ServerNova · Docs
Windows RDP

Saving Credentials to Your RDP Connection

By Atticus Sondergaard·Updated June 15, 2026·3 min read

Overview

This guide covers saving credentials for a Windows Remote Desktop Connection (mstsc) so you aren't re-typing a username and password every time you connect to the same machine. It's for ServerNova technicians, and it includes the GUI method, a command-line method, where the credentials actually live, and how to fix the common "saving credentials is disabled" block.

Think before you save. Saved RDP credentials live on the machine you're connecting from. Never save privileged or client/admin credentials on a shared workstation, a client's device, or any machine you don't fully control — anyone with access to that profile can reuse them. For privileged access, prefer our password manager / PAM and connect with credentials pulled from there rather than baking them into the endpoint.

Method 1 — Save in the Remote Desktop Connection client

  1. Open Remote Desktop Connection (Start > type mstsc).

  2. Click Show Options to expand the dialog.

  3. On the General tab, enter the Computer name or IP and the User name.

  4. Check Allow me to save credentials, then click Connect.

  5. In the Windows Security prompt, enter the password and check Remember me, then connect.

On the next connection to that host, RDP fills the credentials automatically. To keep the connection's settings too, click Save As on the General tab to write an .rdp file — it stores the computer and username (the password is saved encrypted to the current Windows user, not in the file itself).

Method 2 — Pre-save in Credential Manager

You can store credentials before ever connecting:

  1. Open Control Panel > Credential Manager (or Start > type Credential Manager).

  2. Select Windows Credentials, then Add a generic credential.

  3. In Internet or network address, enter TERMSRV/COMPUTERNAME (use the same hostname or IP you'll RDP to).

  4. Enter the user name and password, then click OK.

Method 3 — Command line (fast for techs)

The cmdkey utility does the same thing as Method 2 in one line — handy for scripting or quick setup:

REM Save credentials for a host
cmdkey /generic:TERMSRV/SERVER01 /user:DOMAIN\username /pass:YourPassword

REM List saved credentials
cmdkey /list

REM Remove saved credentials for a host
cmdkey /delete:TERMSRV/SERVER01

Use the exact same TERMSRV/<name> target you connect to, or RDP won't match the saved entry.

Where the credentials are stored

Saved RDP credentials are kept in Windows Credential Manager under Windows Credentials, as generic entries named TERMSRV/<hostname>. That's the single place to view, edit, or remove them — all three methods above write to the same store.

Updating or removing saved credentials

  • Update: Credential Manager > Windows Credentials > expand the TERMSRV/... entry > Edit.

  • Remove: expand the entry > Remove, or run cmdkey /delete:TERMSRV/COMPUTERNAME.

If a saved password is wrong (e.g., it was changed), RDP will keep failing silently — delete the stale entry and re-save.

Troubleshooting: "saving credentials is disabled" or "Your credentials did not work"

If the Allow me to save credentials box is greyed out, or saved credentials are ignored and you're prompted every time, Group Policy is usually the cause. Two policies to check (via gpedit.msc locally, or the relevant GPO):

  • Computer Configuration > Administrative Templates > Windows Components > Remote Desktop Services > Remote Desktop Connection Client > "Do not allow passwords to be saved" — if Enabled, it blocks saving. Set to Disabled or Not Configured.

  • Computer Configuration > Administrative Templates > System > Credentials Delegation > "Allow delegating saved credentials" — Enable it and add the target servers (e.g. TERMSRV/* for all hosts, or TERMSRV/SERVER01 for one). For NTLM-only auth, also enable "Allow delegating saved credentials with NTLM-only server authentication" with the same entry.

Run gpupdate /force after changing policy, then retry.

Was this helpful?