Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

To manage a workgroup or otherwise untrusted Windows Server in Server Manager, enable remote management on the target, add that server to the management computer’s WinRM TrustedHosts list when using workgroup/NTLM authentication, and confirm firewall, credentials, and WinRM settings. A TrustedHosts entry does not authenticate the server, so limit it to the specific computers you intend to manage.

Before you start

Microsoft lists Server Manager applicability for Windows Server 2016, 2019, 2022, and 2025. Older releases may need additional updates or version-specific steps. See Microsoft’s remote management guidance and Server Manager overview.

  • Identify the target server’s Windows Server version and name.
  • Sign in with an account that has the necessary rights on the target.
  • Run PowerShell elevated on the computer where Server Manager is running for the TrustedHosts change.

Enable remote management on the target server

Remote management must be enabled on the server you want to manage. Microsoft documents both a graphical route and an elevated command-line route.

Use Server Manager

  1. On the target server, open Server Manager and select Local Server.
  2. Select the remote management property and enable remote management.

Use an elevated command prompt

On the target, run:

Configure-SMremoting.exe -enable

To inspect or turn off the setting, use Configure-SMremoting.exe -get or Configure-SMremoting.exe -disable, respectively. These settings apply to Server Manager and Windows PowerShell components that use WinRM; they do not configure every Windows remote-management component, including those that use DCOM. Microsoft documents the setting in its remote management instructions.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Add the workgroup server to TrustedHosts

For a workgroup server using NTLM authentication, add its name to TrustedHosts on the computer running Server Manager. Microsoft’s documented example is:

Set-Item wsman:localhostClientTrustedHosts Server01 -Concatenate -Force

Replace Server01 with the target’s actual name. The -Concatenate option appends the host rather than replacing the existing list. Check your current entries before changing them, and keep the list limited to the specific hosts needed.

TrustedHosts is not a mechanism for authenticating the remote computer. Microsoft warns: “The computers in the trusted hosts list aren’t authenticated. The client might send credential information to those computers.” See Microsoft’s WinRM installation and configuration guidance.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Microsoft’s Windows Admin Center troubleshooting guidance includes a wildcard example, but a wildcard such as * trusts a broader set of destinations than a host-specific entry. Use specific hostnames or addresses instead.

Check firewall and network conditions

Whether you need to change the target’s inbound Windows Remote Management (HTTP-In) firewall rule depends on the network. Microsoft says to check whether the management computer and target are on the same subnet or the target uses a Private network profile. If neither condition applies, explicitly permit the relevant remote computers in that inbound rule. Restrict access to intended management clients where practical; see Microsoft’s instructions for adding servers to Server Manager.

Add the server and verify manageability

  1. In Server Manager, add the target server to the managed server pool using its server name.
  2. Supply credentials with the required rights on the target. Microsoft’s workgroup guidance notes that the account may need to belong to the target’s local Administrators group; some scenarios also call for membership in Remote Management Users.
  3. Refresh the All Servers view and check the server’s manageability status.

Server Manager can add remote servers to a managed pool, organize them into custom groups, manage supported roles and features, and launch tools such as PowerShell and MMC snap-ins. Microsoft describes these capabilities in its Server Manager overview.

Troubleshoot “Credentials not valid” or failed data collection

If Server Manager reports Credentials not valid or cannot collect data, check the relevant settings in order rather than broadening trust or firewall access indiscriminately.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  1. Account and rights: Confirm the credentials are for the target and that the account has the required local permissions. Check the target’s local Administrators membership and, where applicable, Remote Management Users membership.
  2. TrustedHosts: In a workgroup/NTLM setup, verify that the target’s correct name or address is in the client’s TrustedHosts list. Ensure the change did not overwrite other needed entries.
  3. Firewall and network: Confirm the target’s inbound WinRM rule allows the management client. Review subnet and network-profile conditions.
  4. Listener, authentication, and port: Verify the target’s actual WinRM listener and authentication configuration. Microsoft documents default WinRM ports of HTTP 5985 and HTTPS 5986, but customized ports or authentication settings can prevent Server Manager from communicating. Server Manager relies on default WinRM listener settings, so do not assume those defaults are present in a modified environment.
  5. Refresh: Refresh All Servers and check the manageability status again after correcting a setting.

For official workgroup-server steps, consult Microsoft’s server-addition guidance; for WinRM defaults and configuration, see its WinRM documentation.

Rank #4
Sale
Mastering Active Directory: Design, deploy, and protect Active Directory Domain Services for Windows Server 2022
  • Mastering Active Directory: Design, deploy, and protect Active Directory Domain Services for Windows Server 2022, 3rd Edition
  • ABIS BOOK
  • Packt Publishing
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Domain and workgroup connections are not the same

The TrustedHosts step is specifically relevant to workgroup or other NTLM scenarios. Domain-managed servers may use Kerberos instead; do not add a domain server to TrustedHosts automatically just because it is remote. In either case, the target must be configured for remote management, and network access, credentials, listener configuration, and the applicable authentication method must allow communication.

When to consider another management tool

Server Manager is suitable for its supported inventory, roles, features, and included management tools. Microsoft describes Windows Admin Center as a modern evolution of in-box tools such as Server Manager and MMC, alongside other management solutions. It is an option for broader management needs, not a prerequisite for adding an untrusted server to Server Manager. See Microsoft’s Windows Admin Center overview.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.