after a few hours so abandoned sessions do not hold licences and memory (-DisconnectedSessionLimitMin), and set an idle limit (-IdleSessionLimitMin).
  • Security: keep Allow connections only from computers running Remote Desktop with Network Level Authentication enabled (-AuthenticateUsingNLA $true).
  • Load Balancing: give larger hosts a higher relative weight and a session limit.
  • Client Settings: decide which redirections (drives, clipboard, printers) the collection allows; -ClientDeviceRedirectionOptions is the scripted setting.

User Profile Disks vs FSLogix

User Profile DisksFSLogix profile containers
Where configuredCollection properties or Set-RDSessionCollectionConfiguration -EnableUserProfileDisk -DiskPath -MaxUserProfileDiskSizeGBFSLogix agent on each Session Host, settings under HKLM\SOFTWARE\FSLogix\Profiles (Enabled, VHDLocations) or the FSLogix ADMX
ScopeOne collection; each collection keeps its own disk per userAny host or collection that points at the same share
LicensingIncludedIncluded with RDS CALs and SALs
StrengthsNo extra softwareHandles Outlook and OneDrive caches and search better; Cloud Cache for resilient storage; Microsoft’s actively developed profile solution

For new farms we recommend FSLogix. Leave User Profile Disks disabled on the collection, install the FSLogix agent on every Session Host, and configure VHDLocations to point at a share such as \\fs01\Profiles$. Exclude HKLM\SOFTWARE\FSLogix and HKLM\SOFTWARE\Policies\FSLogix from antivirus scanning, as Microsoft advises.

Step 7: Install certificates

An RDS farm Windows Server 2025 deployment uses four certificate roles. Open Edit Deployment Properties » Certificates to see them:

Wizard roleSet-RDCertificate -RoleSubject name
RD Connection Broker – Enable Single Sign OnRDRedirectorBroker FQDN (or the HA DNS name)
RD Connection Broker – PublishingRDPublishingBroker FQDN (or the HA DNS name)
RD Web AccessRDWebAccessPublic name, for example remote.contoso.com
RD GatewayRDGatewayPublic name, for example remote.contoso.com

A single SAN or wildcard certificate that clients trust can cover all four. Self-signed certificates created in the wizard work for testing only; clients show warnings and the web client refuses them.

$pw = Read-Host -AsSecureString -Prompt "PFX password"
foreach ($r in "RDGateway","RDWebAccess","RDRedirector","RDPublishing") {
  Set-RDCertificate -Role $r -ImportPath "C:\Certs\remote-contoso.pfx" -Password $pw -ConnectionBroker "rdcb01.contoso.com" -Force
}

Renew these certificates before they expire and re-run the import for every role. After a broker certificate change, re-import it into the web client as shown below.

Step 8: Publish RemoteApps and enable the web client

Publish RemoteApp programs

  1. Install the application on every Session Host in the collection.
  2. Open the collection and choose RemoteApp Programs » Tasks » Publish RemoteApp Programs, tick the applications and click Publish.
  3. Open each app’s properties to limit it to a group under User Assignment, or to place it in a folder for RD Web Access.
New-RDRemoteApp -CollectionName "Office" -DisplayName "Word" -FilePath "C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE" -UserGroups "CONTOSO\RDS-Office-Users" -ConnectionBroker "rdcb01.contoso.com"
Get-RDRemoteApp -CollectionName "Office" -ConnectionBroker "rdcb01.contoso.com"

Publishing any RemoteApp hides the full desktop from RD Web Access for that collection. If users need both, create a second collection for the desktop.

Install the Remote Desktop web client

The HTML5 web client lets users open desktops and apps in a browser. On the RD Web Access server:

Install-Module -Name PowerShellGet -Force
Install-Module -Name RDWebClientManagement
Install-RDWebClientPackage
Import-RDWebClientBrokerCert "C:\Certs\rdcb01.cer"
Publish-RDWebClientPackage -Type Production -Latest

The .cer file is the public part of the Connection Broker certificate. Users browse to https://remote.contoso.com/RDWeb/webclient/index.html. The web client needs per-user CALs; it does not work with per-device licensing.

Step 9: Make the Connection Broker highly available

A single broker is a single point of failure for the whole RDS farm Windows Server 2025 deployment: if it is down, no new sessions start. For production, run two brokers against a shared SQL database.

  1. Prepare a SQL Server instance (or Azure SQL Database). Put the broker computer accounts in a security group and give that group a SQL login with the dbcreator role so the broker can create its database.
  2. Install the SQL Server Native Client or ODBC Driver for SQL Server that matches your connection string on each Connection Broker.
  3. Create DNS round-robin A records with one name, for example rdcb.contoso.com, pointing at each broker’s IP address.
  4. In the overview, right-click RD Connection Broker » Configure High Availability, choose Shared database server, and enter the DNS name and connection string.
  5. Right-click the broker again and choose Add RD Connection Broker Server to add rdcb02.
  6. Re-issue the SSO and Publishing certificates so they include the round-robin name.
Set-RDConnectionBrokerHighAvailability -ConnectionBroker "rdcb01.contoso.com" -DatabaseConnectionString "DRIVER=SQL Server Native Client 11.0;SERVER=sql01.contoso.com;Trusted_Connection=Yes;APP=Remote Desktop Services Connection Broker;DATABASE=RDCB" -ClientAccessName "rdcb.contoso.com"
Add-RDServer -Server "rdcb02.contoso.com" -Role "RDS-CONNECTION-BROKER" -ConnectionBroker "rdcb01.contoso.com"

For the rest of the RDS farm Windows Server 2025 design, add a second RD Web Access and RD Gateway behind a load balancer, add Session Hosts to the collection, and run two licence servers with CALs split between them.

Verify it works

  1. Check roles and collections from the broker:
    Get-RDServer -ConnectionBroker "rdcb01.contoso.com"
    Get-RDSessionCollection -ConnectionBroker "rdcb01.contoso.com"
    Get-RDSessionHost -CollectionName "Office" -ConnectionBroker "rdcb01.contoso.com"
    Get-RDLicenseConfiguration -ConnectionBroker "rdcb01.contoso.com"
    Get-RDDeploymentGatewayConfiguration -ConnectionBroker "rdcb01.contoso.com"
  2. From an external client, browse to https://remote.contoso.com/RDWeb, sign in and launch the desktop or a RemoteApp. There should be no certificate warning.
  3. Sign in with two test users and run Get-RDUserSession -ConnectionBroker "rdcb01.contoso.com": the sessions should be spread across both Session Hosts.
  4. Disconnect a user and reconnect: the broker must return them to the same host and session.
  5. On a Session Host, open RD Licensing Diagnoser and confirm it reports no problems.

Troubleshooting

SymptomLikely causeFix
Wizard fails with “The server is not available” or WinRM errorsServer not added to Server Manager, WinRM blocked, or account not local adminAdd all servers, run Test-WSMan against each, use an account with admin rights on every server
“Remote Desktop licensing mode is not configured” balloonMode or licence server not set in deployment propertiesSet it under RD Licensing or with Set-RDLicenseConfiguration
Certificate warning when launching appsSelf-signed or mismatched broker certificatesImport a trusted certificate for all four roles; subject must match the broker or HA name
External users cannot connect through the gatewayTCP 443 not forwarded, CAP/RAP too narrow, or external DNS wrongTest Test-NetConnection remote.contoso.com -Port 443, review policies in RD Gateway Manager
Users get temporary profilesProfile share permissions or antivirus locking VHDX filesCheck share and NTFS permissions on the profile share, add FSLogix exclusions
All users land on one Session HostHost set to not allow new connections, or unequal load-balancing weightsCheck Get-RDSessionHost (NewConnectionAllowed) and the collection’s Load Balancing page
Full desktop missing in RD Web AccessRemoteApps published in that collectionUse a separate collection for the desktop

Before you open the RDS farm Windows Server 2025 deployment to users, apply your Session Host Group Policy (usually with loopback processing), patch all hosts to the same level, and document the collection, certificate and licensing settings so a second admin can rebuild the farm from the script.

RDS farm Windows Server 2025 at a glance

RDS Farm Windows Server 2025 summary card: On a domain-joined management server, open Server Manager » Manage » Add Roles and Features, choose Remote Desktop…
In short: On a domain-joined management server, open Server Manager » Manage » Add Roles and Features, choose Remote Desktop Services installation, Standard deployment and Session-based desktop deployment, then pick your Connection Broker, Web…

Official documentation: Deploy your Remote Desktop environment, New-RDSessionDeployment, Add the RD Connection Broker server to the deployment and configure high availability.

Related guides: RDS license server activation and CALs · Enable RDS session shadowing and allow non-admin users RDP access · Group Policy loopback processing: merge vs replace for RDS hosts and kiosks.

Frequently asked questions

Can I install all RDS roles on one Windows Server 2025 server?

Yes. The Quick Start deployment puts RD Connection Broker, RD Web Access and RD Session Host on one server, and you can add RD Licensing and RD Gateway to it. It suits labs and very small offices, but production farms should separate the roles.

Should I use User Profile Disks or FSLogix on Windows Server 2025 RDS?

For new farms, use FSLogix profile containers. RDS CAL holders are entitled to FSLogix, it works across collections and it handles Outlook and OneDrive caches better than User Profile Disks.

Which RDS CALs do I need for Windows Server 2025 Session Hosts?

You need Windows Server 2025 RDS CALs installed on a Windows Server 2025 licence server. CALs for earlier versions cannot license 2025 Session Hosts.

What PowerShell cmdlet creates an RDS deployment?

New-RDSessionDeployment creates a session-based deployment with -ConnectionBroker, -SessionHost and -WebAccessServer. Add-RDServer adds Licensing, Gateway or more hosts, and New-RDSessionCollection creates the collection.

Does the Remote Desktop web client work with per-device CALs?

No. The web client requires the deployment to use per-user licensing.

Free website test

Is your website set up right?

Check SSL, security headers, redirects, robots.txt, sitemap, llms.txt and security.txt in one test. It takes about 30 seconds.