The essentials
Quick reference
One focused task per row. Jump to the related section for complete, working examples.
| Use | Syntax | Examples |
|---|---|---|
| Check RDS cmdlets | Get-Module -ListAvailable 'RemoteDesktop' |
Select-Object Name, Version, Path | View examples |
| List deployment servers | Get-RDServer -ConnectionBroker 'rdcb01.contoso.com' |
Sort-Object Server | View examples |
| List session hosts | Get-RDServer -ConnectionBroker 'rdcb01.contoso.com' `
-Role 'RDS-RD-SERVER' | View examples |
| List session collections | Get-RDSessionCollection -ConnectionBroker 'rdcb01.contoso.com' |
Sort-Object CollectionName | View examples |
| List collection hosts | Get-RDSessionHost -CollectionName 'Finance Apps' `
-ConnectionBroker 'rdcb01.contoso.com' | View examples |
| Inspect connection policy | Get-RDSessionCollectionConfiguration -CollectionName `
'Finance Apps' -Connection -ConnectionBroker `
'rdcb01.contoso.com' | View examples |
| Inspect security policy | Get-RDSessionCollectionConfiguration -CollectionName `
'Finance Apps' -Security -ConnectionBroker `
'rdcb01.contoso.com' | View examples |
| Inspect authorized groups | Get-RDSessionCollectionConfiguration -CollectionName `
'Finance Apps' -UserGroup -ConnectionBroker `
'rdcb01.contoso.com' | View examples |
| List published RemoteApps | Get-RDRemoteApp -CollectionName 'Finance Apps' `
-ConnectionBroker 'rdcb01.contoso.com' | View examples |
| Inspect RDS licensing | Get-RDLicenseConfiguration -ConnectionBroker `
'rdcb01.contoso.com' | View examples |
| List deployment sessions | Get-RDUserSession -ConnectionBroker 'rdcb01.contoso.com' |
Sort-Object HostServer, UnifiedSessionId | View examples |
| List collection sessions | Get-RDUserSession -CollectionName 'Finance Apps' `
-ConnectionBroker 'rdcb01.contoso.com' | View examples |
| Resolve one user's sessions | Get-RDUserSession -ConnectionBroker 'rdcb01.contoso.com' |
Where-Object { $_.DomainName -eq 'CONTOSO' -and $_.UserName -eq 'alice' } | View examples |
| Query host-local sessions | quser.exe /server:rdsh01.contoso.com | View examples |
| Notify one session | Send-RDUserMessage -HostServer 'rdsh01.contoso.com' `
-UnifiedSessionID 12 -MessageTitle 'Maintenance' `
-MessageBody 'Save work by 22:00 UTC.' | View examples |
| Disconnect one session | Disconnect-RDUser -HostServer 'rdsh01.contoso.com' `
-UnifiedSessionID 12 | View examples |
| Log off one session | Invoke-RDUserLogoff -HostServer 'rdsh01.contoso.com' `
-UnifiedSessionID 12 | View examples |
| Read Session Host events | Get-WinEvent -LogName `
'Microsoft-Windows-TerminalServices-LocalSessionManager/Operational' `
-MaxEvents 100 | View examples |
Remote Desktop Services is a deployment of broker, session host, web, gateway, licensing, and sometimes virtualization roles—not merely the RDP protocol. Resolve the authoritative RD Connection Broker, collection, host FQDN, user, and host-local UnifiedSessionId before acting. Disconnect preserves applications; logoff closes them and can lose unsaved work. The RemoteDesktop module targets Windows Server RDS deployments and requires installed management tools, domain connectivity, and delegated deployment permissions.
Step by step
Detailed examples
Query the authoritative broker with explicit FQDNs
The RemoteDesktop module is installed with Windows Server RDS management tools and is distinct from the similarly named RemoteDesktopServices module. Its deployment cmdlets expect an existing Windows Server RDS deployment, normally joined to Active Directory. Run from a supported management host with DNS, WinRM, broker database, and delegated RDS permissions. Read operations usually need no reboot or elevation when rights are delegated, but local administrator alone does not guarantee deployment authority.
Get-Module -ListAvailable RemoteDesktop | Select-Object Name, Version, Path
$broker = 'rdcb01.contoso.com'
Get-RDServer -ConnectionBroker $broker | Sort-Object Server | Select-Object Server, Roles Read every configuration facet instead of trusting a collection name
A collection ties session hosts to access, connection, security, load-balancing, client-redirection, and profile settings. Query the host membership plus each parameter set of Get-RDSessionCollectionConfiguration. Read cmdlets are observational and do not support WhatIf. Set-RDSessionCollectionConfiguration and membership cmdlets can disconnect users, change capacity, or alter security and do not provide a universal safe simulation; stage and approve them with a rollback and broker recovery path.
$p = @{ CollectionName = 'Finance Apps'; ConnectionBroker = 'rdcb01.contoso.com' }
Get-RDSessionHost @p
Get-RDSessionCollectionConfiguration @p -Connection
Get-RDSessionCollectionConfiguration @p -Security
Get-RDSessionCollectionConfiguration @p -LoadBalancing
Get-RDSessionCollectionConfiguration @p -Client Audit authorization separately from application publication
Collection user groups define who may connect; RemoteApp publication defines which programs the collection exposes. Neither replaces NTFS, share, application, or database authorization inside a session. Resolve nested AD group membership separately, review application paths and aliases, and test as a representative non-admin user. Publishing or removing an app changes user-visible service and may break feeds; some RDS mutation cmdlets lack WhatIf, so a maintenance and rollback plan is required.
$p = @{ CollectionName = 'Finance Apps'; ConnectionBroker = 'rdcb01.contoso.com' }
Get-RDSessionCollectionConfiguration @p -UserGroup
Get-RDRemoteApp @p | Select-Object CollectionName, Alias, DisplayName, FilePath, ShowInWebAccess Verify licensing configuration before grace periods become outages
Get-RDLicenseConfiguration reports the deployment licensing mode and registered licensing servers, but it does not prove activation, CAL availability, discovery, firewall access, or policy consistency on every Session Host. Correlate it with RD Licensing Diagnoser and relevant event logs. RDS licensing and role changes require Windows Server editions and roles, domain planning, administrative rights, and can require restarts; do not improvise registry fixes or reset grace-period data.
$broker = 'rdcb01.contoso.com'
Get-RDLicenseConfiguration -ConnectionBroker $broker
Get-RDServer -ConnectionBroker $broker -Role 'RDS-LICENSING'
Get-RDServer -ConnectionBroker $broker -Role 'RDS-RD-SERVER' Use host plus UnifiedSessionId as the action identity
UnifiedSessionId is unique only on its HostServer, so an ID by itself can select the wrong user elsewhere in the deployment. Re-query immediately before action and require an exact domain-qualified user, collection, host FQDN, session state, and ID. Broker data can lag during failover or network partitions; quser is a useful host-local cross-check but produces localized text and also needs remote rights and firewall reachability.
$sessions = Get-RDUserSession -ConnectionBroker 'rdcb01.contoso.com'
$target = @($sessions | Where-Object { $_.DomainName -eq 'CONTOSO' -and $_.UserName -eq 'alice' -and $_.HostServer -eq 'rdsh01.contoso.com' })
if ($target.Count -ne 1) { throw "Expected exactly one session; found $($target.Count)" }
$target | Select-Object DomainName, UserName, HostServer, UnifiedSessionId, SessionState, CollectionName Notify, disconnect, and log off as three different impacts
Send-RDUserMessage interrupts the user's desktop with text. Disconnect-RDUser leaves applications running and may preserve resource consumption. Invoke-RDUserLogoff closes applications and can destroy unsaved work. These RemoteDesktop cmdlets do not expose dependable WhatIf simulation; omitting Force preserves their confirmation prompt where documented, but confirmation is not target validation. Communicate the UTC deadline, record approval, re-query the tuple, prefer disconnect when appropriate, and verify the outcome. No reboot is normally required.
$target = [pscustomobject]@{ HostServer = 'rdsh01.contoso.com'; UnifiedSessionID = 12; DomainName = 'CONTOSO'; UserName = 'alice' }
$current = Get-RDUserSession -ConnectionBroker 'rdcb01.contoso.com' | Where-Object { $_.HostServer -eq $target.HostServer -and $_.UnifiedSessionId -eq $target.UnifiedSessionID -and $_.DomainName -eq $target.DomainName -and $_.UserName -eq $target.UserName }
$current | Select-Object DomainName, UserName, HostServer, UnifiedSessionId, SessionState
# After approval and exact-user revalidation, notify first. Disconnect and logoff have no WhatIf; do not add -Force casually. Correlate broker state with host-local operational logs
Connection failures can originate in DNS, certificates, gateway and CAP/RAP policy, broker availability, collection membership, licensing, profiles, authentication, or the Session Host. Collect broker and host identity, UTC timestamps, session state, role inventory, and bounded TerminalServices operational logs before restarting services. Remote event access requires firewall and permissions. Restarting a broker or Session Host is disruptive and can trigger failover or disconnect users; evidence collection itself needs no reboot.
$hostName = 'rdsh01.contoso.com'
Get-RDUserSession -ConnectionBroker 'rdcb01.contoso.com' | Where-Object HostServer -eq $hostName
Invoke-Command -ComputerName $hostName -ScriptBlock {
Get-WinEvent -LogName 'Microsoft-Windows-TerminalServices-LocalSessionManager/Operational' -MaxEvents 100 | Select-Object TimeCreated, Id, LevelDisplayName, Message
} Sources and further reading
References
Authoritative documentation used to verify and expand this cheat sheet.
- MicrosoftRemoteDesktop modulelearn.microsoft.com
- MicrosoftGet-RDUserSessionlearn.microsoft.com
- MicrosoftGet-RDSessionCollectionConfigurationlearn.microsoft.com
- MicrosoftDisconnect-RDUserlearn.microsoft.com
- MicrosoftInvoke-RDUserLogofflearn.microsoft.com
- MicrosoftSend-RDUserMessagelearn.microsoft.com
- MicrosoftRemote Desktop Services roleslearn.microsoft.com
Help us improve
Found a typo or missing example?
Tell us what would make this cheat sheet clearer, more complete, or more useful.



