How to Change the RDP Port on Windows - V2 Cloud

How to Change the RDP Port on Windows

March 18, 2025

Summarize: ChatGPT Perplexity

Remote Desktop Protocol (RDP) allows secure remote access to Windows computers and servers. By default, it uses port 3389, a well-known port that can make your system vulnerable to attacks.

Hackers often target this default port, so changing it can add a layer of security, helping to obscure your RDP connection from automated scans.

This guide will walk you through the steps to change the RDP port on Windows, enhancing the security of your remote connections.

 

IN THIS GUIDE

Why Change the RDP Port?

Step-by-Step Guide to Changing the RDP Port in Windows

Configuring Firewall Rules for the New RDP Port

Elevate Your Remote Desktop Security with V2 Cloud

 

WordPress Table of Contents by Topic

 

 

Why Change the RDP Port?

Changing the RDP port can greatly improve your system’s security.

When RDP uses the default port (3389), it’s an easy target for automated scans and hacking attempts. Attackers look for this default port to exploit vulnerabilities or perform brute-force attacks to gain unauthorized access.

Switching to a non-standard port reduces the visibility of your RDP service, making it harder for malicious actors to find. Security experts recommend using ports between 49152 and 65535, as these are less likely to conflict with other services.

While changing the port won’t stop all potential threats, it adds a useful layer of obscurity and reduces exposure. Combined with other security practices, like strong passwords and VPNs, it can help secure your remote desktop access against unauthorized access.

 

Step-by-Step Guide to Changing the RDP Port in Windows

Here’s a detailed guide to help you change the default RDP port in Windows. This involves editing the Windows Registry, so take care with each step, as incorrect changes can affect system functionality.

Before you begin, ensure you have physical or remote access to the computer you want to configure.

It’s also a good practice to back up your registry first. To back up the registry, open the Registry Editor, go to File > Export, and save a copy. This backup can be used to restore settings if any issues arise.

 

 

Step 1: Access the Registry Editor

  • Open the Run Dialog: Press WIN + R to open the Run dialog.
  • Launch the Registry Editor: Type regedit and press Enter. This opens the Windows Registry Editor, where system settings can be viewed and modified.
  • Accept User Access Control (UAC): If prompted, select Yes to allow changes, as Administrator access is required.

Note: The Registry Editor is a powerful tool. Avoid making changes to keys unless you understand their function.

 

Background Image

Step 2: Locate the RDP Port Configuration Key

  • Navigate to the RDP-Tcp Key: In the Registry Editor, use the left navigation pane to locate the following path:
    • HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Terminal Server\WinStations\RDP-Tcp
  • This folder (RDP-Tcp) holds the configuration for RDP settings, including the default port value.

Tip: Expand each folder in the path until you reach RDP-Tcp.

 

Background Image

Step 3: Modify the PortNumber Entry

  • Find the PortNumber Value: Once inside the RDP-Tcp key, look for a registry entry called PortNumber. This is the setting that defines the current RDP port.
  • Edit the Port Number:
    • Double-click on the PortNumber entry.
    • A dialog box will open. Select the Decimal option, as this allows you to input the port number directly in decimal format, which is easier to understand than hexadecimal.
    • Choose a New Port Number: Enter a port number between 49152 and 65535 (e.g., 33091). This range is less likely to conflict with other services.
  • Save Changes: Click OK to save the new port setting.

Important: Avoid using ports that are already in use by other applications to prevent conflicts.

 

Background Image

Step 4: Apply and Confirm the Changes

  • Restart the RDP Services: To make the change take effect without rebooting, restart the Remote Desktop Service. Here’s how:
    • Open Command Prompt as Administrator. You can do this by typing cmd in the Windows search bar, right-clicking on Command Prompt, and selecting Run as administrator.
    • In Command Prompt, type the following command to restart the RDP service: ‘net stop termservice && net start termservice’
    • This will stop and restart the Terminal Services (RDP) service.
  • Reboot Option: Alternatively, you can restart the computer to fully apply the changes, which may be more straightforward.

Note: Restarting the RDP service will disconnect any active RDP sessions, so save your work before proceeding.

 

Step 5: Verify the New Port Configuration

  • Test the Remote Desktop Connection: To verify that the new port is active, try connecting to the computer using the new port in your Remote Desktop client.
    • Format the IP or hostname with the new port in this format: IP_address:new_port (e.g., 192.168.1.1:33091).
  • Check if the Port is Listening:
  • In Command Prompt, enter the following command to confirm that the new port is open and listening: netstat -an | find “<new_port_number>"
  • Replace <new_port_number> with the port you set in Step 3. This command will show if the port is actively listening for connections.

Troubleshooting: If you’re unable to connect, verify that the firewall is configured to allow inbound traffic on the new port. This can often be the cause if the connection fails.

 

Background Image

Configuring Firewall Rules for the New RDP Port

After changing the RDP port, it’s essential to update your Windows Firewall settings to allow incoming connections on the new port. Without this step, your firewall may block remote desktop traffic, making it impossible to connect remotely.

 

Step 1: Open Windows Firewall with Advanced Security

  • Access Firewall Settings: Open the Start menu, type Windows Defender Firewall, and select Windows Defender Firewall with Advanced Security.
  • This will open the Advanced Security console, where you can create custom rules for network traffic.

 

Step 2: Create a New Inbound Rule for the RDP Port

  • Navigate to Inbound Rules: In the left sidebar, click on Inbound Rules. This section contains all rules governing incoming traffic.
  • Create a New Rule:
    • Click New Rule… in the right-hand Actions pane.
    • Select Rule Type: In the New Inbound Rule Wizard, choose Port and click Next.
  • Specify the New Port:
    • Choose TCP and select Specific local ports.
    • Enter the new port number you chose for RDP (e.g., 33091) and click Next.
  • Set the Action:
    • Choose Allow the connection and click Next. This will allow inbound connections on this port.
  • Choose Profile:
    • Select the network profile(s) where this rule applies (Domain, Private, or Public). Typically, select all three unless you have specific requirements.
    • Click Next to proceed.

 

Step 3: Name and Save the Rule

  • Add a Name and Description:
    • Enter a descriptive name for the rule, such as RDP New Port 33091.
    • Optionally, add a description for easy identification in the future.
  • Click Finish to save the rule.

Important: Ensure that the port number matches the one set in the Registry Editor. An incorrect port in the firewall rule will prevent RDP from connecting.

 

Step 4: Verify the Firewall Rule

  • Test the Connection: After setting up the firewall rule, test the RDP connection using the new port (e.g., 192.168.1.1:33091). If the firewall rule is configured correctly, you should be able to connect.
  • Check for Connectivity Issues: If the connection fails, double-check that the rule is active and correctly configured to allow TCP traffic on the specific port.

 

Additional Security Tip

If this computer is accessible via the internet, consider limiting the IP addresses allowed through this rule to trusted sources only. This minimizes exposure and adds a layer of protection to your remote desktop setup.

Updating the firewall ensures your RDP connection on the new port is accessible and secure. In the next section, we’ll discuss additional security measures to strengthen your RDP setup further.

 

Elevate Your Remote Desktop Security with V2 Cloud

Changing the RDP port is a great first step, but it’s just one part of a strong remote desktop security strategy. V2 Cloud takes remote access security to the next level, offering a cloud-based virtual desktop solution that prioritizes both security and simplicity.

V2 Cloud provides a secure, managed Virtual Desktop Infrastructure (VDI) that allows users to access their desktops from anywhere. Here’s how V2 Cloud makes your remote desktop experience better:

  • Advanced Security Features: Unlike standard RDP, V2 Cloud protects your data with built-in security measures, including two-factor authentication (2FA), automated backups, and private network access, significantly reducing the risk of unauthorized access.
  • No Manual Configuration: With V2 Cloud, you don’t need to worry about configuring ports, firewalls, or other complex security settings. V2 Cloud’s infrastructure is managed by security experts, ensuring you’re protected from the latest threats without additional setup.
  • Seamless Access and Performance: V2 Cloud’s VDI is optimized for high performance, so you can work without interruptions or slow load times. The platform is designed for ease of use, with a smooth, reliable experience that’s accessible from any device.

 

Ready to Upgrade Your Remote Desktop Security?

If you’re looking to simplify and secure remote desktop access, try V2 Cloud. Talk to a Cloud Expert Now and experience the benefits firsthand.

Enjoy unmatched security, easy management, and a seamless remote desktop experience—all backed by a team dedicated to helping you stay secure and productive.

Talk to a Cloud Expert Today and see why V2 Cloud is the preferred choice for businesses seeking secure, hassle-free remote desktop solutions.

You might also like...

Back to top

Still have questions?

Let us help you find the solution that fits your business.

Schedule a call
Your V2 CloudCare team — real people, on the line.
On a call now34s avg. pickup
SL FC AR MK +6

Your V2 CloudCare team — real people, on the line.