How to secure your Windows RDP server in 2026

The five settings that stop almost every automated attack on a fresh RDP server.

A brand new RDP server starts getting login attempts within minutes of coming online. Almost all of them are automated, and almost all of them are stopped by the same handful of settings.

1. Start with the credentials

The default administrator account is the one every bot tries first. Create a new administrative user, give it a long passphrase, and disable the built-in account.

2. Move RDP off port 3389

Changing the port is not real security on its own, but it removes your server from the untargeted scans that make up most of the noise.

Set-ItemProperty -Path 'HKLM:\SYSTEM\CurrentControlSet\Control\Terminal Server\WinStations\RDP-Tcp' -Name PortNumber -Value 3390

3. Restrict who can reach the port

If you connect from a static address, allow only that address in Windows Firewall. Everything else is refused before it can even try a password.

4. Turn on account lockout

  • Lock accounts after 5 failed attempts.
  • Reset the counter after 15 minutes.
  • Review the security event log weekly.

5. Keep it patched

Enable automatic updates and reboot on a schedule you choose, rather than one an exploit chooses for you.