Fix it now
The client reached the end of its attempt without a Remote Desktop listener answering. Microsoft publishes no meaning for the codes the client prints here, so treat them as a prompt rather than a diagnosis, and start with the one cause no configuration can fix: Microsoft states that Windows Home editions cannot serve as Remote Desktop hosts, although they can be used as clients.
Get-ComputerInfo -Property WindowsProductName
Get-Service TermService
netstat -ano | findstr :3389
Get-NetConnectionProfile
- If the edition comes back as Home, stop. Microsoft states Remote Desktop can connect to Windows Professional, Enterprise and Education editions and to Windows Server editions, and that Home cannot host. No registry value adds the host side.
- On a Pro, Enterprise or Education host, turn it on: Start, Settings, System, then Remote Desktop, and switch Enable Remote Desktop on, confirming the prompt.
- Check the listener. TermService should be running and the netstat line should return a listening entry on 3389. A running service with nothing listening is a different problem from a stopped one.
- Note which profile the adapter is on, then enable the Remote Desktop inbound rules in Windows Defender Firewall with Advanced Security for that profile. A rule enabled for Domain does nothing on an adapter classified as Public.
- From the client, run
Test-NetConnection hostname -Port 3389. False means the path or the firewall, not your credentials.
Confirm the name you typed resolves to the host you mean. Resolve-DnsName hostname on the client against ipconfig on the host settles it, and a stale record is a common cause of a perfectly healthy host being unreachable.
If you reach the desktop you are done. If not, the next section covers everything that has to be true before a session can start.
Why it happens
Remote Desktop is not a feature either end can decide to offer. The host runs a service that listens on TCP 3389 and, where enabled, UDP 3389 alongside it. That listener exists only in editions licensed to host sessions. Microsoft’s own wording is that you can use Remote Desktop to connect to computers running Windows Professional, Enterprise and Education editions and Windows Server editions, and that Windows Home editions cannot serve as Remote Desktop hosts although they can be used as clients.
Assuming the host can listen, four more things have to line up: the service is running, the firewall permits the connection on the profile the adapter is currently using, the machine is awake, and the name you typed resolves to its current address. A laptop that has moved to a new network, taken a new address and been reclassified as a Public connection fails the last three at once, which is why this error so often follows a machine being moved rather than anything being changed.
Be careful with the numbers themselves. Microsoft does not publish meanings for the codes the Remote Desktop client prints when a connection fails, and none of them appears in the protocol specification’s error table either. They are worth recording in a ticket because they distinguish one failure from another, and they are not worth reasoning from. Every step here is a test of something you can observe rather than an inference from the digits.
The host runs a Home edition
You have this one if There is no Remote Desktop page with a switch in Settings, and the product name comes back as a Home edition.
- Confirm the edition on the host, not the client. Only the host needs an edition that can serve sessions.
- Upgrade the host to Windows Pro, or use a remote access product that does not rely on the built-in host.
- After an edition upgrade, enable Remote Desktop in Settings, System, Remote Desktop, and confirm the listener appears.
Third-party remote access products work perfectly well on Home and are a legitimate answer where the machine needs nothing else Pro provides.
The listener is not there even though the edition is right
You have this one if The edition is Pro or better, the switch looks on, and nothing is listening on 3389.
- Start the service and set it to start automatically, in the Services console under Remote Desktop Services.
- Check whether Group Policy is turning connections off again. If it is, change the policy rather than the machine, or the next refresh undoes you.
- Recheck with
netstat -ano | findstr :3389and only then look at the network.
The firewall is blocking it on the current profile
You have this one if The host listens, the service runs, and the port test from the client fails.
- Run
Get-NetConnectionProfileon the host and note whether the adapter is Domain, Private or Public. - Enable the Remote Desktop inbound rules in Windows Defender Firewall with Advanced Security for that profile.
- If the network should be trusted, change its category to Private rather than opening the rule on Public.
- Retest with
Test-NetConnection hostname -Port 3389.
The host is asleep or has taken a new address
You have this one if It works when somebody is sitting at the machine and fails overnight, or the name resolves to an address that no longer answers.
- Set the host not to sleep on mains power, in Settings, System, Power.
- Give the host a DHCP reservation so its address is stable, or a DNS record that updates.
- Compare
Resolve-DnsName hostnameon the client withipconfigon the host, and clear a stale entry withipconfig /flushdns.
You are reaching the wrong machine entirely
You have this one if Something answers on 3389 and it is not the desktop you expected, or the name resolves to an address nobody recognises.
- Resolve the name from the client and compare it with the host’s own address.
- Check for a duplicate DNS record left behind by a machine that was rebuilt or renamed.
- Connect by address once, as a test, to confirm the host itself is reachable before fixing the record.
Full reference
What is and is not published about these codes
| Code | What Microsoft publishes |
|---|---|
0x204 |
Nothing. It appears when the client finishes its attempt without a session |
0x904 |
Nothing. It appears in the same dialog, typically where the address could not be turned into a reachable host |
0x104 |
Nothing for the client-displayed code |
0x207 |
Nothing |
0x5000004 |
Nothing. It is reported by the Remote Desktop app rather than by the classic client |
This is worth stating plainly because there are a great many pages that will tell you exactly what each of these means. They are guessing, and the guesses tend to be built backwards from whatever fixed one person’s problem. Record the code so you can tell two tickets apart, and diagnose from the host.
What has to be true on the host
| Requirement | How to check it |
|---|---|
| An edition that can host | Get-ComputerInfo -Property WindowsProductName, or winver |
| Remote Desktop enabled | Start, Settings, System, Remote Desktop |
| The service running | Get-Service TermService |
| Something listening | netstat -ano | findstr :3389 |
| The firewall permitting it on this profile | Get-NetConnectionProfile, then the Remote Desktop rules for that profile |
| The machine awake | Settings, System, Power |
| The name resolving to it | Resolve-DnsName on the client against ipconfig on the host |
Work down that table rather than around it. Six of the seven are one command, and the order matters: there is no point testing a port on a machine whose edition cannot listen, and no point resolving a name for a host that is asleep.
Reaching a host from outside the network
Reach the host through a VPN or a Remote Desktop Gateway. Both put the authentication somewhere designed for it and keep the listener off the public internet.
Do not forward port 3389 from your router to work around this. An exposed Remote Desktop listener is found by automated scanning within hours, and it will appear to work perfectly while that happens.
One session or several
A client edition that can host serves the desktop to one person at a time, which is what somebody connecting to their own machine needs. Where several people must each have their own session on the same machine, that is Remote Desktop Services on Windows Server with the appropriate client access licences, and it is a different design rather than a setting. Products that claim to add multiple sessions to a client edition do it by modifying system files, which is unsupported and breaks at the next feature update.
When the host checks out and it still will not connect
- Test from a second client on the same network, to separate the client from the path.
- Check whether an endpoint security product on the host is blocking the port locally. Its own logs will say so and the Windows firewall will look correct.
- Check whether the host has a second adapter that the name resolves to, which is common on machines with a virtualisation stack installed.
- Try connecting by address rather than by name once, purely to split name resolution from reachability.
- Check the host’s own Remote Desktop connection logs in Event Viewer, under Applications and Services Logs, Microsoft, Windows, TerminalServices-RemoteConnectionManager, Operational.
When a licence is the actual fix
If the host is running a Home edition, this error has no configuration fix. Microsoft states that Home editions cannot serve as Remote Desktop hosts, and no registry value, firewall rule or update adds the host side. The supported answer is to move the machine to Windows Pro, which includes the host role along with domain join, Group Policy and BitLocker. Arco supplies Windows 11 Pro upgrade licences and can confirm the edition and build a machine is currently running before you order, so you are not buying an upgrade for a machine that already has it. If all you need is occasional remote access and nothing else Pro offers, a third-party remote access tool on Home is a legitimate alternative and we will say so.
Every code this article covers
| Code | What it points at | Source |
|---|---|---|
0x204 |
Printed by the Remote Desktop client when the attempt ends without a session. Microsoft publishes no meaning for it, so diagnose from the host rather than from the number | not published by the vendor |
0x904 |
Printed in the same dialog, commonly where the address supplied could not be turned into a reachable host. No published meaning | not published by the vendor |
0x104 |
Printed by the client at the same stage. No published meaning for the client-displayed code | not published by the vendor |
0x207 |
Printed by the client when a connection attempt ends early. No published meaning | not published by the vendor |
0x5000004 |
Reported by the Remote Desktop app rather than the classic client when a connection ends without a session. No published meaning | not published by the vendor |
Confirm the fix worked
- Run
Test-NetConnection hostname -Port 3389from the client and confirm it returns True. - Connect and confirm you reach the desktop, not only the credential prompt.
- On the host, confirm
netstat -ano | findstr :3389shows a listening entry after a reboot. - Check the host’s TerminalServices-RemoteConnectionManager Operational log for the successful connection.
- Reboot the host, let it settle, and confirm the connection still works without anyone logging on locally first.
Questions people ask about this
Can I enable Remote Desktop hosting on Windows Home with a registry edit?
No. Microsoft states that Home editions cannot serve as Remote Desktop hosts. The host components are not present, so setting a value that permits connections changes nothing. Modifications that claim to add them are unsupported and break at the next feature update.
What does 0x204 actually mean?
Microsoft has not published a meaning for it, or for the others in that family. It tells you the client finished its attempt without a session and nothing more, which is why every step here tests something on the host instead.
Do I need a Windows Server licence to be remoted into?
Not for one person connecting to one desktop: a Pro, Enterprise or Education client edition serves that desktop to one person at a time. Server with Remote Desktop Services client access licences is what you need when several people must each have their own session on the same machine.
Why does it work on the office network and not from home?
Because the office path is direct and the home path is not. From outside you need a VPN or a gateway. Forwarding the port on your router will appear to work and will also invite constant automated attacks.
The switch is on but nothing is listening. What now?
Check whether Group Policy is turning connections off again, and whether an endpoint protection product is blocking the port locally. Both are common and both hide behind a switch that looks correct.
