It comes up constantly. You and a trading partner run strategies together. You manage accounts for family members. You have a developer who maintains your EAs and needs occasional access. A small fund has two people who both need to see the terminals.
The instinct is to share one VPS and hand out the password. That works for a while, and then it does not, usually at the worst possible moment — two people logged in at once, one of them kicking the other off mid-trade, with no record of who changed what.
Windows Server has a specific and non-obvious constraint here that most traders discover by running into it. Understanding it early lets you design something that actually holds up.
The Constraint Nobody Mentions
Windows Server permits two concurrent administrative Remote Desktop sessions by default. That is not a setting your provider chose to be stingy about; it is how Microsoft licenses remote access. Those two sessions exist for server administration, not for using the machine as a shared workstation.
To go beyond two concurrent users properly, you need the Remote Desktop Services role and per-user or per-device RDS Client Access Licences. Those cost money, need a licensing server, and are a genuine administrative undertaking. For a trading setup with two or three people, it is almost always the wrong answer.
⚠️ Warning: You will find guides describing registry edits and patched system files that lift the concurrent-session limit without licences. Do not do this on a machine that manages money. You are modifying core system files in a way that Windows Update will periodically break, you are outside the licence terms, and the failure mode is a server that will not accept connections after a patch cycle. It will fail eventually, and it will fail unattended.
So the real design question is not “how do I get ten people onto one VPS.” It is “how do I structure access for the two or three people who actually need it, without stepping on each other.”
First: Decide Whether You Need Shared Access At All
Before designing anything, sort your people into categories, because most “we need shared access” situations turn out to need something simpler.
Needs to watch, not touch. Someone who wants to see how the account is doing does not need RDP. They need reporting. MetaTrader investor passwords give read-only access to an account from their own machine — no VPS involvement whatsoever. This covers a large proportion of real cases, and it is both safer and free.
Needs occasional access. A developer updating an EA once a month does not need a standing account. They need access when they are working and none when they are not.
Needs continuous access. Two people genuinely trading the same setup daily. This is the case that requires actual design.
Needs their own environment. Someone running their own strategies on their own accounts is not a shared-access case at all. They need their own VPS, and trying to squeeze them onto yours creates problems in every direction.
📊 Key Stat: Two Core plans at $29/mo cost $58 — less than one Scaling plan at $79/mo. For two traders running separate strategies, separate machines are usually both cheaper and better. The shared-VPS instinct is often a false economy.
Pattern 1: Separate Accounts on One Machine (2 People)
For two people who genuinely work on the same setup, this is the clean approach and it fits inside the default session limit.
Create a separate Windows user account for each person rather than sharing one login. This is the single most important step and it is the one people skip.
Why it matters:
- Separate profiles. Each person gets their own desktop, their own MetaTrader configuration, their own chart layouts. No more one person rearranging the other’s workspace.
- An audit trail. Windows Event Log records who logged in and when. When something changes unexpectedly, you can answer the question rather than argue about it.
- Revocable access. When someone leaves, you disable their account. You do not have to change a password that four other things depend on.
- Permission control. You can restrict what each account can do. A developer does not need administrator rights to edit an EA file.
Set it up as: one administrator account that you control, plus a standard user account per person. Grant each user account Remote Desktop permission explicitly.
💡 Tip: Give each person’s MetaTrader its own installation directory rather than sharing one. MetaTrader stores configuration per installation, and two people sharing one install will overwrite each other’s settings, templates and chart layouts continuously. Separate installs eliminate an entire class of friction. See installing more MT4 platforms with the same broker.
Pattern 2: One Operator, Read-Only Observers
The most common real requirement, and the simplest to satisfy.
One person administers the VPS and runs the terminals. Everyone else gets investor (read-only) passwords to the MetaTrader accounts, which they use from their own laptop or phone. They see positions, balance and history in real time. They cannot trade, cannot change settings, and never touch the server.
This handles partners, family members, investors and anyone who needs visibility rather than control. It has no session-limit problem because the observers never connect to the VPS at all, and it removes the security exposure of extra RDP accounts entirely.
Add MT4 and MT5 push notifications on top and observers get alerts on their phones without any access to the machine.
Pattern 3: Separate VPS Instances, Coordinated
For two traders running genuinely different strategies, stop trying to share.
Separate instances give each person full control of their own environment, remove all session contention, isolate the blast radius when someone breaks something, and let each machine be sized for its actual workload. They also sidestep a compliance issue that catches people out: if you both run prop firm accounts, shared IP addresses can trigger account-correlation reviews. Read multiple prop firm accounts on one VPS and the IP rules before you consolidate anything prop-related.
If the strategies need to talk to each other — a copier relationship, for instance — that can run across machines. It does not require one shared box.
Pattern 4: Scheduled Access for Occasional Helpers
For the developer who touches your EAs once a month, the right model is temporary access.
Create their account, enable it when they are working, disable it when they are done. Keep their permissions to standard user. Have them work in a specific directory rather than roaming the machine. When the engagement ends, delete the account.
This is a small amount of work each time and it eliminates the standing risk of a dormant privileged account that nobody thinks about.
✅ Best Practice: Whatever pattern you use, never share a single login between people. The moment two humans use one credential you have lost the ability to know who did what, you cannot revoke one person’s access without disrupting everyone, and you have no answer when something changes and nobody admits to changing it.
Security Implications of Any Shared Setup
Every additional account is additional attack surface, and RDP endpoints are scanned continuously. If you are adding users, tighten the machine at the same time.
- Restrict RDP by source IP where you can. This is the single most effective control available, and it is worth the inconvenience.
- Enforce strong, unique passwords per account. Not variations on a theme.
- Enable account lockout policies so repeated failed attempts lock rather than continue indefinitely.
- Grant standard user rights, not administrator, unless there is a specific reason otherwise.
- Review the account list quarterly and remove anyone who no longer needs access. Dormant accounts are the ones that get compromised, precisely because nobody is watching them.
- Consider a VPN in front of RDP rather than exposing it directly — see enhancing your VPS security with VPNs.
Our full checklist is in VPS security hardening for traders. It matters more on a shared machine than a personal one, because there are more doors and more people who might leave one open.
Sizing a Shared Machine
If you do share, size it for the sum of the workloads, not the average, and remember that two concurrent RDP sessions each carry their own overhead — desktop rendering, separate profiles, separate application instances.
Core ($29/mo, 2GB RAM, 1 vCPU) is a single-user plan. It is not the right basis for a shared setup.
Pro ($39/mo, 4GB RAM, 2 vCPUs) is a realistic minimum for two users with light terminal loads each.
Scaling ($79/mo, 8GB RAM, 4 vCPUs) is the sensible choice for two active users each running multiple terminals, or any setup where both people are working simultaneously during volatile sessions.
Run the arithmetic against separate instances before committing. Two Core plans cost less than one Scaling plan and give each person a machine they fully control. Sharing makes sense when people genuinely work on the same accounts; it rarely makes sense purely to save money.
🚀 Try FXVPS for $2.99 — test a shared configuration on a 7-day trial with both people connecting before you settle on a design.
A Setup Checklist
- Sort each person into watcher, occasional helper, co-operator, or independent trader
- Give watchers investor passwords; they never need the VPS
- Give independent traders their own instance
- For the one or two genuine co-operators, create separate named Windows accounts
- Give each their own MetaTrader installation directory
- Grant standard user rights unless administrator access is specifically required
- Enable Remote Desktop permission per account, explicitly
- Restrict RDP by source IP and enforce account lockout
- Configure auto-start for terminals under the account that owns them
- Document who has access to what, and review it every quarter
Frequently Asked Questions
How many people can use one Windows VPS at the same time?
Two concurrent RDP sessions by default. Going beyond that properly requires Remote Desktop Services licensing, which is rarely worth it for a trading setup.
Can two people use the same Windows account simultaneously?
No. A second login with the same credentials disconnects the first session. This is the most common source of friction in shared setups and the reason separate accounts per person is not optional.
What happens if someone logs in while I am trading?
If you share a login, you are disconnected. Your terminals keep running on the server — Windows does not close them when a session ends — but you lose your view and your control until you reconnect. With separate accounts, two people can work simultaneously without interfering.
Do my EAs keep running when nobody is logged in?
Yes, provided you disconnect properly rather than signing out. Signing out terminates your session’s applications; disconnecting leaves them running. This distinction catches people out constantly — see how to properly disconnect from an RDP session.
Can I give someone access to just one MetaTrader terminal?
Not cleanly through Windows permissions alone. The practical approach is a separate Windows account with its own MetaTrader installation and file permissions restricting them to that directory. If you need genuinely hard isolation, use separate VPS instances.
Is it safe to share a VPS with a trading partner?
It is safe if you use separate accounts, appropriate permissions and proper RDP hardening. It is not safe if you share one password, because you lose both accountability and the ability to revoke access selectively.
Can two prop firm accounts run on one shared VPS?
Technically yes, but check the firms’ rules first. Shared IP addresses between accounts can trigger correlation reviews, and the consequences range from an inconvenient questionnaire to a failed evaluation. Multiple prop firm accounts on one VPS covers the specifics.
Related Reading
- How to Properly Disconnect From an RDP Session — the difference between disconnect and sign out, and why it matters
- VPS Security Hardening for Traders — essential on any multi-user machine
- Multiple Prop Firm Accounts on One VPS: The IP Rules — before you share a machine for prop accounts
- MAM and PAMM Account Manager VPS Guide — the right structure if you manage capital for others
- Running Multiple MT4 and MT5 Terminals on a VPS — resource planning for a loaded machine