The RDP port is 3389, and Microsoft lists it as both TCP and UDP: its documentation calls TCP and UDP 3389 the standard Remote Desktop Protocol port and notes it can be configured to a different number on the host and client.
The more useful fact is the second port. A Remote Desktop Gateway takes connections on TCP 443, with UDP 3391 for the RDP over UDP transport, and reaches the session hosts on 3389 from inside.
That is how 3389 stops facing the internet without anybody losing remote access. Changing 3389 to another number is the control people reach for first and the one that changes least.
- The RDP port is 3389, listed by Microsoft as both TCP and UDP
- An RD Gateway takes TCP 443 outside and speaks 3389 inside
- UDP 3391 carries RDP over UDP to that gateway
- CISA: disabling RDP blocks initial access and lateral movement
- Changing the port number reduces log noise and not much else
On this page
What uses itWhat actually listens on 3389
What port does RDP use? The RDP default port is 3389. Remote Desktop Protocol is Microsoft's protocol for controlling a Windows computer across a network: the screen travels one way, the keyboard and mouse the other.
The Remote Desktop service on a Windows server or a Windows PC listens on port 3389 by default. A client such as Remote Desktop Connection, mstsc.exe, connects to that RDP port number unless it is told to use another.
Microsoft's own port list for Remote Desktop Services is short about it and precise: TCP and UDP 3389: Standard Remote Desktop Protocol (RDP) port. It can be configured to a different port number on the host and client.
Two things follow from that one line.
It is both protocols, not one. The answer to RDP TCP or UDP is both. The common firewall rule permits TCP 3389 and stops there, which leaves the UDP half unavailable. RDP works over TCP alone; the UDP transport exists because it carries the session better on links where it matters.
The number is configurable, on both ends. Which is the sentence people build a security plan on, and it is worth reading in context: it is a configuration note, not a recommendation.
The rest of a Remote Desktop deployment is not on 3389 at all, and that is the part worth knowing before opening a firewall:
| Component | Port |
|---|---|
| Client to the session host | TCP and UDP 3389 |
| Client to the RD Gateway, from outside | TCP 443 |
| RDP over UDP to the gateway | UDP 3391 |
| Connection Broker to Web Access | TCP 5504 |
| Gateway to the directory, for Kerberos | TCP 88 |
| Gateway to the directory, for LDAP | TCP and UDP 389 |
| Administration by WMI and PowerShell remoting | TCP 5985 |
The other portThe port that should be facing the internet instead
This is the design the question usually needs and rarely gets. The RD Gateway port, not port 3389, is the remote desktop port that belongs on the internet.
A Remote Desktop Gateway sits at the edge and accepts client connections on TCP 443, which Microsoft describes as HTTP including RPC over HTTP over SSL, with UDP 3391 carrying RDP over UDP. Both are configurable in the gateway's management console. From the inside, the gateway reaches the session hosts on the ordinary TCP and UDP 3389.
So the RDP port still exists and it is now an internal port. Nothing on the internet ever speaks to 3389, the edge presents one TLS service, and the gateway authenticates against the directory before a session host is touched at all.
That shape is what CISA is pointing at. Its countermeasure for RDP is blunt about the first option: disabling the Remote Desktop Protocol (RDP) blocks adversary initial access and lateral movement using RDP.
And where it cannot be disabled, the guidance is that RDP should be made accessible to users via a secure virtual private network (VPN) connection after authenticating via multi factor authentication (MFA) or through a zero trust remote access gateway.
Read the second half as a list of three requirements rather than a menu: something in front, an identity check that is not only a password, and no direct path from the internet to the port.
Changing itChanging the port number, and what it is worth
The instructions to change RDP port 3389 are real and easy to find. On a Windows computer the listening port lives in the registry at HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Terminal Server\WinStations\RDP-Tcp, in the PortNumber value, entered in decimal.
Microsoft's own instructions add the two steps people skip: add an inbound firewall rule for the new port, and restart.
What it buys is a quieter log. What it does not buy is protection from anybody who has decided to attack that host, because scanning every port of one address takes seconds and services that scan the whole internet publish what they find.
This is the same argument as moving SSH off port 22, and it lands harder here, because RDP on the internet is a named initial access route for ransomware rather than a source of background noise. A port change that makes the log quiet can also make an exposure feel handled when it is not.
If you change it anyway, change it because you want readable logs, record the new number where the next administrator will find it, and do the rest of the work regardless.
The steps on Windows and Windows Server
Microsoft's procedure for changing the Remote Desktop listening port has four parts.
1. Check the current port. In PowerShell as an administrator, run Get-ItemProperty -Path 'HKLM:\SYSTEM\CurrentControlSet\Control\Terminal Server\WinStations\RDP-Tcp' -name 'PortNumber'. 2. Set the new port. Use Set-ItemProperty on the same path and value.
Or open Registry Editor, select PortNumber, choose Edit, Modify, Decimal, and type the new number. 3. Allow it through Windows Firewall. Create two inbound rules with New-NetFirewallRule, one for TCP and one for UDP, on the new port.
Any other firewall in the path needs the same change. 4. Restart the computer, then connect with the port in the address. Microsoft's example is pc1.contoso.com:3390 typed into Remote Desktop Connection.
Pick a number that no other service on the system uses. Keep a second way in, such as the console, until the new port is confirmed open, because a mistake here removes remote access to the server.
NLANetwork Level Authentication, and why it matters more than the number
What is Network Level Authentication, and why does it matter to the RDP port? It is the one Windows security setting on the host that changes what an unauthenticated stranger can reach, and it is worth more than any amount of moving the port around.
Microsoft describes it plainly: Network Level Authentication (NLA) adds an extra layer of security to Remote Desktop connections. With NLA enabled, users must authenticate themselves before a remote session is established, reducing the risk of unauthorized access. Its recommendation is unambiguous: enabling NLA is recommended for most environments.
Read the middle clause again, because it is the whole point. Before a remote session is established. Without NLA the host builds a session for anybody who connects and asks for credentials inside it, which means the session stack itself is exposed to an unauthenticated caller.
With NLA the authentication happens first and there is nothing to talk to until it succeeds.
The one reason it gets turned off is compatibility. Microsoft names it: if you need to connect from older devices or clients that don't support NLA, you might need to disable this option temporarily.
Temporarily is doing work in that sentence: a setting turned off for one old device stays off for every connection until someone turns it back on, so it belongs on the list of things to check.
Two more things from the same page are worth knowing before enabling Remote Desktop anywhere.
Enabling it opens a port. Microsoft: enabling Remote Desktop opens a port on your PC, making it accessible to devices on your local network. Only enable Remote Desktop on trusted networks.
Administrators get in by default. Microsoft: when Remote Desktop is enabled, members of the Administrators group and any users you specify can connect remotely. So the allow list is never empty, and the group it starts with is the one worth protecting most.
What to doWhat to do about 3389 on a network you run
Is port 3389 secure? On an internal network, behind a gateway, with NLA and multi factor authentication, it is an ordinary Windows service. Open to the internet it is not secure, whatever the password policy says.
Find out what is exposed. Not what the firewall rules say, what answers from outside. An address that answers on port 3389 from the internet is the finding, whatever the intent was.
From another computer, Test-NetConnection <host> -Port 3389 in PowerShell reports whether the TCP port is open. On the server, netstat -an | findstr 3389 shows whether the system is listening.
Put a gateway or a VPN in front of it. Both satisfy the same requirement, which is that the internet does not reach the port. A gateway presents TLS on 443; a VPN presents its own service and puts the client on the inside.
Require more than a password. CISA names multi factor authentication in the same sentence as the VPN for a reason: credentials for RDP are bought and sprayed, and a password alone is the control that fails.
Restrict who may connect at all. Remote Desktop access limited to named accounts and groups is a smaller target than access limited to whoever can authenticate.
Watch the account lockouts, not just the failures. A slow spray against a handful of accounts produces few failures per account and a pattern that only shows up when the accounts are counted together.
Ask whether the host needs it. CISA's own advice includes eliminating systems running RDP where possible. A server that nobody has connected to interactively in a year does not need the service enabled.
PitfallsWhere people go wrong
Opening TCP only. Microsoft lists TCP and UDP port 3389 together. A rule for one leaves the other half unavailable.
Treating a port change as the fix. It reduces log volume and does not remove the exposure. Anything targeting your host specifically will find the new number.
Exposing 3389 because a VPN is inconvenient. This is the route the ransomware advisories keep naming, which is the whole reason CISA lists disabling it as the first countermeasure.
Forgetting the firewall rule after changing the port. The registry accepts the new number and the host stops answering, which reads as a broken registry edit and is a missing inbound rule.
Assuming the gateway is only for large deployments. It is a role on Windows Server, and one gateway removes 3389 from the internet for every host behind it.
Leaving port 3389 open internally and calling it segmented. Lateral movement is the second thing CISA says disabling RDP blocks. An internal network where every host answers on 3389 is one credential away from all of them.
FAQFrequently asked questions
What port does RDP use?
3389, and Microsoft lists it as both TCP and UDP. Its documentation calls TCP and UDP 3389 the standard Remote Desktop Protocol port and adds that it can be configured to a different port number on the host and client.
Is RDP TCP or UDP?
Both. TCP 3389 carries the session and UDP 3389 carries the accelerated transport. A firewall rule permitting only TCP produces a working connection with the UDP half unavailable.
How do I change the RDP port?
The listening port is the PortNumber value under HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Terminal Server\WinStations\RDP-Tcp, set in decimal. Microsoft's instructions add an inbound firewall rule for the new port and a restart. Both ends can be configured, so the client has to be told the new number too.
Should I change the RDP port?
Only for quieter logs. It does not protect a host from anybody who has targeted it, because a full port scan of one address takes seconds. Put a gateway or a VPN in front of the service instead, which is the change that removes the exposure.
Is port 3389 secure?
The protocol is not the question, the exposure is. CISA states that disabling RDP blocks adversary initial access and lateral movement using RDP, and that where it is needed it should be reached over a VPN with multi factor authentication or through a zero trust remote access gateway. An internet-facing 3389 is the arrangement all of that is written against.
What port does the Remote Desktop Gateway use?
TCP 443 for client connections from outside, described by Microsoft as HTTP including RPC over HTTP over SSL, and UDP 3391 for RDP over UDP. Both are configurable in the gateway management console. Inside, the gateway reaches session hosts on the ordinary 3389.
Can I put RDP behind port 443 without a gateway?
Not meaningfully. Moving the listener to 443 changes the number and not the protocol, so anything scanning for RDP still finds RDP. A gateway is a different service that speaks TLS to the client and RDP to the inside.
What is UDP 3391 for?
RDP over UDP, between an external client and a Remote Desktop Gateway. It is separate from UDP 3389, which is the client to host transport on the inside.
Do I still need 3389 open if I use a gateway?
Internally, yes, between the gateway and the session hosts. Externally, no, and that is the point of the arrangement.
Why does RDP fail after I change the port?
Check the inbound firewall rule for the new port first, then whether the client is still connecting to 3389. Microsoft's own procedure names the firewall rule as a separate step for that reason, and the value is entered in decimal rather than hexadecimal.
What is Network Level Authentication?
A Remote Desktop setting that, in Microsoft's words, adds an extra layer of security: with NLA enabled, users must authenticate themselves before a remote session is established, which reduces the risk of unauthorized access. Without it, the host builds a session first and asks for credentials inside it.
Should Network Level Authentication be enabled?
Yes. Microsoft states that enabling NLA is recommended for most environments. The exception it names is connecting from older devices or clients that do not support NLA, and even then it describes disabling the option as temporary.
What else should I lock down alongside the port?
Who may connect, and with what. Restrict Remote Desktop to named accounts and groups, require multi factor authentication, and watch account lockouts rather than raw failures, because a slow spray across several accounts hides in the per account numbers.
What is the RDP default port, and which port does RD Gateway use?
The RDP default port is 3389, on TCP and also UDP for better performance. The RD Gateway port is TCP 443, with UDP 3391 as an optional transport. RD Gateway wraps RDP in HTTPS, so only 443 needs to be open to the outside, never 3389.
Keep readingRelated concepts
Read next · Identity and access What Is MFA? The control CISA names in the same sentence as the VPN, and the one that survives a stolen password. Open this next16 min- Ports · 12 min What Is a Port Number? What a port number is before any protocol claims one, and how the ranges are divided.
- Ports · 10 min Port 22, and Why Changing It Is Not the Fix People Think The same argument about moving a service off its well known port, made where it started.
- Ports · 10 min Port 1433, and Why SQL Server Is Rarely Only on 1433 The same argument for a database: scope the rule, because moving the number is not protection.