Change the RDP port on Windows Server
Kort antwoord
Change the PortNumber value in the registry under the RDP-Tcp key, open the new port in Windows Firewall, then reboot to apply the change.
Moving RDP off port 3389 cuts down on automated scanning traffic. It isn't a replacement for strong passwords, MFA, and IP restrictions, so use it alongside those, not instead of them.
Change the port
Open the Registry Editor
Press Windows key + R, type regedit, and press Enter.
Navigate to the RDP-Tcp key
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Terminal Server\WinStations\RDP-TcpLocate the PortNumber value.
Modify PortNumber
Right-click PortNumber, select Modify, set the base to Decimal, then enter your chosen port.
If you've already configured the firewall rule for the new port (see below), you can reboot now to apply the change.
Configure the firewall
Open firewall settings
Press Windows key + R, type firewall.cpl, and press Enter.
Go to Advanced Settings
Create a new inbound rule
Right-click Inbound Rules and select New Rule.
Select Port
Choose Port as the rule type, select TCP, and specify your new RDP port.
Allow the connection
Select Allow the connection, choose the applicable network profiles, and give the rule a descriptive name.
Reboot and verify
Reboot the server to apply the registry change, then reconnect using the new port. You can confirm the change took effect with PowerShell:
Get-ItemProperty -Path 'HKLM:\System\CurrentControlSet\Control\Terminal Server\WinStations\RDP-Tcp' -Name PortNumberDisable the old rule
Once you've confirmed the new port works, disable the old firewall rule for port 3389 so it's no longer reachable.