#Requires -Version 5.1 <# JbTecWiz Support Centre -- generated fix script Fault : Remote Desktop: "an internal error has occurred" -- 0x204, 0x1104, 0x3 Fix : Confirm something is listening and reachable on 3389 Source: https://jbtecwiz.com/support/win-net-rdp-internal Run as : Elevated PowerShell on the target machine Expect : 15 minutes Risk : low Reversible : yes WHEN THIS IS THE RIGHT FIX It fails instantly. Establish the basics before touching protocol settings. HOW TO UNDO IT Set fDenyTSConnections back to 1 and Disable-NetFirewallRule for the group. This script walks the fix one step at a time and asks before each one. Steps with no command are things you do yourself -- it prints those and waits. Run with -DryRun to print without executing. -------------------------------------------------------------------- NO WARRANTY - USE AT YOUR OWN RISK This script is provided by JbTecWiz as-is and with no warranty of any kind, express or implied. You run it entirely at your own risk. JbTecWiz accepts no liability for any loss or damage arising from its use, including but not limited to data loss, downtime, or configuration changes that turn out to be wrong for your system. You are responsible for reading this script before running it, for satisfying yourself that it suits the machine in front of you, and for having a working backup first. Some steps cannot be undone. -------------------------------------------------------------------- #> [CmdletBinding()] param( # Print every step and command without running anything. [switch]$DryRun, # Do not ask before each step. Read the script first if you use this. [switch]$Unattended ) $ErrorActionPreference = 'Stop' $script:Failed = 0 function Write-Rule { param([string]$Text) Write-Host '' Write-Host ('-' * 70) -ForegroundColor DarkGray if ($Text) { Write-Host $Text -ForegroundColor Cyan } } function Show-Prose { param([string]$Text, [string]$Colour = "Gray") if (-not $Text) { return } $words = $Text -split "\s+"; $line = " " foreach ($w in $words) { if (($line.Length + $w.Length) -gt 74) { Write-Host $line -ForegroundColor $Colour; $line = " " } $line += "$w " } if ($line.Trim()) { Write-Host $line -ForegroundColor $Colour } } function Invoke-Step { param( [int]$Number, [string]$Do, [string]$Why, [scriptblock]$Command, [switch]$Manual, [string]$Shell = "powershell" ) Write-Rule " Step $Number of 4" Show-Prose $Do "White" if ($Why) { Write-Host ""; Show-Prose $Why "DarkGray" } if ($Manual) { Write-Host '' Write-Host ' -> Do this yourself, then press Enter to carry on.' -ForegroundColor Yellow if (-not $Unattended -and -not $DryRun) { [void](Read-Host) } return } Write-Host '' foreach ($l in ($Command.ToString().Trim() -split "`n")) { Write-Host (" " + $l.Trim()) -ForegroundColor Green } Write-Host '' if ($DryRun) { Write-Host " (dry run -- not executed)" -ForegroundColor DarkGray; return } if (-not $Unattended) { $a = Read-Host " Run this step? [Y]es / [S]kip / [Q]uit" if ($a -match "^[Qq]") { Write-Host " Stopped at your request."; exit 0 } if ($a -match "^[Ss]") { Write-Host " Skipped." -ForegroundColor DarkGray; return } } try { & $Command } catch { $script:Failed++ Write-Host (" Step $Number failed: " + $_.Exception.Message) -ForegroundColor Red Show-Prose "The rest of the fix may depend on this. Read the write-up before carrying on." "Red" if (-not $Unattended) { $c = Read-Host " Carry on anyway? [y/N]" if ($c -notmatch "^[Yy]") { exit 1 } } } } Write-Rule Write-Host ' Remote Desktop: "an internal error has occurred" -- 0x204, 0x1104, 0x3' -ForegroundColor White Write-Host ' Confirm something is listening and reachable on 3389' -ForegroundColor Cyan Write-Host '' Write-Host ' Risk: low Reversible 15 minutes' Write-Host '' Show-Prose 'No warranty. Use at your own risk - JbTecWiz accepts no liability. Read it before you run it, and have a backup.' 'DarkYellow' Write-Rule if (-not $Unattended -and -not $DryRun) { $go = Read-Host ' Ready? [y/N]' if ($go -notmatch "^[Yy]") { Write-Host " Nothing was changed."; exit 0 } } Invoke-Step -Number 1 -Do 'Check RDP is enabled and the service is up.' -Command { Get-ItemProperty 'HKLM:\System\CurrentControlSet\Control\Terminal Server' -Name fDenyTSConnections Get-Service TermService,UmRdpService | Format-Table Name,Status,StartType } Invoke-Step -Number 2 -Do 'Check what port it is on -- a previous change or a conflicting application moves it.' -Command { Get-ItemProperty 'HKLM:\System\CurrentControlSet\Control\Terminal Server\WinStations\RDP-Tcp' -Name PortNumber Get-NetTCPConnection -State Listen -LocalPort 3389 } Invoke-Step -Number 3 -Do 'Check the firewall rules are enabled for the profile the machine is actually on.' -Why 'A machine that has flipped to the Public profile after a network change has the rules in place but not applied to it, which produces exactly this error with nothing logged.' -Command { Get-NetConnectionProfile | Format-Table Name,NetworkCategory Get-NetFirewallRule -DisplayGroup 'Remote Desktop' | Format-Table DisplayName,Enabled,Profile } Invoke-Step -Number 4 -Do 'Enable it properly if it is off.' -Command { Set-ItemProperty 'HKLM:\System\CurrentControlSet\Control\Terminal Server' -Name fDenyTSConnections -Value 0 Enable-NetFirewallRule -DisplayGroup 'Remote Desktop' } Write-Rule " Confirm it worked" Show-Prose 'The port answers from the client machine.' 'White' Write-Host '' if (-not $DryRun) { Test-NetConnection target -Port 3389 -InformationLevel Detailed } Write-Rule if ($script:Failed -gt 0) { Write-Host (" Finished with " + $script:Failed + " failed step(s).") -ForegroundColor Yellow Show-Prose 'Read the full write-up at https://jbtecwiz.com/support/win-net-rdp-internal' 'Yellow' } else { Write-Host ' Finished.' -ForegroundColor Green } Write-Host '' Show-Prose 'To undo: Set fDenyTSConnections back to 1 and Disable-NetFirewallRule for the group.' 'DarkGray' Write-Rule