Remote Desktop certificate warnings

You double-click your Remote Desktop shortcut to reach your work computer or your company's remote desktop server, and instead of connecting, Windows stops you with a warning box. Maybe two of them, using phrases like "could harm your local or remote computer" and "the identity of the remote computer cannot be verified". That's alarming enough that plenty of people stop right there and write in, which is a perfectly sensible instinct. Here's what those boxes actually mean, and what to do about them.

The short version: On a company Remote Desktop connection you use regularly, these warnings are routine. The main one appears because the server identifies itself with a certificate it created for itself, rather than one from an authority Windows already recognizes — so Windows asks you instead of deciding for you. On that one, tick "Don't ask me again for connections to this computer" and click Yes, and it will stop appearing.

Why a company Remote Desktop connection warns you

When you connect with Remote Desktop, the computer on the other end has to prove who it is. It does that with a certificate — a small digital ID card that travels with the connection.

Certificates for public websites are issued by a handful of organizations Windows already trusts, which is why your bank's website never warns you. A Remote Desktop server inside a company is different. Windows automatically generates a certificate for Remote Desktop on each machine, and that certificate is self-signed: the server issued it to itself. It works perfectly well — but nobody outside the building is vouching for it. Your computer was never told to trust that particular ID card, so it does the honest thing and asks you.

That's the whole story behind a warning on a familiar internal server. It isn't a sign that the server is compromised, that something is broken, or that you did anything wrong.

Why some connections never warn you at all. On a company network, Windows can often confirm a server's identity through the domain sign-in system without needing a certificate it recognizes. That's why some internal connections have never prompted you — and why a prompt suddenly appearing on one that never prompted before is worth reporting.

Is my session still encrypted?

On a normally configured connection, yes. It's worth being precise about why, because the certificate isn't itself the encryption. The certificate identifies the server and is used to set up the keys that encrypt the session — and that encryption happens whether or not Windows recognizes who issued the certificate. The warning isn't telling you your session is traveling in the clear.

We'd rather you understand the limit of that reassurance than simply be told it's nothing. Encryption stops the traffic being read along the way. It doesn't, on its own, prove who is on the other end. Someone who managed to insert themselves between you and your server could present a self-made certificate of their own, and you'd see a warning that looks exactly like the usual one.

So the useful question is never "is there a warning?" It's: is this the connection I use every day, to the server I expect, started from my own shortcut? When the answer is yes, the warning is routine. When it isn't, that's when it's worth stopping.

The certificate warning — the one you can turn off

This is the box most people are asking about, and it's the one where ticking "don't ask me again" genuinely works. It appears once Windows has started connecting to the server. Its heading reads:

"The identity of the remote computer cannot be verified. Do you want to connect anyway?"

Followed by: "The remote computer could not be authenticated due to problems with its security certificate. It may be unsafe to proceed."

The box names the computer you asked for and the name on the server's certificate, and under Certificate errors it lists what Windows objected to. On an ordinary internal server, that line is:

"The certificate is not from a trusted certifying authority."

That's the self-signed certificate described above, and on a connection you recognize it's exactly what you'd expect to see.

Illustration of the Remote Desktop certificate warning A Windows dialog headed "The identity of the remote computer cannot be verified. Do you want to connect anyway?" showing the certificate name REMOTE-SERVER and a certificate error stating the certificate is not from a trusted certifying authority, with the checkbox "Don't ask me again for connections to this computer" ticked and highlighted, above Yes and No buttons. Remote Desktop Connection The identity of the remote computer cannot be verified. Do you want to connect anyway? The remote computer could not be authenticated due to problems with its security certificate. It may be unsafe to proceed. Name in the certificate from the remote computer: REMOTE-SERVER Certificate errors The following errors were encountered while validating the remote computer's certificate: The certificate is not from a trusted certifying authority. Don't ask me again for connections to this computer Yes No

An illustration of the certificate warning, with the checkbox you want highlighted. Your server name will differ.

What to do

  1. Check that the server name shown is the one you expect.
  2. Tick Don't ask me again for connections to this computer.
  3. Click Yes. This prompt uses Yes and No — not Connect and Cancel.
Yes, it's fine to tick that box. When this is the company connection you use every day, from your own shortcut, to a server you recognize, ticking it is the right answer and it's what we recommend. It doesn't switch a security feature off. It records your answer for that one server, so Windows stops asking you the same question every morning.

Other lines you might see

You may see extra lines in that list. "The server name on the certificate is incorrect." appears when the address in your shortcut doesn't match the name on the certificate — always the case when a shortcut connects by IP address, because a certificate can't vouch for an IP address. "The certificate has expired or is not yet valid." appears when the certificate has passed its end date. Neither is something you can fix from your end, but do mention them if you send us a ticket.

If the box tells you "You may not proceed due to the severity of the certificate errors." there's no option to continue — Windows has judged the problem serious enough to block the connection outright. Don't try to work around it. Submit a support request and include that wording.

The other box — the connection warning

Before the certificate warning, you'll often get a second, separate box asking whether you trust the connection itself. Which version you see depends on how you start the connection, and they behave differently — this is where people get caught, so it's worth knowing which one is in front of you.

If you open a saved shortcut or connection file

Since an April 2026 Windows security update, opening a saved Remote Desktop file shows a redesigned box headed Caution: Unknown remote connection, with Publisher shown as Unknown publisher, the address of the computer you're connecting to, and a checkbox for each thing on your own computer the connection wants to reach.

Illustration of the redesigned Remote Desktop connection security dialog A Windows dialog with a caution banner reading "Caution: Unknown remote connection", showing Publisher as Unknown publisher and Remote computer as REMOTE-SERVER, above a list of unticked checkboxes for local resources including Clipboard, Printers, Drives and Cameras and microphones, with Connect and Cancel buttons. Remote Desktop Connection Caution: Unknown remote connection Publisher: Unknown publisher Remote computer: REMOTE-SERVER Clipboard Printers Drives Cameras and microphones and others, depending on the connection Connect Cancel

An illustration of the redesigned connection box. The exact list of items varies with the connection.

Two things about this version surprise people, and both are deliberate on Microsoft's part rather than a fault:

  • It appears every single time you open the file, and there's no "don't ask me again" option on it. That's by design — Microsoft removed the ability to suppress it.
  • Everything is switched off by default. Each box you leave unticked stays unavailable inside the session. If you normally copy and paste between your own computer and the remote one, or print from the remote session to a printer beside your desk, those are the boxes to tick.

So on this version: check the computer name, tick only what you actually need, and click Connect. Unknown publisher here only means the connection file isn't digitally signed — it says nothing about whether the server is safe.

Tired of ticking boxes every morning? There's a proper fix, and it's ours to make rather than yours. We can digitally sign your organization's connection files so they show a known publisher instead, and we can issue the server a certificate your computers already recognize. Between them, those remove the reason for both boxes. If this is a daily irritation for people in your office, submit a support request — it's a change we can plan and make properly.

If you type the computer name in yourself

The April 2026 change only applies to opening a Remote Desktop file. If you open Remote Desktop Connection and type the computer name in directly, nothing about that has changed. You may see the older version of this box, headed "The publisher of this remote connection can't be identified. Do you want to connect anyway?" — and that one does carry a Don't ask me again for connections to this computer checkbox. Tick it and click Connect.

Our setup guide has you save a shortcut and open that, so its step 8 covers the redesigned box above, with the certificate box at step 10 — see Remote access on Windows for the full walkthrough.

What "Don't ask me again" actually does

Where the checkbox exists, it doesn't disable anything. It records your answer for that one server, so Windows stops asking the same question every time. The certificate box remembers that you accepted that specific certificate from that server; the older connection box remembers that you approved that connection.

Both decisions are saved for your Windows account, on the computer you're sitting at. On a different computer, or for a colleague who signs in as themselves, the prompts appear once again. That's normal.

Why a prompt can come back later

Ticking the box isn't a permanent switch. The ordinary reason a warning returns is that the server's certificate was replaced — your answer is pinned to one specific certificate, and certificates get regenerated over time, while servers get rebuilt or renamed. When the certificate changes, the prompt returns once so you can accept the new one.

That's legitimate. But a warning reappearing out of nowhere is also the one item on this page genuinely worth telling us about, so please don't just click through it.

When not to dismiss the warning

Everything above assumes a connection you already know. These warnings exist for a real reason, and attackers do send Remote Desktop files as bait. Stop, tick nothing, and submit a support request if any of the following is true:

  • You weren't expecting it. A Remote Desktop prompt appearing when you weren't deliberately starting a remote connection isn't something to click past.
  • You don't recognize the server name. Microsoft's own advice is blunt: if you don't recognize the computer name or address shown in the dialog, don't connect.
  • The file arrived by email, chat, or a link. Never open a Remote Desktop file you weren't expecting, even if the message looks legitimate and appears to come from someone you know. If it came by email, leave it alone and report it — see How to report a suspicious email.
  • A prompt reappeared where you'd already ticked the box. That can mean the server was rebuilt, renamed, or had its certificate replaced — all things we'd know about — but it can also mean something changed that shouldn't have. It takes us a couple of minutes to tell you which.
  • The connection is asking for more than it used to. Drives is the one to be most careful with: it lets the far end read files from your computer and write files to it. Clipboard access lets it see anything you copy, including a password. Approve only what your work actually needs, and ask us if you aren't sure.
  • A prompt appears for a Microsoft-hosted desktop service. Connection files from services such as Azure Virtual Desktop and Windows 365 are signed by Microsoft and shouldn't produce this security dialog. If one does, don't proceed.

One more thing worth knowing: a real-looking company name next to Publisher isn't a guarantee by itself. Attackers can sign files too, using names built to resemble a company you know. Whether you were expecting the connection matters more than the name you recognize.

A different notice you may also see

There's a third Remote Desktop pop-up that's easy to confuse with these. Also introduced with the April 2026 update, it's headed Opening Remote Desktop Connection and explains what Remote Desktop files are and why unexpected ones are risky. Its checkbox says I understand and allow RDP files to open on this device for my account.

That one is a one-time notice per Windows account rather than a per-connection warning, and it appears before the boxes covered here. We wrote it up separately in Remote Desktop: new security notice.

If something looks wrong, or you aren't sure

When in doubt, don't connect — nothing is lost by waiting a few minutes for us to confirm. You can submit a support request or email [email protected], and include as much of this as you can:

  • What you were doing — which shortcut, icon, or file you opened, and where it came from.
  • The exact wording on screen, word for word — the title bar, the heading, and any lines listed under Certificate errors. A screenshot is ideal if you can take one.
  • The server name shown in the box, plus the name on the certificate if both are listed.
  • Whether you've connected to this server before without seeing the prompt, and roughly when that changed.
  • Your computer's name — under Settings → System → About, shown as Device name.
  • Whether the file arrived by email, chat, or a link, and who it appeared to come from. Don't open it again in the meantime.
Bottom line: warnings on your everyday company Remote Desktop connection are normal — they mean the server uses its own self-signed certificate and the connection file isn't signed, not that anything is broken or unencrypted. On the certificate box, tick "Don't ask me again for connections to this computer" and click Yes. On the connection box, tick what you need and click Connect. Save your suspicion for the connection you weren't expecting.
Was this article helpful?