© 2026 TruGrid.com. All rights reserved.
An RDS CAL (Remote Desktop Services Client Access License) is the Microsoft license required for every user or device that connects to Remote Desktop Services. You buy these on top of Windows Server licenses, and the RD Licensing role issues and tracks them. Once the grace period ends, clients must have a valid RDS CAL issued by a license server before they can sign in to an RDS session.
Every user or device connecting to RDS needs a valid CAL, licensed separately from Windows Server itself.
CALs are required any time users connect to RDS session-based desktops or RemoteApp programs, meaning any time the RD Session Host role is in use. RDS CALs are not required for the two administrative Remote Desktop connections permitted for server management. Those administrative connections are not licensed as a substitute for RDS session-based desktop or RemoteApp access. Using admin-mode connections to deliver apps to actual users is a licensing violation, not an approved workaround.
A User CAL licenses a named person to connect from any number of devices, which is the right call when staff bounce between a laptop, a home PC, and a phone. A Device CAL licenses one specific machine for any number of users instead, which is the right call for shift work on shared workstations, kiosks, and clinical floors. The two can generally be mixed within one deployment (confirm the specifics for whichever licensing program you are on). Each connecting user or device must be appropriately licensed under the applicable RDS CAL model, and User CALs dominate wherever the workforce is mobile. Get this choice wrong and it gets expensive fast, since per-seat counts diverge sharply the moment device sharing or multi-device users enter the picture.
These two stack. They do not substitute for each other. A Windows Server CAL licenses a user or device to access Windows Server services at all, file, print, authentication. An RDS CAL adds the right to an actual Remote Desktop session on top of that. So every RDS user, in practice, typically needs both a Windows Server CAL and an RDS CAL.
The RD Licensing role stores purchased CALs and issues them out as connections occur. Every deployment gets a built-in grace period, 120 days, after which session hosts start refusing any connection that cannot obtain a license. User CAL issuance is tracked per user account. Device CALs get issued as certificates to machines and renew on use instead. The licensing server has to be activated with Microsoft, reachable from session hosts, and specified in deployment properties, and that classic "no license server configured" outage is almost always a configuration error, not a purchasing one.
CAL versions have to be equal to or newer than the Windows Server version of the session hosts they license. RDS 2025 CALs cover 2025 and earlier hosts. RDS 2019 CALs cannot license 2022 or 2025 hosts. In practice, buy CALs at the newest version in your estate and plan CAL upgrades alongside server upgrades. There is no supported downgrade path here, only the right to run newer CALs against older hosts, never the reverse.
Microsoft sells RDS CALs through volume licensing and CSP partners, and street prices vary enough by program, quantity, and Software Assurance that any fixed number here would be wrong within a year. What stays true: User CALs carry a modest premium over Device CALs. CALs are typically sold as perpetual per-version licenses, with subscription options available through some programs. And the licensing cost per seat is often the deciding line item when RDS gets compared against a DaaS platform with bundled licensing. Budget for CALs plus Server licenses plus infrastructure together. The CAL line by itself will always understate the real cost of RDS.
Count the maximum concurrent-rights population, not concurrent sessions. RDS CALs are per user or per device, never per connection. Fifty named users working shared shifts across twenty workstations need either fifty User CALs or twenty Device CALs, and the licensing model and current pricing determine which option is more economical.
"CALs are concurrent." They are not. They are per named user or device, always. "The grace period is a free tier." It is a deployment window, not a discount; running production past 120 days without CALs is simply unlicensed. "Admin sessions can serve users." No. The two administrative connections exist for management only. "Old CALs work on new servers." Compatibility only runs newer-CAL-to-older-host, never the other way around. "External users are free." They are not; external-user scenarios have their own licensing paths, service-provider licensing among them, and that is a conversation for a licensing specialist, not an assumption you get to make.
The per-user or per-device license to connect to Remote Desktop Services.
Perpetual CALs do not; subscription CALs run with their term.
Microsoft volume licensing, CSP partners, and OEM channels. Never a "free key" site; those are piracy, and the keys get revoked routinely.
Microsoft licensing rules vary by agreement, deployment model, and product version. Confirm licensing requirements with Microsoft or an authorized licensing partner.
Where TruGrid fits. TruGrid SecureRDP secures access to licensed RDS environments without touching Microsoft's licensing requirements at all, and its own per-user pricing is public. See TruGrid pricing →
TruGrid SecureRDP delivers Zero Trust remote desktop access: MFA, least privilege, and zero open inbound ports.
Explore SecureRDP →