Guides · Connecting
Remote Desktop (RDP)
Open Windows desktops in a MangoSSH tab, next to your SSH sessions. The RDP client is built in, so it works the same on Windows, macOS and Linux, with clipboard, shared folders, sound, RD Gateway, SSH tunnels and session recording.
- Built-in RDP client
- Windows · macOS · Linux
- About 10 minutes
Add an RDP host
Open Add Session → Add RDP session. Or click RDP on the main toolbar and then Add RDP Host.
Fill in Host / IP and Username. The username can be
user,DOMAIN\useroruser@domain.com. Add a Domain only for domain accounts; leave it blank for local and Microsoft accounts.Type the Password to keep it in your operating system's keychain, or leave it blank to be asked each time you connect.
Click Add & Connect. The host is saved to the sidebar and the session opens.
The first time, MangoSSH shows the server's TLS certificate fingerprint under Unknown server certificate. Check it if you can, then click Yes, Trust & Connect. From then on the certificate is pinned (see Certificates).
Click the screen once to give it the keyboard. Until you do, a hint reads Click the screen to send keys. To reconnect later, click the saved host in the sidebar. Each connected host gets its own tab, so several desktops can stay open at once.
The host form
The form has four sections down its left side. You meet it in two places: Add RDP session and Edit open it inside the RDP page, and the + button on the main toolbar, then RDP, opens it as the Add new RDP Session dialog. The fields are the same apart from the ones marked below.
| Section | Field | What it does |
|---|---|---|
| General | Host / IP, Port | The target. The port defaults to 3389. The dialog calls it Hostname / IP and adds a Display name. |
| General | Username, Domain, Password | Sign-in details. The password is stored in the OS keychain; the dialog has a Save password box for it. Leave it blank to be asked at connect. |
| General | Resolution | Auto-fit window (crispest) sizes the remote desktop to the viewer and keeps following it. Or pick a fixed size, from 1280 × 800 up to 2560 × 1440. |
| General | Group | Where the host sits in the sidebar. |
| Gateway | Tunnel via SSH host | Reach the target through a saved SSH host (RDP page only). See Reaching hosts you cannot dial. |
| Gateway | RD Gateway, Gateway username, Gateway password | Tunnel through a Microsoft Remote Desktop Gateway. Blank means a direct connection. |
| Security | Choose Vault | Which vault the host is stored and synced in. See Vaults. |
| Security | PAM-broker mode | In the dialog, for a host synced through a Self Hosting or Cloud Vault: the relay signs in for you and this machine never holds the password. See PAM Broker. |
| Access | Multi-monitor | Experimental. Spans all of your local displays. The resolution setting is ignored while it is on. |
| Access | Smartcard redirection | Lets the remote session use a smartcard reader on this machine. |
| Access | Printer redirection | Anything printed in the session is saved here as a PDF. |
| Access | Disable clipboard | In the dialog: no clipboard channel is opened, so nothing can be copied out of the session or pasted in. |
| Access | Console session (/admin) | Attach to the existing console session instead of opening a new one, like mstsc /admin. If someone is signed in at the console, you take it over. |
| Access | Shared folders | Local folders that appear as drives inside the session. |
The session toolbar
While a session is open, a slim bar across the top shows the host name, the remote desktop size and a row of icon buttons. Hover over one to see its tooltip. From left to right:
| Tooltip | What it does |
|---|---|
| Send local clipboard text to the RDP session | Types your clipboard text into the session as keystrokes. Useful where a normal paste does not reach, such as a sign-in box. |
| Record session (screen capture) | Starts recording. The icon turns into a square (Stop & save recording) until you click it again. See Recording. |
| Auto-reconnect on disconnect | A checkbox. When on, a dropped session reconnects by itself. Applies to this session. |
| Refit display | Re-fits the picture to the viewer, keeping its shape. You may see empty bars at the sides. It never changes the remote resolution. |
| Match window | A toggle: highlighted means on. On, the remote desktop is resized to fill the window whenever the window changes. Click it to freeze the current resolution; click again to snap back to the window. |
| Fill the whole viewer | A checkbox that stretches the picture to fill the viewer, ignoring its shape. Text will look squashed or stretched. |
| Pop out into its own window | Moves the session into a separate window. Click again to bring it back. |
| Debug | Opens the RDP Debug log: every step of connecting (TCP, TLS, NLA, channels) and every disconnect, kept while the app is open. Copy or Save it for a support request. |
| Disconnect | Ends the session. |
| Edit or delete this host | The ⋮ menu for the host behind this session. |
Display and resolution
With Auto-fit window (crispest), the remote desktop is created at the viewer's size, so text is drawn one-to-one rather than scaled. Match window starts on, and MangoSSH asks Windows to resize the desktop when you resize or maximise the window. Opening or closing a sidebar does not shrink it; the desktop only grows into space that frees up. If you would rather a resize never happens mid-task, turn Match window off.
A fixed resolution never changes during the session. The picture is scaled to fit the viewer instead.
Resizing needs the server to accept MangoSSH's resize requests. When it doesn't, for example on some servers at the Windows sign-in screen, the picture is scaled to fill the window instead, and a true resize happens once the server accepts it.
Defaults for every RDP host live in Settings → RDP Session. A host's own settings override them, and changes apply at the next connect.
| Setting | What it does |
|---|---|
| Engine | Windows only. Embed Engine is the built-in client and the default. Native Engine is a bundled FreeRDP-based helper with smoother graphics for video. A host with Disable clipboard always uses the Embed Engine. |
| Resolution | Match Window, a fixed size, or Fullscreen. |
| Display Scale | The remote UI scale, 50–200%, used with a fixed resolution. |
| High DPI (Retina) | On a high-DPI screen, uses your monitor's real scale factor so the remote UI is not tiny. Automatic sizes are capped at 1920 pixels wide to keep bandwidth sane. |
| Color Depth, Quality | Trade picture quality for bandwidth on slow links. |
| Sound | Play on this computer or Do not play. |
| Send my timezone | Gives the session your time zone instead of UTC. |
| RDPGFX pipeline (experimental) | A more efficient graphics stream. Off is the stable path; turn it on only to try it. |
Keyboard and clipboard
Text copies both ways. Copy in the session and it lands on your local clipboard. Copy locally, click into the session, and it is ready to paste there. The toolbar's paste button is the fallback: it types up to 16 KB of clipboard text as keystrokes.
Ctrl+Alt+Del is claimed by your own operating system before any app sees it. To send it to the session, pop the session out and use Send Ctrl + Alt + Del on the pop-out toolbar.
To keep data inside the session, tick Disable clipboard on the host. No clipboard channel is opened, and the paste button refuses as well. This is enforced by MangoSSH; for a boundary that does not depend on the client, use the PAM Broker, whose sessions have no clipboard at all.
Shared folders, printing and smartcards
- Shared folders. In Access, click Add Shared Folder and pick a folder. Its drive name defaults to the folder name and you can change it. Inside the session it appears in File Explorer as name on MANGOSSH, and you can open, copy, rename and delete files there. Explorer does not refresh by itself when something changes on your side; press F5.
- Printing. With Printer redirection on, the session gets a printer called MangoSSH PDF Printer. Each job is saved to your Downloads folder as
mangossh-print-<number>.pdf. It cannot print to a physical printer on your side; print the PDF from there. - Smartcards. Smartcard redirection passes a local reader through, so you can sign in or sign documents with your card. Windows and macOS include the smartcard service this needs; on Linux, install and start
pcscd.
Sound
Sound from the remote desktop plays on this computer unless Sound in Settings → RDP Session is set to Do not play. Your microphone is not sent to the session.
Pop-out window
Pop out into its own window moves a session into a window you can put on another monitor, maximise or keep on top. Its floating toolbar has Keep this window on top, Send Ctrl + Alt + Del, Refit the display to this window, paste, record, Toggle fullscreen, the connect log, Return this session to the main window and Disconnect this session. Drag the toolbar to move it, or collapse it out of the way.
Recording
Click the record button to capture what the screen shows. Click it again to stop; MangoSSH confirms with “Session log saved — see Tools → Session Logs”. Open Tools → Session Logs, select the recording, and click Play to watch it in the Recording Player, or export it as an .mrdprec file.
This recording is made on your device, so the person connecting can turn it off. For recordings they cannot switch off, broker the host and tick Record every session on the relay (see PAM Broker).
Reaching hosts you cannot dial
| Situation | Use |
|---|---|
| The PC is on a network you can SSH into | Tunnel via SSH host. Pick a saved SSH host that can reach the PC. MangoSSH opens that SSH session, forwards a local port to the PC's RDP port and connects through it. A policy or host setting that blocks port forwarding on the SSH host blocks this too. |
| Your organisation publishes desktops through an RD Gateway | RD Gateway. Enter the gateway as host:port (for example gateway.example.com:443) with its own username and password. The gateway password is kept in the keychain, separately from the host password. The gateway must accept HTTP Basic sign-in. |
| The PC is behind NAT with no port forwarding | Connect by ID, on the RDP page. The PC runs MangoSSH and registers with your relay; you connect with its ID and password. See Remote Access. |
| People should use the desktop without ever seeing its password | PAM-broker mode. The relay holds the credential and runs the session; you get the screen. Clipboard and shared folders are not available on a brokered session. See PAM Broker. |
With an RD Gateway, MangoSSH does not check the gateway's own TLS certificate. The RDP connection inside the tunnel is still encrypted end to end to the PC, and the PC's certificate is still pinned.
Certificates
Windows RDP servers usually present a self-signed certificate, so there is no certificate authority to check it against. MangoSSH trusts on first use instead, like SSH host keys: you confirm the fingerprint once, it is pinned, and every later connection must present the same certificate. If it changes, the connection is refused with RDP HOST KEY MISMATCH and both fingerprints.
A certificate changes legitimately when the PC is reinstalled or its certificate is reissued. If you know that is what happened, right-click the host, choose Properties…, click Forget RDP Host Key, and connect again to confirm the new one.
Limits in this version
- No RemoteApp. MangoSSH opens full desktops. Single published applications (RemoteApp) are not available.
- No file copy through the clipboard. Copying files with Ctrl+C and Ctrl+V is built but switched off while a crash it triggers is fixed. Use a shared folder to move files.
- Text-only clipboard. Images and rich text do not cross.
- No microphone. Sound comes out of the session, but nothing goes in.
- Multi-monitor is experimental.
Troubleshooting
| Symptom | Likely cause |
|---|---|
| Refused or timed out, and MangoSSH suggests Connecting to a Mac? | Nothing is answering RDP on that port. macOS has no RDP server; use VNC for a Mac. On Linux, install xrdp or use VNC. On Windows, check that Remote Desktop is enabled and port 3389 is open. |
| “RDP HOST KEY MISMATCH” | The PC's certificate changed. See Certificates. |
| “Connection cancelled — the RDP server's TLS certificate was not trusted” | The first-connect prompt was declined or left unanswered. Connect again and choose Yes, Trust & Connect. |
| Keys do nothing | The session does not have focus. Click the screen once. |
| Remote text is tiny on a high-DPI laptop | Turn on High DPI (Retina) in Settings → RDP Session, then reconnect. |
| The desktop does not follow the window | Match window is off (click it: highlighted means on), the host uses a fixed resolution, or the server does not support resizing. The picture is scaled instead. |
| Connect by ID accepts the ID and password, then fails | The other PC has MangoSSH Direct enabled instead of RDP, or the reverse. Reopen Connect by ID and switch the protocol to match. |
| Anything else | Open Debug on the session toolbar. The log shows the step where the connection stopped. |