A user phones: Outlook is “Not Responding”, the screen is frozen, and they’re on the other side of the building or working from a branch office. Remoting into their desktop means taking over the session they’re stuck in. Ending the one process from your own console is quicker, and the user can keep working in everything else. There are four ways to do this with built-in or free tools, and each needs different network paths. Pick the one your environment already allows.
Use only on systems you administer and with your organisation’s authorization. Ending a process discards anything unsaved in it, so tell the user before you do it.
Rights and paths, up front
Every method below needs local administrator rights on the target. That usually means a workstation-admin group applied by GPO, not Domain Admins. What changes between methods is the network path:
| Method | Transport | Typical firewall need |
|---|---|---|
tasklist / taskkill |
RPC / WMI | Windows Management Instrumentation (WMI) rule group |
Get-CimInstance (default) |
WinRM (WS-Man) | TCP 5985, WinRM enabled |
Get-CimInstance with DCOM |
DCOM / RPC | TCP 135 + dynamic RPC range |
| PsList / PsKill | SMB admin share, remote registry/perf counters | TCP 445 |
If one method fails with “RPC server unavailable” or “access denied”, the next one may still work. The target isn’t broken, you’ve just hit a firewall rule or UAC restriction that blocks that path.
Step 1 — Find the process and its PID
Start with the built-in command. The first command lists every process on the machine. The second filters to one image name and adds window titles and owners:
tasklist /s PC-0421 /fo table
tasklist /s PC-0421 /v /fi "IMAGENAME eq outlook.exe"
The obvious filter /fi "STATUS eq NOT RESPONDING" doesn’t work against a remote computer. Microsoft’s documentation says so, and WINDOWTITLE has the same restriction. You’ll identify the hung process by name, owner and CPU time instead.
With PowerShell and CIM you get objects you can sort. This helps when the culprit is “the Chrome child using 3 GB”:
Get-CimInstance -ComputerName PC-0421 -ClassName Win32_Process -Filter "Name='outlook.exe'" |
Select-Object ProcessId, Name, SessionId,
@{n='WS_MB';e={[math]::Round($_.WorkingSetSize/1MB)}},
@{n='Owner';e={(Invoke-CimMethod -InputObject $_ -MethodName GetOwner).User}}
If WinRM isn’t enabled on workstations, create a DCOM session instead:
$opt = New-CimSessionOption -Protocol Dcom
$cs = New-CimSession -ComputerName PC-0421 -SessionOption $opt
Get-CimInstance -CimSession $cs -ClassName Win32_Process -Filter "Name='outlook.exe'"
On a shared machine or RDS host, check SessionId so you end this user’s copy and not someone else’s.
Step 2 — Tell the user, then end it
A quick heads-up avoids “I lost my email draft”. Once they know, pick one of these:
- taskkill by PID.
/talso takes out child processes. Remote kills are always forceful, so/fmakes no difference remotely.taskkill /s PC-0421 /pid 7312 /t - CIM Terminate, useful inside scripts. A
ReturnValueof 0 means success:Get-CimInstance -CimSession $cs -ClassName Win32_Process -Filter "ProcessId=7312" | Invoke-CimMethod -MethodName Terminate - PowerShell remoting, if WinRM is your standard path:
Invoke-Command -ComputerName PC-0421 -ScriptBlock { Stop-Process -Id 7312 -Force }Get-Process -ComputerNameandStop-Processhave no remote parameter in PowerShell 7, so go throughInvoke-Command. - PsKill from Sysinternals, over the admin share.
-tkills the process tree:pskill -t \\PC-0421 7312
Step 3 — Capture evidence if it keeps happening
If the same app hangs every week, ending it again won’t fix anything. Before you end it next time, capture a full dump the vendor can analyse. On the target, for example in an Invoke-Command block or an elevated remote shell, run ProcDump:
procdump -ma 7312 C:\Temp\outlook-hang.dmp
Windows Admin Center’s Processes tool can also create a dump from the browser, but only on machines you’ve added to it. Dumps can contain mail content and credentials in memory, so treat them as sensitive and delete them once the ticket is closed.
Step 4 — Confirm and note it in the ticket
Run tasklist /s PC-0421 /fi "IMAGENAME eq outlook.exe" again to confirm it’s gone. The user can then restart the app. Note the PID, the time and the method in the ticket. The Security log on the target records your network logon (4624 type 3), which is the audit trail for this action.
Common mistakes
- Killing by image name on a shared host.
taskkill /im outlook.exeon an RDS server ends it for every user. Use the PID. - Using
/fand expecting a graceful close remotely. It’s forceful either way. For a graceful exit, the user has to close the app themselves. - Local-account admin over the network. UAC remote restrictions filter local administrator tokens on network logons, so
.\Administratorfails where a domain account in the local Administrators group works. - Opening DCOM ports broadly to make one tool work. Scope firewall rules to your admin subnet.
When a GUI helps
If you do this several times a day across many PCs, a console with a live process tree and CPU and memory columns is faster than typing PIDs. LizardSystems Remote Process Explorer works over WMI via DCOM. The vendor lists killing and starting processes, changing priority, and restarting the remote computer. It’s free for personal use and paid per machine for business use. The Sysinternals tools are free and scriptable. Remote Process Explorer vs Sysinternals compares the two approaches. More options are listed in Server & Workstation Triage, with a review of the Sysinternals Suite.