Start typing to search across invoices, services, domains, tickets, and more...
Windows Remote Desktop listens on port 3389 by default, and that port is constantly hit by scanners and brute-force bots. Changing the RDP port is one of the simplest ways to cut down on scans and failed-logon noise. This guide shows how to change the Remote Desktop port on Windows Server 2016 / 2019 / 2022 using the PortNumber registry value or PowerShell, open the new port in Windows Firewall and restart Remote Desktop Services so the change takes effect.
Pick an unused port between 10000 and 65535, for example 33890 or 52025. Confirm on the server that nothing is using it:
netstat -ano | findstr :33890
No output means the port is free. Avoid well-known service ports such as 80, 443, 1433 and 3306, and anything below 1024. The examples below use 33890 — replace it with your own port.
Open PowerShell as Administrator and add inbound TCP and UDP rules for the new port (RDP also uses UDP for faster transport):
New-NetFirewallRule -DisplayName "RDP-TCP-33890" -Direction Inbound -Protocol TCP -LocalPort 33890 -Action Allow
New-NetFirewallRule -DisplayName "RDP-UDP-33890" -Direction Inbound -Protocol UDP -LocalPort 33890 -Action Allow
If you run third-party security software or network-level access control, allow the new port there as well.
The Remote Desktop port is stored in the PortNumber value under HKLM\SYSTEM\CurrentControlSet\Control\Terminal Server\WinStations\RDP-Tcp. Change it with PowerShell:
Set-ItemProperty -Path "HKLM:\SYSTEM\CurrentControlSet\Control\Terminal Server\WinStations\RDP-Tcp" -Name PortNumber -Value 33890
Get-ItemProperty -Path "HKLM:\SYSTEM\CurrentControlSet\Control\Terminal Server\WinStations\RDP-Tcp" -Name PortNumber
Or do the same from CMD with reg:
reg add "HKLM\SYSTEM\CurrentControlSet\Control\Terminal Server\WinStations\RDP-Tcp" /v PortNumber /t REG_DWORD /d 33890 /f
Prefer a GUI? Run regedit, browse to the path above, double-click PortNumber, select "Decimal" and enter the new port.
Restart the TermService service so the new port takes effect. Your current RDP session will drop — that is expected:
Restart-Service TermService -Force
If the service fails to restart, reboot the server with Restart-Computer. Afterwards, confirm the new port is listening:
netstat -ano | findstr :33890
From your local PC, test the new port, then connect in the Remote Desktop client (mstsc) using the IP:port format, e.g. 203.0.113.10:33890:
Test-NetConnection 203.0.113.10 -Port 33890
mstsc /v:203.0.113.10:33890
Once you have confirmed you can log in on the new port, you can disable the default 3389 Remote Desktop firewall rules to reduce exposure:
Disable-NetFirewallRule -Group "@FirewallAPI.dll,-28752"
Log in to the client area → My Products & Services → select the server → Manage and open the VNC console. Check that the firewall rules exist and PortNumber has the expected value, or set PortNumber back to 3389 and restart TermService. If you cannot find the console, open a ticket.
No. If you use an RD Gateway, a bastion host or saved .rdp files, update the port there too.
Yes, the same registry path and commands apply to Windows 10/11 Pro.
Still stuck? Submit a ticket to IMIDC 24/7 technical support with your server IP and the new port and we will help you troubleshoot.