Remote Logins Are Currently Disabled on Server 2016: How to Fix
Here in this post, we list 3 ways for you to solve the issue “Remote logins are currently disabled on Server 2016”. Keep reading and take the ways into practice.
By Ellie
/ Last Updated November 24, 2022
Run into the issue “Remote logins are currently disabled on Server 2016
Greetings to the well of knowledge. I have a Server 2016 that I am unable to remote into a PC. I get a «Remote logins are disabled» error. This happens to be a Remote Desktop Broker server for an RD server farm. All of the Remote Desktop settings in the Local Group policy are «not configured». Where else should I be looking to fix this? Thanks
— Question from Spiceworks

It will be frustrated to run into the error “Remote logins are currently disabled” on Server 2016 when you try to connect to another PC via RDP. Usually, the issue occurs when a user is attempting to log on to a Terminal Server where an administrator has disabled logon by issuing the CHANGE LOGON /DISABLE command.
How to fix “Remote logins are currently disabled on Server 2016
Here we summarize 3 solutions to fix “Remote logins are currently disabled” on Server 2016. Before the operation, please press Win + R and then input “sysdm.cpl” and click on OK. Make sure the option “Allow remote connections to this computer” under the Remote tab has been ticked. Now follow me to operate.
Fix 1. Use Command Prompt
Here in this part, we’ll manually enable the remote login using the command prompt.
Step 1. Right-click on the Start menu, and choose Command Prompt(Admin).

Step 2. In the command prompt window, type the following command:
psexec.exe \\SERVERNAME\ change logon /enable

Then, connect again to check out whether the command enables the remote logins and eliminate the error “Server 2016 RDP remote logins are currently disabled”.
Fix 2. Take advantage of Remote Desktop Session Host configuration utility
We will enable the logon services using the Remote Desktop Session Host Configuration Utility.
Step 1. Press Win + R and then type in tsconfig.msc and then hit the Enter key.

Step 2. In the Remote Desktop Session Host Configuration window. And locate the Edit settings. You’ll see that Restrict each user to a single session has been put Yes.

Step 3. Right-click on Restrict each user to a single session > Properties and then uncheck the Restrict each user to a single session checkbox.

Step 5. Click on Apply then OK for getting back of this type of Remote Logins are Currently Disabled on Server 2016.
Fix 3. Use Registry Editor
In this method, we will use the registry editor to resolve the Remote Logins are Currently Disabled issues.
Step 1. Press Win + R and then input “regedit”.

Step 2. In the registry editor navigate to the following path:
HKEY_LOCAL_MACHINE > SYSTEM > CurrentControlSet > Control > Terminal Server
Step 3. On the Right Locate the fSingleSessionPerUser, then double click on it.

Step 4. In the Value data put 0, to allow Multiple sessions.

Step 5. Save the changes and restart your system to check whether the error “Remote logins are currently disabled server 2016” still remains.
AnyViewer: Get remote connection with little effort
Now you may have already fixed the issue “Remote Logins are currently disabled on Server 2016”. However, if the issue remains still or you don’t want to take too much time on fixing it, why not choose a free & professional remote access software, like AnyViewer.
With AnyViewer, you could get remote access anywhere and anytime. Apart from that, you can get one-click connection once you log into the same AnyViewer account on 2 PCs. And it’s workable for multiple Windows versions, like Windows Server 2022/2016/2012 R2 as well as Windows 11/10/8/7. Now follow me to know the operation.
Step 1. Install AnyViewer on both 2 PCs and then open it. Go to the “Log in” tab, and click on “Sign up”.

Step 2. Fill in the information to sign up.

Step 3. Now you can see your interface as the following picture. And your device will automatically be assigned to the account you’ve logged in to.

Step 4. If you log the same account on another device, there will be 2 devices in the “My devices” tab. Click the PC that you need to control and click «One-click control» to achieve unattended access with one click.

Step 5. The connection is established successfully.
You can also choose to upgrade to an advanced plan, with which you are able to enjoy the following advantages:
- Enjoy Privacy Mode. With the feature Privacy Mode, the screen of the remote PC will be blackened and the keyboard & mouse would be disabled.
- Transfer large files. No matter how large your files are, you can get file transfer without any limitation.
- Bind more devices. After the upgrade, you are able to bind 10 devices for one-click unattended remote access and manage 100 devices.
Conclusion
The methods for resolving «Remote logins are currently disabled” on Server 2016 are illustrated in this post. However, you could use a third-party remote access software, such as AnyViewer, to easily establish a remote connection.
Особенности обслуживания RDSH Windows Server в режиме Drain Mode
10.01.2021
itpro
Windows Server 2016, Windows Server 2019
комментариев 6
Для обслуживания терминальных серверов в составе RDS фермы существует специальный режим Drain Mode (режим стока, слива). Переведя RDS сервер в drain режим, вы можете запретить серверу принимать новые RDP подключения пользователей, а текущие подключения будут активными пока пользователи не отключатся через logoff или по таймауту RDS сессии. После этого вы можете выполнить техническое обслуживание сервера, не останавливая работу RDS фермы (установить обновления, изменить настройки сервера или программ, обновить конфигурационные файлы и т.д.)
Что такое Drain Mode в Windows Server RDS?
Drain mode впервые появился в Windows Server 2008 (Terminal Services Server Drain mode) и позволяет запретить RDS хосту принимать новые подключения. Как правило этот режим используется, когда администратору сервера нужно произвести обслуживание сервера (установить обновления Windows, настроить или обновить приложения), не затрагивая доступность всей RDS фермы. RDS хост может работать в трех режимах Drain Mode:
Запрет входа новых пользователей на RDS сервер
Вы можете включить Drain Mode на хост сервере RDS в настройка RDS коллекции.
- Откройте Server Manager -> All Servers -> Добавьте все RDS сервера фермы;
- Выберите Remote Desktop Services в левой панели Server Manager. Выберите раздел RDS коллекций (Collections);
- В секции HOST SERVERS выберите сервер, которые нужно перевести в Drain и в контекстном меню выберите пункт “Do not allow new connections” (Не разрешать новые подключения).

Пользователи с активными сессиями смогут переподключиться к этому серверу, а все новые подключения будут перенаправлены Connection Broker-ом на другие хосты RDS фермы.
Также вы можете изменить Drain режим локально на RDS хосте из командной строки. Для этого используется команда change logon .
Чтобы запретить вход новых пользователей, выполните команду:
change logon /drain
Теперь, если новый пользователь попытается напрямую подключится к RDS хосту (когда RD Connection Broker не используется), появится ошибка:

При этом в логах RDS хоста будет появляться событие с Event ID 1070 от источника TerminalServices-RemoteConnectionManager:
Следующая команда включает режим Drain до перезагрузки хоста:
change logon /drainuntilrestart
Чтобы запретить подключаться к хосту даже пользователям с активными сессиями, выполните команду:
change logon /disable
Чтобы разрешить подключения, выполните:
change logon /enable
Проверить, включен ли режим стока на вашем RDS сервере можно командой:
change logon /query
Если при попытке изменить режим Drain на сервере командой change logon появляется ошибка:

Значит у вас настроен режим Drain через GPO. Параметр называется Allow users to connect remotely using Remote Desktop Services и находится в разделе политик Administrative Templates -> Windows Components -> Remote Desktop Services -> Remote Desktop Session Host -> Connections.

Отключите данную политику, или переведите ее в режим Not Configured.
Управление Drain Mode с помощью PowerShell
Вы можете управлять настройками Drain mode для коллекции RDS хостов или на отдельном сервере с помощью PowerShell:
Import-Module RemoteDesktop
# запретить новые RDS подключения к этому серверу
Set-RDSessionHost -SessionHost rdsh1.winitpro.ru -NewConnectionAllowed No -ConnectionBroker rdshcb.winitpro.ru
# разрешить подключение пользователям
Set-RDSessionHost -SessionHost rdsh1.winitpro.ru -NewConnectionAllowed Yes -ConnectionBroker rdshcb.winitpro.ru
-
WinStationsDisabled в HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\

Например в Drain Mode они устанавливаются WinStationsDisabled = 0 и TSServerDrainMode = 2 .
Также вы можете проверить текущий режим Drain на хосте таким PowerShell скриптом:
gwmi win32_terminalservicesetting -N «root\cimv2\terminalservices» | %<
if ($_.logons -eq 1)<
«Disabled»>
Else <
switch ($_.sessionbrokerdrainmode)
<
0 <"Enabled">
1 <"DrainUntilRestart">
2 <"Drain">
default <"error">
>
>
>
Включается режим Drain в PowerShell так (аналог Change logon /Drain ):
$temp = (gwmi win32_terminalservicesetting -N «root\cimv2\terminalservices»)
$temp.sessionbrokerdrainmode=2
$temp.put()
Для перевода сервера в обычный режим ( change logon /enable ), выполните:

$temp = (gwmi win32_terminalservicesetting -N » root\cimv2\terminalservices «)
$temp.sessionbrokerdrainmode=0
$temp.logons=0
$temp.put()
Предыдущая статья Следующая статья
Remote logins are currently disabled что значит
If you trying to connect to a RDP server and you get this error:
Remote logins are currently disabled.
Description: The user is attempting to log on to a Terminal Server where an administrator has disabled logon by issuing the CHANGE LOGON /DISABLE command. In order to enable logon, the CHANGE LOGON /ENABLE command must be issued.
You would require the help of psexec utility to gain access to the command prompt of the desired server. You the below syntax:
psexec.exe “\\SERVERNAME\ change logon /enable”
Overview of the CHANGE LOGON Command
The change logon command uses the following syntax:
change logon /enable | /disable | /query
The parameters that are used by the change logon command are:
/enable: Use this parameter to turn on logons from client sessions.
/disable: Use this parameter to turn off any further logons from client sessions. Currently- logged-on users are not affected.
/query: Use this parameter to display the current logon status.
NOTES: The change logon command applies to logons from client sessions. Logons from the console session are not affected.
Windows Administrators Blog!
Online knowledge base and an Known Error DataBase (KEDB)
Remote Logins Are Currently Disabled
If you trying to connect to a RDP server and you get this error:
Remote logins are currently disabled.
Description: The user is attempting to log on to a Terminal Server where an administrator has disabled logon by issuing the CHANGE LOGON /DISABLE command. In order to enable logon, the CHANGE LOGON /ENABLE command must be issued.
You would require the help of psexec utility to gain access to the command prompt of the desired server. You the below syntax:
psexec.exe “\\SERVERNAME\ change logon /enable”
Overview of the CHANGE LOGON Command
The change logon command uses the following syntax:
change logon /enable | /disable | /query
The parameters that are used by the change logon command are:
/enable: Use this parameter to turn on logons from client sessions.
/disable: Use this parameter to turn off any further logons from client sessions. Currently-logged-on users are not affected.
/query: Use this parameter to display the current logon status.
NOTES: The change logon command applies to logons from client sessions. Logons from the console session are not affected.