The essentials

Quick reference

One focused task per row. Jump to the related section for complete, working examples.

UseSyntaxExamples
Check RDS cmdletsGet-Module -ListAvailable 'RemoteDesktop' | Select-Object Name, Version, PathView examples
List deployment serversGet-RDServer -ConnectionBroker 'rdcb01.contoso.com' | Sort-Object ServerView examples
List session hostsGet-RDServer -ConnectionBroker 'rdcb01.contoso.com' ` -Role 'RDS-RD-SERVER'View examples
List session collectionsGet-RDSessionCollection -ConnectionBroker 'rdcb01.contoso.com' | Sort-Object CollectionNameView examples
List collection hostsGet-RDSessionHost -CollectionName 'Finance Apps' ` -ConnectionBroker 'rdcb01.contoso.com'View examples
Inspect connection policyGet-RDSessionCollectionConfiguration -CollectionName ` 'Finance Apps' -Connection -ConnectionBroker ` 'rdcb01.contoso.com'View examples
Inspect security policyGet-RDSessionCollectionConfiguration -CollectionName ` 'Finance Apps' -Security -ConnectionBroker ` 'rdcb01.contoso.com'View examples
Inspect authorized groupsGet-RDSessionCollectionConfiguration -CollectionName ` 'Finance Apps' -UserGroup -ConnectionBroker ` 'rdcb01.contoso.com'View examples
List published RemoteAppsGet-RDRemoteApp -CollectionName 'Finance Apps' ` -ConnectionBroker 'rdcb01.contoso.com'View examples
Inspect RDS licensingGet-RDLicenseConfiguration -ConnectionBroker ` 'rdcb01.contoso.com'View examples
List deployment sessionsGet-RDUserSession -ConnectionBroker 'rdcb01.contoso.com' | Sort-Object HostServer, UnifiedSessionIdView examples
List collection sessionsGet-RDUserSession -CollectionName 'Finance Apps' ` -ConnectionBroker 'rdcb01.contoso.com'View examples
Resolve one user's sessionsGet-RDUserSession -ConnectionBroker 'rdcb01.contoso.com' | Where-Object { $_.DomainName -eq 'CONTOSO' -and $_.UserName -eq 'alice' }View examples
Query host-local sessionsquser.exe /server:rdsh01.contoso.comView examples
Notify one sessionSend-RDUserMessage -HostServer 'rdsh01.contoso.com' ` -UnifiedSessionID 12 -MessageTitle 'Maintenance' ` -MessageBody 'Save work by 22:00 UTC.'View examples
Disconnect one sessionDisconnect-RDUser -HostServer 'rdsh01.contoso.com' ` -UnifiedSessionID 12View examples
Log off one sessionInvoke-RDUserLogoff -HostServer 'rdsh01.contoso.com' ` -UnifiedSessionID 12View examples
Read Session Host eventsGet-WinEvent -LogName ` 'Microsoft-Windows-TerminalServices-LocalSessionManager/Operational' ` -MaxEvents 100View examples

Remote Desktop Services is a deployment of broker, session host, web, gateway, licensing, and sometimes virtualization roles—not merely the RDP protocol. Resolve the authoritative RD Connection Broker, collection, host FQDN, user, and host-local UnifiedSessionId before acting. Disconnect preserves applications; logoff closes them and can lose unsaved work. The RemoteDesktop module targets Windows Server RDS deployments and requires installed management tools, domain connectivity, and delegated deployment permissions.

Step by step

Detailed examples

01

Query the authoritative broker with explicit FQDNs

The RemoteDesktop module is installed with Windows Server RDS management tools and is distinct from the similarly named RemoteDesktopServices module. Its deployment cmdlets expect an existing Windows Server RDS deployment, normally joined to Active Directory. Run from a supported management host with DNS, WinRM, broker database, and delegated RDS permissions. Read operations usually need no reboot or elevation when rights are delegated, but local administrator alone does not guarantee deployment authority.

Establish module, broker, server, and role identity
Get-Module -ListAvailable RemoteDesktop | Select-Object Name, Version, Path
$broker = 'rdcb01.contoso.com'
Get-RDServer -ConnectionBroker $broker | Sort-Object Server | Select-Object Server, Roles
Back to quick reference ↑
02

Read every configuration facet instead of trusting a collection name

A collection ties session hosts to access, connection, security, load-balancing, client-redirection, and profile settings. Query the host membership plus each parameter set of Get-RDSessionCollectionConfiguration. Read cmdlets are observational and do not support WhatIf. Set-RDSessionCollectionConfiguration and membership cmdlets can disconnect users, change capacity, or alter security and do not provide a universal safe simulation; stage and approve them with a rollback and broker recovery path.

Capture a collection configuration baseline
$p = @{ CollectionName = 'Finance Apps'; ConnectionBroker = 'rdcb01.contoso.com' }
Get-RDSessionHost @p
Get-RDSessionCollectionConfiguration @p -Connection
Get-RDSessionCollectionConfiguration @p -Security
Get-RDSessionCollectionConfiguration @p -LoadBalancing
Get-RDSessionCollectionConfiguration @p -Client
Back to quick reference ↑
03

Audit authorization separately from application publication

Collection user groups define who may connect; RemoteApp publication defines which programs the collection exposes. Neither replaces NTFS, share, application, or database authorization inside a session. Resolve nested AD group membership separately, review application paths and aliases, and test as a representative non-admin user. Publishing or removing an app changes user-visible service and may break feeds; some RDS mutation cmdlets lack WhatIf, so a maintenance and rollback plan is required.

Compare authorized principals and published applications
$p = @{ CollectionName = 'Finance Apps'; ConnectionBroker = 'rdcb01.contoso.com' }
Get-RDSessionCollectionConfiguration @p -UserGroup
Get-RDRemoteApp @p | Select-Object CollectionName, Alias, DisplayName, FilePath, ShowInWebAccess
Back to quick reference ↑
04

Verify licensing configuration before grace periods become outages

Get-RDLicenseConfiguration reports the deployment licensing mode and registered licensing servers, but it does not prove activation, CAL availability, discovery, firewall access, or policy consistency on every Session Host. Correlate it with RD Licensing Diagnoser and relevant event logs. RDS licensing and role changes require Windows Server editions and roles, domain planning, administrative rights, and can require restarts; do not improvise registry fixes or reset grace-period data.

Capture deployment and licensing context
$broker = 'rdcb01.contoso.com'
Get-RDLicenseConfiguration -ConnectionBroker $broker
Get-RDServer -ConnectionBroker $broker -Role 'RDS-LICENSING'
Get-RDServer -ConnectionBroker $broker -Role 'RDS-RD-SERVER'
Back to quick reference ↑
05

Use host plus UnifiedSessionId as the action identity

UnifiedSessionId is unique only on its HostServer, so an ID by itself can select the wrong user elsewhere in the deployment. Re-query immediately before action and require an exact domain-qualified user, collection, host FQDN, session state, and ID. Broker data can lag during failover or network partitions; quser is a useful host-local cross-check but produces localized text and also needs remote rights and firewall reachability.

Resolve and revalidate one exact session
$sessions = Get-RDUserSession -ConnectionBroker 'rdcb01.contoso.com'
$target = @($sessions | Where-Object { $_.DomainName -eq 'CONTOSO' -and $_.UserName -eq 'alice' -and $_.HostServer -eq 'rdsh01.contoso.com' })
if ($target.Count -ne 1) { throw "Expected exactly one session; found $($target.Count)" }
$target | Select-Object DomainName, UserName, HostServer, UnifiedSessionId, SessionState, CollectionName
Back to quick reference ↑
06

Notify, disconnect, and log off as three different impacts

Send-RDUserMessage interrupts the user's desktop with text. Disconnect-RDUser leaves applications running and may preserve resource consumption. Invoke-RDUserLogoff closes applications and can destroy unsaved work. These RemoteDesktop cmdlets do not expose dependable WhatIf simulation; omitting Force preserves their confirmation prompt where documented, but confirmation is not target validation. Communicate the UTC deadline, record approval, re-query the tuple, prefer disconnect when appropriate, and verify the outcome. No reboot is normally required.

Prepare an intervention without executing it
$target = [pscustomobject]@{ HostServer = 'rdsh01.contoso.com'; UnifiedSessionID = 12; DomainName = 'CONTOSO'; UserName = 'alice' }
$current = Get-RDUserSession -ConnectionBroker 'rdcb01.contoso.com' | Where-Object { $_.HostServer -eq $target.HostServer -and $_.UnifiedSessionId -eq $target.UnifiedSessionID -and $_.DomainName -eq $target.DomainName -and $_.UserName -eq $target.UserName }
$current | Select-Object DomainName, UserName, HostServer, UnifiedSessionId, SessionState
# After approval and exact-user revalidation, notify first. Disconnect and logoff have no WhatIf; do not add -Force casually.
Back to quick reference ↑
07

Correlate broker state with host-local operational logs

Connection failures can originate in DNS, certificates, gateway and CAP/RAP policy, broker availability, collection membership, licensing, profiles, authentication, or the Session Host. Collect broker and host identity, UTC timestamps, session state, role inventory, and bounded TerminalServices operational logs before restarting services. Remote event access requires firewall and permissions. Restarting a broker or Session Host is disruptive and can trigger failover or disconnect users; evidence collection itself needs no reboot.

Collect host-local session evidence
$hostName = 'rdsh01.contoso.com'
Get-RDUserSession -ConnectionBroker 'rdcb01.contoso.com' | Where-Object HostServer -eq $hostName
Invoke-Command -ComputerName $hostName -ScriptBlock {
  Get-WinEvent -LogName 'Microsoft-Windows-TerminalServices-LocalSessionManager/Operational' -MaxEvents 100 | Select-Object TimeCreated, Id, LevelDisplayName, Message
}
Back to quick reference ↑

Sources and further reading

References

Authoritative documentation used to verify and expand this cheat sheet.

  1. MicrosoftRemoteDesktop modulelearn.microsoft.com
  2. MicrosoftGet-RDUserSessionlearn.microsoft.com
  3. MicrosoftGet-RDSessionCollectionConfigurationlearn.microsoft.com
  4. MicrosoftDisconnect-RDUserlearn.microsoft.com
  5. MicrosoftInvoke-RDUserLogofflearn.microsoft.com
  6. MicrosoftSend-RDUserMessagelearn.microsoft.com
  7. MicrosoftRemote Desktop Services roleslearn.microsoft.com

Help us improve

Found a typo or missing example?

Tell us what would make this cheat sheet clearer, more complete, or more useful.

Share feedback