Fix it now
Event 1004 is the documented event for this failure: “The Remote Desktop Session Host server cannot issue a client license”, because of a changed or mismatched client licence, insufficient memory, or an internal error. Three things cause it in practice: the licensing mode does not match the CALs, the CAL version is too old, or the licence server was never activated.
- On the licence server open Server Manager, Tools, Remote Desktop Services, Remote Desktop Licensing Manager and read the Installed and Issued columns for every CAL pack.
- Compare the CAL version with the Windows Server version of your Session Hosts. CALs must be the same version or newer; older CALs do not licence a newer host.
- Confirm the host is asking for the type you own. A Per Device host will not consume User CALs, and the reverse is also true.
- If the server shows as not activated, activate it. An unactivated licence server issues only temporary licences, which is Event 18.
- If Per Device CALs really are exhausted, revoke the ones held by retired machines: select the installed Per Device CAL version node, select an issued CAL and use Action, Revoke RDS CAL.
Per User CALs cannot be revoked at all. Revocation is a Per Device feature and is capped at 20 per cent of the installed CALs of a version.
If clients connect and the issued count rises, you are done. If not, the next section explains which event belongs to which machine.
Why it happens
The event that says a Remote Desktop licence could not be issued is Event 1004, written by Microsoft-Windows-TerminalServices-RemoteConnectionManager into the System log on the Session Host. Its symbolic name is EVENT_CANNOT_ISSUE_LICENSE and its text names three possible reasons: a changed or mismatched client licence, insufficient memory, or an internal error. In practice the first of those covers almost every real case.
“Mismatched” does most of the work. There are three ways a request and a pool can fail to match. The mode: a Session Host configured Per Device asks for a Device CAL, and a licence server holding only User CALs has nothing to give it. The version: CALs licence Session Hosts of their own Windows Server version or older, never newer, so Windows Server 2022 CALs will not licence a 2025 host. And the activation state: an unactivated licence server can only issue temporary licences, which is what Event 18 records – “The Remote Desktop license server has not been activated and therefore will only issue temporary licenses.”
Two more events belong to the same investigation and are frequently misread as symptoms of a shortage. Event 57 is TLS_E_CERTIFICATE_VERIFICATION_FAILED: “The certificate chain verification failed with Win32 error code <n>. Use the Telephone method to install the Remote Desktop Services client access licenses.” Event 58 is TLS_E_KEYPACK_INVALID_HASH: “The key-pack hash validation failed with error <n>. Please use Telephone method for CAL installation.” Both are CAL installation failures on the licence server, and both name the same remedy – install the key pack by telephone through the Microsoft Clearinghouse. Neither means you need more CALs.
Event 1067 does not belong to licensing at all, despite turning up in searches for this problem. In the RD Session Host connection events it reads “The terminal server cannot register ‘TERMSRV’ Service Principal Name to be used for server authentication” – a Kerberos and directory fault. As a bare Win32 code it is ERROR_PROCESS_ABORTED, which is what Service Control Manager reports when a service dies on start-up. Either is worth fixing; neither is a CAL that could not be issued.
The licensing mode does not match the CALs installed
You have this one if Event 1004 on the Session Host, and the licence server shows plenty of installed CALs – of the other type.
- Read the mode on the host: LicensingMode is 2 for Per Device and 4 for Per User.
- Set it to match what you own:
Set-RDLicenseConfiguration -Mode PerDevice -ConnectionBroker cb.contoso.local, or the equivalent policy. - Re-run the RD Licensing Diagnoser and reconnect a test client.
This costs nothing and is the first thing to rule out. A mode mismatch looks exactly like a shortage from the client’s side.
The CAL version is older than the Session Host
You have this one if A new Session Host in an estate that has been licensed for years, failing while older hosts are fine.
- Compare the CAL version in Remote Desktop Licensing Manager against the Windows Server version of the failing host.
- Buy CALs matching the newest Session Host version. They will licence older hosts as well, so you do not need one pack per version.
- Before ordering, check the licence server’s own Windows Server version: CALs install only on a licence server running the same version or later.
The licence server was never activated
You have this one if Event 18 on the licence server, and clients that connect for a while and then stop.
- Open Remote Desktop Licensing Manager, select the server and choose Action, Activate Server.
- Choose Automatic connection if the server has outbound TCP 443 to the Microsoft Clearinghouse, otherwise Web Browser or Telephone.
- Install the CAL packs with Action, Install Licenses once activation completes.
An unactivated server is not inert – it hands out temporary licences, which is why the failure appears weeks after the build rather than on day one.
CAL installation is failing on the licence server
You have this one if Event 57 or Event 58 on the licence server while installing a CAL pack.
- Read which one you have: 57 is certificate chain verification, 58 is key-pack hash validation.
- Switch the licence server’s connection method to Telephone, which is the remedy Microsoft names in both events.
- Install the key pack through the Microsoft Clearinghouse operator.
- Do not buy more CALs on the strength of these events – the packs you have are fine, the installation path is not.
Per Device CALs are genuinely exhausted
You have this one if Issued has caught up with Installed on the Per Device packs, and the estate really has that many devices.
- Reclaim CALs held by retired machines: expand the licence server, select the installed Per Device CAL version node, select an issued CAL in the list, then Action, Revoke RDS CAL and confirm.
- Repeat per device; the Status column changes to Revoked. There is no bulk revoke.
- Buy the genuine shortfall and install it through Action, Install Licenses.
A revoked Per Device CAL returns to the available pool immediately and can be issued to another device straight away. The only limit is that no more than 20 per cent of the installed CALs of a version may be revoked at one time.
Full reference
Which event is on which machine
| Event | Source | Log and machine | What it means |
|---|---|---|---|
| 1004 | TerminalServices-RemoteConnectionManager | System log, RD Session Host | The Session Host cannot issue a client licence – mismatched licence, insufficient memory, or an internal error |
| 18 | TerminalServices-Licensing | Licence server | The licence server has not been activated and will only issue temporary licences |
| 57 | TerminalServices-Licensing | Licence server | Certificate chain verification failed; use the Telephone method to install RDS CALs |
| 58 | TerminalServices-Licensing | Licence server | Key-pack hash validation failed; use the Telephone method for CAL installation |
| 1067 | TerminalServices-RemoteConnectionManager | RD Session Host | The terminal server cannot register the TERMSRV service principal name for server authentication. Not a licensing event |
Revoking Per Device CALs, properly
- Open Remote Desktop Licensing Manager on the licence server.
- Expand the licence server node.
- Select the node for the installed RDS Per Device CALs of the version you want to reclaim from.
- Select the issued CAL belonging to the retired device in the list.
- Click Action, then Revoke RDS CAL, and confirm.
- Repeat for each device. The Status column changes to Revoked, and the CAL is immediately available to issue to another device.
There is no bulk revoke, and there is no revoke reached from a CAL pack. Per User CALs cannot be revoked at all – that is a documented difference between the two types, not a limitation of the console.
Version rules, both halves
- RDS CALs licence Session Hosts of their own Windows Server version or earlier. Later CALs work against earlier hosts; earlier CALs never work against later hosts.
- The licence server itself must run the same version of Windows Server as the CALs, or later. Windows Server 2025 CALs cannot be installed on a Windows Server 2022 licence server.
- That second rule is the one that turns a CAL purchase into a server upgrade. Check the licence server’s version before you order, not after the packs arrive.
- There is a related known issue: a Windows Server 2016 RD Licensing server cannot handle Windows Server 2019 CALs, which Microsoft fixed in later licensing components.
Where the licensing data lives
The RD Licensing database is created when the role service is installed and sits by default in %systemroot%\system32\lserver, which on a standard build is C:\Windows\System32\LServer. Event 37 on the licence server names it directly: if the Remote Desktop Licensing service will not start, check that the required groups have the correct permissions on the TermServLicensing registry key and that the DBPath registry value matches the location of the LServer directory.
When the counts are right and it still fails
- Check the Session Host’s own certificate. Refreshing the X509 Certificate values under
HKLM\SYSTEM\CurrentControlSet\Control\Terminal Server\RCMand reactivating is a documented remedy for licensing failures that survive everything else. - Check whether the License server security group policy is enabled on the licence server; if it is, the Session Host’s computer account must be in the Terminal Server Computers local group.
- Confirm the Remote Desktop Licensing service is running, and look for Events 0, 1, 2 and 3 which record it starting, pausing, resuming and stopping.
- Look for Event 20, which warns that only a small number of permanent CALs remain for a product before Event 21 says there are none.
- In a multi-domain deployment, check the trusts between the hosts, the licence server and the users’ domain.
When a licence is the actual fix
Buy only after ruling out the three free explanations: a mode mismatch, a CAL version older than the Session Host, and a licence server that was never activated. Each of those looks exactly like a shortage from the client’s side and none of them is. Revocation is also free and more useful than it is usually given credit for: a revoked Per Device CAL returns to the pool immediately and can be reissued straight away, subject only to a cap of 20 per cent of the installed CALs of a version, so retired machines are worth reclaiming before you count a shortfall. When the shortfall is real, RDS Device CALs suit environments where the same physical machines are used by different people through the day, because you licence the terminal once instead of every person who sits at it. Check the licence server’s Windows Server version before ordering – CALs install only on a licence server running the same version or later. Send Arco your installed and issued counts, your Session Host version and your licence server version, and we will work out the genuine shortfall and supply packs that will install.
Every code this article covers
| Code | What it points at | Source |
|---|---|---|
Event ID 1067 |
Not an RD Licensing event. In the Session Host connection log it reads “The terminal server cannot register ‘TERMSRV’ Service Principal Name to be used for server authentication”. As a bare Win32 code, 1067 is ERROR_PROCESS_ABORTED, “The process terminated unexpectedly” | Microsoft Learn |
Event ID 18 |
TerminalServices-Licensing on the licence server: “The Remote Desktop license server has not been activated and therefore will only issue temporary licenses.” Activate it to issue permanent RDS CALs | Microsoft Learn |
Event ID 57 |
TLS_E_CERTIFICATE_VERIFICATION_FAILED: “The certificate chain verification failed with Win32 error code <n>. Use the Telephone method to install the Remote Desktop Services client access licenses (RDS CALs).” A CAL installation failure | Microsoft Learn |
Event ID 58 |
TLS_E_KEYPACK_INVALID_HASH: “The key-pack hash validation failed with error <n>. Please use Telephone method for CAL installation.” Also a CAL installation failure, not a shortage | Microsoft Learn |
Event ID 1004 |
EVENT_CANNOT_ISSUE_LICENSE, from TerminalServices-RemoteConnectionManager in the System log on the Session Host: “The Remote Desktop Session Host server cannot issue a client license. It was unable to issue the license due to a changed (mismatched) client license, insufficient memory, or an internal error.” This is the event for this failure | Microsoft Learn |
Confirm the fix worked
- Remote Desktop Licensing Manager shows the licence server as activated.
- The installed CAL version is the same as, or newer than, the Windows Server version of every Session Host.
- The licensing mode on the hosts matches the CAL type installed on the server.
- The Issued count rises as test clients connect, and Event 1004 stops recurring.
- Any CALs you revoked show Status Revoked and the available count has risen by the same number.
Questions people ask about this
Is Event ID 1067 an RD Licensing event?
No. In the RD Session Host connection events it means the terminal server could not register the TERMSRV service principal name for server authentication, which is a Kerberos and directory issue. As a plain Win32 code it is ERROR_PROCESS_ABORTED. Neither means a CAL could not be issued – that is Event 1004.
How long before a revoked CAL can be reused?
Immediately. Microsoft states that after you revoke an RDS Per Device CAL it is immediately available to be issued to another client computer or device. The only limit is that no more than 20 per cent of the installed CALs of a given version may be in a revoked state at any one time.
Can I revoke Per User CALs?
No. Revocation is a Per Device feature only. Per User CALs cannot be revoked, which is one of the practical trade-offs between the two types.
Do newer CALs licence older Session Hosts?
Yes, and that is the useful half of the rule. The half people miss is that the licence server must run the same Windows Server version as the CALs or later, so 2025 CALs cannot be installed on a 2022 licence server. Check the server’s version before ordering.
Event 57 and 58 appeared while installing CALs. Do I need more licences?
No. Both are installation failures on the licence server – certificate chain verification and key-pack hash validation – and Microsoft’s remedy for both is to switch the connection method to Telephone and install the key pack through the Microsoft Clearinghouse.
