# Enable RDS session shadowing and allow non-admin users RDP access

Source: https://srvscripts.com/guides/rds-session-shadowing-non-admin-rdp/
Updated: 2026-10-06
Publisher: srvScripts (https://srvscripts.com/)

Session shadowing lets a support engineer see or take over an existing Remote Desktop session on an RDS host or a Windows 10/11 workstation, which avoids third-party remote support tools for machines already on the domain. Out of the box it works only for local administrators and asks the user for consent. Group Policy controls the consent behaviour, and a small permission change on the RDP listener lets a helpdesk group shadow without being administrators. The settings apply to Windows Server 2019/2022/2025 session hosts and Windows 10/11 Pro and Enterprise.

In short: Set Computer Configuration » Policies » Administrative Templates » Windows Components » Remote Desktop Services » Remote Desktop Session Host » Connections » “Set rules for remote control of Remote Desktop Services user sessions” to “Full…

**Short answer:** Set Computer Configuration » Policies » Administrative Templates » Windows Components » Remote Desktop Services » Remote Desktop Session Host » Connections » “Set rules for remote control of Remote Desktop Services user sessions” to “Full Control with user’s permission” (or “without user’s permission” for unattended hosts), open the Remote Desktop Shadow firewall rule, then connect with `mstsc /v:host /shadow:<SessionID> /control /prompt`. To let non-administrators shadow or connect, add them to the local Remote Desktop Users group and grant Remote Control permission on the RDP-Tcp listener with `wmic /node:host /namespace:\\root\CIMV2\TerminalServices PATH Win32_TSPermissionsSetting WHERE TerminalName="RDP-Tcp" CALL AddAccount "CORP\Helpdesk",2`.

## Set the shadowing policy

In a GPO linked to the OU holding the session hosts or workstations, enable Computer Configuration » Policies » Administrative Templates » Windows Components » Remote Desktop Services » Remote Desktop Session Host » Connections » “Set rules for remote control of Remote Desktop Services user sessions” and pick one of the modes: No remote control allowed, Full Control with user’s permission, Full Control without user’s permission, View Session with user’s permission, or View Session without user’s permission.

The value lands in `HKLM\SOFTWARE\Policies\Microsoft\Windows NT\Terminal Services\Shadow` (REG_DWORD; 0 disabled, 1 full control with consent, 2 full control without consent, 3 view with consent, 4 view without consent). Consent is the right default for staff desktops; unattended full control suits kiosks and shared floor machines where nobody is there to click Yes, and should be stated in your acceptable-use policy.

The shadow connection uses TCP 3389 through the Remote Desktop listener plus a separate rule. Under Computer Configuration » Policies » Windows Settings » Security Settings » Windows Defender Firewall with Advanced Security add the predefined “Remote Desktop” group and confirm “Remote Desktop – Shadow (TCP-In)” is included; this allows `RdpSa.exe` to accept the shadow session. Run `gpupdate /force` on the target.

## Shadow a session

Find the session ID from the helpdesk workstation, then connect:

```
query session /server:rds01.corp.example.com
quser /server:rds01.corp.example.com
mstsc /v:rds01.corp.example.com /shadow:3 /control /prompt
mstsc /v:rds01.corp.example.com /shadow:3 /noConsentPrompt
```

`/control` requests full control rather than view only, `/prompt` asks for alternate credentials, and `/noConsentPrompt` only works when the policy allows shadowing without permission. The user sees a bar noting that their session is being viewed. On an RDS deployment with a Connection Broker, Server Manager » Remote Desktop Services » Collections lists sessions with a right-click Shadow option that wraps the same command. To shadow the console session on a workstation rather than an RDP session, use the session ID shown as “console” in `query session`, which requires Windows 10/11 Pro or Enterprise.

## Let non-administrators connect and shadow

Two separate permissions are involved. Logging on through Remote Desktop requires membership of the local Remote Desktop Users group, which you can set centrally through Restricted Groups as covered in [enable Remote Desktop and the firewall rules through Group Policy](/guides/enable-remote-desktop-group-policy/). Shadowing another user’s session requires the Remote Control permission on the listener, which by default only Administrators hold. Grant it to a helpdesk group on each host:

```
wmic /node:"rds01" /namespace:\\root\CIMV2\TerminalServices PATH Win32_TSPermissionsSetting WHERE (TerminalName="RDP-Tcp") CALL AddAccount "CORP\Helpdesk",2
wmic /node:"rds01" /namespace:\\root\CIMV2\TerminalServices PATH Win32_TSAccount WHERE "TerminalName='RDP-Tcp' AND AccountName='CORP\\Helpdesk'" CALL ModifyPermissions 4,1
```

The 2 in AddAccount grants the User access level, and ModifyPermissions 4,1 adds Remote Control. Because WMIC is removed in Windows 11 26H1 and later, use PowerShell CIM on new builds:

```
$ts = Get-CimInstance -Namespace root\CIMV2\TerminalServices -ClassName Win32_TSPermissionsSetting -Filter "TerminalName='RDP-Tcp'"
Invoke-CimMethod -InputObject $ts -MethodName AddAccount -Arguments @{AccountName='CORP\Helpdesk'; PermissionPreSet=2}
```

Run this as a startup script or through a scheduled task deployed by Group Policy so new hosts inherit the permission. The helpdesk group also needs the “Allow log on through Remote Desktop Services” user right if they will connect interactively; for shadowing alone, the Remote Control permission and network access are sufficient. Without these, a non-admin attempting `/shadow` gets “Access is denied” or “The shadow session cannot be established”, even when the policy allows it.

## Verify

From a helpdesk account that is not a local administrator, run `query session /server:rds01` and confirm sessions are listed, then shadow one with `/control`. The user should see the consent prompt (or the session should attach immediately in no-consent mode). On the host, the TerminalServices-RemoteConnectionManager operational log records Event ID 20508 for a shadow start and 20503 for the end, with the shadowing account and target session.

A common pitfall is trying to shadow a session on a Windows 10/11 machine where Remote Desktop itself is disabled; the Shadow firewall rule and the RDP listener must both be enabled even if nobody logs on through RDP. Combine this with the redirection restrictions in [disable RDP drive, clipboard and USB redirection](/guides/disable-rdp-drive-redirection-gpo/) on hosts that handle sensitive data.

## RDS session shadowing at a glance

**Official documentation:** [Windows Server documentation](https://learn.microsoft.com/en-us/windows-server/).

**Related guides:** [Deploy printers with Group Policy Preferences](https://srvscripts.com/guides/deploy-printers-group-policy/) · [Reset the Default Domain Policy and Default Domain Controllers Policy with dcgpofix](https://srvscripts.com/guides/dcgpofix-reset-default-domain-policy/) · [Enable Remote Desktop and the firewall rules through Group Policy](https://srvscripts.com/guides/enable-remote-desktop-group-policy/).

## Frequently asked questions

### Does session shadowing work on Windows 11 workstations or only RDS servers?

It works on Windows 10/11 Pro, Enterprise and Education for both the console session and RDP sessions, using the same policy and mstsc /shadow syntax as on Windows Server session hosts.

### How long does it take for the shadowing policy to take effect?

The setting applies at the next Group Policy refresh, within 90 minutes or immediately with `gpupdate /force`, and existing sessions honour the new mode without the user logging off.

### Can I undo non-admin shadow permissions?

Yes; remove the account from the listener permissions with the `RemoveAccount` method or through the legacy tsconfig permissions dialog, and remove the group from Remote Desktop Users, after which non-admins receive access denied again on their next attempt.
