The Tool Desk
Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →If the prompt appears when you take control of an existing Remote Desktop Services (RDS) session, configure the Session Host policy Set rules for remote control of Remote Desktop Services user sessions. Choose a mode that allows viewing or full control without the user’s permission only when your organization authorizes that access. This setting is not for the separate security warning shown when opening an RDP file.
First identify which prompt you mean
Windows can show different warnings at different stages. A prompt asking the person already signed in to approve an administrator’s attempt to view or control that session is an RDS remote-control, or shadowing, prompt. An RDP-file security warning appears on the connecting computer when someone opens an .rdp file, before the session is established. The Session Host policy below governs shadowing; it does not suppress the RDP-file warning. See Microsoft’s remote-control troubleshooting guidance and its explanation of RDP-file security warnings.
Choose the right remote-control policy mode
The policy lets an administrator set the level of remote control and whether the user must give permission. Choose the narrowest mode that fits the approved support task. The policy options documented by Microsoft are:
| Policy mode | What it permits | User permission required? |
|---|---|---|
| No remote control allowed | Does not allow remote control of sessions | Not applicable |
| Full Control with user’s permission | View and interact with the session | Yes |
| Full Control without user’s permission | View and interact with the session | No |
| View Session with user’s permission | View the session without controlling it | Yes |
| View Session without user’s permission | View the session without controlling it | No |
Microsoft lists these modes in its ADMX_TerminalServer Policy CSP documentation. Disabling consent changes who can observe or interact with a user’s session without an approval step. Confirm the access is authorized and appropriate for your support and privacy requirements before selecting a no-permission mode.
#1 Best Overall
- 64 bit | 1 Server with 16 or less processor cores | provides 2 VMs
- For physical or minimally virtualized environments
- Requires Windows Server 2025 User and/or Device Client Access Licenses (CALs) | No CALs are included
- Core-based licensing | Additional license packs required for servers with more than 16 processor cores or to add VMs | 2 VMs whenever all processor cores are licensed.
- Product ships in plain envelope | Activation key is located under scratch-off area on label |Beware of counterfeits | Genuine Windows Server software is branded by Microsoft only.
Configure the policy on the Remote Desktop Session Host
-
On the intended Remote Desktop Session Host, open the Local Group Policy Editor, or open the applicable domain Group Policy Object using your organization’s normal policy-management process.
-
Go to Computer Configuration > Administrative Templates > Windows Components > Remote Desktop Services > Remote Desktop Session Host > Connections.
-
Open Set rules for remote control of Remote Desktop Services user sessions.
Rank #2
Windows Server 2025 User CAL 5 pack- Offers quick and easy installation on PC
- The software is licensed for 5 User CAL
-
Select the approved mode. To allow full control without an approval prompt, select Full Control without user’s permission. To allow observation only without approval, select View Session without user’s permission.
Free tools Windows power users keep installed
One-click scans. No signup required.
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy. -
Apply the policy through your normal Group Policy update process. For an immediate local policy update, Microsoft’s older procedure uses
gpupdate /force. Then check the effective policy and test the behavior on the target Windows Server release before treating the change as complete.
Microsoft’s current troubleshooting page identifies this computer policy as the workaround when the user-permission setting does not address the prompt, including the physical-console case described on that page.
Rank #3
- Server 2022 Standard 16 Core
Start a shadow session with the required access
To shadow another user’s session, you need Full Control permission or the Remote Control special access right. Microsoft documents the shadow command and the use of query user to find a session ID in its shadow command reference.
-
Run
query userto display available sessions and identify the target user’s session name or ID.Quick wins for a faster PC:
Clear out junk files and repair common Windows errorsFree Scan →Scan for outdated or missing drivers - takes under a minuteDriver Scan →Repair Windows errors before they cause bigger problemsFix Now →Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy. -
Use
shadowwith that session name or ID, following the syntax supported on the server. For example,shadow 3targets session ID 3; substitute the actual ID shown byquery user.Rank #4
Microsoft Windows Server 2025 Standard Edition 64-bit, Base License, 24 Core - OEM- 64 bit | 1 Server with 24 or less processor cores | provides 2 VMs
- For physical or minimally virtualized environments
- Requires Windows Server 2025 User and/or Device Client Access Licenses (CALs) | No CALs are included
- Core-based licensing | Additional license packs required for servers with more than 16 processor cores or to add VMs | 2 VMs whenever all processor cores are licensed.
- Product ships in plain envelope | Activation key is located under scratch-off area on label |Beware of counterfeits | Genuine Windows Server software is branded by Microsoft only.
-
Verify that the session opens with the intended view-only or full-control behavior and that the result matches the configured policy.
Account for console-session differences
Do not assume that a policy setting makes every console session shadowable. Microsoft’s current shadow command reference states: “The console session can neither remotely control another session nor can it be remotely controlled by another session.” Its older procedure for shadowing a Terminal Server session, however, describes a policy configuration for shadowing console session 0 without a prompt. Because those Microsoft documents describe different console behavior, verify the Windows Server version, session type, and supported configuration in the specific environment rather than promising console shadowing as universal.
If the prompt still appears
-
Recheck the prompt type. The policy addresses remote control of an existing RDS session, not an RDP-file warning displayed before connecting.
Do these 3 things before closing this tab:
1Scan for outdated or missing drivers - takes under a minute2Repair Windows errors before they cause bigger problems3Fix the driver behind crashes, sound loss and screen glitchesSpecial offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.Best Value
Windows Server 2025 User CAL- Unlock all the features by installing this product on PC
- The software is licensed for 1 User CAL
-
Check policy scope and effective settings. Confirm the setting is applied to the intended Session Host and that the selected mode is the one approved for the task.
-
Check session permissions. Confirm the administrator has Full Control permission or Remote Control special access for the target session.
-
Check whether the target is a console session. Microsoft’s current command reference and older procedure differ on console behavior; test the precise server release and session type.
Quick Recap
Bestseller No. 2SaleBestseller No. 3Bestseller No. 5
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

