What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Disable Remote Desktop Protocol (RDP) wherever it is not needed, and never leave it directly exposed to the public internet. If staff need remote desktop access, route it through a protected VPN with multifactor authentication (MFA) or a zero-trust remote-access gateway, then limit who can connect, monitor sessions, patch the access path, and restrict movement between network segments.

Why RDP needs more than a strong password

RDP lets users control Windows computers remotely, but an exposed or poorly controlled service can give attackers a route into an organization. The risk does not end at the perimeter: attackers who gain an initial foothold may use RDP to move between internal systems. CISA’s ransomware guidance recommends reducing unnecessary exposure and strengthening access controls, while its advisory on Iranian government-sponsored actors describes RDP being used for lateral movement. CISA StopRansomware Guide · CISA advisory on Iranian government-sponsored actors

RDP hardening lowers risk; it does not by itself prevent ransomware. It belongs alongside incident response planning and tested backups protected from the same accounts and network paths attackers might compromise.

How to harden RDP, in priority order

1. Find every RDP-enabled system and disable what is not needed

Inventory the systems that accept RDP, the people and services that use it, the business reason, and the source networks they connect from. Disable RDP on hosts without a current business requirement, and close unused RDP ports and related services in host firewalls, network firewalls, and cloud security groups. CISA recommends auditing RDP use and disabling unneeded services and ports. CISA StopRansomware Guide

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

2. Remove direct internet exposure

Check perimeter firewalls, cloud security groups, edge appliances, and external exposure assessments for public access to RDP. Do not publish RDP directly to the internet. CISA’s countermeasure CM0025 says to disable RDP or, when it is needed, make it accessible through a secure VPN after MFA or a zero-trust remote-access gateway. CISA CM0025

Allow access only for explicitly authorized people and approved source networks. A VPN is an access boundary, not a reason to trust every connected device or to allow unrestricted access to the internal network. Keep the VPN or gateway patched, monitored, and configured with narrow access rules. CISA LockBit advisory

3. Require MFA and least privilege

Require MFA at the remote-access boundary. Where supported by the organization’s identity system and policy, use phishing-resistant MFA for privileged and critical accounts. Separate administrator accounts from everyday user accounts, grant only the permissions needed for each task, and remove access for accounts that no longer require it. CISA’s ransomware guidance recommends MFA, separation of administrator and user accounts, and limiting privileged access. CISA StopRansomware Guide

A FIDO2 security key can be one phishing-resistant MFA option when the identity provider and organizational policy support it. It does not make publicly exposed RDP safe, nor does it replace access restrictions, patching, monitoring, or segmentation. CISA visibility and hardening guidance

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

4. Limit password guessing and stale access

Set account lockouts after a defined number of failed sign-in attempts, taking operational needs into account so an attacker cannot easily cause a denial of service by deliberately locking out users. Protect remote-access credentials, remove stale accounts, and investigate suspicious authentication activity. CISA specifically recommends account lockouts for systems using RDP. CISA StopRansomware Guide

5. Patch RDP hosts and the surrounding access infrastructure

Keep operating systems, remote-access gateways, VPN devices, and relevant network infrastructure patched and securely configured. Prioritize internet-facing systems and known exploited vulnerabilities. Review configuration changes and turn off unused services and protocols. CISA’s ransomware and LockBit guidance address patching and limiting remote access as part of reducing risk. CISA StopRansomware Guide · CISA LockBit advisory

6. Log access and restrict movement between systems

Collect RDP authentication events and review both failed and successful logons. Look for unusual access times, accounts connecting to multiple hosts, and activity that follows an unexpected session. CISA’s advisory on Iranian government-sponsored actors identifies Windows Event ID 4624 with Logon Type 10 as an example of an RDP logon event. Treat it as a useful signal to correlate with host and network activity—not as proof of compromise on its own. CISA advisory on Iranian government-sponsored actors

Use network segmentation to restrict which systems can initiate RDP sessions to other systems, especially around critical assets. This limits the paths available if an account or host is compromised. CISA’s ransomware guidance discusses segmentation as a measure to impede lateral movement. CISA StopRansomware Guide

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

7. Prepare to contain suspicious access

If you find a suspicious RDP session or sign-in, follow your incident-response process. Identify the accounts and systems involved, contain continued access, and preserve relevant logs for investigation. Pair preventive controls with recovery arrangements and backups that are tested and protected from the credentials and network routes used for routine access. CISA’s ransomware guide covers response, containment, and recovery measures. CISA StopRansomware Guide

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Choose an access design that fits your operations

There is no single commercial product or architecture that CISA identifies as best for every organization. Evaluate the actual controls around your chosen design:

  • Exposure: Is RDP disabled, directly internet-facing, or reachable only through a controlled gateway?
  • Authentication: Is MFA required at the access boundary, with stronger options for privileged accounts where supported?
  • Scope: Can access be limited to named users, managed devices, and approved source networks?
  • Containment: Can RDP traffic be restricted between network segments and away from critical systems?
  • Visibility: Are sign-in attempts and session activity logged, retained, and reviewed?
  • Maintenance: Can your team keep the hosts and access infrastructure patched and maintain the access rules and recovery procedures?

CISA’s concise recommendation is to disable RDP when it is unnecessary; when it is needed, provide access through a secure VPN after MFA or through a zero-trust remote-access gateway. CISA CM0025

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.