How to Secure RDP on a Windows Server: 7 Steps That Stop 95% of Attacks
VPS and servers Published: 08.09.2026 · 6 min read
A Windows server with open RDP starts receiving password brute-force attempts within hours of being created — you can see it in the event log of any new server. The seven settings below take about 30 minutes and cut off almost all automated attacks.
1. Change the default port 3389
Bots scan the internet specifically on port 3389. Moving RDP to a non-standard port (for example, 53389) doesn’t make the server invulnerable, but it removes 90% of the noise. It’s changed in the registry: HKLM\System\CurrentControlSet\Control\Terminal Server\WinStations\RDP-Tcp, value PortNumber. Don’t forget to open the new port in Windows Firewall and close the old one.
2. Enable account lockout after failed attempts
Local Security Policy → Account Policies → Account Lockout Policy: threshold of 5 attempts, lockout for 30 minutes. Password guessing at thousands of attempts per hour turns into 10 attempts per hour.
3. Restrict access by IP
The single most effective measure. In the firewall rule for RDP, set “Remote IP addresses” to only your office addresses and those of people who actually connect. If employees have dynamic addresses, allow the ISP’s range or use a VPN to the server — then RDP isn’t exposed to the internet at all.
4. Disable or rename Administrator
All dictionary attacks target the Administrator login. Create a user with a different name and admin rights, and disable the default account. Give employees separate users without admin rights — they don’t need them to work in 1C or Excel.
5. Strong passwords — no exceptions
12 characters or more, upper- and lowercase letters, digits, special characters. Passwords like Qwerty123 and Server2024! are in every dictionary. Enable the complexity requirement in your password policy so users can’t set a weak one.
6. Enable NLA
Network Level Authentication requires the password before an RDP session is established — the server doesn’t waste resources on unauthenticated connections and doesn’t show the login screen to just anyone. System Properties → Remote → “Allow connections only from computers running Remote Desktop with Network Level Authentication.” It’s on by default in newer versions — check that nobody has turned it off.
7. Updates and backups
Critical RDP vulnerabilities (BlueKeep and the like) are patched by Windows updates. Enable automatic installation of at least security updates. And take a server snapshot before any change — in our client panel it’s one click, and a rollback takes a minute.
What else you can do
- RD Gateway or VPN — the server isn’t directly reachable from the internet; employees connect to the VPN first. Recommended for companies handling sensitive data.
- Two-factor authentication — free solutions such as Duo, or built-in tools like Windows Hello for Business.
- Logon auditing — reviewing events 4624/4625 in the Security log once a week shows who is trying to log in, and from where.
Check yourself
Open the Security log and filter events 4625 (failed logon) for the past 24 hours. If there are hundreds, the port is the default and IPs aren’t restricted. After steps 1 and 3, there should be zero.
If you’re just planning a Windows server, the Windows VPS with RDP page has configurations and answers to licensing questions. Help with firewall and port setup is free — just message support.
We’ll pick a configuration, calculate the cost and migrate your project for free.