Remote Desktop NLA rejects credentials

What to do first

Remote Desktop NLA rejects credentials. The destination account may lack permission, saved credentials may be stale, clocks may differ, or the domain/local username format may be wrong. Record the current state before changing it, use only the supported Windows path described below, and verify the same operation again after any required restart.

This is a general troubleshooting guide, not an announcement of a current outage.

Affected products and symptoms

Product
Remote Desktop
Versions and conditions
Windows 11 (confirm the edition and hardware requirements for the feature)
Error codes and identifiers
NLA

Symptoms

  • Remote Desktop NLA rejects credentials.
  • The same condition can persist after a retry or restart.

Causes and conditions

The destination account may lack permission, saved credentials may be stale, clocks may differ, or the domain/local username format may be wrong.

Before you start

  • Save open documents and allow time for a Windows restart if required.
  • Run administrative actions only on a personally managed PC or with administrator approval.
  • Save the diagnostic command output so the before and after states can be compared.

Precautions

  • Do not bulk-delete registry entries, system folders, credentials, or storage metadata.
  • Do not run unofficial scripts or unknown drivers with administrator rights.
Remote Desktop troubleshooting sequence: Distinguish a PIN from the remote account password; Check the state with cmdkey; Repair through the supported path; Update only the saved RDP credential; Verify under the same conditions
Procedure overview created by FaultNote. Read the precautions and full instructions before changing settings. Read the full steps

Step-by-step instructions

  1. 01

    Distinguish a PIN from the remote account password

    #

    A Windows Hello PIN is device-specific and is not the ordinary password for an RDP password prompt. Confirm the remote account name, domain and password validity. Work with the remote computer’s administrator or your IT team so account ownership can be verified.

  2. 02

    Check the state with cmdkey

    #

    List saved credentials and identify only the TERMSRV entry for the destination host.

    Command or path
    cmdkey /list
  3. 03

    Repair through the supported path

    #

    Replace HOST_NAME with the actual value for your system before using this example.

    On the client, remove the stale TERMSRV/<host> credential. On the destination, confirm the account is allowed under Settings > System > Remote Desktop > Remote Desktop users, then reconnect using the correct domain or local-account format.

    Command or path
    cmdkey /delete:TERMSRV/HOST_NAME
  4. 04

    Update only the saved RDP credential

    #

    In Remote Desktop Connection, choose Show Options and check the destination and username. If an old credential is saved, remove only that destination’s saved credential and enter the current account details. Keep NLA enabled and work with the administrator to check domain reachability and allowed users.

  5. 05

    Verify under the same conditions

    #

    Replace HOST_NAME with the actual value for your system before using this example.

    Run Test-NetConnection <host> -Port 3389 and repeat the original operation once under the same conditions. If it succeeds, verify again after a restart and record the setting that changed.

    Check that no new critical event with the same timestamp and component appears in Event Viewer.

    Command or path
    Test-NetConnection HOST_NAME -Port 3389

Check the result

  • The feature starts, connects, or completes without the original error.
  • The verification command reports the expected enabled, healthy, or connected state.
  • The result remains correct after a Windows restart and no new matching critical event appears.

If the problem continues

  • If the same code persists, provide the full message, Windows build, command output, and occurrence time to the PC administrator or Microsoft Support.
  • If hardware requirements, organization policy, or server settings are responsible, ask the owner to make the change instead of bypassing it on the client.

Scope of this guide

Troubleshooting guide — Restore the feature so it starts, connects, or completes normally and passes the same verification after a Windows restart.

Frequently asked questions

Are my PIN and Microsoft account password the same?

No. A PIN is device-bound. RDP commonly expects the account password or an organization-approved method.

Should I disable NLA to connect?

Do not use that as the first fix because it weakens pre-authentication. Check time, username format, permissions, and saved credentials first.

Official sources and dates

Source publication or resolution date: Not specified. Sources checked: 2026-09-05. The check date is not the date the problem first occurred. Interface labels can vary between versions and display languages.

Related troubleshooting guides

← Search English guides