Fix Azure VM RDP Connection Failed: NSG Rules, Run Command and Bastion
Cannot RDP into an Azure Windows VM? Check the NSG rule, test the port, use Run Command to repair RDP inside the VM and fall back to Bastion.
Common Symptoms and Quick Fixes
| Symptom | Likely Cause | Quick Fix |
|---|---|---|
| RDP times out | NSG has no allow rule for 3389 | Add an inbound rule for your IP |
| Connection works then drops | Remote Desktop service stopped | Start TermService with Run Command |
| Credentials rejected | Wrong or expired password | Reset password in the portal |
Method 1: Check and Add the NSG Rule
Replace the resource group, NSG name and IP with yours.
az network nsg rule list -g MyRG --nsg-name MyNSG -o table
az network nsg rule create -g MyRG --nsg-name MyNSG -n Allow-RDP --priority 1000 --access Allow --protocol Tcp --direction Inbound --destination-port-ranges 3389 --source-address-prefixes 203.0.113.25/32
Method 2: Test the Port from Your PC
TcpTestSucceeded must be True.
Test-NetConnection 20.50.10.5 -Port 3389
Method 3: Repair RDP Inside the VM with Run Command
Run Command works even when RDP does not.
az vm run-command invoke -g MyRG -n MyVM --command-id RunPowerShellScript --scripts "Set-ItemProperty 'HKLM:\System\CurrentControlSet\Control\Terminal Server' -Name fDenyTSConnections -Value 0; Enable-NetFirewallRule -DisplayGroup 'Remote Desktop'; Start-Service TermService"
Method 4: Use Azure Bastion or Reset the Password
Azure Bastion connects over TLS from the portal without a public RDP port. If credentials fail, open the VM > Help > Reset password.
Pro Tip for AdministratorsDo not leave 3389 open to the internet. Use Bastion or Just-in-Time VM access instead.
Frequently Asked Questions (FAQ)
Q: Do I need a public IP?
Not with Azure Bastion. It connects to the private IP of the VM.
Q: Does Run Command need a working RDP?
No. It uses the Azure VM agent, so the agent must be running.