Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

If the prompt appears when you take control of an existing Remote Desktop Services (RDS) session, configure the Session Host policy Set rules for remote control of Remote Desktop Services user sessions. Choose a mode that allows viewing or full control without the user’s permission only when your organization authorizes that access. This setting is not for the separate security warning shown when opening an RDP file.

First identify which prompt you mean

Windows can show different warnings at different stages. A prompt asking the person already signed in to approve an administrator’s attempt to view or control that session is an RDS remote-control, or shadowing, prompt. An RDP-file security warning appears on the connecting computer when someone opens an .rdp file, before the session is established. The Session Host policy below governs shadowing; it does not suppress the RDP-file warning. See Microsoft’s remote-control troubleshooting guidance and its explanation of RDP-file security warnings.

Choose the right remote-control policy mode

The policy lets an administrator set the level of remote control and whether the user must give permission. Choose the narrowest mode that fits the approved support task. The policy options documented by Microsoft are:

Policy mode What it permits User permission required?
No remote control allowed Does not allow remote control of sessions Not applicable
Full Control with user’s permission View and interact with the session Yes
Full Control without user’s permission View and interact with the session No
View Session with user’s permission View the session without controlling it Yes
View Session without user’s permission View the session without controlling it No

Microsoft lists these modes in its ADMX_TerminalServer Policy CSP documentation. Disabling consent changes who can observe or interact with a user’s session without an approval step. Confirm the access is authorized and appropriate for your support and privacy requirements before selecting a no-permission mode.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Microsoft Windows Server 2025 Standard Edition 64-bit, Base License, 16 Core - OEM
  • 64 bit | 1 Server with 16 or less processor cores | provides 2 VMs
  • For physical or minimally virtualized environments
  • Requires Windows Server 2025 User and/or Device Client Access Licenses (CALs) | No CALs are included
  • Core-based licensing | Additional license packs required for servers with more than 16 processor cores or to add VMs | 2 VMs whenever all processor cores are licensed.
  • Product ships in plain envelope | Activation key is located under scratch-off area on label |Beware of counterfeits | Genuine Windows Server software is branded by Microsoft only.

Configure the policy on the Remote Desktop Session Host

  1. On the intended Remote Desktop Session Host, open the Local Group Policy Editor, or open the applicable domain Group Policy Object using your organization’s normal policy-management process.

  2. Go to Computer Configuration > Administrative Templates > Windows Components > Remote Desktop Services > Remote Desktop Session Host > Connections.

  3. Open Set rules for remote control of Remote Desktop Services user sessions.

    Rank #2
    Windows Server 2025 User CAL 5 pack
    • Offers quick and easy installation on PC
    • The software is licensed for 5 User CAL
  4. Select the approved mode. To allow full control without an approval prompt, select Full Control without user’s permission. To allow observation only without approval, select View Session without user’s permission.

    Free tools Windows power users keep installed

    One-click scans. No signup required.

    Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  5. Apply the policy through your normal Group Policy update process. For an immediate local policy update, Microsoft’s older procedure uses gpupdate /force. Then check the effective policy and test the behavior on the target Windows Server release before treating the change as complete.

Microsoft’s current troubleshooting page identifies this computer policy as the workaround when the user-permission setting does not address the prompt, including the physical-console case described on that page.

Start a shadow session with the required access

To shadow another user’s session, you need Full Control permission or the Remote Control special access right. Microsoft documents the shadow command and the use of query user to find a session ID in its shadow command reference.

  1. Run query user to display available sessions and identify the target user’s session name or ID.

    Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  2. Use shadow with that session name or ID, following the syntax supported on the server. For example, shadow 3 targets session ID 3; substitute the actual ID shown by query user.

    Rank #4
    Microsoft Windows Server 2025 Standard Edition 64-bit, Base License, 24 Core - OEM
    • 64 bit | 1 Server with 24 or less processor cores | provides 2 VMs
    • For physical or minimally virtualized environments
    • Requires Windows Server 2025 User and/or Device Client Access Licenses (CALs) | No CALs are included
    • Core-based licensing | Additional license packs required for servers with more than 16 processor cores or to add VMs | 2 VMs whenever all processor cores are licensed.
    • Product ships in plain envelope | Activation key is located under scratch-off area on label |Beware of counterfeits | Genuine Windows Server software is branded by Microsoft only.
  3. Verify that the session opens with the intended view-only or full-control behavior and that the result matches the configured policy.

Account for console-session differences

Do not assume that a policy setting makes every console session shadowable. Microsoft’s current shadow command reference states: “The console session can neither remotely control another session nor can it be remotely controlled by another session.” Its older procedure for shadowing a Terminal Server session, however, describes a policy configuration for shadowing console session 0 without a prompt. Because those Microsoft documents describe different console behavior, verify the Windows Server version, session type, and supported configuration in the specific environment rather than promising console shadowing as universal.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

If the prompt still appears

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.