Flamingo Raises $4.5M Seed Round

Skip to content

Updated: October 2026

Every admin with more than a handful of servers ends up with a tool that remembers all the RDP connections. For a lot of Windows shops that tool is still Microsoft's own free one. Here's how RDCMan works, how to set it up so a new password means one edit, where its saved credentials put you at risk, and which alternatives teams move to.

What RDCMan Is

RDCMan, short for Remote Desktop Connection Manager, is a free Sysinternals tool that keeps many RDP connections in one window. You build a tree of groups and servers, connect to one or a whole group, and watch every session as a live thumbnail.

Under the hood it uses the Remote Desktop ActiveX control, the same component behind mstsc. RDCMan adds the server tree, the thumbnails and a file that stores your layout and logon settings.

Microsoft's Sysinternals page (updated August 2026) lists it for Windows 11 and later on the client side and Windows Server 2016 and later on servers. There's no installer. You download the zip or run it straight from Sysinternals Live.

The Short History: Retired in 2020, Back in 2021

RDCMan had a bumpy few years, and it explains why some admins still treat it as abandoned.

On 10 March 2020, Microsoft published CVE-2020-0765, an information disclosure flaw. A crafted .rdg file could use an XML external entity to read files from the machine of whoever opened it. Microsoft's advisory said it wasn't planning to fix the bug, called the application deprecated, and told people to use supported Remote Desktop clients instead.

Then it came back. On 10 August 2021, Microsoft revised the same advisory: RDCMan 2.82 was out through Sysinternals and the vulnerability was addressed. It has stayed a Sysinternals tool since and keeps getting new releases.

The takeaway for a support team is simple. Any copy older than 2.82 is the vulnerable one. If someone on the team still runs a version from the 2.7 era because "it works", that's the first thing to replace.

How to Set Up RDCMan Properly

The part people skip is the structure. Get it right once and a password change becomes a single edit instead of forty.

Files, groups, servers. The top level is a file (an .rdg). Inside it sit groups, and inside groups sit servers. A group holds either more groups or servers, never both. A common layout is one file per client or per environment, with groups for roles like domain controllers, file servers and RDS hosts.

Inheritance. Every property page has an "Inherit from parent" box. Set logon, gateway and display settings once at the file or group level and let the servers inherit them. A server only overrides what's different about it.

Bulk adds. The Add Server dialog takes patterns. server[001-15] adds fifteen servers, and {dca,dcb}rack[1-5] expands every combination. You can also import a text file with one server name per line.

Credential profiles. Instead of typing a password into each group, create a profile once and point groups at it. When the password changes, you edit the profile. For shared .rdg files, create a profile with the same name in each admin's own global store, so the shared file carries the profile name and no password.

Gateway settings. If the servers sit behind Remote Desktop Gateway, set it on the group's Gateway Settings tab. Microsoft's FAQ adds one gotcha: gateways must be entered as a fully qualified domain name, or you get errors like 50331656.

URTech's walkthrough covers the groups, thumbnails and settings tabs on a current build.

Where RDCMan Puts You at Risk

The tool itself is small. The risk sits in what it remembers.

Saved passwords. RDCMan encrypts stored passwords with CryptProtectData, which ties them to your Windows user, or with an X509 certificate. That stops someone copying the .rdg file to another machine and reading it. It doesn't stop code running as you. Public red-team tooling documents decrypting RDCMan.settings and .rdg passwords from an unprivileged session, as long as it runs under the user who saved them. One phishing click on an admin's laptop, and every saved server password comes with it.

Domain admin in the tree. The worst case is a group at the top of the tree that inherits a domain admin account down to every server. That turns one compromised workstation into the whole domain. The same pattern shows up in our privileged access management guide: standing admin credentials on a daily-driver machine are what attackers look for first.

Untrusted .rdg files. The 2020 bug came from opening a file someone else crafted. Treat .rdg files like scripts. Don't open ones that arrive by email or from a vendor you haven't checked.

Thumbnail focus. Microsoft's own page warns that keyboard navigation in the thumbnail view can hand focus to a connected server without it being obvious. Typing a command into the wrong production box is a less glamorous risk, but it happens.

Safer Ways to Run It

You can keep RDCMan and still close most of that risk.

  1. Save no domain admin passwords. Store a low-privilege account or nothing, and let RDCMan prompt. Use Connect As when you need elevated rights for one session.
  2. Use a separate admin workstation or jump host. Run RDCMan from a hardened machine that doesn't browse or read email, not from the laptop you use for everything else.
  3. Put RD Gateway in front. Servers shouldn't accept RDP from the internet. A gateway gives you one hardened entry point, and it can require MFA.
  4. Keep Network Level Authentication on. NLA makes the client authenticate before a full session starts. Leave "authentication of the remote machine is required" on in RDCMan's Security Settings too.
  5. Check the version. Anything older than 2.82 still has the 2020 XXE bug.

If you can't do the first two, the credential store is the weak point. That's the moment to look at a tool built around a proper vault, and the checklist in our RMM security guide applies to it as well.

That thread from December 2025 is a fair snapshot of where admins land: RDCMan, Devolutions, Royal TS and mRemoteNG, in roughly that order of mentions.

RDCMan Alternatives

RDCMan is Windows-only, RDP-only and single-user by design. Teams usually move on for one of four reasons: they need SSH and other protocols in the same tree, a shared vault for several admins, macOS support, or audit logs of who connected where.

ToolProtocolsCredential storageGood fit
RDCManRDPEncrypted per user or by certificate, in the .rdgSolo admin, Windows servers, free
mRemoteNGRDP, SSH, VNC, Telnet and moreLocal connection file, optionally password-protectedFree multi-protocol, one admin
Royal TSRDP, SSH, VNC, web and moreDocument-based, can be sharedSmall teams, Windows and macOS
Devolutions Remote Desktop ManagerVery broad protocol listLocal or shared vault, integrates with password managersTeams needing a shared vault and audit trail
Windows AppRDPWork account for cloud services, no sign-in for remote PCsAzure Virtual Desktop, Windows 365 and remote PCs

Windows App needs a note of its own. Microsoft positions it as the replacement for the Remote Desktop client. Its own documentation, updated July 2026, still lists remote PC connections on Windows as a preview and doesn't cover Remote Desktop Services on Windows yet. So for on-premises servers, mstsc or a manager like the ones above is still the practical choice.

In that October 2025 thread, the top reply points at Devolutions for its free solo tier and vault integrations. Another answer settles a common worry: mRemoteNG runs fine on current .NET, not only the older runtime its original poster was worried about.

When a Connection Manager Isn't the Right Tool

A connection manager assumes you reach every machine over RDP from a network that can see it. That holds for a server room. It breaks for laptops at home, clients behind other firewalls, and anything you'd rather not expose on port 3389.

That's where agent-based remote access takes over, which our remote access software roundup covers. OpenFrame, for example, can run a script across a client's devices and collect the output in one place, so a quick check doesn't need an RDP session at all.

RDCMan, in Short

RDCMan is still a solid free way to manage RDP sessions to Windows servers, as long as you run version 2.82 or later. Set it up with inheritance and credential profiles, keep domain admin passwords out of it, and run it from a hardened machine behind RD Gateway. When you need a shared vault, other protocols or audit logs, move to a multi-protocol manager.

Next, see how the same thinking applies to standing admin rights in our guide to privileged access management.

Dmytro Koval

Dmytro Koval

Head of Product Engineering

Hi! My name is Dmytro, but everyone calls me Dima. I’m a Software Developer and together with the development team, I help bring Flamingo to life — putting it on its feet from a technical perspective. Originally from Lviv, Ukraine 🇺🇦, but currently based in Spain, where I’ve been enjoying the blend of great weather, culture, and nature. I’m passionate about the mountains and love traveling — exploring new places and cultures really inspires me. These experiences constantly recharge me and give me a fresh perspective, both personally and professionally.

Related Content

Blog Posts

Product Releases

Podcasts

Webinars

Case Studies

Events

Onboarding Guides

Frequently Asked Questions

RDCMan

RDCMan (Remote Desktop Connection Manager) is a free Microsoft Sysinternals tool that keeps many RDP connections in one window. You organize servers into groups, connect to one server or a whole group at once, and see every session as a live thumbnail. Groups can pass logon, gateway and display settings down to the servers inside them.
Yes. Microsoft deprecated RDCMan in March 2020 when it declined to fix CVE-2020-0765, then brought it back through Sysinternals with version 2.82 in August 2021, which addressed that vulnerability. It is still on the Sysinternals site and runs on Windows 11 and Windows Server 2016 and later. Any copy older than 2.82 should be replaced.
RDCMan encrypts saved passwords to your Windows user with CryptProtectData or to an X509 certificate, so a copied .rdg file is unreadable on another machine. Code running as the same user can decrypt them, though. Avoid saving domain admin passwords, use Connect As for elevated sessions, and run RDCMan from a hardened admin workstation.
It depends on what you outgrew. mRemoteNG and Royal TS add SSH, VNC and other protocols in one tree. Devolutions Remote Desktop Manager adds a shared vault and audit logs for teams. Windows App is Microsoft's client for Azure Virtual Desktop, Windows 365 and remote PCs, but it does not yet cover Remote Desktop Services on Windows.

MSP AI Agents

On a five-person desk, reported deployments show $78,000 to $130,000 in annual direct labor savings, roughly 30% fewer escalations, and 15% to 20% better SLA compliance. Broader MSP adoption data adds ticket handling time cut by 45% and five to 12 points of margin, all from reclaimed capacity rather than headcount cuts.
Yes. In production MSP shops today, 10% to 25% of tickets close before a human opens them. Thread alone has processed 173 million tickets across 750-plus MSP partners at 96% triage accuracy, handing back 490,000-plus technician hours. Agents own the low-risk, high-volume work (password resets, MFA enrollment, known installs, onboarding and offboarding) and flag anything that touches production data or needs judgment for a human to take.

About OpenFrame

OpenFrame isn't built to plug into your stack. It replaces it. Instead of duct-taping a dozen tools together (RMM, MDM, SIEM, patching, remote access, each its own login and bill), we bundle it into one unified platform: RMM, MDM, monitoring, automation, remote access, patch management, security monitoring, and ticketing, plus built-in AI copilots. So "does it integrate with X?" usually means: you won't need X anymore.
Most platforms give you one piece and expect you to bolt the rest on. OpenFrame unifies the whole stack in one place, with AI copilots built in. Fewer logins, fewer bills, less duct tape.
In the cloud, on US soil. Your data stays stateside.
Both. It's built for MSPs and MSSPs alike.