DashRDP
RDP

How to Block Unauthorized RDP Access with Windows Firewall

Protect your Windows server from automated RDP brute-force attacks. Whether you buy Windows RDP for business or personal use, learning how to restrict Remote...

How to Block Unauthorized RDP Access with Windows Firewall
5 min read

Last updated on July 24, 2026

Share this article

Protect your Windows server from automated RDP brute-force attacks. Whether you buy Windows RDP for business or personal use, learning how to restrict Remote Desktop access to specific IP addresses using Windows Defender Firewall helps secure your server without installing any third-party tools.

Every exposed RDP port is a target for brute-force attacks and unauthorized logins. According to official cybersecurity guidance from the Cybersecurity and Infrastructure Security Agency (CISA), properly restricting remote access tools and locking down exposed management ports is one of the most effective ways to protect networks against initial access exploits.Β 

Instead of relying on passwords alone, you can use the built-in Windows Firewall to block all RDP traffic except from IP addresses you specifically allow. This step-by-step tutorial covers the full setup from opening the firewall console to applying your whitelist.

Log Into Your Server Through Remote Desktop

First things first make sure you’re already connected to your server via RDP before you start changing firewall rules. You don’t want to accidentally lock yourself out while making changes.

Open the Remote Desktop Connection app on your local PC (you can search for mstsc in the Start menu), type in your server’s IP address, and connect with your admin account. If you plan to buy Windows RDP setups for additional projects, applying these security configurations from day one will keep every instance protected. 

Once you’re in, you’re ready to move forward.

Step 2: Open Windows Defender Firewall

On your server, hit the Windows key and type “Windows Defender Firewall” in the search bar. You’ll see it come up under the search results click on it to open the firewall control panel.

Step 3: Go to Advanced Settings, Then Inbound Rules

On the left side of the firewall window, you’ll see a link that says “Advanced settings” click on it. This opens the full firewall management console where you can work with individual rules.

Once the advanced console opens, click on “Inbound Rules” in the left pane. This is where all the rules that control incoming traffic live.

Step 4: Find the Remote Desktop Rule

You’ll now see a long list of firewall rules in the centre panel. Scroll down (or click the “Name” column to sort alphabetically) and look for this one:

Step 5: Open the Rule Properties and Go to the Scope Tab

Double-click on the rule to open its properties window. You’ll see several tabs at the top General, Programs and Services, Protocols and Ports, Scope, and so on.

Click on the “Scope” tab. This is the one we need. It controls which IP addresses are allowed to use this rule.

Step 6: Switch to “These IP Addresses” Under Remote IP

On the Scope tab, look at the bottom section labeled “Remote IP address.” By default, it’s set to “Any IP address” which means anyone on the internet can try to connect.

Change it to “These IP addresses” by clicking that radio button. This tells the firewall to only allow RDP connections from the addresses you manually add.

Click the “Add” button below the empty IP list. A small dialog box will pop up asking for an IP address.

Step 7: Add Your IP Address

A small dialog box will pop up asking for an IP address. Enter your public IPv4 address and click OK. If you need to allow multiple IPs (for example, your office and your home), click Add again and enter each one separately.

Not sure what your IP is? Open a browser on the computer you want to allow access from and go to https://ipinfo.io your public IP will be right at the top of the page

Step 8: Apply and Save

Once you’ve added all the IP addresses you need, take a second to double-check the list. Make sure your current IP is in there.

  1. Click OK to close the Add dialog (if still open)
  2. Click Apply in the properties window
  3. Click OK to close the properties window
  1. Click Apply in the properties window
  2. That’s really all there is to it. Five minutes in the Windows Firewall and your server is no longer visible to every scanner on the internet. Only the IP addresses you’ve approved can even attempt to connect.
  3. It’s one of the simplest and most effective things you can do to protect a Windows server, and it doesn’t cost a thing.

To keep your remote workspace secure, keep these guidelines in mind:

  • πŸ”’ Regularly review your IP whitelist: Remove old IP addresses that are no longer needed and add new ones as your locations change.
  • πŸ”’ Handle Dynamic IPs carefully: If your home or office ISP changes your public IP frequently, you may get locked out. Consider using a static IP or a corporate VPN with a fixed exit IP to avoid this.
  • πŸ”’ Secure UDP traffic as well: There is a companion rule in the Inbound Rules list called Remote Desktop – User Mode (UDP-In). Go back and apply the exact same IP scope restrictions to this rule to completely secure your RDP port.
  • πŸ”’ Keep Windows updated: Whitelisting is incredibly powerful, but keeping your operating system updated ensures any newly discovered security vulnerabilities in Remote Desktop are patched.
Will this disconnect me immediately?

No. Your current RDP session stays active. The restriction only applies to new incoming connections. Just make sure your IP is whitelisted before you disconnect.

Can I add more IPs later?

Absolutely. Go back to the same rule, open the Scope tab, and click Add to include new addresses. You can also remove old ones the same way.

What if I’m using a VPN?

Whitelist your VPN’s exit IP address instead of your home IP. This way, you connect to the VPN first, then RDP to the server through the VPN’s fixed IP.

Share this article