RDS drawer · RDS & Session Management
RDS and session management tools for the hosts you run
On the ticket: “Who is on which session host, and who connected when?”
Most RDS problems arrive as a ticket that says “the server is slow” or “I can’t get back into my desktop”. Behind it is usually one of three things: a disconnected session still holding a profile lock, a user logged on to the wrong collection host, or a process in someone’s session eating a core. Windows gives you the raw ingredients to answer each — qwinsta, quser, logoff, the Remote Desktop Services node in Server Manager, the TerminalServices-LocalSessionManager log — but spread across hosts and consoles. The tools on this page pull those ingredients into one place.
We judge each one by the question that runs through this site: which recurring chore does it remove, what rights does it need to do it, and what does it leave behind in the audit trail? A session tool that needs domain admin to list sessions is a worse fit for a help desk than one that works with delegated RDS permissions, even if its interface is nicer. And a tool that reads logon history is only as good as the log retention you have configured on the hosts. The table is ordered by how directly each tool removes the session-housekeeping chore; the methodology page explains how we weigh the rest.
6 RDS and session tools side by side
Ordered by how directly each tool handles day-to-day session work on a farm of Windows session hosts. General-purpose consoles and auditing platforms sit lower because session management is one feature among many for them. Click a tool name for the desk review; “Visit” links lead to the maker’s own website.
| Tool | Licence | Platforms | Key feature | Best for | Rights it needs |
|---|---|---|---|---|---|
| LizardSystems Terminal Services ManagerLizardSystems | Personal free / paid | Windows 10/11, Windows Server 2016–2025 (agentless, via the WTS API) | One agentless view of sessions, users and processes across many RDS hosts, with disconnect, log off and message actions | Admins who look after several session hosts and want one list instead of Task Manager on each | Administrative rights on the RDS hosts, with RPC reachable through their firewalls |
| LizardSystems Remote Desktop AuditLizardSystems | Commercial | Windows 8/8.1/10, Windows Server 2012–2019 (vendor’s published list) | Builds an RDP logon/logoff history from the event logs of the computers you point it at | Answering “who connected to this server over RDP, and when” without hand-filtering Event Viewer | Permission to read the event logs on each target (admin or Event Log Readers) |
| Windows Admin CenterMicrosoft | With Windows licence | Browser-based; gateway on Windows Server 2016–2025 or local client on Windows 11 | Browser console for services, events, processes, updates, roles and storage over PowerShell remoting | Small teams replacing a pile of MMC snap-ins and RDP-to-the-server habits | Gateway access plus admin rights on each managed server via WinRM / PowerShell remoting |
| Sysinternals SuiteMicrosoft | Freeware | Windows client and Windows Server; ARM64 and Nano Server builds; also in the Microsoft Store | Around seventy utilities — Process Explorer, Process Monitor, Autoruns, PsTools, TCPView, Sysmon | Admins who need to see exactly what a process, service or logon is doing | Most tools want an elevated prompt; PsExec needs admin rights on the remote host |
| Netwrix AuditorNetwrix | Commercial | On-premises; installs on Windows Server 2012 R2–2025 or Windows 10/11 (not on a DC) | Who-changed-what-when reports and alerts for AD, Group Policy, logons and file servers | Organisations that must answer auditors and need change history kept beyond event-log retention | A data-collection account with read access to logs and configuration; audit policy set on DCs |
| LizardSystems Remote Process ExplorerLizardSystems | Personal free / paid | Windows 10/11, Windows Server 2012 R2–2025 | Process tree for remote machines with nothing installed on them; end, start and re-prioritise processes | Help-desk and server admins ending hung processes without opening a remote session | Local administrator on the target computer; WMI/RPC allowed through its firewall |
Written independently: TopNet247 is none of these vendors, and table position cannot be bought. We verified licence and platform details on each maker’s website as of the date shown above.
How to choose
- Count the hosts, then look at the view
With one or two session hosts, quser /server:rdsh01 and Server Manager are enough. Past four or five, the value of a tool is a single list of every session on every host, sortable by idle time and state, so you can see the disconnected sessions that have been sitting there since last Tuesday.
- Check what rights the tool expects
Listing sessions remotely needs RPC access and, by default, administrative rights on the host. Resetting sessions for a help-desk team is better handled by delegating RDS permissions (for example with the Win32_TSPermissionsSetting WMI class) than by adding technicians to local Administrators. Prefer tools that work with whatever you delegate.
- Separate live sessions from history
Managing sessions now and reporting who connected last month are different jobs with different data sources. Live tools query the session manager; history tools read event IDs such as 4624 (logon type 10), 21, 24 and 25. Decide which question you are actually being asked before you shop.
- Know where the history really lives
An RDP logon report can only be as long as your event log retention. The Security log on a busy session host can roll over in days at default size. Raise the log size, forward events to a collector, or accept that any reporting tool will show a short window.
- Tell users before you act
Logging off a session discards unsaved work. Send a message first — most session tools and msg.exe can do this — and keep your actions within your organisation’s change and acceptable-use policies. Session tools are for keeping hosts healthy, not for watching what people do.
Where the built-in tools are already enough
If you manage a single session host, do not buy anything yet. quser, qwinsta, logoff and msg cover listing, resetting and warning users from any admin prompt, and the RDS collection page in Server Manager shows sessions per collection. The LizardSystems tools become worth a look when you are running the same four commands against six hosts every morning; Windows Admin Center earns its place when the session work is part of broader server housekeeping; Netwrix Auditor is a compliance purchase rather than a session tool. Whatever you choose, get it from the vendor’s own site — the where-to-get page lists each official address and how to check what you receive.
Vendor pages: LizardSystems Terminal Services Manager lizardsystems.com · LizardSystems Remote Desktop Audit lizardsystems.com · Windows Admin Center learn.microsoft.com · Sysinternals Suite learn.microsoft.com · Netwrix Auditor netwrix.com · LizardSystems Remote Process Explorer lizardsystems.com
Questions admins ask about RDS and session tools
How do I see who is logged on to an RDS host without a third-party tool?
Run quser /server:HOSTNAME (or qwinsta /server:HOSTNAME) from an elevated prompt on a machine that can reach the host over RPC. It lists each session, its ID, state and idle time. logoff ID /server:HOSTNAME ends a session and reset session ID /server:HOSTNAME resets one that is stuck. Our how-to on RDS sessions walks through the full routine.
Which event IDs record Remote Desktop logons?
The Security log records 4624 with logon type 10 for RemoteInteractive logons (type 7 for unlocks and some reconnects). The TerminalServices-LocalSessionManager/Operational log records 21 (logon), 24 (disconnect) and 25 (reconnect), and RemoteConnectionManager records 1149 when network authentication succeeds. Reporting tools build their history from these.
Do session tools need domain admin rights?
Usually not. Querying and resetting sessions needs administrative rights on the session hosts themselves, or RDS permissions you delegate. Reading history needs event log read access, which the built-in Event Log Readers group can provide. Give tools the narrowest account that works and record where its password lives.
Can I message users before I log them off?
Yes. msg * /server:HOSTNAME "text" sends a message to every session on a host, and most session managers include a send-message action. Give people a few minutes and a reason; it saves a lot of follow-up tickets.
Is Windows Admin Center a replacement for a dedicated session manager?
Partly. It is a good general console for the servers themselves, but it is not organised around a farm-wide list of sessions. Many teams use both: Windows Admin Center for server housekeeping and a session tool, or plain quser, for the session queue.
Keep going
Money note: every vendor link here is a direct, commission-free link to that maker’s official site. Details in our affiliate disclosure.