I'm troubleshooting a recurring RDP error affecting only one user in a Proxmox environment with three Windows Server 2025 virtual machines: a domain controller, a file server, and a terminal server.
The user connects from a fully updated, non-domain-joined Windows 11 Pro workstation through a persistent IPsec IKEv2 VPN and authenticates with domain credentials. After working normally for a few minutes, he disconnects from the terminal server. When he tries to reconnect, the connection fails with error 0x904 and no additional message appears.
The session shows as Disconnected, but he cannot reconnect to it or create a new session. RDP from the same workstation to the domain controller and file server works normally. Other users can connect and reconnect to the terminal server without problems, and the affected user's credentials work from other computers.
There are no relevant events in the terminal server's System, Application, TerminalServices-LocalSessionManager, or TerminalServices-RemoteConnectionManager logs, and nothing unusual appears on the other servers. We have tested different accounts, networks, Bitdefender exclusions, and WatchGuard firewall rules, but the issue remains specific to this user and this terminal server.
Restarting the terminal server clears the problem temporarily. The user can log in once after the reboot, but the error returns after disconnecting and attempting to reconnect. What should I check next?
3 Answers
Try connecting to the terminal server by IP address rather than hostname or FQDN. If that works, investigate DNS resolution and the server certificate being presented to the client. As a diagnostic test, temporarily disabling Network Level Authentication may also help distinguish a certificate or pre-authentication problem from a session-management problem. Since the issue follows one user, client-side event logs should be checked as well.
The disconnected session may be stuck while the server is enforcing a single-session-per-user limit. From an administrative session, use qwinsta to identify the session and logoff to terminate it instead of rebooting the whole server. Also review the RDS session time-limit and reconnection settings in Group Policy. If the user can connect through mstsc /admin, that can help confirm whether the issue is limited to the normal session.
Because the problem appears tied to this user, start by checking the per-user RDP state on the Windows 11 workstation. Clear the contents of %AppData%MicrosoftTerminal Server Client and review or remove the user’s HKCUSoftwareMicrosoftTerminal Server Client entries after backing them up. A stale cached certificate or connection setting can cause failures for only one user. Also check the client’s CAPI2 operational log for certificate errors around the time of the failed reconnect.

Related Questions
Can't Load PhpMyadmin On After Server Update
Redirect www to non-www in Apache Conf
How To Check If Your SSL Cert Is SHA 1
Windows TrackPad Gestures