In short
A Windows Server Client Access License (CAL) gives a user or device the right to access Windows Server software under Microsoft's customer licensing model. For Windows Server 2025 Standard and Datacenter, the normal rule is simple: each internal user or device that accesses the licensed Windows Server needs a qualifying Windows Server CAL, unless a specific Microsoft exception or CAL-equivalent right applies.
You choose between:
- User CAL — license one user who can access licensed Windows Servers from any device.
- Device CAL — license one device that can be used by any user to access licensed Windows Servers.
An RDS CAL is separate. It is an additive access license for Remote Desktop Services. If a user needs RDS functionality in a customer-owned Windows Server deployment, the licensing stack can include both a base Windows Server CAL and an RDS CAL.
Windows Server license + Windows Server CAL (base access) + RDS CAL when the user/device uses Remote Desktop Services
This article owns the general Windows Server CAL question. For the broader Raff licensing model—SPLA, BYOL, evaluation, outsourcing rights, and hosted Windows licensing—see Windows Server Licensing on Raff. For RDS-specific licensing, see RDS CAL Licensing Guide.
Microsoft licensing is contract-based. Product Terms and your executed Microsoft agreement control if they differ from this guide.
What is a Windows Server CAL?
A Windows Server CAL is an access license. It is not the Windows Server operating-system license itself.
Microsoft's current Windows Server 2025 licensing guidance separates licensing into two layers:
- Server licensing — licenses the Windows Server software, usually through core-based licensing.
- Access licensing — licenses users or devices that access the server software.
For Windows Server, the normal base access license is a Windows Server CAL.
Microsoft classifies Windows Server CALs as Base CALs. Other capabilities, such as Remote Desktop Services, use Additive CALs that sit on top of the base access license where applicable.
Windows Server User CAL vs Device CAL
The two CAL types grant access in different ways.
| CAL type | Assigned to | Best fit | Example |
|---|---|---|---|
| User CAL | One named user | A user who accesses Windows Server from several devices | One employee uses an office PC, laptop, and home computer |
| Device CAL | One device | A shared device used by several people | Three shift workers share one warehouse terminal |
Microsoft defines a User CAL as allowing one licensed user, using any device, to access the corresponding Windows Server version or earlier versions on the customer's licensed servers. A Device CAL allows one licensed device, used by any user, to access those servers.
Choose User CALs when
User CALs usually make more sense when:
- employees have their own accounts;
- one person uses multiple devices;
- users work from office, home, and mobile laptops;
- the number of users is lower than the number of devices they may use.
Example:
10 employees Each employee uses: * office desktop * laptop * home computer User model: 10 User CALs
The key is that the CAL follows the licensed user, not each endpoint.
Choose Device CALs when
Device CALs usually make more sense when:
- several users share the same workstation;
- the business operates shifts;
- kiosks or terminals are shared;
- the number of accessing devices is lower than the number of users.
Example:
24 shift workers 6 shared warehouse terminals Device model: 6 Device CALs
The CAL follows the device, so different users can use the same licensed device.
Can you mix User and Device CALs?
Yes. Microsoft's current Windows Server guidance permits customers to use a combination of User and Device CALs when appropriate.
For example:
- office employees may use User CALs;
- a shared reception workstation may use a Device CAL;
- a warehouse may use Device CALs for shared terminals.
Do not mix models just to reduce the apparent count without documenting which users and devices each CAL covers. The assignments still need to match actual access.
User CAL vs Device CAL decision table
Use this quick comparison before purchasing.
| Situation | Usually better |
|---|---|
| One employee uses 3 devices | User CAL |
| Three employees share 1 PC | Device CAL |
| Remote employees use work and personal devices | User CAL |
| Call center uses fixed shared terminals across shifts | Device CAL |
| Executives access from laptop, desktop, and home PC | User CAL |
| Factory floor has more workers than terminals | Device CAL |
| Number of users and devices is nearly identical | Compare cost and administration |
Do not treat CALs as concurrent-session licenses. Licensing five User CALs does not mean “any five users at a time.” A User CAL is assigned to a specific user; a Device CAL is assigned to a specific device under the applicable licensing terms.
When are Windows Server CALs required?
Microsoft's Windows Server 2025 licensing guidance says CALs are required for users who are the customer's or its affiliates' employees, or onsite contractors or onsite agents, when they access licensed Windows Server software.
For Standard and Datacenter, the typical internal-user model is:
Licensed Windows Server → each accessing internal user OR device needs a Windows Server CAL
The choice is User CAL or Device CAL for the base access right. You do not normally buy both for the same access simply because both types exist.
Examples where base Windows Server CAL planning matters
Common examples include internal users or their devices accessing:
- Active Directory services;
- Windows file shares;
- print services;
- line-of-business applications running on Windows Server;
- application services that do not fall under a specific CAL exception;
- server resources accessed indirectly through an application or middleware layer.
A common mistake is assuming that if the user never sees the Windows desktop, no CAL is needed. Microsoft licensing looks at access to the server software, not only interactive logon.
CALs are not the same as server licenses
Buying Windows Server Standard or Datacenter does not automatically license every employee to access it.
Think of the layers separately:
| Layer | What it licenses |
|---|---|
| Windows Server core/server license | The Windows Server software/workload |
| Windows Server CAL | Base user/device access to licensed Windows Servers |
| RDS CAL | Additional Remote Desktop Services access rights |
| SQL Server licensing | SQL Server product rights; separate from Windows Server |
| Microsoft 365 licensing | Microsoft 365 Apps/services; separate from Windows Server |
Changing from Standard to Datacenter does not eliminate the ordinary Windows Server CAL requirement in the conventional customer licensing model. Read Windows Server Standard vs Datacenter for the edition decision.
Windows Server CAL vs RDS CAL
This is the distinction that causes the most confusion.
A Windows Server CAL is the base access license.
An RDS CAL is an additive license for Remote Desktop Services functionality.
Microsoft's current Windows Server 2025 guidance explicitly classifies:
- Windows Server CAL — Base CAL;
- Windows Server Remote Desktop Services CAL — Additive CAL.
For a normal customer-owned RDS deployment, the stack can therefore look like:
Windows Server license + Windows Server CAL + RDS CAL
The RDS CAL does not replace the base Windows Server CAL.
Example: employees use an RD Session Host
Suppose a business has 12 employees who use a Windows Server 2025 RD Session Host for a shared desktop.
Under a conventional customer licensing model, licensing analysis includes:
- Windows Server licensing for the server;
- Windows Server CALs for the applicable users/devices;
- RDS CALs for those users/devices because they use RDS functionality.
For the full RDS decision—including Per User vs Per Device mode, version compatibility, 120-day grace period, license server requirements, and hosted RDS SALs—use RDS CAL Licensing Guide.
Administrative RDP does not turn a CAL into an RDS CAL
Windows Server supports limited Remote Desktop connections for server administration without requiring RDS CALs for those administrative sessions.
That does not mean a business can use administrative RDP as a free employee desktop system.
The distinction is:
Administrators maintaining the server → administrative Remote Desktop rights Employees using Windows sessions / RemoteApp for daily work → Remote Desktop Services licensing model
The base Windows Server access-license question and the RDS access-license question are separate.
Windows Server CAL version compatibility
Windows Server CALs are version-aware.
Microsoft's current Windows Server 2025 licensing guidance says a CAL permits access to the corresponding version of Windows Server and earlier versions.
| CAL version | Windows Server 2025 | Windows Server 2022 | Windows Server 2019 |
|---|---|---|---|
| Windows Server 2025 CAL | Yes | Yes | Yes |
| Windows Server 2022 CAL | No | Yes | Yes |
| Windows Server 2019 CAL | No | No | Yes |
So:
- a 2025 CAL can access Windows Server 2025, 2022, or 2019;
- a 2022 CAL does not grant access to Windows Server 2025;
- a 2019 CAL does not grant access to Server 2022 or 2025.
If you upgrade the server generation, include CAL compatibility in the migration plan instead of assuming existing CALs automatically cover the newer server.
Do CALs apply to every possible Windows Server access scenario?
No. Microsoft documents specific exceptions and alternative licensing mechanisms.
Current Windows Server 2025 guidance lists scenarios where CALs or External Connectors are not required, including:
- access by another appropriately licensed server;
- access to server software running a qualifying public Internet web workload;
- qualifying high-performance computing (HPC) workloads;
- access to a physical operating-system environment used solely to host and manage virtual operating-system environments, subject to Microsoft's version/access rules.
Do not stretch an exception beyond its defined scope. For example, an internal line-of-business application running on IIS is not automatically a public Internet web-workload exemption simply because it uses HTTP.
What about external users?
Microsoft treats external access differently from internal employees and onsite contractors.
For external users, organizations can generally license access using either:
- the applicable CALs for each accessing user/device; or
- a Windows Server External Connector assigned to each accessed physical server, when the licensing conditions fit.
Microsoft also offers additive External Connectors for advanced functionality such as RDS.
An External Connector is not automatically cheaper. Compare the number of external users, number of servers being accessed, and the exact Microsoft licensing terms.
For internal employees, the External Connector is not a substitute for the required employee CAL model.
CAL equivalents may change the answer
Microsoft Product Terms recognize certain subscriptions or license suites as CAL Equivalent Licenses for specific base or additive access rights.
This can matter for organizations with Microsoft volume/subscription licensing, but do not assume that owning “Microsoft 365” generically replaces every Windows Server or RDS CAL.
The exact equivalence depends on:
- the exact subscription/license SKU;
- whether it corresponds to the base or additive CAL right;
- the version and Product Terms in effect;
- the user's assignment and access scenario.
Check the current Product Terms or your Microsoft licensing specialist before counting a subscription as a CAL equivalent.
Indirect access and multiplexing do not automatically reduce CAL requirements
Putting an application, API, connection pool, proxy, middleware server, or other technology between users and Windows Server does not automatically reduce the number of required access licenses.
Microsoft licensing refers to this as multiplexing or pooling.
Example:
100 employees → business application → middleware service → Windows Server
The fact that only one middleware service account connects directly to the server does not necessarily mean only one CAL is required. The underlying users/devices accessing the Windows Server functionality still need to be evaluated under Microsoft's multiplexing rules.
This is especially important for ERP, accounting, internal web applications, and database-backed business systems.
Do you need Windows Server CALs for SQL Server users?
SQL Server licensing is separate, but running SQL Server on Windows Server can involve both product layers.
A user accessing SQL Server does not become exempt from Windows Server licensing simply because the application is a database.
Depending on the architecture and Microsoft agreements, you may need to evaluate:
- Windows Server license;
- Windows Server access rights/CALs or qualifying alternatives;
- SQL Server licensing under its own Server/CAL or Per Core model.
Do not use an SQL Server CAL as a substitute for a Windows Server CAL. They license different products.
Do you need CALs for Active Directory?
Active Directory Domain Services is a Windows Server workload. Under the conventional customer licensing model, internal users/devices accessing Windows Server services need the applicable Windows Server access rights unless a specific exception or CAL equivalent applies.
This means AD deployments should not be planned only around core licensing for the domain controller. The user/device access layer matters too.
For infrastructure setup, see Promote a Windows VPS to an Active Directory Domain Controller.
What changes when Windows Server is hosted by Raff?
This is where customer CAL licensing and service-provider licensing must be kept separate.
Raff-provided SPLA licensing
When Raff provides the Windows Server workload under Microsoft's Services Provider License Agreement (SPLA) model, the hosted service is licensed under Microsoft's service-provider use rights rather than by asking the customer to purchase ordinary Windows Server User or Device CALs for that provider-licensed workload.
The Windows Server SPLA product itself uses the service-provider licensing model. Certain additional functionality can still require additional service-provider access licensing.
The important example is RDS:
Raff-provided Windows Server under SPLA + RDS SALs when authorized users consume RDS functionality
Do not purchase retail/customer RDS CALs merely because a hosted RDS service uses Windows Server. The correct model depends on who provides the Microsoft license.
Customer BYOL
If a customer brings eligible Windows Server licenses to Raff under Microsoft's applicable outsourcing or Flexible Virtualization rights, the customer's own Microsoft licensing terms apply.
That can include the applicable Windows Server CAL requirements and RDS CAL requirements.
This is why the question “Do I need CALs on Raff?” cannot be answered only from the VM size. First identify the licensing model:
| Raff deployment | CAL direction |
|---|---|
| Raff-provided SPLA Windows Server | Service-provider licensing model; do not treat it as ordinary customer CAL licensing |
| Customer BYOL Windows Server | Customer's Microsoft access-license rights must be reviewed |
| Customer-owned RDS rights | Review base Windows Server CAL + RDS CAL requirements |
| Raff-provided hosted RDS under SPLA | Review applicable Windows Server SPLA + RDS SAL model |
For the complete decision, use Windows Server Licensing on Raff.
How many Windows Server CALs do you need?
Count the assignment model, not concurrent sessions.
User CAL example
18 employees access Windows Server Each may use multiple computers → evaluate 18 User CALs
Device CAL example
40 employees work in shifts They share 12 fixed terminals → evaluate 12 Device CALs
Mixed example
12 office employees with multiple devices + 5 shared warehouse terminals → 12 User CALs + 5 Device CALs may fit
These examples illustrate assignment logic only. Final licensing depends on actual access, CAL-equivalent rights, exceptions, external users, and the customer's Microsoft agreement.
Common Windows Server CAL mistakes
Assuming the Windows Server license includes unlimited user access
The server license and access licenses are different layers under the conventional Server/CAL model.
Buying RDS CALs but forgetting base Windows Server CALs
RDS CALs are additive. They do not replace the base Windows Server CAL where that base CAL is required.
Counting concurrent users instead of licensed users/devices
Windows Server CALs are assigned by User or Device, not by peak concurrent session count.
Using an older CAL with a newer Windows Server version
A 2022 CAL does not grant access to Windows Server 2025.
Assuming a proxy removes CAL requirements
Multiplexing and indirect access do not automatically reduce the number of required licenses.
Treating all external users as ordinary employee CALs
External users can have a different licensing path, including External Connectors where appropriate.
Mixing customer CALs and hosted SPLA SALs
Customer-owned licensing and service-provider licensing are different models. Identify who provides the Microsoft license before counting access licenses.
Windows Server CAL planning checklist
Before production, document:
- Windows Server version.
- Standard or Datacenter edition.
- Who provides the Windows Server license.
- Whether the deployment uses customer licensing or provider SPLA.
- Number of internal users accessing Windows Server.
- Number of shared accessing devices.
- User CAL vs Device CAL decision.
- Existing CAL-equivalent rights, if any.
- CAL version compatibility with the server version.
- External-user access and External Connector analysis.
- Any multiplexing/indirect access paths.
- Whether RDS functionality is used.
- Separate RDS CAL or hosted RDS SAL analysis.
- SQL Server or other product licensing reviewed separately.
- Final design checked against current Microsoft Product Terms.