Applies to: Windows Server 2016 to 2025 and Windows 10 and 11 (Remote Desktop)

Remote Desktop (RDP) listens on TCP and UDP port 3389 by default. Moving it to another port cuts down the automated login attempts that target 3389. It is not real protection on its own: strong passwords, account lockout and limiting who can connect matter more. The port number is stored in the registry, and the steps below follow Microsoft’s instructions.

Before you start

  • Pick a free port between 1025 and 65535, for example 3390 or 50123.
  • Make sure you have another way in if something goes wrong. On a Ucartz Windows VPS that is the VNC console in the VPS control panel, or our support team.
  • Add the firewall rule before you restart, or you lock yourself out.

1. Check the current port

Open PowerShell as administrator:

Get-ItemProperty -Path 'HKLM:\SYSTEM\CurrentControlSet\Control\Terminal Server\WinStations\RDP-Tcp' -Name PortNumber

It shows PortNumber : 3389.

2. Allow the new port in Windows Firewall

$port = 50123
New-NetFirewallRule -DisplayName "RDP $port TCP" -Direction Inbound -Action Allow -Protocol TCP -LocalPort $port
New-NetFirewallRule -DisplayName "RDP $port UDP" -Direction Inbound -Action Allow -Protocol UDP -LocalPort $port

Add -Profile Public (or Private, Domain) if you want to limit the rules to one network profile. If there is another firewall in front of the server, open the port there too.

3. Change the port

Set-ItemProperty -Path 'HKLM:\SYSTEM\CurrentControlSet\Control\Terminal Server\WinStations\RDP-Tcp' -Name PortNumber -Value $port

Or in Registry Editor: go to HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Terminal Server\WinStations\RDP-Tcp, open PortNumber, choose Decimal and enter the new port.

4. Restart and connect

Restart the server (Restart-Computer). Then connect with the port after the address: in Remote Desktop Connection enter 203.0.113.10:50123, or server.example.com:50123. Keep your current session open until the new connection works.

5. Clean up

Once the new port works, disable the old rule for 3389, for example with Disable-NetFirewallRule -DisplayGroup "Remote Desktop", or restrict it to your own IP address.

Safer than a new port

  • Allow RDP only from your own IP addresses in the firewall.
  • Use long passwords and an account lockout policy.
  • Keep Windows updated.

Connecting for the first time: how to connect to a Windows VPS with Remote Desktop. Other port numbers: HTTPS and SSL ports.

Official documentation: Microsoft: change the Remote Desktop listening port.

Ucartz services for this topic

  • Hire an expert: engineers per 15 minutes, per hour or per month, with no contract.
  • Server management: on-demand administration, hardening, migrations and monitoring.
Was this answer helpful? 0 Users Found This Useful (0 Votes)