ESC

Start typing to search across invoices, services, domains, tickets, and more...

Search... Ctrl+K
Windows Server

How to Change the Windows Remote Desktop (RDP) Port: Registry PortNumber, Firewall Rule and PowerShell

5 steps 9 min read 5 views 0
On this page

Windows Remote Desktop listens on port 3389 by default, and that port is constantly hit by scanners and brute-force bots. Changing the RDP port is one of the simplest ways to cut down on scans and failed-logon noise. This guide shows how to change the Remote Desktop port on Windows Server 2016 / 2019 / 2022 using the PortNumber registry value or PowerShell, open the new port in Windows Firewall and restart Remote Desktop Services so the change takes effect.

Order matters: open the new port in the firewall first, then change the port and restart the service. Otherwise the old port stops working, the new one is blocked, and you will only be able to get back in through the VNC console.

Step 1: Choose a new Remote Desktop port

Pick an unused port between 10000 and 65535, for example 33890 or 52025. Confirm on the server that nothing is using it:

netstat -ano | findstr :33890

No output means the port is free. Avoid well-known service ports such as 80, 443, 1433 and 3306, and anything below 1024. The examples below use 33890 — replace it with your own port.

Step 2: Allow the new RDP port in Windows Firewall

Open PowerShell as Administrator and add inbound TCP and UDP rules for the new port (RDP also uses UDP for faster transport):

New-NetFirewallRule -DisplayName "RDP-TCP-33890" -Direction Inbound -Protocol TCP -LocalPort 33890 -Action Allow
New-NetFirewallRule -DisplayName "RDP-UDP-33890" -Direction Inbound -Protocol UDP -LocalPort 33890 -Action Allow

If you run third-party security software or network-level access control, allow the new port there as well.

Step 3: Change the RDP port in the PortNumber registry value

The Remote Desktop port is stored in the PortNumber value under HKLM\SYSTEM\CurrentControlSet\Control\Terminal Server\WinStations\RDP-Tcp. Change it with PowerShell:

Set-ItemProperty -Path "HKLM:\SYSTEM\CurrentControlSet\Control\Terminal Server\WinStations\RDP-Tcp" -Name PortNumber -Value 33890
Get-ItemProperty -Path "HKLM:\SYSTEM\CurrentControlSet\Control\Terminal Server\WinStations\RDP-Tcp" -Name PortNumber

Or do the same from CMD with reg:

reg add "HKLM\SYSTEM\CurrentControlSet\Control\Terminal Server\WinStations\RDP-Tcp" /v PortNumber /t REG_DWORD /d 33890 /f

Prefer a GUI? Run regedit, browse to the path above, double-click PortNumber, select "Decimal" and enter the new port.

Step 4: Restart Remote Desktop Services

Restart the TermService service so the new port takes effect. Your current RDP session will drop — that is expected:

Restart-Service TermService -Force

If the service fails to restart, reboot the server with Restart-Computer. Afterwards, confirm the new port is listening:

netstat -ano | findstr :33890

Step 5: Connect to Remote Desktop on the new port

From your local PC, test the new port, then connect in the Remote Desktop client (mstsc) using the IP:port format, e.g. 203.0.113.10:33890:

Test-NetConnection 203.0.113.10 -Port 33890
mstsc /v:203.0.113.10:33890

Once you have confirmed you can log in on the new port, you can disable the default 3389 Remote Desktop firewall rules to reduce exposure:

Disable-NetFirewallRule -Group "@FirewallAPI.dll,-28752"
Double-check that your custom 33890 rules are active and working before disabling the defaults. A non-standard port only reduces scanning; keep using strong passwords and an account lockout policy.

FAQ

I changed the port and now RDP will not connect.

Log in to the client area → My Products & Services → select the server → Manage and open the VNC console. Check that the firewall rules exist and PortNumber has the expected value, or set PortNumber back to 3389 and restart TermService. If you cannot find the console, open a ticket.

Do I need to change anything else?

No. If you use an RD Gateway, a bastion host or saved .rdp files, update the port there too.

Does this work on Windows 10/11?

Yes, the same registry path and commands apply to Windows 10/11 Pro.

Still stuck? Submit a ticket to IMIDC 24/7 technical support with your server IP and the new port and we will help you troubleshoot.

Was this answer helpful?

Related Tutorials