How to RDP from a Mac to a Windows host
By Lucas Russo, developer of SSHive · Updated
A Windows desktop in a tab next to your SSH sessions: NLA and Active Directory sign-in, a shared text clipboard, and port 3389 kept private behind an SSH tunnel.
RDP is Microsoft's remote desktop protocol, built into Windows. From a Mac, the usual tool is Windows App (formerly Microsoft Remote Desktop): it works, but in a window of its own, away from your terminal and your SFTP panel. SSHive has an RDP client built in, with Network Level Authentication (NLA), Active Directory domain accounts, a Ctrl+Alt+Del button, a choice of resolution and a shared text clipboard, and it opens each session as a tab next to your SSH and SFTP tabs. RDP is part of SSHive Pro. If you are still comparing clients, the RDP clients for Mac side by side is the place to start.
Step-by-step
Enable Remote Desktop on the Windows host
On Windows 11: Start › Settings › System › Remote Desktop, turn Remote Desktop on and confirm. Note the PC name or IP. The PC must run a Pro edition of Windows: a Home edition can connect out but cannot be connected to. On Windows Server: Server Manager › Local Server › Remote Desktop. If your account is not an administrator, add it to the Remote Desktop Users group. Turning Remote Desktop on normally opens port 3389 in the Windows firewall by itself.Create the RDP profile in SSHive (Pro)
Sidebar › +. The Type row at the top offers SSH, SFTP / FTP, Telnet, RDP and VNC. Pick RDP: the port switches to3389. Fill Name, Host, Username and Password, with Save password ticked so it is stored encrypted, and Domain for an Active Directory account (the placeholder readsDOMAIN). RDP needs Pro: in the free version the RDP button carries a PRO badge and opens the upgrade window instead.Choose a quality and a resolution
RDP Quality offers High, Balanced (the default) and Low: Low trades image quality for responsiveness on a slow link. Resolution is either Auto (fit window), which follows the size of the SSHive window, or a fixed size from 1280 × 720 to 3840 × 2160. Leave Allow legacy RDP security off: it is only for servers that speak neither NLA nor TLS, and it gives up checking the server's identity.Connect: keyboard, clipboard and window size
Double-click the profile. With Resolution on Auto, resizing the SSHive window resizes the Windows desktop. Cmd acts as Ctrl (Cmd+C sends Ctrl+C), AltGr works on international keyboards, and the Ctrl+Alt+Del button in the session toolbar sends that combination to Windows. Text copied on one side pastes on the other. Drives and printers are not redirected: move files over SFTP instead, in a tab next to the session.Tunnel RDP through SSH when 3389 is not exposed
There is no jump-host field on an RDP profile: the route goes through two profiles. (1) On the SSH profile of your bastion, under Advanced options › Local Tunnels (-L), add13389 → windows-host:3389. (2) Point the RDP profile atlocalhost, port13389. Connect the SSH profile first (the tunnel comes up with it), then the RDP one. Never expose 3389 directly to the Internet: RDP password guessing runs on an industrial scale. The SSH tunnel guide covers the tunnel fields in detail.
Frequently asked questions
Does SSHive RDP work with cloud-hosted Windows VMs?+
Can I copy files between the Mac and the Windows host?+
Related SSHive features
Remote Desktop (RDP)
Embedded remote desktop
SSH Tunnels
Local, remote & SOCKS5 proxy
Try SSHive Free for macOS
Get the all-in-one SSH, SFTP, RDP and VNC client for Mac. Free download, no signup required.
Download SSHive Free