A complete RDS farm Windows Server 2025 deployment combines five role services (RD Connection Broker, RD Session Host, RD Web Access, RD Gateway and RD Licensing) into one managed deployment that gives users full desktops or RemoteApp programs on shared servers. This guide walks through role placement, the Server Manager wizard, the same build in PowerShell, session collections, user profiles, certificates, RemoteApp publishing and a highly available Connection Broker.
Short answer: On a domain-joined management server, open Server Manager » Manage » Add Roles and Features, choose Remote Desktop Services installation, Standard deployment and Session-based desktop deployment, then pick your Connection Broker, Web Access and Session Host servers. Add RD Licensing and RD Gateway from the deployment overview, set the licensing mode, create a session collection and install public certificates. The PowerShell equivalent is New-RDSessionDeployment, Add-RDServer and New-RDSessionCollection.
Table of Contents
RDS role services and where to put them
Each role service has a distinct job. Small farms can combine some of them; larger farms keep them apart so each can scale or fail over on its own.
| Role service | What it does | Typical placement |
|---|---|---|
| RD Connection Broker | Holds the deployment configuration, load-balances new sessions across Session Hosts and reconnects users to their existing session | Dedicated server; two brokers plus SQL Server for high availability |
| RD Session Host | Runs the user sessions, desktops and RemoteApp programs | Two or more servers sized for the user load |
| RD Web Access | IIS portal (/RDWeb) and web client that list the published desktops and apps | Can share a server with RD Gateway |
| RD Gateway | Tunnels RDP over HTTPS (TCP 443, plus UDP 3391) so users can connect from the internet without exposing TCP 3389 | DMZ or edge server, often with RD Web Access |
| RD Licensing | Issues RDS Client Access Licences (CALs) to users or devices | Any member server; often the broker or a management server |
A common layout for an RDS farm Windows Server 2025 build for a small or mid-sized business is four servers: one broker that also holds RD Licensing, one RD Web Access and RD Gateway server, and two Session Hosts. Do not install RD Session Host on a domain controller. Keep the Session Hosts identical (same applications, same updates) because the broker treats every host in a collection as interchangeable.
Which deployment method to use
| Method | Result | Best for | Limits |
|---|---|---|---|
| Quick Start (Server Manager) | Connection Broker, RD Web Access and RD Session Host on one server, plus a default session collection | Labs and proofs of concept | No choice of role placement; you still add Licensing and Gateway yourself |
| Standard deployment (Server Manager) | Each role on the servers you choose | Production farms built interactively | Manual steps are harder to repeat |
PowerShell (RemoteDesktop module) | Same as Standard deployment, scripted | Repeatable builds, test and production pairs | Needs the same prerequisites; errors are less descriptive than the wizard |
For any production RDS farm Windows Server 2025 build, use the Standard deployment, either through the wizard or the script, so you control where each role runs.
Prerequisites
- All servers run Windows Server 2025 (Standard or Datacenter), are joined to the same Active Directory domain and have static IP addresses.
- A domain account that is a local administrator on every server in the farm. Run the deployment from the server that will be the Connection Broker, or from a management server that has all farm servers added in Server Manager.
- Remote management (WinRM) enabled on every server; it is on by default in Windows Server 2025.
- Windows Server 2025 RDS CALs. Earlier CAL versions cannot license 2025 Session Hosts, and the licence server must run Windows Server 2025 to hold 2025 CALs.
- For internet access: a public DNS name (for example
remote.contoso.com) and a trusted certificate covering it, plus a firewall rule for TCP 443 and UDP 3391 to the RD Gateway. - A file share for user profiles (User Profile Disks or FSLogix containers), ideally on a separate file server.
The examples below use rdcb01 (Connection Broker and RD Licensing), rdgw01 (RD Web Access and RD Gateway), and rdsh01 and rdsh02 (Session Hosts) in contoso.com.
Step 1: Add the servers to Server Manager
- On
rdcb01, open Server Manager, choose Manage » Add Servers. - On the Active Directory tab, click Find Now, select every farm server and add it to the list.
- Check All Servers: each server must show Online in the Manageability column. Fix WinRM or firewall issues before continuing.
Step 2: Run the Standard deployment wizard
- Choose Manage » Add Roles and Features.
- On Installation Type, select Remote Desktop Services installation.
- On Deployment Type, select Standard deployment.
- On Deployment Scenario, select Session-based desktop deployment.
- Review the role services page, then add
rdcb01as RD Connection Broker,rdgw01as RD Web Access and bothrdsh01andrdsh02as RD Session Host. - On the confirmation page, tick Restart the destination server automatically if required and click Deploy.
The Session Hosts restart during installation. When the progress page shows every server as Succeeded, the core RDS farm Windows Server 2025 deployment exists, and Server Manager » Remote Desktop Services » Overview shows the deployment diagram.
Step 3: The same build with PowerShell
Scripting the RDS farm Windows Server 2025 build makes it easy to rebuild a test farm or a second site with identical settings. The RemoteDesktop module is installed with the RDS management tools. Run the commands from the Connection Broker in an elevated session:
Import-Module RemoteDesktop
$cb = "rdcb01.contoso.com"
New-RDSessionDeployment -ConnectionBroker $cb -WebAccessServer "rdgw01.contoso.com" -SessionHost @("rdsh01.contoso.com","rdsh02.contoso.com")
Add-RDServer -Server "rdcb01.contoso.com" -Role "RDS-LICENSING" -ConnectionBroker $cb
Add-RDServer -Server "rdgw01.contoso.com" -Role "RDS-GATEWAY" -ConnectionBroker $cb -GatewayExternalFqdn "remote.contoso.com"
Set-RDLicenseConfiguration -LicenseServer "rdcb01.contoso.com" -Mode PerUser -ConnectionBroker $cb -Force
Get-RDServer -ConnectionBroker $cb
Valid -Role values for Add-RDServer are RDS-RD-SERVER, RDS-CONNECTION-BROKER, RDS-WEB-ACCESS, RDS-GATEWAY, RDS-LICENSING and RDS-VIRTUALIZATION. Use RDS-RD-SERVER later to add a third Session Host to the farm.
Step 4: Add RD Licensing and set the licensing mode
If you used the wizard, add the licence server from the diagram:
- In Remote Desktop Services » Overview, click the + RD Licensing icon, select
rdcb01and finish the wizard. - Choose Tasks » Edit Deployment Properties » RD Licensing, select Per User or Per Device to match the CALs you bought, and confirm the licence server is listed.
- Activate the licence server and install the CALs in Remote Desktop Licensing Manager.
Without a configured mode, Session Hosts run in a 120-day grace period and then refuse connections. Activation, CAL types and Group Policy alternatives are covered in our RDS licensing guide.
Step 5: Add RD Gateway for external access
- In the overview, click + RD Gateway, select
rdgw01and enter the external nameremote.contoso.comas the SSL certificate name. - Open Edit Deployment Properties » RD Gateway and choose Use these RD Gateway server settings. Keep Bypass RD Gateway server for local addresses ticked if internal users should connect directly, and set the logon method to Password Authentication.
- Tick Use RD Gateway credentials for remote computers so users sign in once.
The wizard creates a connection authorisation policy (who may connect) and a resource authorisation policy (which servers they may reach) in RD Gateway Manager. Restrict both to your RDS user group and the farm servers. The scripted equivalent of the deployment settings is:
Set-RDDeploymentGatewayConfiguration -GatewayMode Custom -GatewayExternalFqdn "remote.contoso.com" -LogonMethod Password -UseCachedCredentials $true -BypassLocal $true -ConnectionBroker "rdcb01.contoso.com" -Force
Step 6: Create the session collection
A collection is the group of Session Hosts that serves one set of users and one set of desktops or apps.
- Go to Remote Desktop Services » Collections » Tasks » Create Session Collection.
- Name it (for example Office), add
rdsh01andrdsh02, and replace Domain Users with a dedicated group such as CONTOSO\RDS-Office-Users. - On Specify user profile disks, either enable them with a UNC path or leave them off if you will use FSLogix (see below).
- Click Create.
With PowerShell:
New-RDSessionCollection -CollectionName "Office" -SessionHost @("rdsh01.contoso.com","rdsh02.contoso.com") -CollectionDescription "Office desktop" -ConnectionBroker "rdcb01.contoso.com"
Set-RDSessionCollectionConfiguration -CollectionName "Office" -UserGroup "CONTOSO\RDS-Office-Users" -IdleSessionLimitMin 60 -DisconnectedSessionLimitMin 120 -AuthenticateUsingNLA $true -ConnectionBroker "rdcb01.contoso.com"
Collection settings worth changing
- Session: end disconnected sessions after a few hours so abandoned sessions do not hold licences and memory (
-DisconnectedSessionLimitMin), and set an idle limit (-IdleSessionLimitMin). - Security: keep Allow connections only from computers running Remote Desktop with Network Level Authentication enabled (
-AuthenticateUsingNLA $true). - Load Balancing: give larger hosts a higher relative weight and a session limit.
- Client Settings: decide which redirections (drives, clipboard, printers) the collection allows;
-ClientDeviceRedirectionOptionsis the scripted setting.
User Profile Disks vs FSLogix
| User Profile Disks | FSLogix profile containers | |
|---|---|---|
| Where configured | Collection properties or Set-RDSessionCollectionConfiguration -EnableUserProfileDisk -DiskPath -MaxUserProfileDiskSizeGB | FSLogix agent on each Session Host, settings under HKLM\SOFTWARE\FSLogix\Profiles (Enabled, VHDLocations) or the FSLogix ADMX |
| Scope | One collection; each collection keeps its own disk per user | Any host or collection that points at the same share |
| Licensing | Included | Included with RDS CALs and SALs |
| Strengths | No extra software | Handles Outlook and OneDrive caches and search better; Cloud Cache for resilient storage; Microsoft’s actively developed profile solution |
For new farms we recommend FSLogix. Leave User Profile Disks disabled on the collection, install the FSLogix agent on every Session Host, and configure VHDLocations to point at a share such as \\fs01\Profiles$. Exclude HKLM\SOFTWARE\FSLogix and HKLM\SOFTWARE\Policies\FSLogix from antivirus scanning, as Microsoft advises.
Step 7: Install certificates
An RDS farm Windows Server 2025 deployment uses four certificate roles. Open Edit Deployment Properties » Certificates to see them:
| Wizard role | Set-RDCertificate -Role | Subject name |
|---|---|---|
| RD Connection Broker – Enable Single Sign On | RDRedirector | Broker FQDN (or the HA DNS name) |
| RD Connection Broker – Publishing | RDPublishing | Broker FQDN (or the HA DNS name) |
| RD Web Access | RDWebAccess | Public name, for example remote.contoso.com |
| RD Gateway | RDGateway | Public name, for example remote.contoso.com |
A single SAN or wildcard certificate that clients trust can cover all four. Self-signed certificates created in the wizard work for testing only; clients show warnings and the web client refuses them.
$pw = Read-Host -AsSecureString -Prompt "PFX password"
foreach ($r in "RDGateway","RDWebAccess","RDRedirector","RDPublishing") {
Set-RDCertificate -Role $r -ImportPath "C:\Certs\remote-contoso.pfx" -Password $pw -ConnectionBroker "rdcb01.contoso.com" -Force
}
Renew these certificates before they expire and re-run the import for every role. After a broker certificate change, re-import it into the web client as shown below.
Step 8: Publish RemoteApps and enable the web client
Publish RemoteApp programs
- Install the application on every Session Host in the collection.
- Open the collection and choose RemoteApp Programs » Tasks » Publish RemoteApp Programs, tick the applications and click Publish.
- Open each app’s properties to limit it to a group under User Assignment, or to place it in a folder for RD Web Access.
New-RDRemoteApp -CollectionName "Office" -DisplayName "Word" -FilePath "C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE" -UserGroups "CONTOSO\RDS-Office-Users" -ConnectionBroker "rdcb01.contoso.com"
Get-RDRemoteApp -CollectionName "Office" -ConnectionBroker "rdcb01.contoso.com"
Publishing any RemoteApp hides the full desktop from RD Web Access for that collection. If users need both, create a second collection for the desktop.
Install the Remote Desktop web client
The HTML5 web client lets users open desktops and apps in a browser. On the RD Web Access server:
Install-Module -Name PowerShellGet -Force
Install-Module -Name RDWebClientManagement
Install-RDWebClientPackage
Import-RDWebClientBrokerCert "C:\Certs\rdcb01.cer"
Publish-RDWebClientPackage -Type Production -Latest
The .cer file is the public part of the Connection Broker certificate. Users browse to https://remote.contoso.com/RDWeb/webclient/index.html. The web client needs per-user CALs; it does not work with per-device licensing.
Step 9: Make the Connection Broker highly available
A single broker is a single point of failure for the whole RDS farm Windows Server 2025 deployment: if it is down, no new sessions start. For production, run two brokers against a shared SQL database.
- Prepare a SQL Server instance (or Azure SQL Database). Put the broker computer accounts in a security group and give that group a SQL login with the
dbcreatorrole so the broker can create its database. - Install the SQL Server Native Client or ODBC Driver for SQL Server that matches your connection string on each Connection Broker.
- Create DNS round-robin A records with one name, for example
rdcb.contoso.com, pointing at each broker’s IP address. - In the overview, right-click RD Connection Broker » Configure High Availability, choose Shared database server, and enter the DNS name and connection string.
- Right-click the broker again and choose Add RD Connection Broker Server to add
rdcb02. - Re-issue the SSO and Publishing certificates so they include the round-robin name.
Set-RDConnectionBrokerHighAvailability -ConnectionBroker "rdcb01.contoso.com" -DatabaseConnectionString "DRIVER=SQL Server Native Client 11.0;SERVER=sql01.contoso.com;Trusted_Connection=Yes;APP=Remote Desktop Services Connection Broker;DATABASE=RDCB" -ClientAccessName "rdcb.contoso.com"
Add-RDServer -Server "rdcb02.contoso.com" -Role "RDS-CONNECTION-BROKER" -ConnectionBroker "rdcb01.contoso.com"
For the rest of the RDS farm Windows Server 2025 design, add a second RD Web Access and RD Gateway behind a load balancer, add Session Hosts to the collection, and run two licence servers with CALs split between them.
Verify it works
- Check roles and collections from the broker:
Get-RDServer -ConnectionBroker "rdcb01.contoso.com"
Get-RDSessionCollection -ConnectionBroker "rdcb01.contoso.com"
Get-RDSessionHost -CollectionName "Office" -ConnectionBroker "rdcb01.contoso.com"
Get-RDLicenseConfiguration -ConnectionBroker "rdcb01.contoso.com"
Get-RDDeploymentGatewayConfiguration -ConnectionBroker "rdcb01.contoso.com" - From an external client, browse to
https://remote.contoso.com/RDWeb, sign in and launch the desktop or a RemoteApp. There should be no certificate warning. - Sign in with two test users and run
Get-RDUserSession -ConnectionBroker "rdcb01.contoso.com": the sessions should be spread across both Session Hosts. - Disconnect a user and reconnect: the broker must return them to the same host and session.
- On a Session Host, open RD Licensing Diagnoser and confirm it reports no problems.
Troubleshooting
| Symptom | Likely cause | Fix |
|---|---|---|
| Wizard fails with “The server is not available” or WinRM errors | Server not added to Server Manager, WinRM blocked, or account not local admin | Add all servers, run Test-WSMan against each, use an account with admin rights on every server |
| “Remote Desktop licensing mode is not configured” balloon | Mode or licence server not set in deployment properties | Set it under RD Licensing or with Set-RDLicenseConfiguration |
| Certificate warning when launching apps | Self-signed or mismatched broker certificates | Import a trusted certificate for all four roles; subject must match the broker or HA name |
| External users cannot connect through the gateway | TCP 443 not forwarded, CAP/RAP too narrow, or external DNS wrong | Test Test-NetConnection remote.contoso.com -Port 443, review policies in RD Gateway Manager |
| Users get temporary profiles | Profile share permissions or antivirus locking VHDX files | Check share and NTFS permissions on the profile share, add FSLogix exclusions |
| All users land on one Session Host | Host set to not allow new connections, or unequal load-balancing weights | Check Get-RDSessionHost (NewConnectionAllowed) and the collection’s Load Balancing page |
| Full desktop missing in RD Web Access | RemoteApps published in that collection | Use a separate collection for the desktop |
Before you open the RDS farm Windows Server 2025 deployment to users, apply your Session Host Group Policy (usually with loopback processing), patch all hosts to the same level, and document the collection, certificate and licensing settings so a second admin can rebuild the farm from the script.
RDS farm Windows Server 2025 at a glance

Official documentation: Deploy your Remote Desktop environment, New-RDSessionDeployment, Add the RD Connection Broker server to the deployment and configure high availability.
Related guides: RDS license server activation and CALs · Enable RDS session shadowing and allow non-admin users RDP access · Group Policy loopback processing: merge vs replace for RDS hosts and kiosks.
Frequently asked questions
Can I install all RDS roles on one Windows Server 2025 server?
Yes. The Quick Start deployment puts RD Connection Broker, RD Web Access and RD Session Host on one server, and you can add RD Licensing and RD Gateway to it. It suits labs and very small offices, but production farms should separate the roles.
Should I use User Profile Disks or FSLogix on Windows Server 2025 RDS?
For new farms, use FSLogix profile containers. RDS CAL holders are entitled to FSLogix, it works across collections and it handles Outlook and OneDrive caches better than User Profile Disks.
Which RDS CALs do I need for Windows Server 2025 Session Hosts?
You need Windows Server 2025 RDS CALs installed on a Windows Server 2025 licence server. CALs for earlier versions cannot license 2025 Session Hosts.
What PowerShell cmdlet creates an RDS deployment?
New-RDSessionDeployment creates a session-based deployment with -ConnectionBroker, -SessionHost and -WebAccessServer. Add-RDServer adds Licensing, Gateway or more hosts, and New-RDSessionCollection creates the collection.
Does the Remote Desktop web client work with per-device CALs?
No. The web client requires the deployment to use per-user licensing.