How to Change the Remote Desktop (RDP) Port on Windows Server
Moving Remote Desktop off the default TCP 3389 is one of the quickest ways to cut the flood of automated login attempts that every public Windows server receives. This guide shows how to change the RDP port on Windows Server 2016, 2019 and 2022 with PowerShell, open the new port in Windows Firewall before switching, and roll back safely through the VNC console if something goes wrong. It works the same on JUSTG cloud servers in Johannesburg, Moscow, Tokyo and Seoul and on JUSTG dedicated servers. Our example uses port 40125 and server IP 203.0.113.10.
Step 1: Pick a free port for Remote Desktop
Choose a number between 1025 and 49151 that no other application uses. Avoid 49152-65535, which Windows reserves as its dynamic range for outgoing connections. Confirm the current RDP port and make sure your chosen port is free (the second command should return nothing):
Get-ItemProperty -Path 'HKLM:\SYSTEM\CurrentControlSet\Control\Terminal Server\WinStations\RDP-Tcp' -Name PortNumber
Get-NetTCPConnection -LocalPort 40125 -ErrorAction SilentlyContinueBefore you start, open the VNC console from the client area (My Products & Services → your server → management/control panel) in another browser tab. If the new port does not work, this is how you get back in.
Step 2: Open the new RDP port in Windows Firewall first
Always allow the new port before changing the registry; otherwise the next restart of Remote Desktop Services locks you out. RDP uses TCP for the session and UDP to improve performance on high-latency links, so create both rules:
$port = 40125
New-NetFirewallRule -DisplayName "RDP custom TCP $port" -Direction Inbound -Protocol TCP -LocalPort $port -Action Allow
New-NetFirewallRule -DisplayName "RDP custom UDP $port" -Direction Inbound -Protocol UDP -LocalPort $port -Action AllowIf you run another firewall in front of the server (for example a hardware firewall on a dedicated server), allow the same port there too.
Step 3: Change PortNumber in the registry and restart TermService
The RDP listener port is stored in the PortNumber value under the RDP-Tcp key. Update it and restart the Remote Desktop Services service. The -Force switch is required because another service (UmRdpService) depends on it:
$port = 40125
Set-ItemProperty -Path 'HKLM:\SYSTEM\CurrentControlSet\Control\Terminal Server\WinStations\RDP-Tcp' -Name PortNumber -Value $port
Restart-Service -Name TermService -ForceStep 4: Connect with IP:port and verify
In the Remote Desktop client, enter the server address followed by a colon and the port. From PowerShell you can test the port and launch the client in one go:
# On the server (VNC console or new RDP session)
Get-NetTCPConnection -LocalPort 40125 -State Listen
# On your PC
Test-NetConnection -ComputerName 203.0.113.10 -Port 40125
mstsc /v:203.0.113.10:40125For IPv6, wrap the address in brackets: [2001:db8::10]:40125. Remember to update any saved .rdp files, password managers and colleagues' bookmarks.
Step 5: Close port 3389 and restrict access
Once you have logged in successfully on the new port, disable the default Remote Desktop rules so that 3389 is no longer reachable, and optionally limit the new rule to your office address range:
# Built-in Remote Desktop rules (language-independent group ID)
Disable-NetFirewallRule -Group "@FirewallAPI.dll,-28752"
# Optional: only allow your own IP to reach the new port
Set-NetFirewallRule -DisplayName "RDP custom TCP 40125" -RemoteAddress 198.51.100.0/24Step 6: Roll back through the VNC console if you are locked out
If you cannot connect on the new port, open the VNC console, log in and restore the default settings:
Set-ItemProperty -Path 'HKLM:\SYSTEM\CurrentControlSet\Control\Terminal Server\WinStations\RDP-Tcp' -Name PortNumber -Value 3389
Enable-NetFirewallRule -Group "@FirewallAPI.dll,-28752"
Restart-Service -Name TermService -ForceRemote Desktop will be back on 3389 within seconds. Then repeat Steps 2-4 carefully, paying attention to typos in the port number and to any external firewall.
FAQ
Do I need to reboot Windows Server after changing the RDP port?
No. Restarting the TermService service is enough. A full reboot also works if the service refuses to restart.
I changed the port but RDP still listens on 3389.
Check whether a Group Policy or a remote management tool rewrites the value, and confirm you edited the RDP-Tcp key, not another WinStation. Run the verification commands from Step 4 again.
Does a custom RDP port affect performance from China or Africa?
No. Latency depends on routing, not on the port number. JUSTG Moscow and Johannesburg servers use China Telecom CN2 GIA, and Tokyo uses China Telecom premium routing, whichever port RDP uses.
If you still cannot reach Remote Desktop after changing the port, submit a ticket to JUSTG technical support with the port you chose and the output of Step 4.