Updated: October 2026
Every admin with more than a handful of servers ends up with a tool that remembers all the RDP connections. For a lot of Windows shops that tool is still Microsoft's own free one. Here's how RDCMan works, how to set it up so a new password means one edit, where its saved credentials put you at risk, and which alternatives teams move to.
What RDCMan Is
RDCMan, short for Remote Desktop Connection Manager, is a free Sysinternals tool that keeps many RDP connections in one window. You build a tree of groups and servers, connect to one or a whole group, and watch every session as a live thumbnail.
Under the hood it uses the Remote Desktop ActiveX control, the same component behind mstsc. RDCMan adds the server tree, the thumbnails and a file that stores your layout and logon settings.
Microsoft's Sysinternals page (updated August 2026) lists it for Windows 11 and later on the client side and Windows Server 2016 and later on servers. There's no installer. You download the zip or run it straight from Sysinternals Live.
The Short History: Retired in 2020, Back in 2021
RDCMan had a bumpy few years, and it explains why some admins still treat it as abandoned.
On 10 March 2020, Microsoft published CVE-2020-0765, an information disclosure flaw. A crafted .rdg file could use an XML external entity to read files from the machine of whoever opened it. Microsoft's advisory said it wasn't planning to fix the bug, called the application deprecated, and told people to use supported Remote Desktop clients instead.
Then it came back. On 10 August 2021, Microsoft revised the same advisory: RDCMan 2.82 was out through Sysinternals and the vulnerability was addressed. It has stayed a Sysinternals tool since and keeps getting new releases.
The takeaway for a support team is simple. Any copy older than 2.82 is the vulnerable one. If someone on the team still runs a version from the 2.7 era because "it works", that's the first thing to replace.
How to Set Up RDCMan Properly
The part people skip is the structure. Get it right once and a password change becomes a single edit instead of forty.
Files, groups, servers. The top level is a file (an .rdg). Inside it sit groups, and inside groups sit servers. A group holds either more groups or servers, never both. A common layout is one file per client or per environment, with groups for roles like domain controllers, file servers and RDS hosts.
Inheritance. Every property page has an "Inherit from parent" box. Set logon, gateway and display settings once at the file or group level and let the servers inherit them. A server only overrides what's different about it.
Bulk adds. The Add Server dialog takes patterns. server[001-15] adds fifteen servers, and {dca,dcb}rack[1-5] expands every combination. You can also import a text file with one server name per line.
Credential profiles. Instead of typing a password into each group, create a profile once and point groups at it. When the password changes, you edit the profile. For shared .rdg files, create a profile with the same name in each admin's own global store, so the shared file carries the profile name and no password.
Gateway settings. If the servers sit behind Remote Desktop Gateway, set it on the group's Gateway Settings tab. Microsoft's FAQ adds one gotcha: gateways must be entered as a fully qualified domain name, or you get errors like 50331656.
URTech's walkthrough covers the groups, thumbnails and settings tabs on a current build.
Where RDCMan Puts You at Risk
The tool itself is small. The risk sits in what it remembers.
Saved passwords. RDCMan encrypts stored passwords with CryptProtectData, which ties them to your Windows user, or with an X509 certificate. That stops someone copying the .rdg file to another machine and reading it. It doesn't stop code running as you. Public red-team tooling documents decrypting RDCMan.settings and .rdg passwords from an unprivileged session, as long as it runs under the user who saved them. One phishing click on an admin's laptop, and every saved server password comes with it.
Domain admin in the tree. The worst case is a group at the top of the tree that inherits a domain admin account down to every server. That turns one compromised workstation into the whole domain. The same pattern shows up in our privileged access management guide: standing admin credentials on a daily-driver machine are what attackers look for first.
Untrusted .rdg files. The 2020 bug came from opening a file someone else crafted. Treat .rdg files like scripts. Don't open ones that arrive by email or from a vendor you haven't checked.
Thumbnail focus. Microsoft's own page warns that keyboard navigation in the thumbnail view can hand focus to a connected server without it being obvious. Typing a command into the wrong production box is a less glamorous risk, but it happens.
Safer Ways to Run It
You can keep RDCMan and still close most of that risk.
- Save no domain admin passwords. Store a low-privilege account or nothing, and let RDCMan prompt. Use Connect As when you need elevated rights for one session.
- Use a separate admin workstation or jump host. Run RDCMan from a hardened machine that doesn't browse or read email, not from the laptop you use for everything else.
- Put RD Gateway in front. Servers shouldn't accept RDP from the internet. A gateway gives you one hardened entry point, and it can require MFA.
- Keep Network Level Authentication on. NLA makes the client authenticate before a full session starts. Leave "authentication of the remote machine is required" on in RDCMan's Security Settings too.
- Check the version. Anything older than 2.82 still has the 2020 XXE bug.
If you can't do the first two, the credential store is the weak point. That's the moment to look at a tool built around a proper vault, and the checklist in our RMM security guide applies to it as well.
That thread from December 2025 is a fair snapshot of where admins land: RDCMan, Devolutions, Royal TS and mRemoteNG, in roughly that order of mentions.
RDCMan Alternatives
RDCMan is Windows-only, RDP-only and single-user by design. Teams usually move on for one of four reasons: they need SSH and other protocols in the same tree, a shared vault for several admins, macOS support, or audit logs of who connected where.
| Tool | Protocols | Credential storage | Good fit |
|---|---|---|---|
| RDCMan | RDP | Encrypted per user or by certificate, in the .rdg | Solo admin, Windows servers, free |
| mRemoteNG | RDP, SSH, VNC, Telnet and more | Local connection file, optionally password-protected | Free multi-protocol, one admin |
| Royal TS | RDP, SSH, VNC, web and more | Document-based, can be shared | Small teams, Windows and macOS |
| Devolutions Remote Desktop Manager | Very broad protocol list | Local or shared vault, integrates with password managers | Teams needing a shared vault and audit trail |
| Windows App | RDP | Work account for cloud services, no sign-in for remote PCs | Azure Virtual Desktop, Windows 365 and remote PCs |
Windows App needs a note of its own. Microsoft positions it as the replacement for the Remote Desktop client. Its own documentation, updated July 2026, still lists remote PC connections on Windows as a preview and doesn't cover Remote Desktop Services on Windows yet. So for on-premises servers, mstsc or a manager like the ones above is still the practical choice.
In that October 2025 thread, the top reply points at Devolutions for its free solo tier and vault integrations. Another answer settles a common worry: mRemoteNG runs fine on current .NET, not only the older runtime its original poster was worried about.
When a Connection Manager Isn't the Right Tool
A connection manager assumes you reach every machine over RDP from a network that can see it. That holds for a server room. It breaks for laptops at home, clients behind other firewalls, and anything you'd rather not expose on port 3389.
That's where agent-based remote access takes over, which our remote access software roundup covers. OpenFrame, for example, can run a script across a client's devices and collect the output in one place, so a quick check doesn't need an RDP session at all.
RDCMan, in Short
RDCMan is still a solid free way to manage RDP sessions to Windows servers, as long as you run version 2.82 or later. Set it up with inheritance and credential profiles, keep domain admin passwords out of it, and run it from a hardened machine behind RD Gateway. When you need a shared vault, other protocols or audit logs, move to a multi-protocol manager.
Next, see how the same thinking applies to standing admin rights in our guide to privileged access management.
Dmytro Koval
Head of Product Engineering
Hi! My name is Dmytro, but everyone calls me Dima. I’m a Software Developer and together with the development team, I help bring Flamingo to life — putting it on its feet from a technical perspective. Originally from Lviv, Ukraine 🇺🇦, but currently based in Spain, where I’ve been enjoying the blend of great weather, culture, and nature. I’m passionate about the mountains and love traveling — exploring new places and cultures really inspires me. These experiences constantly recharge me and give me a fresh perspective, both personally and professionally.
