Workbench is a browser-based remote connection tool built into the ECS console. Connect to a Windows Elastic Compute Service (ECS) instance directly from your browser over Remote Desktop Protocol (RDP) — no local RDP client or additional software required.
Prerequisites
Before you begin, make sure that:
The instance is running. The instance must be in the Running state with a Health Status of Normal.
You have Workbench permissions. If you encounter permission errors, contact your Alibaba Cloud account owner or administrator to grant you the required permissions. For details, see Workbench service-linked role.
Security group rules allow Workbench access. Add inbound rules to allow the Workbench IP addresses to reach your instance. Rules differ based on the instance's network type. For details, see Security group settings related to Workbench. If no security group is configured, Workbench prompts you to configure one when you open the Instance Login dialog box.
Connect to a Windows instance
The following steps use a Windows Server 2022 instance as an example. By default, a Workbench session stays open for up to 6 hours. If no activity is detected for more than 6 hours, the session closes and you must reconnect.
Go to ECS console - Instances.
In the top navigation bar, select the region and resource group of the instance.

Click the instance ID. On the instance details page, click Connect.
In the Remote connection dialog box, click Sign in now in the Workbench section.
In the Instance Login dialog box, configure the connection parameters.
Parameter Description Instance Auto-populated with the current instance. You can also enter an instance ID or name manually. Connection Method Select Terminal to connect over RDP. Connection Choose whether to connect via the public or private IP address. RDP port Default is 3389. To use a different port, click More Options. See Specify the RDP port. Authentication Windows instances support password-based authentication only. Enter your username (for example, Administrator) and password. To reuse saved credentials, click Use Credential. See Save and use logon credentials.Click Log On and wait for the connection to be established.
The Windows desktop appears. You can now manage the instance.
Additional options
Specify the RDP port
By default, Workbench connects to Windows instances on port 3389. To use a different port, click More Options in the Instance Login dialog box before logging on.
![]() | ![]() |
|---|
Save and use logon credentials
Credential-based authentication lets you save a username and password as a reusable credential, so you can log on without re-entering them each time.
Credentials are private to the creator and cannot be shared with other accounts.
| Task | Steps |
|---|---|
| Save a credential | When logging on, select the save option shown below to store the credentials for future use. |
| Log on with a saved credential | In the Instance Login dialog box, click Use Credential, then select a saved credential from the Select Credential list. |
FAQ
If you cannot connect to a Windows instance, see RDP connection issues for troubleshooting steps.

