Changing the RDP port
Moving off 3389 removes your server from most automated scans.
Changing the port is not security on its own, but it does remove your server from the untargeted scanning that makes up most login attempts.
Change the registry value
Set-ItemProperty -Path 'HKLM:\SYSTEM\CurrentControlSet\Control\Terminal Server\WinStations\RDP-Tcp' -Name PortNumber -Value 3390
Open the new port first
Add the firewall rule before you restart the service, or you will lock yourself out:
New-NetFirewallRule -DisplayName "RDP 3390" -Direction Inbound -LocalPort 3390 -Protocol TCP -Action Allow
Then restart the service and reconnect using your-ip:3390.
Did this answer your question?
Thanks — noted.