NEO RDP Manager logoNEO RDP Manager
Guide

“Unknown remote connection”: start RDP without the security warning

Why Windows warns when you open an .rdp file, what the warning does – and which ways there are to start your own connections without it.

In short: Windows warns when an .rdp file isn't signed by a trusted publisher. If you start mstsc directly with /v:host instead, there is no file and no warning – mstsc then reads the options from Default.rdp. NEO RDP Manager does exactly that for every connection and restores Default.rdp bit for bit afterwards.

Where does the warning come from?

.rdp files are a popular phishing tool: a crafted file from an email connects to a foreign server and can redirect drives, the clipboard or smart cards to it. Current Windows versions therefore show a notice about an unknown remote connection when you open an unsigned .rdp file, and switch the requested redirections off at first.

That makes sense as protection against foreign files. But if you open dozens of your own servers every day, you get an extra dialog on every start and have to confirm drive or clipboard redirection again each time. Signing with a self-made certificate usually doesn't make the warning go away.

Three ways without the warning

1. Start mstsc directly with the host

Without an .rdp file there is nothing to check – and no warning:

mstsc /v:server01.example.com
mstsc /v:server01.example.com:3390 /admin
mstsc /v:server01.example.com /w:1920 /h:1080
mstsc /v:server01.example.com /f /multimon

All other options – redirections, colour depth, gateway, performance – are read from Documents\Default.rdp, the file mstsc also writes its most recent settings to. The catch: every connection shares this one file.

2. Sign .rdp files with a trusted certificate

In environments with their own PKI, .rdp files can be signed with rdpsign.exe. Signed files show their publisher; if the certificate thumbprint is marked as trusted by group policy, the prompt goes away.

rdpsign /sha256 <certificate thumbprint> server01.rdp

You'll find the policy under Administrative Templates → Windows Components → Remote Desktop Services → Remote Desktop Connection Client. The downside: every change to a file needs a new signature, and the certificate has to be trusted on every client. Microsoft has tightened the handling of .rdp files several times – so test the behaviour in your environment.

3. Use a manager that starts mstsc directly

NEO RDP Manager combines way 1 with options of their own for every connection: it starts mstsc with /v:host and swaps Default.rdp only for the moment of the start.

How NEO RDP Manager does it

  1. It backs up your existing Default.rdp – also as a crash safeguard under %APPDATA%\NeoRDPManager\default_rdp.backup.
  2. It writes the connection's options (resolution, redirections, gateway, RemoteApp …) to Default.rdp – without a password.
  3. It briefly puts the credentials into the Windows Credential Manager (TERMSRV/host) and starts mstsc /v:host.
  4. It restores Default.rdp bit for bit right away and removes the credentials once the connection is set up.
  5. If mstsc writes its settings back to Default.rdp when a session ends, the app undoes that too. After a crash it restores the backup on the next start.
Prefer the classic way? Under Settings → Remote desktop – global display → Launch method choose “Classic via .rdp file” (in the app: „Klassisch über .rdp-Datei“). The app then starts mstsc with a temporary .rdp file – and Windows shows its warning again.

Frequently asked questions

Is it safe to avoid the warning?

The warning protects against foreign .rdp files from emails or downloads. NEO RDP Manager doesn't open foreign files but connections you created yourself or imported on purpose; you decide per connection which redirections are active. You still shouldn't open .rdp files of unknown origin.

Is my own Default.rdp kept?

Yes. The app restores it bit for bit right after starting mstsc and also keeps a backup under %APPDATA%\NeoRDPManager, which it restores on the next start after a crash.

Does this work with RD Gateway and RemoteApp too?

Yes. All of the connection's options reach mstsc through Default.rdp, including gateway, RemoteApp and start program. Separate gateway credentials are also placed in the Credential Manager only briefly.

No warning, every option.

Try NEO RDP Manager with your own servers.