Change the default RDP port on Windows Server by staging a Windows Firewall rule, updating the RDP-Tcp registry value, and reconnecting through the new port. The PowerShell workflow takes about ten minutes and includes a rollback path if the first connection test fails.
Prerequisites
- A supported Windows Server installation with Remote Desktop already enabled. The procedure applies to Windows Server 2016, 2019, 2022, and 2025.
- An active RDP session using a local or domain account with local administrator rights. Keep the VPS control panel’s console or another out-of-band recovery method available in case the new rule is wrong.
- A new unused TCP port. This guide uses
3390; choose another port if a service already owns it. Ports from1024through49151are usually a practical range for a manually assigned service port. - The server’s public IP address or DNS name and a separate computer for testing the new endpoint.
- If you need an administrator-ready Windows environment, see VPSLake Windows RDP hosting.
Step 1: Choose and check the new port
Check the existing listener first so you do not move RDP onto a port already used by another service.
Open Windows PowerShell → Run as administrator and run this block. Replace 3390 with your chosen port before continuing.
$RdpKey = 'HKLM:\SYSTEM\CurrentControlSet\Control\Terminal Server\WinStations\RDP-Tcp'
$CurrentPort = (Get-ItemProperty -Path $RdpKey -Name PortNumber).PortNumber
$NewPort = 3390
[pscustomobject]@{ CurrentRdpPort = $CurrentPort; ProposedRdpPort = $NewPort }
Get-NetTCPConnection -LocalPort $NewPort -ErrorAction SilentlyContinue | Select-Object LocalAddress,LocalPort,State,OwningProcess
The first line of output should show the current port, normally 3389. The final command should return no rows; if it shows a listener, pick another port and run the check again. Windows’ dynamic client port range commonly begins at 49152, so do not blindly choose a number from that range just because it is high.
Step 2: Back up the RDP registry key
The listening port is stored as a registry value, so export that key before changing it.
Run this in the same elevated PowerShell window:
$RdpKey = 'HKLM\SYSTEM\CurrentControlSet\Control\Terminal Server\WinStations\RDP-Tcp'
$BackupPath = Join-Path ([Environment]::GetFolderPath('Desktop')) 'RDP-Tcp-backup.reg'
reg.exe export $RdpKey $BackupPath /y
Get-Item $BackupPath | Select-Object FullName,Length
You should see The operation completed successfully. followed by a file on the administrator’s desktop. Microsoft documents the same listening-port registry location in its Remote Desktop listening-port procedure.
Step 3: Allow the new port through Windows Firewall
Create the firewall exception before restarting RDP; this keeps the new listener reachable as soon as the service comes back.
First identify the network profile used by the server’s active adapter:
Get-NetConnectionProfile | Select-Object InterfaceAlias,NetworkCategory,IPv4Connectivity
For an internet-facing VPS, the value is often Public. Use the exact NetworkCategory returned by your server in $FirewallProfile below. The two rules cover TCP and UDP because modern RDP can use both transports.
$NewPort = 3390
$FirewallProfile = 'Public'
$TcpRule = "RDP custom TCP $NewPort"
$UdpRule = "RDP custom UDP $NewPort"
New-NetFirewallRule -DisplayName $TcpRule -Direction Inbound -Action Allow -Protocol TCP -LocalPort $NewPort -Profile $FirewallProfile -Description 'Remote Desktop custom listening port'
New-NetFirewallRule -DisplayName $UdpRule -Direction Inbound -Action Allow -Protocol UDP -LocalPort $NewPort -Profile $FirewallProfile -Description 'Remote Desktop custom listening port'
The commands should create two enabled inbound allow rules. If the VPS provider exposes a separate perimeter firewall or security-group setting, allow the same TCP and UDP port there as well. The New-NetFirewallRule reference explains the profile, protocol, and address filters used here.
For a private administration network, tighten the rule instead of accepting every source. Add -RemoteAddress TRUSTED_IP_OR_CIDR to each command, using an administrator workstation address or an approved network such as 203.0.113.0/24.
Step 4: Change the RDP port and restart Windows
Write the new number to PortNumber, then reboot so the Remote Desktop service binds to it.
$RdpKey = 'HKLM:\SYSTEM\CurrentControlSet\Control\Terminal Server\WinStations\RDP-Tcp'
$NewPort = 3390
Set-ItemProperty -Path $RdpKey -Name PortNumber -Value ([int]$NewPort)
Get-ItemProperty -Path $RdpKey -Name PortNumber | Select-Object PortNumber
Expected output:
PortNumber
----------
3390
Do not close your current session until the firewall rules are in place and you have recorded the new port. Restart the server when ready; the command will terminate the current RDP session:
Restart-Computer -Force
If you prefer the graphical route, open Windows key + R → regedit, then browse to HKEY_LOCAL_MACHINE → SYSTEM → CurrentControlSet → Control → Terminal Server → WinStations → RDP-Tcp. Open PortNumber, select Decimal, enter the new value, select OK, and restart the server. You still need to create the matching firewall rules from Step 3.
Verify the new RDP endpoint
After the reboot, use the server console if necessary and confirm that the registry and TCP listener agree:
$NewPort = 3390
$RdpKey = 'HKLM:\SYSTEM\CurrentControlSet\Control\Terminal Server\WinStations\RDP-Tcp'
Get-ItemProperty -Path $RdpKey -Name PortNumber | Select-Object PortNumber
Get-NetTCPConnection -LocalPort $NewPort -State Listen | Select-Object LocalAddress,LocalPort,State,OwningProcess
The port value should be 3390, and the listener should report Listen. Next, test from a different computer, not from the server itself:
Test-NetConnection -ComputerName SERVER_IP -Port 3390
Replace SERVER_IP with the public address or DNS name. A successful result includes:
ComputerName : SERVER_IP
RemotePort : 3390
TcpTestSucceeded : True
Open the RDP client with the port appended to the address:
mstsc.exe /v:SERVER_IP:3390
You can also enter SERVER_IP:3390 in the Computer field of Remote Desktop Connection. Leave the original RDP rules alone until this new connection succeeds; changing the registry means nothing is listening on 3389, but those rules may still be useful for other services or a rollback.
Troubleshooting
The new RDP connection times out
The firewall profile, provider firewall, or port may be wrong. From the server console, run Get-NetConnectionProfile, confirm that $FirewallProfile matched the active category, inspect both rules with Get-NetFirewallRule -DisplayName 'RDP custom*', and confirm the upstream firewall allows the port.
TcpTestSucceeded is False, but the registry shows the new value
The Remote Desktop service may not have restarted, or another firewall rule may be blocking the path. Confirm Get-NetTCPConnection -LocalPort 3390 -State Listen returns a listener; if it does not, reboot again from the console and check the Remote Desktop Services service in Server Manager → Tools → Services.
The chosen port is already in use
The check in Step 1 returned another listener. Select a different unused port, update $NewPort in the firewall and registry commands, and test that number before restarting. Do not take over a port used by a web server, database, VPN, or management agent.
PowerShell says Access is denied
The registry and firewall commands require elevation. Close the window, search for Windows PowerShell, choose Run as administrator, and repeat the commands with an account that is a local administrator.
Hardening
- Restrict the new firewall rules to trusted source IP addresses or a VPN rather than exposing RDP to the entire internet.
- Keep Network Level Authentication enabled and use strong, unique administrator credentials. A nonstandard port changes automated scan noise but does not replace authentication or access controls.
- Save the exported registry file somewhere protected, and document the new port in your server inventory and monitoring checks.
- If the migration fails, use the server console to import the backup with
reg.exe import "$env:USERPROFILE\Desktop\RDP-Tcp-backup.reg", recreate the TCP and UDP rules for3389, and reboot.
FAQ
Does changing the RDP port prevent brute-force attacks?
It can reduce the volume of automated scans that target the default port, but it is not a security boundary. Use Network Level Authentication, source-IP restrictions or a VPN, account lockout policies, and monitoring for meaningful protection.
What port should I use instead of 3389?
Choose an unused TCP port between 1024 and 49151 that is not assigned to another application. Check it locally before making the change, and avoid ports reserved for services your server will host later.
Do I need both TCP and UDP firewall rules?
Allowing both on the same custom port lets RDP use either transport when supported. TCP is required for the basic connection; if you intentionally want TCP-only access, create only the TCP rule and confirm that your RDP client works as expected.
Can I connect without changing the RDP client settings?
No. Add the new port to the destination, such as SERVER_IP:3390, or launch mstsc.exe /v:SERVER_IP:3390. A client that uses only the server address will continue trying the default port 3389.