Emergency server help: get in touch

RDS Licensing Server: Activate, Install CALs and Set the Mode in 6 Steps

Install and activate an RD Licensing server, install per-user or per-device RDS CALs, point Session Hosts at it through deployment properties, Group Policy or WMI, and clear the "licensing mode is not configured" warning before the 120-day grace period ends.

Published Updated 13 min read

An RDS licensing server issues Remote Desktop Services Client Access Licences (RDS CALs) to the users or devices that connect to your Session Hosts, and without one every Session Host stops accepting connections when its 120-day grace period ends. This guide installs and activates the RD Licensing role on Windows Server 2025, installs CALs, sets the licensing mode and licence server on the Session Hosts by three methods, and fixes the most common licensing errors.

Short answer: Install the Remote Desktop Licensing role service, open Remote Desktop Licensing Manager, right-click the server and choose Activate Server (Automatic connection), then Install Licenses with your agreement number or licence code. On the RD Connection Broker, set Edit Deployment Properties » RD Licensing to Per User or Per Device and add the server. Without a broker, use the Group Policy settings “Use the specified Remote Desktop license servers” and “Set the Remote Desktop licensing mode”.

How RDS licensing works

A Session Host contacts its configured RDS licensing server every time a client connects. The licence server either issues a CAL (per device) or records the user (per user). Two rules decide whether licensing works at all:

  • CAL version: CALs must be the same version as the Session Host or newer. Windows Server 2025 Session Hosts accept only 2025 CALs; a 2025 CAL also licenses 2016, 2019 and 2022 Session Hosts.
  • Licence server version: the RDS licensing server must run the same Windows Server version as the CALs or a later one. To install 2025 CALs, the licence server must run Windows Server 2025.

Per user vs per device

Per User CALPer Device CAL
LicensesOne named user on any number of devicesOne device used by any number of users
EnforcementTracked but not enforced; you must stay compliant yourselfEnforced: temporary CAL (valid 90 days) on first connection, permanent CAL on a later connection
Where trackedUser object in Active Directory; licence server must be in the Terminal Server License Servers groupLicence server database
Workgroup Session HostsNot supportedSupported
Remote Desktop web clientSupportedNot supported
Best forStaff who connect from laptops, home PCs and phonesShared PCs and shift workers on thin clients

The licensing mode on the Session Hosts must match the CAL type you installed. A per-user Session Host cannot use per-device CALs, and the reverse also fails.

Which configuration method to use

MethodUse it whenStored inNotes
Deployment properties (Server Manager)You have an RD Connection Broker deploymentHKLM\SYSTEM\CurrentControlSet\Control\Terminal Server\RCM\Licensing Core and ...\TermService\Parameters\LicenseServersApplies to every Session Host in the deployment
Group PolicyStandalone Session Hosts without a broker, or to enforce settings centrallyHKLM\SOFTWARE\Policies\Microsoft\Windows NT\Terminal ServicesOverrides the deployment settings
PowerShell (Set-RDLicenseConfiguration)Scripted broker deploymentsSame as deployment propertiesNeeds the RemoteDesktop module
WMI (Win32_TerminalServiceSetting)One standalone host, or workgroup serversSame as deployment propertiesNo GPO needed

Prerequisites

  • A domain member server running Windows Server 2025 for the RDS licensing server. It can share a server with the Connection Broker; it does not need to be a domain controller.
  • Your RDS CAL purchase details: licence code, or agreement number for Enterprise Agreement, Open and similar programmes.
  • Outbound HTTPS (TCP 443) from the licence server to the Microsoft Clearinghouse for automatic activation. Otherwise use the web browser or telephone method.
  • Domain Admin rights once, to add the licence server to the Terminal Server License Servers group.
  • Network access from each Session Host to the licence server: TCP 135 plus the dynamic RPC range (TCP 49152-65535) and TCP 445. Per-user tracking also needs LDAP (389) to domain controllers.

Step 1: Install the RD Licensing role service

In a broker deployment

Open Server Manager » Remote Desktop Services » Overview, click the + RD Licensing icon, select the server and finish the wizard. Or from the broker:

Add-RDServer -Server "rdlic01.contoso.com" -Role "RDS-LICENSING" -ConnectionBroker "rdcb01.contoso.com"

On a standalone server

Use Add Roles and Features » Role-based or feature-based installation » Remote Desktop Services » Remote Desktop Licensing, or:

Install-WindowsFeature -Name RDS-Licensing -IncludeManagementTools
Get-WindowsFeature RDS-Licensing, RDS-Licensing-UI

The management tools add Remote Desktop Licensing Manager (licmgr.exe) and RD Licensing Diagnoser (lsdiag.msc). Both are under Server Manager » Tools » Remote Desktop Services.

Step 2: Activate the RDS licensing server

An RDS licensing server must be activated before it can hold permanent CALs. Activation gives it a digital certificate from the Microsoft Clearinghouse.

  1. Open Remote Desktop Licensing Manager. The server shows Not activated.
  2. Right-click the server and choose Activate Server, then click Next.
  3. Choose a Connection method:
    • Automatic connection (recommended): the server contacts the Clearinghouse directly over TCP 443.
    • Web Browser: copy the product ID, complete the form on the Remote Desktop Licensing website from any internet-connected PC, and paste the licence server ID it returns.
    • Telephone: select your country or region, call the number shown and read out the product ID; the operator gives you the licence server ID.
  4. Enter the required company information (first name, last name, company and country or region). The optional page can be skipped.
  5. Clear Start Install Licenses Wizard now if you want to check the configuration first, then click Finish.

The server status changes to Activated. If you ever rebuild the licence server, you must activate the new one and reinstall the CALs; contact the Clearinghouse by telephone if the CALs were already installed on the old server.

Step 3: Add the server to Terminal Server License Servers

In a domain, the licence server records per-user CAL issuance on user objects. It can only do that if its computer account is in the built-in domain local group Terminal Server License Servers.

  1. In Remote Desktop Licensing Manager, right-click the server and choose Review Configuration.
  2. If the dialog shows a warning for group membership, click Add to Group and confirm. This needs Domain Admin rights.
  3. Restart the Remote Desktop Licensing service, or the server, so the new group membership applies.

The same with PowerShell on a machine with the Active Directory module:

Add-ADGroupMember -Identity "Terminal Server License Servers" -Members "rdlic01$"
Get-ADGroupMember -Identity "Terminal Server License Servers"
Restart-Service -Name TermServLicensing -ComputerName rdlic01

In a multi-domain forest, add the licence server to this group in every domain whose users connect.

Step 4: Install the RDS CALs

  1. Right-click the server and choose Install Licenses, then Next.
  2. Select the license program you bought through, for example License Pack (Retail Purchase), Open License or Enterprise Agreement. Service providers choose Service Provider License Agreement.
  3. Enter the licence code or agreement number the programme requires.
  4. Select the Product version (for example Windows Server 2025), the License type (RDS Per User CAL or RDS Per Device CAL) and the Quantity.
  5. Click Next. The wizard contacts the Clearinghouse and installs the CALs; click Finish.

Expand the server in Licensing Manager: the new pack appears with Total, Available and Issued counts. Install the CAL version that matches your newest Session Host.

Step 5: Point the Session Hosts at the licence server

Option A: RD Connection Broker deployment

  1. On the broker, open Server Manager » Remote Desktop Services » Overview.
  2. Choose Tasks » Edit Deployment Properties » RD Licensing.
  3. Select Per User or Per Device, type the licence server FQDN, click Add and then OK.
Set-RDLicenseConfiguration -LicenseServer @("rdlic01.contoso.com","rdlic02.contoso.com") -Mode PerUser -ConnectionBroker "rdcb01.contoso.com" -Force
Get-RDLicenseConfiguration -ConnectionBroker "rdcb01.contoso.com"

Option B: Group Policy

Use this for Session Hosts without a broker, or to enforce the setting on every host in an OU.

  1. Create a GPO linked to the Session Host OU and go to Computer Configuration » Policies » Administrative Templates » Windows Components » Remote Desktop Services » Remote Desktop Session Host » Licensing.
  2. Enable “Use the specified Remote Desktop license servers” and enter the licence server names, separated by commas, under License servers to use.
  3. Enable “Set the Remote Desktop licensing mode” and choose Per User or Per Device.
  4. Run gpupdate /force on a Session Host.

These settings write LicenseServers (string) and LicensingMode (DWORD: 2 = Per Device, 4 = Per User) under HKLM\SOFTWARE\Policies\Microsoft\Windows NT\Terminal Services. Policy wins over the deployment properties, so keep both consistent or use only one.

Option C: PowerShell and WMI on a standalone host

$ts = Get-CimInstance -Namespace "root/cimv2/TerminalServices" -ClassName Win32_TerminalServiceSetting
Invoke-CimMethod -InputObject $ts -MethodName ChangeMode -Arguments @{ LicensingType = 4 }
Invoke-CimMethod -InputObject $ts -MethodName SetSpecifiedLicenseServerList -Arguments @{ SpecifiedLSList = @("rdlic01.contoso.com") }
Get-CimInstance -Namespace "root/cimv2/TerminalServices" -ClassName Win32_TerminalServiceSetting | Select-Object LicensingName

ChangeMode accepts 2 for Per Device and 4 for Per User. SetSpecifiedLicenseServerList replaces the whole list. Read the result from the LicensingName property, which returns the mode as text; the numeric LicensingType property does not use the same numbering as ChangeMode.

Step 6: Understand the grace period and the warning

A new Session Host works for 120 days without an RDS licensing server. During that time it shows a balloon such as:

Remote Desktop licensing mode is not configured.
Remote Desktop Services will stop working in 97 days. On the RD Connection Broker server, use Server Manager to specify the Remote Desktop licensing mode.

When the grace period ends without a configured mode and licence server, connections are refused with messages such as “The remote session was disconnected because there are no Remote Desktop License Servers available to provide a license.” Check the days left:

$ts = Get-CimInstance -Namespace "root/cimv2/TerminalServices" -ClassName Win32_TerminalServiceSetting
Invoke-CimMethod -InputObject $ts -MethodName GetGracePeriodDays

The warning disappears once the mode and licence server are set and the host can reach an activated server with matching CALs. Do not try to reset the grace period instead of licensing the farm; it breaks the licence terms and only postpones the outage.

Verify it works

  1. On a Session Host, open RD Licensing Diagnoser. It should list the licensing mode, the licence server, and state that no licensing problems were detected.
  2. Confirm the effective settings:
    $ts = Get-CimInstance -Namespace "root/cimv2/TerminalServices" -ClassName Win32_TerminalServiceSetting
    Invoke-CimMethod -InputObject $ts -MethodName GetSpecifiedLicenseServerList
    $ts.LicensingName
    reg query "HKLM\SOFTWARE\Policies\Microsoft\Windows NT\Terminal Services" /v LicensingMode
  3. Connect a test user. For per-device CALs, the Issued count in Licensing Manager rises (first a temporary CAL, then a permanent one on a later connection). For per-user CALs, run a CAL Usage report under Reports in Licensing Manager.
  4. Review Applications and Services Logs » Microsoft » Windows » TerminalServices-Licensing » Operational on the licence server.

Troubleshooting

SymptomLikely causeFix
Diagnoser: licence server not availableFirewall blocks RPC/SMB, wrong name, or Remote Desktop Licensing service stoppedTest Test-NetConnection rdlic01 -Port 135, open the RPC range and TCP 445, start TermServLicensing
Diagnoser: no licences available for this modeMode does not match the CAL type, or CAL version is older than the Session HostAlign mode and CAL type; install 2025 CALs for 2025 hosts
2025 CALs cannot be installedLicence server runs an older Windows Server versionMove the RDS licensing server role to Windows Server 2025
Per-user CALs never show as issuedLicence server not in Terminal Server License ServersAdd it with Review Configuration and restart the service
GPO and deployment properties disagreePolicy overrides the broker settingsCheck gpresult /h; set both the same or remove the GPO
Workgroup host fails with per-user modePer-user CALs need Active DirectoryUse per-device mode and CALs
Connections denied after grace period, licensing looks correctSession Host cannot access the licence server over the networkGrant Access this computer from the network on the licence server to Authenticated Users or the Session Host computer accounts
Clients fail with licensing protocol errors after a rebuildStale licence certificate on the Session HostBack up and delete Certificate, X509 Certificate, X509 Certificate ID and X509 Certificate2 under HKLM\SYSTEM\CurrentControlSet\Control\Terminal Server\RCM, then restart

Per-user CAL reporting and compliance

Because per-user CALs are not enforced, the RDS licensing server will keep letting users in even when you have more users than CALs. Check usage every quarter:

  1. In Remote Desktop Licensing Manager, expand the server, right-click Reports and choose Create Report » CAL Usage.
  2. Pick the scope (a domain or an OU) and let the report run. It lists the per-user CALs issued in that scope.
  3. Export the report and compare the count with your purchased quantity. Remove leavers from the RDS user group so they stop drawing licences.

For per-device CALs, the Issued column is the live count. Permanent per-device CALs are renewed for a random period of 52 to 89 days, so a replaced thin client releases its CAL automatically after that time. If you run out, temporary CALs are still issued for 90 days, which gives you time to buy more.

Licensing checklist for a new Session Host

  • Session Host and CALs are the same Windows Server version, or the CALs are newer.
  • Licensing mode on the host matches the CAL type installed.
  • The host lists at least one reachable, activated RDS licensing server.
  • No old GPO sets a different licence server or mode for the host’s OU.
  • RD Licensing Diagnoser reports no problems.

Redundancy and moving the licence server

For availability, run two RDS licensing servers, split the CALs between them and list both in the deployment properties or the GPO. A Session Host tries the servers in order. To move CALs to a new licence server, activate the new server, then use Manage Licenses in Licensing Manager on the new server to migrate them, or call the Clearinghouse by telephone if the old server is gone. After the move, update the licence server list on the broker and in any GPO, and run RD Licensing Diagnoser on every Session Host.

RDS licensing server at a glance

RDS Licensing Server summary card: Install the Remote Desktop Licensing role service, open Remote Desktop Licensing Manager, right-click the server and…
In short: Install the Remote Desktop Licensing role service, open Remote Desktop Licensing Manager, right-click the server and choose Activate Server (Automatic connection), then Install Licenses with your agreement number or licence code.

Official documentation: Activate the Remote Desktop Services license server, License your RDS deployment with client access licenses (CALs), Remote Desktop licensing mode is not configured.

Related guides: Deploy an RDS farm on Windows Server 2025 · Enable RDS session shadowing and allow non-admin users RDP access · Troubleshoot Group Policy not applying: gpresult, RSoP and Events 1058/1030.

Frequently asked questions

How long is the RDS licensing grace period?

A Session Host can accept connections for 120 days without a licence server. After that, clients need a valid RDS CAL issued by an activated licence server.

Can a Windows Server 2022 licence server issue Windows Server 2025 RDS CALs?

No. RDS CALs can only be installed on a licence server running the same Windows Server version or later, so 2025 CALs need a Windows Server 2025 licence server.

Should I choose per-user or per-device CALs?

Choose per-user when staff connect from several devices and per-device for shared PCs or thin clients. Per-user CALs need Active Directory and are not enforced, while per-device CALs are enforced by the licence server.

What does ‘Remote Desktop licensing mode is not configured’ mean?

The Session Host has no licensing mode or licence server set. Set them in the broker’s deployment properties, with Set-RDLicenseConfiguration, or with the two Licensing Group Policy settings before the 120-day grace period ends.

Why must the licence server be in Terminal Server License Servers?

Membership lets the licence server write per-user CAL information to user objects in Active Directory. Without it, per-user issuance cannot be tracked or reported.

Free website test

Is your website set up right?

Check SSL, security headers, redirects, robots.txt, sitemap, llms.txt and security.txt in one test. It takes about 30 seconds.