Start a program on connection
Verified with Windows 11 25H2 — updated on July 30, 2026
Supported on: At least Windows Server 2003
Path in the GPO console
User Configuration\Administrative Templates\Windows Components\Remote Desktop Services\Remote Desktop Session Host\Remote Session Environment Description
Configures Remote Desktop Services to run a specified program automatically upon connection. You can use this setting to specify a program to run automatically when a user logs on to a remote computer. By default, Remote Desktop Services sessions provide access to the full Windows desktop, unless otherwise specified with this setting, by the server administrator, or by the user in configuring the client connection. Enabling this setting overrides the "Start Program" settings set by the server administrator or user. The Start menu and Windows Desktop are not displayed, and when the user exits the program the session is automatically logged off. To use this setting, in Program path and file name, type the fully qualified path and file name of the executable file to be run when the user logs on. If necessary, in Working Directory, type the fully qualified path to the starting directory for the program. If you leave Working Directory blank, the program runs with its default working directory. If the specified program path, file name, or working directory is not the name of a valid directory, the RD Session Host server connection fails with an error message. If the status is set to Enabled, Remote Desktop Services sessions automatically run the specified program and use the specified Working Directory (or the program default directory, if Working Directory is not specified) as the working directory for the program. If the status is set to Disabled or Not Configured, Remote Desktop Services sessions start with the full desktop, unless the server administrator or user specify otherwise. (See "Computer Configuration\Administrative Templates\System\Logon\Run these programs at user logon" setting.) Note: This setting appears in both Computer Configuration and User Configuration. If both settings are configured, the Computer Configuration setting overrides.
Registry
SOFTWARE\Policies\Microsoft\Windows NT\Terminal Services Value name: fInheritInitialProgram
MDM / Intune (CSP)
./User/Vendor/MSFT/Policy/Config/ADMX_TerminalServer/TS_START_PROGRAM_1 Microsoft Learn documentation Mapping data: Microsoft Learn (CC BY 4.0)
Export Builder
BETAConfigure the state, scope and options, then generate .reg, PowerShell, Intune and SCCM outputs — or add the setting to a multi-setting collection.
These exports write the registry — this is not a managed GPO. ⓘ
.reg file
Windows Registry Editor Version 5.00
; Exported from gporais.com
; Policy: Start a program on connection
; State: Enabled
; Supported on: At least Windows Server 2003
[HKEY_CURRENT_USER\SOFTWARE\Policies\Microsoft\Windows NT\Terminal Services]
"fInheritInitialProgram"=dword:00000001
"InitialProgram"=""
"WorkDirectory"="" More formats (PowerShell, Intune, SCCM)
PowerShell
# Exported from gporais.com
# Policy: Start a program on connection
# State: Enabled
# Supported on: At least Windows Server 2003
# Warning: In SYSTEM context (the Intune default), HKCU targets the SYSTEM profile. Run this script using the logged-on credentials.
$path = 'HKCU:\SOFTWARE\Policies\Microsoft\Windows NT\Terminal Services'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'fInheritInitialProgram' -Value 1 -Type DWord
Set-ItemProperty -Path $path -Name 'InitialProgram' -Value '' -Type String
Set-ItemProperty -Path $path -Name 'WorkDirectory' -Value '' -Type String Intune XML
OMA-URI: ./User/Vendor/MSFT/Policy/Config/ADMX_TerminalServer/TS_START_PROGRAM_1
Data type: String
Value:
<enabled/>
<data id="TS_PROGRAM_NAME" value=""/>
<data id="TS_WORKDIR" value=""/> Intune Remediation
# === Detection script ===
# Exported from gporais.com
# Policy: Start a program on connection
# State: Enabled
# Supported on: At least Windows Server 2003
# Warning: In SYSTEM context (the Intune default), HKCU targets the SYSTEM profile. Run this script using the logged-on credentials.
function Test-RegistryValue {
param(
[Parameter(Mandatory = $true)][string]$Path,
[Parameter(Mandatory = $true)][string]$Name,
[object]$Expected,
[ValidateSet('String', 'DWord', 'MultiString')][string]$Kind = 'String',
[switch]$Absent
)
try {
$item = Get-ItemProperty -LiteralPath $Path -Name $Name -ErrorAction Stop
} catch {
return $Absent.IsPresent
}
if ($Absent.IsPresent) { return $false }
$actual = $item.$Name
if ($Kind -eq 'DWord') { return ([int64]$actual) -eq ([int64]$Expected) }
if ($Kind -eq 'MultiString') {
$actualValues = @($actual)
$expectedValues = @($Expected)
if ($actualValues.Count -ne $expectedValues.Count) { return $false }
for ($i = 0; $i -lt $expectedValues.Count; $i++) {
if ([string]$actualValues[$i] -ne [string]$expectedValues[$i]) { return $false }
}
return $true
}
return [string]$actual -eq [string]$Expected
}
$checks = @(
(Test-RegistryValue -Path 'HKCU:\SOFTWARE\Policies\Microsoft\Windows NT\Terminal Services' -Name 'fInheritInitialProgram' -Expected 1 -Kind DWord)
(Test-RegistryValue -Path 'HKCU:\SOFTWARE\Policies\Microsoft\Windows NT\Terminal Services' -Name 'InitialProgram' -Expected '' -Kind String)
(Test-RegistryValue -Path 'HKCU:\SOFTWARE\Policies\Microsoft\Windows NT\Terminal Services' -Name 'WorkDirectory' -Expected '' -Kind String)
)
if ($checks -notcontains $false) {
Write-Output 'Compliant'
exit 0
}
Write-Output 'Non-compliant'
exit 1
# === Remediation script ===
# Exported from gporais.com
# Policy: Start a program on connection
# State: Enabled
# Supported on: At least Windows Server 2003
# Warning: In SYSTEM context (the Intune default), HKCU targets the SYSTEM profile. Run this script using the logged-on credentials.
$path = 'HKCU:\SOFTWARE\Policies\Microsoft\Windows NT\Terminal Services'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'fInheritInitialProgram' -Value 1 -Type DWord
Set-ItemProperty -Path $path -Name 'InitialProgram' -Value '' -Type String
Set-ItemProperty -Path $path -Name 'WorkDirectory' -Value '' -Type String SCCM scripts
# Exported from gporais.com
# Policy: Start a program on connection
# State: Enabled
# Supported on: At least Windows Server 2003
# SCCM Configuration Item guidance:
# Create a Configuration Item of type "Setting: Script".
# Discovery script: use the Detection script below.
# Remediation script: use the Remediation script below.
# Compliance rule: the Discovery script output equals 'Compliant'.
# === Detection script ===
# Exported from gporais.com
# Policy: Start a program on connection
# State: Enabled
# Supported on: At least Windows Server 2003
# Warning: In SYSTEM context (the Intune default), HKCU targets the SYSTEM profile. Run this script using the logged-on credentials.
function Test-RegistryValue {
param(
[Parameter(Mandatory = $true)][string]$Path,
[Parameter(Mandatory = $true)][string]$Name,
[object]$Expected,
[ValidateSet('String', 'DWord', 'MultiString')][string]$Kind = 'String',
[switch]$Absent
)
try {
$item = Get-ItemProperty -LiteralPath $Path -Name $Name -ErrorAction Stop
} catch {
return $Absent.IsPresent
}
if ($Absent.IsPresent) { return $false }
$actual = $item.$Name
if ($Kind -eq 'DWord') { return ([int64]$actual) -eq ([int64]$Expected) }
if ($Kind -eq 'MultiString') {
$actualValues = @($actual)
$expectedValues = @($Expected)
if ($actualValues.Count -ne $expectedValues.Count) { return $false }
for ($i = 0; $i -lt $expectedValues.Count; $i++) {
if ([string]$actualValues[$i] -ne [string]$expectedValues[$i]) { return $false }
}
return $true
}
return [string]$actual -eq [string]$Expected
}
$checks = @(
(Test-RegistryValue -Path 'HKCU:\SOFTWARE\Policies\Microsoft\Windows NT\Terminal Services' -Name 'fInheritInitialProgram' -Expected 1 -Kind DWord)
(Test-RegistryValue -Path 'HKCU:\SOFTWARE\Policies\Microsoft\Windows NT\Terminal Services' -Name 'InitialProgram' -Expected '' -Kind String)
(Test-RegistryValue -Path 'HKCU:\SOFTWARE\Policies\Microsoft\Windows NT\Terminal Services' -Name 'WorkDirectory' -Expected '' -Kind String)
)
if ($checks -notcontains $false) {
Write-Output 'Compliant'
exit 0
}
Write-Output 'Non-compliant'
exit 1
# === Remediation script ===
# Exported from gporais.com
# Policy: Start a program on connection
# State: Enabled
# Supported on: At least Windows Server 2003
# Warning: In SYSTEM context (the Intune default), HKCU targets the SYSTEM profile. Run this script using the logged-on credentials.
$path = 'HKCU:\SOFTWARE\Policies\Microsoft\Windows NT\Terminal Services'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'fInheritInitialProgram' -Value 1 -Type DWord
Set-ItemProperty -Path $path -Name 'InitialProgram' -Value '' -Type String
Set-ItemProperty -Path $path -Name 'WorkDirectory' -Value '' -Type String Building a multi-setting collection? Add this setting and generate combined .reg / PowerShell / GPO scripts.