What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Disable Remote Desktop Protocol (RDP) wherever it is not needed, and never leave it directly exposed to the public internet. If staff need remote desktop access, route it through a protected VPN with multifactor authentication (MFA) or a zero-trust remote-access gateway, then limit who can connect, monitor sessions, patch the access path, and restrict movement between network segments.
Why RDP needs more than a strong password
RDP lets users control Windows computers remotely, but an exposed or poorly controlled service can give attackers a route into an organization. The risk does not end at the perimeter: attackers who gain an initial foothold may use RDP to move between internal systems. CISA’s ransomware guidance recommends reducing unnecessary exposure and strengthening access controls, while its advisory on Iranian government-sponsored actors describes RDP being used for lateral movement. CISA StopRansomware Guide · CISA advisory on Iranian government-sponsored actors
RDP hardening lowers risk; it does not by itself prevent ransomware. It belongs alongside incident response planning and tested backups protected from the same accounts and network paths attackers might compromise.
How to harden RDP, in priority order
1. Find every RDP-enabled system and disable what is not needed
Inventory the systems that accept RDP, the people and services that use it, the business reason, and the source networks they connect from. Disable RDP on hosts without a current business requirement, and close unused RDP ports and related services in host firewalls, network firewalls, and cloud security groups. CISA recommends auditing RDP use and disabling unneeded services and ports. CISA StopRansomware Guide
2. Remove direct internet exposure
Check perimeter firewalls, cloud security groups, edge appliances, and external exposure assessments for public access to RDP. Do not publish RDP directly to the internet. CISA’s countermeasure CM0025 says to disable RDP or, when it is needed, make it accessible through a secure VPN after MFA or a zero-trust remote-access gateway. CISA CM0025
#1 Best Overall
Allow access only for explicitly authorized people and approved source networks. A VPN is an access boundary, not a reason to trust every connected device or to allow unrestricted access to the internal network. Keep the VPN or gateway patched, monitored, and configured with narrow access rules. CISA LockBit advisory
3. Require MFA and least privilege
Require MFA at the remote-access boundary. Where supported by the organization’s identity system and policy, use phishing-resistant MFA for privileged and critical accounts. Separate administrator accounts from everyday user accounts, grant only the permissions needed for each task, and remove access for accounts that no longer require it. CISA’s ransomware guidance recommends MFA, separation of administrator and user accounts, and limiting privileged access. CISA StopRansomware Guide
A FIDO2 security key can be one phishing-resistant MFA option when the identity provider and organizational policy support it. It does not make publicly exposed RDP safe, nor does it replace access restrictions, patching, monitoring, or segmentation. CISA visibility and hardening guidance
Recommended Free Tools
4. Limit password guessing and stale access
Set account lockouts after a defined number of failed sign-in attempts, taking operational needs into account so an attacker cannot easily cause a denial of service by deliberately locking out users. Protect remote-access credentials, remove stale accounts, and investigate suspicious authentication activity. CISA specifically recommends account lockouts for systems using RDP. CISA StopRansomware Guide
Rank #3
5. Patch RDP hosts and the surrounding access infrastructure
Keep operating systems, remote-access gateways, VPN devices, and relevant network infrastructure patched and securely configured. Prioritize internet-facing systems and known exploited vulnerabilities. Review configuration changes and turn off unused services and protocols. CISA’s ransomware and LockBit guidance address patching and limiting remote access as part of reducing risk. CISA StopRansomware Guide · CISA LockBit advisory
6. Log access and restrict movement between systems
Collect RDP authentication events and review both failed and successful logons. Look for unusual access times, accounts connecting to multiple hosts, and activity that follows an unexpected session. CISA’s advisory on Iranian government-sponsored actors identifies Windows Event ID 4624 with Logon Type 10 as an example of an RDP logon event. Treat it as a useful signal to correlate with host and network activity—not as proof of compromise on its own. CISA advisory on Iranian government-sponsored actors
Use network segmentation to restrict which systems can initiate RDP sessions to other systems, especially around critical assets. This limits the paths available if an account or host is compromised. CISA’s ransomware guidance discusses segmentation as a measure to impede lateral movement. CISA StopRansomware Guide
Free tools Windows power users keep installed
One-click scans. No signup required.
Rank #4
7. Prepare to contain suspicious access
If you find a suspicious RDP session or sign-in, follow your incident-response process. Identify the accounts and systems involved, contain continued access, and preserve relevant logs for investigation. Pair preventive controls with recovery arrangements and backups that are tested and protected from the credentials and network routes used for routine access. CISA’s ransomware guide covers response, containment, and recovery measures. CISA StopRansomware Guide
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Choose an access design that fits your operations
There is no single commercial product or architecture that CISA identifies as best for every organization. Evaluate the actual controls around your chosen design:
Best Value
- Exposure: Is RDP disabled, directly internet-facing, or reachable only through a controlled gateway?
- Authentication: Is MFA required at the access boundary, with stronger options for privileged accounts where supported?
- Scope: Can access be limited to named users, managed devices, and approved source networks?
- Containment: Can RDP traffic be restricted between network segments and away from critical systems?
- Visibility: Are sign-in attempts and session activity logged, retained, and reviewed?
- Maintenance: Can your team keep the hosts and access infrastructure patched and maintain the access rules and recovery procedures?
CISA’s concise recommendation is to disable RDP when it is unnecessary; when it is needed, provide access through a secure VPN after MFA or through a zero-trust remote-access gateway. CISA CM0025
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

