Skip to content

Est. 2011ยทMicrosoft Partner 7033487ยทDelivery under 3 minยทSupport 7 days a week

Your vault is empty.

License Error Event ID 20499

Event ID 20499: RDS logons hang for minutes loading the user configuration

13 min read Updated October 4, 2026 Windows Server: RDS, Hyper-V & Clustering

Fix it now

Remote Desktop Services is waiting on the chain of directory, profile and policy lookups it has to finish before it can hand over a desktop. The host is almost never the slow part. Find which step is taking the time before you change anything, because every fix below makes something worse if aimed at the wrong step.

Run on the Session Host, as the affected user where you can, immediately after a slow logon

gpresult /h C:\temp\gp.html /f
nltest /dsgetdc:contoso.local
nltest /dsgetsite
  1. Open Event Viewer at Applications and Services Logs, Microsoft, Windows, GroupPolicy, Operational. Each client-side extension records its own start and finish, so the slow one is visible by reading the timestamps rather than by guessing.
  2. Measure the profile. A roaming profile is copied across the network before the desktop appears, so its size is added directly to every logon.
  3. Time each path used at logon from the host itself: the profile share, the home directory, script locations and every mapped drive. Measure-Command { Get-ChildItem \\server\share } gives you a number instead of an impression.
  4. Read the report the first command wrote and count the policy objects applying to the user. Remove the ones that no longer do anything.
  5. Confirm the host is authenticating locally. nltest /dsgetdc:contoso.local queries DNS for domain controllers and contacts each to check connectivity, and nltest /dsgetsite returns the site name in use. A controller in another location is your delay.

Set your own baseline before you tune anything. Time a logon on a healthy host with a small profile, then compare. Chasing a published number tells you nothing about your estate.

If one step in the policy log accounts for the delay, fix that and stop. If the time is spread across everything, the next section explains what the host is waiting for and in what order.

Why it happens

Before a desktop is drawn, Remote Desktop Services has to assemble the user’s configuration. It reads the account’s Remote Desktop settings, profile path and home directory from the directory. It processes Group Policy for the user. It loads or copies the profile. It maps drives, deploys printers and runs whatever scripts are attached. Most of that happens in sequence, and each step is at least one round trip to a server. The host itself is idle for nearly all of it.

That sequencing is why a single slow component ruins the whole logon. A home directory on a server that is answering slowly, a mapping to a share that was decommissioned last year, a policy that queries WMI on every logon, a profile that has grown to include a mail cache: any one of them stalls the chain while everything behind it waits. Adding processors to the Session Host does nothing, because the host is not computing.

The Group Policy operational log is the fastest way to find the culprit, because it timestamps each client-side extension separately. Sort a slow logon by elapsed time and the answer is usually the first line. Do that before you change anything: most of the fixes below are trade-offs, and applying the wrong one leaves you with the same slow logon and a new problem.

Microsoft does not publish meanings for the Remote Desktop and profile event numbers people quote for slow logons, this article’s headline number included. Read the text of each entry and the timings in the policy log; those are real measurements. The numbers themselves are not a diagnosis.

The profile is too large to copy at logon

You have this one if Logon time tracks the individual. New accounts are fast, long-serving staff are slow, and the same person is slow on every host.

  1. Measure the profile folder and find what is in it. Cached mail files, browser caches and downloads are the usual weight.
  2. Redirect Documents, Desktop, Pictures and Downloads with folder redirection.
  3. Use the Exclude directories in roaming profile policy for the caches that cannot be redirected, which is mostly things under AppData.
  4. Consider a profile container so the profile is attached rather than copied, if attaching fits how your hosts are built.

Redirected folders are already outside the roaming profile. Windows synchronises them in the background with Offline Files after the user has logged on rather than copying them at logon, so folder redirection cuts logon time on its own and needs no matching exclusion. Use the exclusion policy only for caches you cannot redirect.

Too much Group Policy, evaluated too often

You have this one if The operational log shows a long total spread thinly across many extensions rather than concentrated in one.

  1. Count the objects applying to the user in C:\temp\gp.html and remove those that no longer serve a purpose.
  2. Replace WMI filters with security filtering or organisational unit scoping where you can. WMI filters are evaluated on every logon.
  3. Set drive maps and printer deployments to update rather than replace, so they stop tearing down and rebuilding each time.

A path in the chain is slow or gone

You have this one if The delay is a consistent block of time for everyone, close to a network timeout, and it disappears if you remove one mapping.

  1. Time every path used at logon from the host: Measure-Command { Get-ChildItem \\server\share }.
  2. Remove or repoint mappings to servers that have been decommissioned. A dead mapping costs the full timeout, every session.
  3. Check that DFS referrals hand this host a local target rather than one across a wide area link.

The host is authenticating against a distant domain controller

You have this one if Logons are slow on one site’s hosts and fast on another’s, and the controller answering is in the wrong place.

  1. Run nltest /dsgetdc:contoso.local, which queries DNS for domain controllers and contacts each one, and nltest /dsgetsite, which returns the site name. Compare what comes back with where the host actually is.
  2. Confirm the host’s subnet is defined in Active Directory Sites and Services and associated with the right site.
  3. Fix the site and subnet definitions rather than pinning the host to a named controller, which breaks the next time that controller is rebuilt.

Printer redirection is doing too much work

You have this one if Only users with many local printers are slow, and the delay scales with how many printers they have.

  1. Restrict redirection to the default printer only, which is a per-user-visible change rather than an outage.
  2. Use the Remote Desktop Easy Print driver instead of installing matching drivers on the host.
  3. Remove obsolete print drivers from the Session Hosts. A crowded driver store slows enumeration for everyone on the machine.

Turning client printer redirection off entirely is a per-host computer policy. It removes redirected printing for everyone who connects to that host, on all new sessions, not just the person you are testing. Do it outside working hours on a single host, or scope the test with a filtered policy object, and write down how to reverse it before you apply it.

Full reference

Where the time usually goes

Contributor Why it costs time What it costs you to fix
Roaming profile size Copied across the network before the desktop appears Nothing; redirection and exclusions are policy settings
Number of policy objects Each is evaluated in turn, and WMI filters run every logon Time spent auditing what each one still does
Drive mappings An unreachable share holds the logon for the full timeout Nothing, once you know which mapping it is
Printer redirection Client printers are enumerated and installed while the user waits A visible change for users; scope the test carefully
Domain controller distance Every directory lookup pays the round trip twice over Nothing; it is a sites and subnets correction

Turning impressions into numbers

Run on the Session Host after a slow logon, not from your workstation

Measure-Command { Get-ChildItem \\fileserver\profiles }
Measure-Command { Get-ChildItem \\fileserver\home }
gpresult /h C:\temp\gp.html /f
nltest /dsgetdc:contoso.local

Run these from the host, not from your desk. A path that answers instantly from your machine can be slow from a Session Host in another site, and that difference is often the entire problem. gpresult /h writes an HTML report of what actually applied; /f overwrites the previous one so you can run it repeatedly without renaming files.

Folder redirection and roaming profiles together

This pairing is worth getting right because it is the single largest lever and it is routinely misunderstood. When you deploy folder redirection alongside roaming user profiles, the redirected data is not part of the roaming profile: Windows synchronises it in the background with Offline Files after the user has logged on, rather than copying it at logon and logoff. The user does not wait for it. That is the whole benefit, and it arrives without any matching exclusion setting.

The Exclude directories in roaming profile policy is for the things you cannot redirect, which in practice means caches under AppData: browser profiles, mail caches, and application working directories that regrow on their own. Excluding a folder you have already redirected achieves nothing. Excluding something an application needs across sessions produces a support ticket a fortnight later, so keep the list short and write down why each entry is on it.

What not to do

  • Do not disable client printer redirection on a production host during working hours as a diagnostic. It is a computer policy, it applies to everyone connecting to that host, and it lands on all new sessions.
  • Do not raise timeouts to make a dead mapping stop hurting. You have made the logon slower on purpose and hidden the fault.
  • Do not add CPU or memory before reading the policy log. An idle host with a slow logon is telling you something specific and hardware is not it.
  • Do not pin a Session Host to a named domain controller. It works until that controller is rebuilt, and then it fails in a way nobody remembers configuring.

Measuring the improvement honestly

Test with a user who has a large profile and a long history, not just a fresh account. A new account is fast on a broken host, so a test with one proves nothing. Compare elapsed times in the Group Policy operational log for the same user before and after, and repeat the test at the same time of day: a host that is fine at eleven in the morning and slow at nine has a contention problem rather than a configuration one.

When a licence is the actual fix

Most of what fixes this is free: trim policy, redirect folders, remove dead mappings, correct the site definitions. Two situations turn it into a purchase. If the hosts run a Windows Server release that no longer receives updates, you are no longer getting the profile and session work that later builds carry, and standardising the collection on Windows Server 2025 Standard is the durable answer. If you move to a newer Windows Server version, check your RDS CAL version at the same time: a CAL reaches a session host of its own version or older, so a 2022 CAL will not cover a 2025 host. Neither is a substitute for the tuning above. Do the free work first and you may find the platform question answers itself.

Every code this article covers

Code What it points at Source
Event ID 20499 Not published by Microsoft. It accompanies a session in which Remote Desktop Services spent a long time assembling the user configuration; the timings in the Group Policy operational log are the measurement to work from not published by the vendor
Event ID 39 Not published by Microsoft. A Local Session Manager entry useful only for building a timeline around the slow logon not published by the vendor
Event ID 40 Not published by Microsoft. The companion session entry; read its reason field rather than the number not published by the vendor
Event ID 9009 Not published by Microsoft. It appears as a session tears down and commonly shows up in slow logoff traces not published by the vendor
Event ID 1534 Not published by Microsoft. A User Profile Service entry; open it in the operational log for the detail of your own case not published by the vendor
Event ID 1542 Not published by Microsoft. Another User Profile Service entry from the same range; read the entry, not the number not published by the vendor

Confirm the fix worked

  1. Elapsed times in the Group Policy operational log are lower for the same user, for the same extension you targeted.
  2. A timed logon for an affected user is close to your healthy baseline.
  3. Every path used at logon answers quickly when timed from the host itself.
  4. nltest /dsgetdc: returns a domain controller in the site nltest /dsgetsite reports.
  5. A user with a large profile improves, not only a freshly created test account.

Questions people ask about this

How slow is too slow?

Set your own baseline rather than chasing a published figure. Time a logon on a healthy host with a small profile and compare. What matters is the gap between that and what your users get.

Will adding CPU or memory to the host fix it?

Rarely. The host is waiting on the network and the directory, not computing. Read the elapsed times in the policy log before buying hardware.

Do I need to exclude redirected folders from the roaming profile as well?

No. Redirected data is not part of the roaming profile; Windows synchronises it in the background with Offline Files after logon. Use the exclusion policy only for caches you cannot redirect, such as browser and mail caches under AppData.

Can I just turn off printer redirection to test it?

Not casually. It is a computer policy on the Session Host and it removes redirected printing for everyone connecting to that host on all new sessions. Test on one host outside working hours, or scope it with a filtered policy object, and note how to reverse it first.

Is a profile container worth it?

Often, on a busy Session Host, because attaching a profile avoids copying it. Check what your existing licences already entitle you to before treating it as a purchase.

Related error codes

Was this article helpful?

Your feedback helps us improve our documentation.

Related articles

License Error 0x80042313 and 0x80042314: VSS freeze and thaw timeouts on busy servers Free Fix Event ID 1 and 20 from iScsiPrt: the initiator keeps losing its target Free Fix Event ID 15005 and 0x00000204: RD Gateway cannot bind port 443 for clients Free Fix Event ID 1135: cluster nodes are evicted by dropped heartbeat traffic
โ† Back to Knowledge Base