Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

A Remote Desktop Gateway (RD Gateway) lets users reach internal Remote Desktop Services (RDS) resources over an encrypted internet connection without first connecting through a VPN. To set one up, install the RD Gateway role service, assign a trusted certificate for the public gateway name, open the required network ports, define who can connect and to which computers, then configure users’ Remote Desktop clients. The gateway is the access path; it does not create a remote PC, session host, or published desktop for users to connect to.

Decide whether you need a gateway or a full RDS deployment

RD Gateway is a Windows Server role in Remote Desktop Services. It can run on a physical or virtual machine in an on-premises, cloud, or hybrid environment. Its job is to provide the secure route into RDS resources; a separate remote computer, session host, or published resource must exist behind it. Microsoft describes the role in its Remote Desktop Gateway deployment guidance.

If you already have remote resources and need to make them reachable through a gateway, use the role-only setup below. For a new session-based RDS deployment, add the gateway through Server Manager under Remote Desktop Services > Overview > + RD Gateway, then configure its certificate and deployment properties as part of that broader deployment.

Prepare the gateway name, certificate, and network

Choose the external DNS name

Choose the fully qualified domain name (FQDN) users will enter, such as rdg.example.com, and configure public DNS to resolve it to the gateway’s public endpoint. Use the same name on the certificate. A certificate-name mismatch is not a normal warning to dismiss: it can indicate that the client is not reaching the server it expects.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Obtain a certificate clients trust

For a gateway intended to be available publicly, Microsoft recommends a publicly issued certificate. If you use a certificate issued by a private certificate authority (CA), ensure its issuing chain is installed and trusted on every client that will connect. The certificate helps clients verify the gateway’s identity and protects against interception; see Microsoft’s certificate guidance for Remote Desktop Services.

Have the certificate as a PFX file and know its password before configuration. The certificate’s subject name or applicable subject alternative name must match the external FQDN users enter.

Plan the firewall rules

Allow inbound TCP 443 and UDP 3391 to the gateway for the documented design. Check the perimeter firewall and, if the server is hosted in a cloud environment, the applicable security group, network ACL, or equivalent network rules. TCP 443 carries HTTPS transport; UDP 3391 supports the related transport path.

Install the RD Gateway role service

  1. Sign in to the Windows Server that will host the gateway with an account in the local Administrators group or an account with equivalent permissions.

    Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  2. Confirm that Remote Desktop Services is installed, as required by Microsoft’s role-only procedure.

  3. In Server Manager, start the role and feature installation workflow, select the Remote Desktop Services role, and choose the Remote Desktop Gateway role service. Complete the wizard and allow any required supporting components to be installed.

Microsoft’s walkthrough is titled Deploy Remote Desktop Gateway role for Remote Desktop Services. Follow the prompts shown by your installed Windows Server version; labels can vary slightly between releases.

Import the certificate in RD Gateway Manager

  1. Open Server Manager > Tools > Remote Desktop Services > Remote Desktop Gateway Manager.

    Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  2. In the left pane, select the gateway server, open its context menu, and choose Properties.

  3. Open the SSL Certificate tab, choose the option to import a certificate, browse to the PFX file, and enter its password when prompted.

  4. Apply the change and verify that the certificate shown for the gateway is the intended one and matches the public FQDN.

Set who can connect and which resources they can reach

A successful role installation does not by itself define a complete access policy. Configure the gateway’s connection authorization policy (RD CAP) to determine which users or groups may connect through it, and its resource authorization policy (RD RAP) to define which internal computers those users may reach. Align those policies with your organization’s user permissions and network design rather than allowing broader access than required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Also confirm that the gateway can reach the intended internal targets and that those targets accept Remote Desktop connections from the gateway. If you are adding the gateway to an existing RDS deployment, review the deployment properties and certificate configuration for that deployment as well.

Configure the Remote Desktop client

Users must specify both the gateway and the destination computer: they are separate settings. In the Windows Remote Desktop client, add or edit the connection and configure its gateway in the client’s gateway settings or Connection Center settings. Enter the gateway’s external DNS name and the account to use for the gateway, then enter the internal PC or other target resource as the remote computer. The exact location of the gateway setting varies by client version.

Optional: add Microsoft Entra MFA through NPS

Multi-factor authentication is an additional design, not a switch in the basic gateway installation. Microsoft’s documented Entra MFA integration uses Network Policy Server (NPS) and the NPS extension on a separate NPS server; Microsoft says not to install the extension on the RD Gateway itself. The gateway uses a central RD CAP store on NPS.

The documented approach requires a working RDS environment, users synchronized from on-premises Active Directory to Microsoft Entra ID and enabled for MFA, and the relevant MFA licensing and user-method setup. Configure the RADIUS relationship and shared secret as described in Microsoft’s RD Gateway and Microsoft Entra MFA integration steps. Microsoft notes that SMS code entry does not work for this RD Gateway scenario; users need an eligible configured phone verification or Microsoft Authenticator approve/deny method. Check current licensing and support requirements before deploying this optional architecture.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Troubleshoot connection failures

The client reports a certificate warning or cannot establish trust

The client cannot reach the gateway

The gateway is reachable, but the target computer is not

  • Review the RD CAP and RD RAP, the connecting user’s permissions, and the target computer’s availability.

  • Check connectivity from the gateway to the internal target and confirm that the target accepts the intended Remote Desktop connection. The fix depends on the organization’s authorization and network policies.

MFA authentication fails

  • Verify the separate NPS server and extension configuration, RADIUS settings and shared secret, user synchronization, MFA enrollment, and the supported verification method for this scenario.

Plan high availability separately

A single gateway is a basic deployment, not a high-availability design. Microsoft documents a separate procedure for adding high availability to the RD Web and Gateway web front. Treat redundancy, traffic distribution, and recovery planning as a distinct architecture decision rather than assuming one installed gateway provides failover.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.